Privacy Policy
Effective date: August 26, 2026
Riffed — the Riffed iOS app and riffedapp.com — is operated by KDN Works LLC, a California company. This policy explains what we collect, how we use it, who we share it with, and the choices you have. It's written to be read: no section here says less than what the system actually does.
The short version: we collect what the product visibly needs (your account, the drinks and posts you create, your bar), plus standard analytics and crash telemetry that never contain the text you type. Everything you post publicly is screened by an automated moderation system before other people can see it, and the AI features send your inputs to the AI providers that power them. We don't sell your data, we don't run ads, and there are no data brokers involved. You can delete your account in the app, and deletion also removes your analytics profile.
What we collect
Account. An email address and password (via our backend provider, Supabase), or your sign-in identity from Apple or Google if you use those instead. A handle, and optionally a bio, an avatar (an icon or a photo you upload), and a name for your home bar. We never collect your date of birth — the age gate records only that you answered, plus a timestamp.
Things you create. Recipes and riffs (names, ingredients, descriptions, sources), drinks you save, your bar inventory, pours you log (the drink, an optional venue or "at home," a rating, optional notes, an optional photo, and the time), comments and emoji reactions, taste-survey answers and drink picks, pinned recipe versions, exploration milestones derived from your pours ("first tiki pour" and the like), and your conversations with the AI assistant.
Events. If you host or join an event: the event details the host writes (title, time, an optional location name and description), who's invited and each person's RSVP, what's on the shared bar and who pledged to bring what, and pours tagged to the event. RSVPing includes a "Share my palate" toggle (on by default): when it's on, your taste profile is visible to that event's guest list and feeds the group's drink suggestions; turn it off at any time and it drops out of both.
Photos. Avatar and pour photos you choose to upload. Photos are resized and re-encoded on your device before upload, which does not carry forward the original file's metadata (such as embedded GPS coordinates). Photos you scan with the recipe or bar-shelf scanner are sent for AI processing (see below) but are not stored.
Inferences. A flavor-preference profile ("palate") computed from your saves, creations, and pours, plus your survey answers. We also keep a dated daily record of that profile — at most one entry per day, and only on days it changed — so features can show how your taste has shifted over time. If you subscribe to Riffed Premium, we additionally store an AI-written analysis of your palate (including an "adventurousness" rating) so it doesn't have to be regenerated on every visit. All of it exists to personalize recommendations inside Riffed and is used for nothing else.
Device and usage data. A push-notification token (if you enable notifications), app version, platform and OS version, product-analytics events, and crash reports. Analytics events carry structured metadata only — which screen, which button, how many ingredients, whether a photo was attached. They never include drink names you typed, note text, search query text, chat content, email addresses, phone numbers, coordinates, or photos, and an automated redaction pass strips anything resembling an email address or phone number before an event leaves your device.
Purchases. If you subscribe to Riffed Premium (or start a trial), we record your subscription status — which plan, whether it's active, and when it expires — so the app knows what you're entitled to. Payment itself is handled entirely by Apple: we never see your card number or billing details. See RevenueCat under "Who we share data with."
Location
Location is used in one place: finding bars near you, when you use venue search or the bars map and grant the iOS location permission. In that moment your approximate coordinates are used to sort venues by distance (passed as parameters to our backend — never written to any database record) and sent to Google Places to find nearby bars. We do not store your coordinates anywhere. Pours record the venue you picked, not your GPS position, and logging a pour works without location access entirely. Venue records store the bar's own public address and coordinates, not yours.
Event link previews
When an event host attaches an external event page (for example a Partiful, Eventbrite, or Luma link), our server fetches that page once to read its public preview metadata (the page title and preview image address) so the app can render a link card. The fetch comes from our server, not your device, and we store only the link and that preview metadata on the event. We don't log in to, scrape accounts from, or exchange any data with those platforms — following the link out is between you and them, under their own terms.
Ingredient name suggestions
When you add a new ingredient, the name field suggests article titles from Wikipedia as you type. Unlike the link previews above, this request goes directly from your device to Wikipedia, so the Wikimedia Foundation receives what you have typed so far and, as with any request your device makes, your IP address. It does not carry your account, and we don't send them anything else. Wikimedia is not one of our service providers — it's a public reference we look things up in — and their own privacy policy covers what they do with it. The suggestions are only a convenience for filling in the field; you can ignore them and type the name yourself.
Automated content moderation
To keep Riffed safe, content is screened by an automated system before it becomes visible to other users: the text of recipes you publish, comments, pour notes, event details (title, description, location name, and an attached link's page title), and profile details (handle, bio, home-bar name), and every photo you upload. Screening is performed by OpenAI's moderation service, which receives the text or image for classification. This screening is not optional and is not used for advertising or training — it exists solely to filter prohibited content. Flagged content is reviewed by us; if something of yours was hidden and you think we got it wrong, email hello@kdnworks.com and we'll review it.
AI features
Some features are powered by third-party AI providers, and using them sends your inputs to those providers through our backend:
- Chat assistant — your messages, the recipe you're working on, your bar inventory, and your palate summary are sent to Anthropic to generate responses.
- Photo scanning — recipe photos and bar-shelf photos you scan are sent to Anthropic to extract their contents.
- Generated descriptions, palate summaries, and drink artwork — recipe and taste-profile data is sent to Anthropic (and, for artwork, image generation runs on OpenAI).
- Balance suggestions — while you're editing a drink, asking for ideas on a flavour pairing sends that drink's ingredients to Anthropic to suggest swaps or additions.
- Adding an ingredient — the name (and any description or category you provide) is sent to Anthropic to research the ingredient and estimate its flavour profile.
- Palate insights (Riffed Premium) — your palate profile, the drinks that shaped it, and your survey answers are sent to Anthropic to write the analysis described under "Inferences" above.
- Search — your search query text is sent to OpenAI to compute a semantic embedding that powers search ranking.
We use these providers' business APIs, whose terms state that content submitted through them is not used to train their models. AI requests are made from our servers, so these providers do not receive your IP address or device identifiers — the data they see is what the feature needs.
Who we share data with
We share data with the service providers that run Riffed, listed below, only for the purposes described here. Two third parties are not on this list because they aren't our service providers and receive a request from your device rather than data from us — Google Places (see "Location") and Wikipedia (see "Ingredient name suggestions"). We do not sell or rent personal information, we have no advertising networks, and we share nothing with data brokers.
- Supabase — our database, authentication, file storage, and server functions. Effectively everything lives here.
- Anthropic — AI features (chat, scanning, descriptions, summaries), as above.
- OpenAI — automated moderation of posts and photos, search embeddings, and drink-art image generation, as above.
- Google — venue search (Google Places receives your search text and, for nearby search, your approximate coordinates directly from your device) and Google Sign-In if you use it. Venue features use Google Maps Platform; by using them you are also subject to Google's Terms of Service, and Google's Privacy Policy applies to what Google receives.
- Apple — Sign in with Apple if you use it, and delivery of push notifications (via APNs). If you sign in with Apple, we store one token Apple issues for your account. We never use it to access anything on your behalf; it exists solely so that deleting your account can tell Apple to revoke Riffed's access, and it is destroyed along with the rest of your account data.
- RevenueCat — subscription management for Riffed Premium. If you subscribe (or start a trial), RevenueCat receives your random account identifier and purchase information from Apple (product, purchase and renewal dates, transaction identifiers) so the app knows what you're entitled to. It never receives your email, name, or anything you make in Riffed.
- Expo — our push-notification delivery service. It receives your push token and notification content (for example, a friend's handle and a drink name). Expo states notification content is held only as long as delivery takes.
- Resend — sends our email. That is two kinds: account emails (signup confirmation and password-reset links — your email address plus the link itself) and notification emails (your email address plus the same short notification copy the push would have carried). Notification email is only ever a fallback: it goes out when a push notification could not be delivered to any of your devices, and only for categories you have email switched on for. By default that's friend requests and event invitations; you control it per category in Riffed → Settings → Notifications. No content of your posts is ever in an email.
- Sentry — crash and error reporting.
- PostHog — product analytics. See the next section for exactly how this behaves on the website versus the app.
- Vercel — hosts this website (and, like any web host, keeps standard server request logs).
We may also disclose information if required by law or to protect Riffed and its users (for example, responding to valid legal process or investigating abuse), and account data would transfer as part of a business transfer (merger or acquisition), under this policy.
Analytics and cookies
On this website, our analytics run in cookieless mode: no analytics cookies, no tracking scripts from ad networks, no identifier saved on your device, and no cookie banner — because there's nothing stored to ask permission for. In place of a stored identifier, PostHog computes a temporary one-way hash on its own servers from your IP address, your browser's user-agent string, and a secret that PostHog rotates every day. That hash is enough to see that one person read three pages in a row; it is not enough to know who that person is, and it stops working the next day.
Two narrow exceptions, both functional: if you sign in on this website (used only for the moderation console and AI-integration consent screens), strictly-necessary session cookies keep you signed in; and your appearance choices — light/dark mode and which colour palette you picked — are saved on your device. Neither is used for analytics or tracking.
We do not record your screen. Session replay is disabled on this website in the site's own code, and it is switched off in the mobile app's code as well. If we ever turn it on, we will update this policy first.
In the app, analytics are tied to a random account identifier so we can understand how features are used. Your email address and handle are never sent to our analytics or crash-reporting providers. The same rule from "What we collect" applies: events carry metadata, never the content you type.
What's public and what isn't
- Profiles are private by default. Your handle is visible to other users (it's how friends find you); your bio, avatar, and activity are visible beyond your friends only if you turn on Public profile.
- Recipes have three visibility levels: private (only you), unlisted (anyone with the link, including on this website, but not listed or indexed), and public (visible in the app, on this website, in search engines, and in link previews when shared).
- Your bar has three visibility levels: private (only you), friends (the default — your friends can browse your bar in the app, and anyone you send a share link to can view it), and public (also shown on your public profile, including its page on this website). Setting your bar to private immediately stops friends' browsing and pauses your share link.
- Pours, comments, and reactions are visible to other signed-in Riffed users.
- Share links work without an account. When you share your bar, a party invite, or a public profile, the link opens a page on this website that anyone holding it can read without signing in — your bar's contents, or the party's title, host, date and guest count, or your public profile. Holding the link is the permission, so treat one as public once you send it. You can turn a bar or party link off at any time in the app, which makes the old link stop working immediately.
- Photos are served from public URLs. Uploaded photos (avatars, pour photos, drink art) are stored at links that are hard to guess but not protected by a sign-in — anyone with a photo's exact URL can view it. Treat photos you attach as potentially public.
How long we keep things
| Data | Retention |
|---|---|
| Account, recipes, saves, pours, comments, bar, palate | Until you delete them or your account |
| Palate history (the dated daily record above) | Until you delete your account |
| Deleted ("archived") drinks | Permanently erased 30 days after you delete them (restorable until then) |
| Chat conversations with the assistant | Until you delete the conversation or your account |
| Notifications | 90 days after read; 180 days at most |
| Push-delivery receipts | 7 days |
| Abuse reports about you or your content | Kept as moderation records, including a snapshot of the reported content — even if the content, or the reported account, is later deleted (the link to the account is removed) |
| Abuse reports you filed | Deleted along with your account |
| Crash and error telemetry | Expires automatically on our provider's rolling window (currently 90 days) |
| Analytics events | Until account deletion (see below) |
Deleting your account
You can delete your account in the app (Settings → Account → Delete Account) — no email required, though hello@kdnworks.com works too. Deletion is permanent. What happens:
- Deleted: your profile details, pours, comments, reactions, bar, friendships, palate data, milestones, chat history, notification and device records, uploaded photos, and every drink of yours nobody else depends on.
- Anonymized, not deleted: drinks that other users have saved, checked into, riffed, pinned a version of, or that appear on a venue's menu. They stay on the service with no name attached (so other people's collections and riff histories don't break).
- Also deleted: your analytics profile and its events at PostHog, and your customer record at RevenueCat if you ever subscribed. Crash telemetry expires on its own within its retention window.
- Kept: abuse reports filed about you or your content, with the link to your account removed — they're moderation records, and losing them would make an account reset a way to erase a history. Reports you filed against other people are deleted with the rest of your data.
- Not affected: an active Riffed Premium subscription. Subscriptions belong to your Apple ID, not your Riffed account, and nothing we do server-side can cancel one — cancel it in your Apple ID settings (Settings → your name → Subscriptions), ideally before deleting your account.
Copies in encrypted backups age out on our providers' backup schedules, and photo URLs already cached by third parties (link previews, CDNs) are outside our control once shared.
Your choices
- See your data: request a complete copy any time — hello@kdnworks.com. We'll verify the request against your account email and send a machine-readable export.
- Fix your data: edit your profile, recipes, and content in the app.
- Delete: in the app, or by email.
- Privacy controls: the Public profile toggle, per-category push/email notification toggles, blocking, and revoking the app's location/camera/photo permissions in iOS Settings at any time (every feature except venue search and photos works without them).
- Connected AI tools: if you've connected an external AI assistant to your account, you can revoke its access in Settings → AI Integrations.
- Website analytics: nothing is stored on your device, so there's nothing to clear; if you'd rather the site sent no events at all, any standard content blocker will block PostHog's endpoint.
California residents
This section covers disclosures California law asks for. The categories of personal information we collect and the third parties we share with are listed above ("What we collect" and "Who we share data with"). We collect it directly from you and from your use of the service — we do not buy data about you. We do not sell or share personal information as those terms are defined in California law, and we haven't in the past 12 months; there is accordingly nothing for a "Do Not Sell or Share" link or the Global Privacy Control signal to opt you out of, though you're welcome to send GPC — it changes nothing because there's nothing to change. We honor requests to know, correct, and delete (the mechanisms above), we don't discriminate for exercising them, and you can designate an authorized agent by having them contact us with proof of authorization. Do Not Track: our website doesn't track visitors across other sites, and no third parties collect personal information about your activity over time and across different sites through our service — so there is nothing for a DNT signal to disable, and we don't respond to one. When we make material changes to this policy, we'll post the updated policy here with a new effective date and give notice in the app or on this site.
Age
Riffed is for people of legal drinking age (21 in the United States) and in all cases at least 18. It is not directed to children, and we don't knowingly collect personal information from anyone under 13; if we learn we have, we'll delete it and close the account. As above: no date of birth is ever collected.
Security
Data is encrypted in transit, access is controlled with row-level security at the database, uploads pass through authenticated, moderated endpoints, and we keep the set of people with production access as small as it can be (currently: one). No system is perfectly secure, and we can't guarantee absolute security — if a breach affects your personal information, we'll notify you as applicable law requires.
Where data lives
Riffed is operated from the United States and data is stored on US infrastructure. If you use Riffed from outside the US, your information is processed in the US.
Changes to this policy
We'll update this policy as the product evolves. Material changes get notice in the app or on this site, plus a new effective date at the top. The change history lives in our source repository.
Contact
Privacy questions or requests: hello@kdnworks.com. Copyright notices go to the agent on our DMCA page.
© 2026 KDN Works LLC.