Privacy Policy
Effective September 9, 2026.
Who runs Riffage
Riffage is operated by David Diefenderfer, based in Florida, United States. For privacy questions or requests, contact support@riffage.app.
Files on your computer
You do not need an account to use the desktop app. Recording and organizing files locally does not upload your library to us. Cloud backup and sharing are optional. The app still sends the diagnostic information described below.
Your account and cloud vaults
When you sign in, we receive account information from Google, including your email address and account identifier. We use this to sign you in, associate your vaults with your account and control access.
When you enable backup, we store the vault's uploaded recordings, lyrics, attachments and library information, such as titles, tags, notes and collections. Shared vaults also include memberships, invitations and comments. We process these to back up your work and make it available to the people you share it with.
Other members can access the content in a shared vault and may see membership and author information, including email addresses. They can download files. Leaving a vault or deleting its cloud copy cannot recall files someone already saved.
Payments and service emails
Stripe processes payments and receives the information you provide at checkout. Riffage stores customer and subscription identifiers, plan status and billing-related account information. We do not receive your full payment card number. Vault names may appear in Stripe checkout, subscriptions and receipts so you can tell projects apart.
We use your email for account-related support, vault invitations, receipts and storage or subscription notices. These are service messages.
App diagnostics and feedback
The app creates a random installation identifier and sends it with launch events, the app version, operating system version and processor architecture. It is not an account identifier, but it lets us recognize reports from the same installation.
Automatic error reports include an error message and a recent section of the app's log. Logs can contain file paths, project names or other information related to what the app was doing. Sending logs manually shares a larger section of the log. Feedback includes what you write, an optional email address and diagnostic context.
We use these reports to understand failures, fix bugs and answer support requests. Diagnostic information is not necessarily anonymous, even when it does not contain your account identifier.
Website visits
The public website sends first-party counts for page visits and download clicks, including the page path, referring site's hostname, download platform and country derived by our hosting provider. These counts do not use advertising cookies or a visitor identifier.
Hosting and security providers receive connection information such as IP addresses when they serve requests. Google sign-in uses its own authentication mechanisms and browser storage. We do not sell personal information or use it for targeted advertising.
Service providers and other disclosures
- Google Firebase and Google Cloud provide sign-in, cloud file and database storage, hosting and diagnostic logging.
- Cloudflare runs our API services, processes website and app metrics, stores feedback and diagnostic uploads, and handles service email delivery.
- Stripe processes payments and manages subscriptions and billing records.
These providers process information needed to supply their services. We may also disclose information when required by law, to protect users and the service from abuse, or as part of a transfer of the business with appropriate notice.
Why we process personal information
We use account, vault and billing information to provide the service you request. Where data protection law requires a legal basis, this is performance of our agreement with you. Our interests in maintaining a reliable, secure service support limited diagnostics, security monitoring and support records. Legal obligations may require us to keep certain billing records. Where consent is required, we ask for it and you can withdraw it.
Retention and deletion
Cloud content is kept while the vault remains available, subject to the storage and deletion policy. In particular, a lapsed Cloud vault that stays over the free limit may have its whole cloud copy deleted after 90 days and warning emails.
Account deletion removes your sign-in account, owned cloud vaults and memberships, and cancels your subscriptions. It does not remove files already saved on your computer or someone else's computer. Deletion may take time to finish.
Billing, security and support records may be retained where needed for accounting, resolving disputes, preventing abuse or meeting legal obligations. Diagnostic log uploads and feedback currently have no automatic deletion schedule. They are stored separately from sign-in accounts, so deleting an account does not automatically remove those records. Contact us about a report you want removed; its date or installation identifier can help us find it.
Location and security
Riffage is operated from the United States. Our providers may process information in the United States and other countries. Where required, international transfers must have the protections required by applicable data protection law.
We use access controls and encrypted connections to protect cloud data. Riffage cloud storage is not end-to-end encrypted. No storage or transmission system can be guaranteed secure.
Your choices and rights
You can use Riffage locally without signing in, choose which vaults to back up, manage shared access, cancel subscriptions and delete your account. Depending on where you live, you may also have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, or complain to your local data protection authority.
Send requests to support@riffage.app. We may verify your identity and will respond within the time required by applicable law. Some requests have legal exceptions, which we will explain if they apply.
Children
Riffage's online services are not directed to children under 13. If you believe a child has provided personal information without appropriate permission, contact us so we can investigate and remove it where required.
Changes
We will update the effective date when this policy changes. For material changes, we will provide additional notice where required, such as in the app or by email.