riffgarden
Sign in

The small print

Privacy Policy

Last updated

The short version

  • We collect what the service needs: your email and display name, the music you make, and how the co-producer is used. We do not sell your data.
  • We do not use your music, your projects or your prompts to train AI models.
  • Everything you make is private until you share it. Shared pages show your display name, never your email.
  • Our analytics uses no cookies and does not follow you across sites. We show no ads.
  • When you use the co-producer, part of your project and what you typed go to OpenAI to produce the reply.
  • Our servers are in Germany. We are a US company, and some of our providers are in the US.
  • You can ask for a copy of your data or for it to be deleted at any time.

This summary is here to help. The full text below is what applies.

The privacy of your data, and it is your data, not ours, matters to us. This policy explains what Second Order Ventures LLC ("we") collects when you use Riffgarden, why, who else handles it, where it lives, and what you can do about it. It belongs with our Terms of Service. We never sell your data. We never have, and we never will.

1. What we collect and why

Our guiding principle is to collect only what we need. Here is what that means in practice.

Identity and access

When you sign in with Google or Discord, we receive your email address, your name and an identifier for your account with that provider. We store your email, a display name you can change, and that identifier, so that you can get back into your account and we can reach you about it. We never receive or store your Google or Discord password, and we store no password of our own. We do not sell your personal data, and we will not use your name in marketing without your permission.

Billing information

We do not ask for payment details. Paid plans are not open yet. Before they open, this section will say what we keep: card details will go straight to a payment processor and never touch our servers, and we will keep a record of each payment for invoicing and support.

Product interactions

What you make. Your projects, stored as a history of every edit so that anything can be undone; your patterns, instruments, recipes and arrangements; recordings and their share images; audio you import; stems from the stem splitter; and anything you save to the library. We keep this so the service can do what it is for. If you upload a song to the stem splitter, that upload is deleted as soon as it has been split.

The co-producer. What you ask it, what it answers, the changes it made, and technical records of each request: the model used, the number of tokens, how long it took and what it cost us. We keep these to provide your chat history, to enforce plan limits and to understand our costs.

How you use the service. When you were last active, how many times you have signed in, and the counts that enforce your plan's limits, such as recording minutes and stem splits used this month.

Where you came from. The first time you visit, we note the page you landed on, the site that referred you, and any campaign tags in the link (UTM tags). This sits in a signed first-party cookie for up to 90 days. If you create an account or join a waitlist, it is stored with that record, so we can tell which pages bring people in.

General geolocation data

We log the IP address of your current and previous sign-in, and the time of each, for security and to spot fraud. Our servers also keep short-lived technical logs that include IP addresses. We do not work out where you are from them and we do not build a location history.

Website interactions

We use Umami, which we host ourselves, to count page views and a few named events, such as pressing play on a public page. It sets no cookies, does not follow you across sites, and stores no personal data: it keeps the page, the referring site, the browser and operating system family, the screen size and the country the visit came from, worked out from the IP address, which is not kept. It runs only on the live site.

Anti-bot assessments

We use no CAPTCHA. The contact form has a hidden field that only automated senders fill in, and the contact form, the report form and the stem splitter are rate limited. We have a legitimate interest in keeping the service and the wider internet free of spam and abuse.

Advertising and cookies

We run no advertising, load no advertising scripts and set no third-party cookies. The cookies and browser storage we use are:

  • A session cookie, which keeps you signed in. It is necessary.
  • The first-visit cookie described above: the page you landed on, the referring site and campaign tags, kept for up to 90 days, readable only by us.
  • Your browser's local storage remembers interface preferences, such as the width of a panel. It never leaves your browser.

A cookie is a small piece of text your browser stores. You can block or delete cookies in your browser's settings, but you cannot stay signed in without the session cookie.

Voluntary correspondence

If you write to us through the contact form, we keep the message, the topic you chose, the page you wrote from, and your name and email address (or your account, if you were signed in), so we can answer and so we have a history if you write again. If you report a shared item we store the reason, anything you wrote, and your email address if you chose to give it, or your account if you were signed in. If you join a waitlist we store your email address, what you asked to hear about, anything you wrote, and the page you joined from.

2. Artificial intelligence

The co-producer is powered by an AI model from OpenAI, reached through their API. Each time you ask it something, we send what you typed, a description of the relevant parts of your project as text (its instruments, patterns and settings, including the names you gave them), the recent conversation, your display name and the name of your plan. We do not send your email address or your audio files. OpenAI processes this to produce the reply, under its API data terms, which do not allow it to train models on what is sent.

We do not use your music, your projects or your prompts to train AI models. Please do not type sensitive personal information into the co-producer.

The stem splitter uses an open model (Demucs). It runs either on our own servers or, when we have it set that way, on machines we rent from Replicate for the minutes the split takes (see the list of providers below). Either way the song is deleted once it has been split, and it is never used to train anything.

3. When we access or disclose your information

To provide the service you asked for. We use these providers, each for one job:

  • Google and Discord, when you choose to sign in with them.
  • OpenAI, for the co-producer, as described above.
  • Our hosting and storage providers. The servers that run the service are rented from Hetzner in Germany. Files (imported audio, stems, recordings and share images) are stored with Cloudflare (R2 object storage).
  • Replicate, when you use the stem splitter and we have it set to run on their machines. The song you upload is sent to Replicate to be pulled apart and is deleted from their store within a day; the stems come back to us. Nothing else about you goes with it.
  • Google Fonts. Our pages load their typefaces from Google, which means your browser makes a request to Google and Google sees your IP address when a page loads.
  • Umami, our analytics software, which we host ourselves, so this data stays with us.
  • Sentry, for error reports. When something goes wrong in the app or in your browser we send Sentry the technical details of the error, the page you were on, your IP address and your account id, and in a sample of sessions a replay of what was on screen (never the marketing pages, and never sensitive fields). We use it to fix bugs, and Sentry holds it for a limited time.

To help you, with your permission. If you ask for help with something in your account, a person at Riffgarden may need to look at it. We will ask before we do.

When an automated process stops partway through. Occasionally an error stops a job, such as a stem split or a recording, and fixing it means looking at a minimum of your data. When we can fix it without looking, we do. When we cannot, we look at as little as possible and fix the cause so it does not recur.

To investigate abuse. Looking into an account when a report comes in is a last resort. We want to protect the privacy and safety of the people who use the service and of the people who report problems, and we try to balance the two. If we find the service being used for one of the restricted purposes, we will act, which may include telling the authorities where that is warranted.

Aggregated and de-identified data. We may combine information so that it identifies nobody, and use that for any purpose, such as understanding what the service costs to run or which features are used.

When the law requires it. We are a United States company with servers in Germany. We disclose personal data to a government or a court only when a request is legally binding on us, and we will tell you before we do unless the law forbids it or someone is in immediate danger. We do not hand data over to anyone who merely asks.

If the business changes hands. If Riffgarden is ever sold or merged, which we do not plan, your information may transfer with it. We will tell you well before it becomes subject to a different privacy policy.

4. What is public, and when

Nothing, until you share it. When you share a song or a library item with a link or with everyone, the page shows the item, its title and your display name. Your email address is never shown to anyone. Items shared with everyone may be listed on our public pages and indexed by search engines. Songs that contain imported audio are never listed publicly. Making an item private again removes it from our pages. We cannot remove copies that search engines or other people already made.

5. Your rights with respect to your information

We try to give the same rights to everyone, wherever they live:

  • Right to know. You have the right to know what personal information is collected and how it is used. This policy is our answer.
  • Right of access. You can ask to see the personal information we hold about you and how it is stored, secured and processed.
  • Right to correction. You can ask us to correct it. Your display name you can change yourself in Settings.
  • Right to portability. You can ask for a copy of your personal information in a portable format. Your music you can export as audio from the studio at any time.
  • Right to erasure. You can ask, within the limits of the law, for your personal information to be erased from our systems and from our providers'. You can close your account yourself in Settings; the section on deleting below says exactly what that does and how to have the rest erased too.
  • Right to restrict processing and right to object. You can ask us to stop or limit a particular use of your information, including any sale, although we never sell it.
  • Right not to be subject to automated decisions that have a legal or similarly significant effect on you. We make none. Plan limits are enforced by software, but they are the same for everyone on a plan and change nothing about your legal position.
  • Right to complain. If you are in the European Economic Area or the United Kingdom, you can complain to your data protection authority.
  • Right to non-discrimination. We will not treat you differently for using any of these rights.

For anything you cannot do in Settings, write to [email protected]. We answer within 30 days. We may need to check that the request really comes from you, which usually means writing from the email address on the account or while signed in. If we refuse a request, we will say why and how to appeal.

If you are a California resident: we do not sell or share personal information as those terms are defined in California law.

6. How we secure your data

Connections to the service are encrypted (TLS). Audio files are kept in private storage and are only ever handed out through short-lived links, after we have checked who is asking. Database backups are encrypted before they leave our servers, with a key our storage provider never sees. Most data is not encrypted while it sits in our database, because it has to be ready to play the moment you open a project. Access to production systems is limited to the people who run them. No system is perfectly secure, and we cannot promise that ours is. If a breach affects your personal data, we will tell you as the law requires.

7. What happens when you delete content

There is no trash can. When you delete a project, a recording, a stem split or an imported audio file, it is gone from the service at once and cannot be brought back, and the file itself is removed from storage within minutes. Deleting a project deletes its history, its branches and its recordings. If other members already used a library item you delete, their copies stay and the item is made private instead of removed.

A copy of a deleted record can remain in a database backup for up to 30 days, after which the backup that held it is overwritten. Copies of audio files are not kept in backups.

Closing your account (Settings) replaces your email address with a meaningless one, removes the link to your Google or Discord sign-in, takes you off any waitlist, and makes everything you made private. After that the account cannot be signed in to, and nothing on the site connects it to you. The music itself stays stored, detached from your identity. To have it erased as well, write to us before or after closing, and we will delete it within 30 days, apart from what the law requires us to keep. Our internal record of changes to accounts, which only we can see and which we keep for security and to sort out disputes, still holds the old email address against the closed account until you ask us to erase it.

8. Data retention

We keep information for as long as it is needed for the purpose it was collected for, and then delete it or reduce it to statistics that identify nobody. In particular:

  • Your account and your music: for as long as your account exists, or until you delete an item.
  • Records that count usage against a plan's monthly limit: kept after the item is deleted, without the audio, for the billing month they belong to and for our own cost accounting.
  • Our records of each co-producer request, which include the text that was sent to the model, its cost and your account id: kept after the project is deleted, because they are how we account for what the service costs. They are removed when you ask us to erase your data.
  • Sign-in times and IP addresses: while your account is active. Server logs: days, not months.
  • Error reports in Sentry: for a limited time set by our Sentry plan, then deleted there.
  • The first-visit cookie: up to 90 days.
  • Waitlist entries: until the thing you asked about opens, or until you ask us to remove you.
  • Messages and reports: for as long as we need them to answer you, to enforce our terms or to sort out a dispute.

We may also keep information where the law requires it, to resolve disputes, or to enforce our agreements.

9. Location of site and data

Second Order Ventures LLC is based in Texas, United States. The servers that run the service, including the database that holds your account and your projects, are in Germany. Files are stored with Cloudflare, in the location its storage was created in. The providers that sign you in (Google and Discord), answer the co-producer (OpenAI) and collect error reports (Sentry) process data in the United States, and the people who run the service work from the United States.

So your information is processed in both the European Union and the United States. If you are outside both, it will be transferred to and stored in those places, which may have different data protection laws from yours. By using the service, you agree to that.

10. Transfers of personal data from the EU and the UK

If you are in the European Economic Area or the United Kingdom, your data is stored in the EU, and it leaves the EU when it goes to our providers in the United States, and when we, a United States company, use it to run the service. For those transfers we rely on the standard contractual clauses in our providers' data processing terms, or on their certification under the EU-US Data Privacy Framework where they hold one. If you want to know which mechanism covers a particular transfer, write to [email protected].

Our legal bases for processing, where the GDPR or the UK GDPR applies, are: performing our agreement with you (running your account and your music), our legitimate interests (security, spam prevention, measuring and improving the service, understanding what it costs) and your consent where we ask for it (for example a waitlist).

11. Children

The service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has an account, write to us and we will delete it.

12. Changes and questions

We may update this policy to reflect new practices or new law. We will post the new version here and change the date at the top. For changes that matter, we will also tell you in the product or by email.

Questions, comments or concerns about this policy, your data or your rights: write to [email protected]. Riffgarden is operated by Second Order Ventures LLC, based in Texas, United States.

Adapted from the 37signals open-source policies, used under CC BY 4.0 and changed to describe this service.