Draft — pending legal review
Privacy Policy
Last updated 29 September 2026
Riffina is an AI music creation app. You write lyrics, pick a style and an engine, and AI engines make the song. This page explains, in plain words, what we collect, why, who helps us run Riffina, and how to delete it all.
Who we are
Riffina is run by Vittoria London, an individual. [TO CONFIRM: legal entity name and postal address]
For anything about your data, email support@riffina.com. For people in the EU, we are the “controller” of your personal data under the GDPR. [TO CONFIRM: EU representative, if one is required]
This policy covers the Riffina website and studio at riffina.com, the iPhone and iPad app, and the Android app when it launches.
What we collect
- Account details. Your email address and password. Sign-in is handled by Supabase Auth, which stores your password in hashed form.
- Age confirmation. When you sign up you confirm you are 13 or older. We record that you confirmed it, and when.
- What you create. Your lyrics, styles, songs and their versions, the fictional artists you create, and the generated audio files.
- Cloned voices. If you choose to, you can clone a singer’s voice, but only from songs made inside Riffina. You can’t upload voice recordings, and Riffina is not for real people’s voices.
- Reports. If you report a song, we keep the report, the reason you chose and any note you add.
- Credits. A record of credits you receive, use and get refunded.
- Basic server logs. Technical records such as request times, IP addresses and errors, used to keep the service running and secure. [TO CONFIRM: exactly what is logged and for how long]
No ads or analytics yet. Riffina doesn’t currently show ads or use analytics tools. [TO CONFIRM: update this section before adding AdMob, PostHog or similar]
Payments. Paid credits are not on sale yet. When they are, payments will go through Apple and Google in-app purchases and Stripe, and we won’t see your full card details. [TO CONFIRM: payment providers and what data we receive from them]
Why we use it
- To create your account, sign you in, and send account emails (such as sign-up and password reset codes).
- To make your songs: we send your lyrics and style prompts to the music engine you pick.
- To keep your library, artists and voices so you can come back to them.
- To keep track of credits, including automatic refunds when a song fails.
- To review reports, remove content that breaks our rules, and keep Riffina safe.
- To answer you when you contact support.
Under the GDPR, we rely on: providing the service you asked for (contract); keeping Riffina safe and working (legitimate interests); and meeting legal duties (legal obligation). [TO CONFIRM: legal bases, with counsel]
We don’t sell your personal data.
Who helps us run Riffina
These service providers process data for us, only to run Riffina:
- Supabase: database, sign-in and file storage (your account, creations and audio files).
- Resend: sends account emails from no-reply@riffina.com.
- Zoho Mail: our support inbox, support@riffina.com.
- Music engines: Mureka, Google (Lyria, through the Gemini API) and ElevenLabs. The engine you pick receives your lyrics and style prompt so it can generate the audio. Each engine may keep its own copies under its own terms. [TO CONFIRM: each engine’s retention and whether it uses inputs for training]
- Hosting: [TO CONFIRM: hosting provider]
Some of these providers may process data outside the EU. [TO CONFIRM: where each provider stores data, and the safeguards used (such as Standard Contractual Clauses)]
How long we keep it
- Your account and creations: until you delete them or your account.
- Reports you filed: kept after you delete your account, but without your name, so we can keep a record of what was reported and what we did.
- Server logs and the credit record: [TO CONFIRM: retention periods]
Deleting your account
You can delete your account yourself, at any time:
- In the app: open the Me tab and tap Delete account.
- On the web: go to riffina.com/studio/account and use Delete account.
This permanently deletes your account, songs and every version, artists and cloned voices from Riffina. The music engines may keep their own copies of what they made for you; deleting your account doesn’t remove those. Reports you filed are kept without your name.
Can’t sign in? Email support@riffina.com from the address on your account and ask us to delete it. See Support for details.
Your rights
Depending on where you live (including in the EU under the GDPR), you can ask to see, correct, delete or get a copy of your personal data, object to or limit how we use it, and withdraw any consent you gave. Email support@riffina.com and we’ll reply within one month. [TO CONFIRM: response time and identity checks]
If you’re in the EU and unhappy with how we handled your data, you can complain to your local data protection authority. [TO CONFIRM: lead supervisory authority]
Children
Riffina is for people aged 13 and over, and you must confirm your age when you sign up. If we learn that someone under 13 has an account, we’ll delete it. If you think that has happened, email support@riffina.com. [TO CONFIRM: whether a higher minimum age or parental consent is needed in some EU countries]
Security
Your data is sent over encrypted connections, and access to it is limited to what’s needed to run Riffina. No system is perfectly secure, so please use a password you don’t use anywhere else. [TO CONFIRM: security measures, with counsel]
Changes to this policy
If we change this policy, we’ll update the date at the top. If a change is important, we’ll tell you in the app or by email before it takes effect.
Contact
Questions about privacy: support@riffina.com.
