Privacy
Privacy, plainly.
Last updated 27 July 2026
RIFFLY uses the recordings and files you submit to produce guitar feedback, tab, scoring, and drills.
Audio uploads, generated tabs, scores, drills, anonymous browser IDs, and basic reliability logs may be stored so results can load after refresh and problems can be fixed.
We do not sell personal practice data. Teacher and student workflows stay scoped to the people explicitly using those links, and teacher pages only show roster details to the people using that workspace.
Do not upload copyrighted songs, private lesson recordings, or child/student material unless you have the rights and the appropriate parent, guardian, student, or teacher permission.
Riffly in ChatGPT
When you record or choose a clip in the Riffly ChatGPT plugin, ChatGPT temporarily hosts the selected file so Riffly can retrieve it. Widget recordings are uploaded as temporary files and are not added to your ChatGPT file library by Riffly.
Riffly receives the selected audio, a temporary ChatGPT file reference, and technical request information needed for security and rate limits. Riffly creates a random guest owner and an encrypted take handle; it does not ask ChatGPT for your name, email address, Riffly account, or conversation text for this flow.
The raw clip is processed by Riffly's transcription service and held in private Vercel Blob storage only while analysis runs. It is deleted when analysis completes or fails. A daily cleanup removes abandoned raw clips within 24 hours. OpenAI may process the temporary file as part of ChatGPT; Vercel provides hosting and private storage. If language-model coaching is enabled, it receives derived music findings and prompt text, not the raw recording.
The encrypted result handle expires after 24 hours. The derived draft tab and practice result are automatically deleted from Riffly within 30 days. You can choose Delete this take in the result card to remove the audio, draft tab, coaching result, and guest take immediately.
Anonymous ChatGPT takes are not eligible for model improvement in the current release, and no anonymous training-consent path is active.
What we store and why
- Audio recordings and uploads
- used to produce timing, pitch, draft-tab, and practice feedback. The ChatGPT flow has the shorter deletion schedule explained below; signed-in Riffly sessions may remain available with the account so results can reload.
- Practice, teacher, and student records
- lesson invites, roster state, scores, feedback, and teacher/student follow-up details stay scoped to the people using those links.
- Analytics and diagnostic events
- anonymous browser IDs, route events, performance, and error details help spot reliability problems without selling personal practice data.
- Payments and subscriptions
- when paid plans are available, checkout will show the price, renewal cadence, cancellation path, and payment terms before you pay; RIFFLY stores only the plan and access details needed to honor your subscription.
- Cookie and local storage stance
- essential sign-in, dark-mode, teacher/student continuity, and checkout safety state can be kept in your browser; non-essential tracking should stay off until explicit consent is added.
How model improvement works
Riffly is designed to make model improvement on by default for a policy-eligible adult account only after the applicable lawful-basis assessment, data-protection impact assessment, notice, and separate data gate are approved. Until then, broad default-on training export stays off and general model-improvement candidates stay restricted.
Separately, the current iOS score-review flow lets you mark a score unfair and deliberately choose Share take for review. If you choose it, Riffly records that choice and stores that session audio and scoring context as a score-review candidate for human review. The server keeps it restricted from model training unless it can independently prove adult-account eligibility, current notice, authority, and first-party rights; current one-take submissions do not enter training. Choosing Send receipt only does not share the audio. This one-take review path is active and is not the broader default-on model-improvement program described above.
Default-on is a product preference, not permission by itself. If Riffly cannot establish the current notice, age, territory, authority, or first-party content rights, the data stays restricted from training. Guest, child, classroom, teacher-submitted, public-share, third-party, and rights-uncertain data stays restricted unless a separately approved rule permits it.
If that separately approved data gate is activated, you can object or turn model improvement off without losing scoring, history, or paid product features. An opt-out blocks future training use, excludes retained candidates from future datasets, and queues deletion of ML-only copies. Product practice history remains until you separately delete a take or account.
Data already used in a released model cannot be surgically removed from model weights. Riffly removes it from future training and follows its approved assessment and clean-retraining policy.
Your right to object
Riffly will not rely on legitimate interests for model-improvement processing until its legitimate-interests assessment, data-protection impact assessment, notice, and separate data gate are approved. If the founder pilot is activated on that basis, you can object at any time. Turning model improvement off stops new training use immediately and does not reduce scoring, saved practice history, or paid features.
You can also use the form below to explain an objection or exercise another privacy right. Riffly will respond without undue delay and normally within one calendar month. If more time or identity evidence is genuinely needed, Riffly will explain why.
For signed-in Riffly use, deletion requests should include the account email. For an anonymous ChatGPT take, use Delete this take while its 24-hour handle is active; after that, the automatic 30-day result cleanup still applies.
Joe Ward is the Riffly controller for this founder pilot. Use the form below for access, correction, deletion, restriction, objection, or another privacy question.
Riffly's privacy-request review window is 90 days. After that point the protected queue stops returning the request and deletes it on the next capture or review operation. The form does not send an analytics event.
Send a privacy request
This form goes to Riffly's protected review queue. Add an email Riffly can use to verify your identity and reply. Do not include passwords, payment details, audio, or private files.
