Privacy
Effective September 2, 2026
riffs is a group chat where rooms are private and invite-only. There are no public rooms, there are no ads, and your data is never sold. This page says what riffs stores, who can see it, and how to get rid of it.
What riffs stores
- Your account. The email address you sign in with and the display name you choose. Signing in with Google gives riffs your email address.
- What you write. Messages, knowledge base files, room names, and the names you give your AI connections.
- Billing. Payments are handled by Stripe. riffs stores your subscription status and a Stripe customer id. Card numbers never touch riffs.
- Operations. Timestamps, when you last had a room open, and the size and cost of each Claude reply. These keep the product working and are not used for advertising.
Who sees what you share
- The people in your room. Everything in a room is visible to its members and to no other user. Rooms are invite-only, and there is no way to make a room public.
- Anthropic, when someone summons Claude. A summon sends the room's conversation and its visible knowledge base files to Anthropic's API to produce the reply. Anthropic does not train models on API data by default. Files hidden from Claude are not sent.
- The AIs members connect. A member can point their own AI at a room. It reads and writes as that member and reaches exactly what they can reach, and files hidden from Claude are refused to it as well. What that AI's provider does with what it reads is governed by the provider's own policy, chosen by the member who connected it.
- The people who run riffs. Like any service that holds your data, riffs can technically read what is stored in its database. We look at message or file content only to keep the service working, debug problems, or investigate abuse, and never to browse.
The services riffs runs on
riffs runs on a small set of services that process data on its behalf: Supabase for the database, file storage, and sign-in, Vercel for hosting and analytics, Anthropic for Claude replies, Stripe for payments, and Resend for email. The database and uploaded files live in Supabase's Canadian region.
Analytics
riffs uses Vercel Web Analytics, which counts visits in aggregate without cookies and without following you across sites. There is no advertising tracking anywhere on riffs.
riffs emails you a sign-in link when you ask for one, and a notification when a room you belong to has new messages while you are away. Notifications are on by default, and every notification email carries a one-click unsubscribe.
Deleting things
- Knowledge base files can be deleted by any room member. Deleting a file also deletes its kept previous version.
- Your account can be deleted in settings. Deletion cancels any subscription, removes your login, profile, and memberships, and detaches your name from everything you wrote. Messages and rooms you created stay in their rooms, attributed to "(deleted)", because the conversation belongs to the people still in it.
Contact
Questions about any of this go to support@riffs.chat. Changes to this page will appear here with a new effective date.