Privacy Policy
Last updated 23 September 2026
This policy covers the Riff website and the Riff Android app (com.riff.app). Both are the same product and share one account and one database, so everything here applies equally to whichever you use.
Who we are
Riff is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For anything about your data, contact support@soundring.io.
What we collect
You give us
- Account: email address and a password. Passwords are stored only as a bcrypt hash — we never hold the password itself and cannot read it.
- Profile: artist/stage name, genres and country, if you provide them.
- Your work: assignment submissions, uploaded files and images, project boards and cards, comments, Studio records (merch, gigs, finances, fans, bookings, goals), and community threads and posts.
- AI Coach messages: what you write to the coach, and a memory summarised from it.
- Two-factor secret: if you enable 2FA.
Created as you use Riff
- Course enrolments, lesson progress, quiz attempts, XP, levels, streaks, badges, missions and certificates.
- Product analytics events — which actions you took and when — used to run features such as streaks, quotas and the leaderboard.
- The referral tag on the link that brought you to Riff, and the date you last used it.
If you connect them
- Social platform accounts (Spotify, YouTube, Facebook, Instagram, TikTok, X) for the audit feature. Access tokens are encrypted before storage.
The Android app collects nothing on its own. It has no advertising identifier, no analytics SDK and no location, contacts or microphone access. It asks only for notification permission, and for access to a file or the camera at the moment you choose to upload something.
Why we use it
- To give you an account and keep you signed in.
- To deliver the courses, track your progress and issue certificates.
- To run features you ask for — the AI coach, audits, boards, Studio tools and the leaderboard.
- To take payment for a paid plan and give you the right level of access.
- To keep the community safe, by acting on reports and blocks.
- To keep the service secure — rate limiting and abuse prevention.
We do not sell your personal data, and we do not use it for advertising or share it with data brokers.
Who we share it with
Only the providers needed to run the service:
- Render — hosting and the database.
- Stripe — payments. Stripe handles your card details directly; card numbers never reach Riff.
- DeepSeek — the AI model behind the coach and assignment feedback. Messages you send to the coach, and assignment text you submit for review, are sent to this provider to generate a reply.
- Social platforms — only those you explicitly connect, and only to read the audit data you asked for.
We may also disclose data where the law requires it.
Keeping it safe
- All traffic is encrypted with HTTPS. The Android app refuses unencrypted connections outright.
- Passwords are hashed with bcrypt and are never recoverable in plain text.
- Social access tokens are encrypted before they are stored.
- Your session is held in a cookie that page scripts cannot read, and the app stores no copy of your password.
How long we keep it
For as long as your account exists. When you delete your account it is erased immediately, other than encrypted database backups that age out within 30 days, and payment records Stripe must retain to satisfy tax and accounting law.
Your choices
- Delete your account at any time from Settings — see how to delete your account.
- Disconnect a social account at any time from the audit screen.
- Turn off notifications in your device settings.
- Depending on where you live you may also have the right to access, correct, export or restrict use of your data. Email us and we will action it.
Children
Riff is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Changes
If this policy changes materially we will update the date above and let you know in the app before the change takes effect.