Riffwise
How it worksPricingSupport
Join beta ↗

Clear terms, plain language

Privacy Policy

Last updated 17 August 2026

This policy explains what information Riffwise processes when you use the website and Chrome extension, why it is needed, and the choices you have.

Data we collect and handle

  • Account data: your email address, Supabase user ID, authentication session, and account status.
  • Account password: when you sign in or reset your Riffwise account password, you enter it in Riffwise Settings or the password-reset page. It is transmitted over HTTPS to Supabase Authentication to verify or update your account.
  • Writing-request data: text you select or draft, detected source-post text, relevant attached post media, optional nearby conversation context, and your selected tone, length, language, and personal writing instructions.
  • Service data: successful-generation count, allowance or plan status, timestamps, and limited error or security metadata.
  • Feedback data: category, description, expected behavior, limited extension diagnostics, and source text, generated output, or a screenshot only when you explicitly choose to attach it.

Riffwise does not collect general browsing history and does not need your social-media passwords or payment-card details.

How we use data

  • Generate the reply, quote, or rewrite you request.
  • Authenticate users, maintain accounts, enforce monthly allowances, prevent abuse, and secure the service.
  • Respond to support, privacy, and deletion requests and diagnose reported failures.
  • Review beta feedback and improve reliability; optional writing content and screenshots are reviewed only when you choose to include them.
  • Meet applicable legal, fraud-prevention, tax, and accounting obligations.

We do not sell personal data, use browser or website content for advertising, or use it to determine creditworthiness. Riffwise never publishes content automatically.

Storage and retention

The Chrome extension keeps your preferences in Chrome sync storage and keeps its active request and result temporarily in Chrome session storage. It keeps the authenticated session in Chrome local storage. The extension and Riffwise application do not store your plaintext account password; Supabase Authentication stores the credential verifier needed to authenticate your account. Riffwise does not intentionally store ordinary writing prompts, attached post media, or generated replies in its application database.

Supabase stores account, entitlement, deletion-request, and monthly usage records while an account is active. Feedback reports are stored only when submitted and are kept while needed to investigate and verify a fix, then deleted or anonymized; our initial target is no longer than 90 days after resolution. Security records are retained only as reasonably necessary. Billing and transaction records may be retained where tax, accounting, fraud-prevention, or other legal rules require it.

How data is shared

  • OpenAI receives writing-request content and relevant attached post media to generate the output you request.
  • Supabase provides authentication and stores account, entitlement, deletion-request, monthly usage, and submitted feedback records.
  • Netlify hosts the Riffwise website and server functions that securely relay authenticated service requests.

Payments are disabled during the private beta. If paid plans launch, the payment provider will handle hosted checkout, payment processing, tax, invoices, refunds, and subscription administration; Riffwise will receive only the identifiers and entitlement state needed to operate a subscription, not full card details. Providers process data under their own contractual and privacy obligations, and data may be processed outside your country subject to applicable transfer safeguards.

Chrome Web Store Limited Use

Riffwise's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser and website content is processed only when needed for the user-invoked writing feature. It is not sold, used for advertising or creditworthiness, or transferred for unrelated purposes. Humans do not read writing content unless the user gives specific consent for support, access is necessary for security or abuse investigation, or disclosure is legally required.

Your choices

You can disable nearby-text context, inspect and edit generated text, change or remove personal instructions, sign out, request account deletion in Riffwise Settings, and uninstall the extension at any time. You may ask to access, correct, or delete account information by email. Some records may need to be retained where the law requires it.

Children

Riffwise is not intended for children under 13, and we do not knowingly collect their personal data.

Changes

If this policy changes materially, the updated date above will change and an appropriate notice will be provided.

Riffwise is operated by Igor Sarkulov, an individual based in Cyprus. Questions? Email igor@sarkulov.com.

Riffwise

Context-aware replies for social platforms and web messaging, right where you communicate.

ProductHow it worksPricingSupport
LegalPrivacyTermsRefundsAcceptable use
© 2026 RiffwiseOperated by Igor Sarkulov, an individual based in Cyprus.igor@sarkulov.com