Privacy Policy
Last updated September 6, 2026
Riff is an iOS app and website (tryriff.site) for musicians who record, publish and discover music. This policy explains what we collect when you use Riff, why, who we share it with, and how you can delete it. It is written to be read, not skimmed past. If anything is unclear, email fasai.phl@gmail.com.
What we collect
Your account
An email address and password, or the identity Apple or Google gives us when you use Sign in with Apple or Sign in with Google (a unique identifier and, if you choose to share them, your name and email). We never see your Apple or Google password. Apple’s Hide My Email relay addresses work fine.
Your profile
Your username, profile photo, billboard (title, city, look), the instruments you play or are looking for, the kinds of music you picked during onboarding, and which side of Riff you said you’re here for. Your username and public profile are visible to other Riff users and to anyone with a share link.
What you make
Audio and video you record or import, the mastered versions Riff renders from them, titles, captions, collections, comments, saves and subscriptions. Drafts are private to you. Samples, collections and comments you publish are public: anyone using Riff, and anyone with a share link, can see and play them.
How you use Riff
We log product events so we can see what works: screens opened, samples played, saved, published, onboarding steps, errors, along with a random per-install device identifier, your app version and iOS version. This is analytics for improving Riff. We don’t run ads, and we don’t use advertising trackers.
Diagnostics
If the app crashes or hangs, a crash report (stack trace, device model, OS version, app version) is sent to Sentry so we can fix it.
Notifications
If you allow notifications, we store your device’s push token so we can tell you about activity on your music (a new subscriber, a comment). You can turn notifications off in iOS Settings at any time.
Reports and blocks
When you report content or block someone, we keep that record so we can act on it and keep the block in force.
How we use it
- To run Riff: store and stream your music, show your profile, deliver your feed.
- To shape what you see: the instruments and genres you picked seed your feed.
- To notify you about activity on your music, if you opted in.
- To keep Riff safe: moderation, reports, blocks, abuse prevention.
- To improve Riff: understanding which features people use and where they get stuck.
We do not sell your personal information, and we do not share it for advertising.
Who we share it with
Only the services that run Riff, and only what they need to do their job:
- Supabase hosts our database, file storage and sign-in.
- Apple and Google handle Sign in with Apple and Sign in with Google, and Apple delivers push notifications.
- Sentry receives crash and hang reports.
- Vercel hosts this website.
Content you publish is shared with other Riff users by design. We may also disclose information when the law requires it, or to protect Riff and its users from harm.
How long we keep it
For as long as your account exists. Analytics events and crash reports are kept for up to two years. Reports and block records are kept as long as needed to keep the block in place and to act on abuse.
Deleting your account
In the app, open your page, tap your photo, and choose Delete Account. That removes your profile, drafts, recordings, saves, subscriptions, push tokens and sign-in identity. One exception: a sample you published that other people have built on stays available to them, with your name removed from it. You can also email us and we’ll delete the account for you.
Your choices and rights
- Keep your music private: nothing is public until you publish it, and you can make a published sample private again unless someone has built on it.
- Choose what your profile shows, including whether your subscriber count is visible.
- Ask us for a copy of your data, a correction, or deletion by emailing us. Where you live may give you additional rights (for example under GDPR or the CCPA); we honour them.
Children
Riff is not for children under 13, and we don’t knowingly collect their information. If you think a child has an account, email us and we will remove it.
Security
Data travels over encrypted connections and is stored with access rules that keep private content private. No system is perfect; if we learn of a breach that affects you, we will tell you.
Changes
When this policy changes in a way that matters, we’ll update the date at the top and let you know in the app.
Contact
Riff is operated by Fasai Phuathavornskul. Questions, requests, concerns: fasai.phl@gmail.com.