RiffList Privacy Policy
Effective September 16, 2026
RiffList is made and operated by Arlemo LLC, a Kansas limited liability company ("Arlemo", "we", "us"). This policy explains what information RiffList collects, how we use it, who can see it, how long we keep it, and the choices you have. It covers the RiffList app for iPhone and the RiffList web app at rifflist.app.
We wrote this in plain language. If anything is unclear, email privacy@rifflist.app.
The short version
- You sign in with an Apple or Google account. We store the email address and name that account gives us. Other members see the username you choose, not your name or email.
- Everything you add to a list (riffs, corrections, comments, reactions, challenges, ranking picks, house rules) is stored on our servers. Riffs, corrections, comments, reactions, and challenges are shown to the members of that list. Your ranking picks are private.
- We collect a small amount of diagnostic data to keep RiffList working.
- You can delete your account from inside the app. You choose whether your riffs stay in your lists without your name or are removed. See "Delete your account" below.
Who we are and how to reach us
Arlemo LLC
Support and reports: support@rifflist.app
Privacy requests: privacy@rifflist.app
Support page: https://rifflist.app/support.html
What RiffList collects
Account information
When you sign in for the first time, RiffList creates an account tied to the Apple or Google account you used and stores:
- an account ID assigned by our authentication service (Firebase Authentication)
- the email address that account gives us. With Sign in with Apple you can choose Hide My Email; Apple then gives us a relay address that forwards to you, and we store that relay address instead
- the name that account gives us. Google shares a display name and a profile photo link. Apple shares a name only the first time you sign in, and only if you choose to share it
- which sign-in methods are connected to your account (Apple, Google, or both)
- when you created the account and when you last used RiffList, with the app version, client schema version, and web build id you used and, on the web, the host name, page path, and browser user agent of that visit
You do not create a password for RiffList. Sign-in is handled by Apple or Google. If your Apple and Google sign-ins give us the same verified email address, they may connect to the same RiffList account, and you can connect the other sign-in method yourself from your profile under Account. Otherwise a different sign-in is a separate account with its own username; RiffList does not combine accounts by guessing. RiffList does not ask your age; by creating an account you confirm you are at least 13 (see "Children" below).
Your username
You choose a username (3 to 20 characters: lowercase letters, numbers, dashes, or underscores) when you first sign in. It cannot be changed after that. Your username is what other members see on your riffs and in a list's member list. RiffList keeps a record of which usernames are taken.
Content you add to lists
RiffList stores what you and other members add to a list, together with who added it and when:
- list titles and house rules (written by the list owner)
- riffs (short text entries), including ones recorded as duplicates
- spelling corrections you make to your own riffs
- comments you attach to your own riffs (up to 1000 characters)
- reactions and "WRONG?" challenges on riffs, including the reason chosen
- your ranking picks: when you use Rank, which of two riffs you preferred, or that you called it a tie
- passes, turn pauses, and the reason an owner gives for a rewind
- invites you create, invite links you open, join requests and the owner's decision on them, and the record that you joined or left a list
Some existing lists were created as word-guessing games before that feature was removed from the current app. Their saved rounds and guesses stay with the list under the same rules as other list content.
Reports and support messages
When you report a riff, a comment, or a member from inside a list, we store the reason you chose, the note you add (up to 1000 characters), a copy of the reported text as it read at that moment, the riff's number and the username of the person who wrote it or the reported member's username, and the list, together with your account ID, your account email address, your username, and your app version. When you send a support request or report a list or the app, we store what you wrote (up to 1000 characters) with the same account details, the page or list you were on and, on the web, your browser's user agent. The form tells you that your account and app context are attached before you send. If you email us, we keep the email. Other members cannot read your reports.
Blocks
If you block someone, RiffList stores a private record under your account naming the blocked account, and records that you left the lists you shared with that person. Only you can see who you have blocked. The other person is not told.
Diagnostics
To find bugs and keep RiffList reliable, the app records a limited set of technical events with fixed names, such as "journey-complete" (a sign-in finished), "offline" and "reconnecting" (connection state), "notification-permission-granted", and "caught" (an error was caught). Each batch of events includes:
- a random device identifier that RiffList generates for that install (it is not your phone's advertising identifier or serial number)
- a random session identifier for that app launch
- the app version and the event names, and sometimes the list ID involved, an outcome code, a timing measurement or, for recovery events, a short error message (up to 300 characters) taken from the error itself
These events do not include riff text, list titles, your email, or your location.
On the web, your browser may also send RiffList a report if the page's security policy is violated; we log that report and the browser user agent.
Turn alerts (push notifications)
If you turn on turn alerts, RiffList stores a push token for your iPhone or a push subscription for your browser so it can tell you when it is your turn. The alert names the list ("It's your turn in [list title]"), so anyone who can see your lock screen can see that list title; your device's notification settings control what is shown. When you turn alerts off, sign out, or a token stops working, RiffList marks that record inactive.
App integrity checks
RiffList asks your device or browser for an app integrity token (Firebase App Check) and sends it with requests. On iPhone the token comes from Apple's App Attest or DeviceCheck service. On the web it comes from Google reCAPTCHA Enterprise, which evaluates browser and interaction signals under Google's privacy policy. RiffList's servers receive the token; RiffList does not receive the underlying device details.
Server logs
RiffList runs on Google Cloud (Firebase). Google keeps standard server logs for these services, which can include your IP address and request details, for its normal operating period. RiffList does not store your IP address in its own database.
Information stored on your device
RiffList keeps some data on your phone or in your browser: your sign-in session, an invite you opened but have not yet joined, display preferences, drafts of riffs you have not sent, diagnostic events waiting to be sent and, on the web, a local copy of your lists so they load faster. Signing out clears most of this.
Cookies and browser storage
The web app uses browser storage (localStorage and IndexedDB) to keep you signed in, remember settings, and cache your lists. Google's sign-in and reCAPTCHA services may set their own cookies under Google's privacy policy.
Device access
RiffList does not request access to your device's location, contacts, photo library, camera, microphone, calendar, or health data. Google Sign-In can use your IP address to estimate your general location to help prevent fraud. The account information Google shares with RiffList is described above.
How we use information
We use the information above to:
- sign you in and keep your account working
- show lists to their members and keep turn order, numbering, duplicates, corrections, and challenges working
- send turn alerts you have turned on
- show each list's leaderboard, built from everyone's ranking picks
- enforce daily limits that help prevent abuse
- check new riffs, corrections, comments, titles, house rules, and usernames against a short fixed list of blocked words and phrases and reject matches (a fixed word list, not a system that reads or judges meaning)
- apply the blocks you set when someone tries to join a list
- respond to reports and support requests, carry out account deletions, and enforce our Terms of Use
- find and fix bugs
- comply with the law and protect RiffList and its members
We email you about your account, requests you make, and changes to these documents.
Who can see what
Members of a list can see every riff, correction, comment, reaction, challenge, and pass in that list, the username of whoever added it, and the usernames of the other members. They cannot see your email address or your profile photo. They see your username, not the name on your Apple or Google account. In some lists created before usernames existed, an older member record may still show the name from that member's Google account.
Anyone who holds an invite link can read the list title, house rules, join mode, and status without signing in. The invite page shows the title before you sign in and the house rules when you arrive at the list. In a list set to "Anyone with link", anyone who signs in with the link becomes a member. Invite links do not expire, and the owner cannot turn them off today. Share links only with people you want in the list.
Members can copy, screenshot, or repeat what they see in a list. RiffList cannot prevent that.
Your ranking picks are private. Members see the leaderboard that combines everyone's picks, not who picked what.
If you leave a list, the riffs, corrections, comments, reactions, and challenges you added stay in the list with your username on them, and you lose access to the list.
If you block someone, you leave the lists you share with them, and your contributions stay in those lists with your username. The other person is not told, and neither of you can join a list the other already belongs to.
If we remove a riff or comment after a report, its text is removed for everyone. A removed riff keeps its number as an empty placeholder so the rest of the list still makes sense.
Arlemo staff (currently one person, the owner of Arlemo) can access account records and list content to respond to reports and support requests, investigate abuse, fix problems, and comply with legal requests. We do not read lists for any other reason.
We may disclose information if required by law, subpoena, or court order, or when we believe in good faith it is necessary to protect someone's safety, prevent fraud or abuse, or protect our legal rights.
If Arlemo is acquired by or merges with another company, account and list data may transfer to the new operator, who must honor this policy or give you notice and a chance to delete your account first.
Service providers
RiffList runs on services from Google and Apple. These providers process data on our behalf under their own terms. They are not permitted to use it for their own purposes except as their terms allow.
- Google Firebase: Authentication, Cloud Firestore (database), Cloud Functions, Hosting, App Check, Cloud Messaging, and Installations. Firebase privacy information: https://firebase.google.com/support/privacy
- Sign in with Apple (sign-in on iPhone and the web)
- Google Sign-In (sign-in on iPhone and the web). Google's sign-in software also processes account, device, usage and diagnostic information under Google's terms. See Google's iPhone sign-in privacy disclosure.
- Google reCAPTCHA Enterprise (app integrity on the web)
- Apple: App Attest and DeviceCheck (app integrity on iPhone) and Apple Push Notification service (turn alerts on iPhone)
- Your browser's push service (turn alerts on the web), operated by your browser maker
How long we keep information
RiffList is built around lists that people return to over months, so most data is kept as long as the account or list it belongs to exists.
- Account records: until your account deletion is completed (see "Delete your account").
- List content: as long as the list exists. Ending a list freezes it but deletes nothing. An owner can delete a list only while they are its only member and every riff is their own. When a riff is voided by a rewind or rejected by the server, RiffList may keep the original text in storage even though it is no longer shown.
- Content from members who left: stays in the list with their username (see "Who can see what").
- Reports and support messages: as long as needed to handle them and keep a record of safety and enforcement actions. When you delete your account, reports you sent are deleted; reports other people sent about you keep their text and outcome with your identity removed.
- After account deletion: contributions you chose to keep stay in their lists under a deleted-member name that is not connected to your account. We also keep a minimal record that the account was deleted, with no name, email, or content, so an old signed-in device cannot recreate it.
- Diagnostic events: until your account deletion is completed. Invite records and join and leave records: while the related account or list exists.
- Push tokens: marked inactive when you turn alerts off or sign out; the inactive record is removed when your account deletion is completed.
- Backups: copies of deleted data may remain in our database provider's backups for a limited time before they expire.
Your choices and requests
Delete your account
In the app, open your profile and choose Account, then Delete account. The app shows the lists you host and what happens to each, lets you choose whether your contributions stay, asks you to type DELETE, and then asks you to confirm your sign-in. Deletion continues on our servers after that. The app shows its progress and tells you when it is complete. Signing in again afterward creates a new account.
Your contributions. By default, your riffs, corrections, comments, reactions, challenges, and ranking picks stay in the lists you were in, under a new deleted-member name in each list, so other members' lists still make sense. Their effect on rankings and reaction totals stays, and your individual picks stay private. Removing your name does not stop someone from recognizing your writing. If you uncheck that choice, your contributions are removed instead: your riffs' numbers stay as empty placeholders, other members' contributions stay, and the remaining rankings are recalculated.
What is deleted either way. Your account record, email address and name, username reservation, sign-in connections (including revoking Sign in with Apple), memberships, push tokens, diagnostic events, invites you created, reports you sent, and blocks you set or that named you. Lists you host pass to another member or end, as the app shows you before you confirm.
What remains. Contributions you chose to keep, under the deleted-member name; reports other people sent about you, with your identity removed; a minimal record that the account was deleted, with no name, email, or content; anything we must keep by law or to resolve a dispute; and copies in backups until they expire.
If you do not see Delete account in the app, or something goes wrong, email privacy@rifflist.app from the email address on your account and we will complete the deletion for you.
See or correct your information
You can see your username and account email in your profile under Account. Inside the app you can correct the spelling of your own riffs and add, edit, or remove your own comments and reactions. To ask for a copy of the information we hold about you, or to correct something you cannot change in the app, email privacy@rifflist.app from your account email.
Turn alerts
RiffList asks for notification permission before sending alerts. Turn alerts on or off any time in your profile under Settings, or in your device's notification settings.
Diagnostics
Diagnostic events are part of how RiffList runs and do not have a separate switch. They contain no list content. They are removed when your account deletion is completed.
Lists and people
You can leave any list you do not own (List options > Leave list). You can hide ended lists from your home screen. You can block a member from People, and unblock from your profile under Account (see "Who can see what").
Notice for residents of California, Delaware, and Nevada
Some states require us to say the following plainly. It applies to everyone.
- The categories of personal information we collect are listed under "What RiffList collects". The categories of companies that receive it are listed under "Service providers".
- You can review the information we hold about you and request changes or deletion by emailing privacy@rifflist.app from your account email. We may ask you to confirm you control that email before acting.
- We tell you about changes to this policy as described under "Changes to this policy".
- Requests under state privacy laws, including a request that we not sell your information, go to privacy@rifflist.app.
- RiffList does not respond to browser "Do Not Track" signals. Other parties do not collect personal information about your activity over time and across different websites through RiffList.
- The effective date is at the top of this policy.
Children
RiffList is for people 13 and older. We do not knowingly collect personal information from children under 13. RiffList does not ask your age. By creating an account you confirm you are at least 13.
If we learn that a child under 13 has an account, we will disable the account and delete its personal information as soon as we can. Parents or guardians who believe a child under 13 has used RiffList can email privacy@rifflist.app.
Security
We protect information with database access rules that limit each person to the lists they belong to, encrypted connections (HTTPS), daily limits on what any account can do, and by keeping staff access to a minimum. No online service can promise perfect security. If we learn of a breach that affects your personal information, we will notify you as the law requires.
Where RiffList operates
RiffList's servers are operated by Google and, as far as RiffList controls it, located in the United States. Arlemo is a United States company. If you use RiffList from another country, you do so on your own initiative, your information is processed on those servers, and you are responsible for following local law. This policy does not describe rights under the GDPR or UK GDPR.
Changes to this policy
When we change this policy, we update the effective date at the top and keep the current version at https://rifflist.app/privacy.html. For changes that matter to you (for example, collecting a new category of information or adding a new type of service provider), we will also tell you in the app or by email to your account address before the change takes effect. Previous versions are available on request from privacy@rifflist.app.
Contact
Arlemo LLC
Support and reports: support@rifflist.app
Privacy requests: privacy@rifflist.app
Support page: https://rifflist.app/support.html
Web: https://rifflist.app