The short version
Riff Engine is private by default. It has no advertising, third-party analytics, tracking, developer-run account, or subscription. The bundled practice deck and on-device thought compiler work without a network connection. Cards, creator preferences, sessions, transcripts, analysis, outcomes, and learned calibration stay on your device by default.
Information stored on your device
Riff Engine stores the information needed to provide and improve your local experience:
- practice, compiled, derived, imported, and personally created cards;
- optional thought-profile details, content focus, audience, goal, style, and presenter preferences;
- card-exposure and preference receipts, session history, and card archives;
- transcripts, per-card analysis, source-moment lineage, publication outcomes, and learned calibration; and
- optional source addresses and configuration. A Fresh Riff bearer token is stored in Apple’s Keychain.
The app maintains one anonymous local profile per installation and has no dedicated name or account field.
Recordings and speech recognition
When you choose an existing audio or video recording, Riff Engine copies it into private app storage so it remains available for replay and analysis. The app does not request camera or microphone access and does not upload imported recordings. Speech recognition is required to run on-device; there is no server-transcription fallback. A pasted transcript is available when on-device recognition is unavailable.
You can remove the managed recording from its session while retaining the transcript and scores. Apple Speech availability varies by language and device, and Riff Engine’s transcript scoring is currently tuned for English.
Optional content sources
Advanced content sources are blank and disabled on a fresh install. If you configure and use one, Riff Engine connects directly to the address you provide:
- Strategy Intelligence receives the optional focus and audience text you entered, each limited to 240 characters, plus the selected content goal and style. It does not receive a dedicated name, app account identifier, or recording.
- Market Tape and Fresh Riff may return cards. A Fresh Riff bearer token is sent only to an HTTPS address. Images or other response assets may load from addresses attached to a returned card.
- A private-network address may cause Apple’s Local Network permission prompt. Local Network access is unnecessary for the clean-install workflow.
The operator of an address you choose controls that service’s data and retention practices. Do not enter secrets or unnecessary personal information in focus, audience, or other free-text fields.
Advertising, analytics, and tracking
Riff Engine contains no advertising or third-party analytics SDK and does not track you across apps or websites. It does not sell personal information.
Retention and deletion
Local information remains until you remove it or delete the app. You can clear optional source addresses and the Fresh Riff token in Settings and remove a managed recording from its session. Deleting Riff Engine removes its app-container data, subject to Apple’s device and backup behavior. Apple Keychain items can survive app deletion, so clear the Fresh Riff token before deleting the app when that credential must also be removed.
Children
Riff Engine is not directed to children under 13 and does not knowingly collect personal information from children under 13.
Changes
If Riff Engine’s data practices change, this page will be updated and the “Last updated” date will be revised.
Contact
Privacy questions can be sent to isaiahdupree33@gmail.com.
Controller
Riff Engine is published by Isaiah Dupree. Contact: isaiahdupree33@gmail.com