Privacy Policy
Last updated: September 18, 2026.
Riffzen is a music campaign creation, YouTube scheduling, automatic publishing, and performance tracking service. This policy explains how Riffzen handles your information, including information received through Google and YouTube APIs.
Information you provide
We store your account email, a password hash, artist profile, release details, campaign instructions, posting preferences, captions, and other information you enter. We also process uploaded songs, transcriptions, corrected lyrics, and generated videos to prepare your campaigns. Account cookies and browser storage support login and saved workflow progress. Billing is handled through Stripe; Riffzen stores subscription and payment identifiers and status rather than your full card details.
Google and YouTube access
YouTube connection is optional. When you choose to connect a channel, Google asks you to authorize Riffzen through OAuth. Riffzen currently requests the youtube.upload and youtube.readonly permissions. These allow uploads and read access to YouTube account information. Riffzen uses that access for the channel, publishing, and campaign analytics features described here. We do not request your Google password or access to Gmail, Google Drive, or your contacts.
We receive OAuth access tokens, a refresh token when Google provides one, token expiry and granted permissions, and the connected channel's identifier and name. We read upload responses, video identifiers, publication status, and views, likes, and comment counts for campaign videos. We do not retrieve individual comment text, viewer identities, or private viewer-level analytics for these features.
How we use Google and YouTube data
- Show which channel is connected and associate it with your artist account.
- Authorize API requests and refresh expired access tokens without requiring you to reconnect each time.
- Upload the campaign video file, title, description, and publication time to your channel when automatic publishing is enabled.
- Upload videos privately with a scheduled publication time and track whether YouTube has published them.
- Display video performance, store daily statistics snapshots, and use campaign performance evidence to improve future posts.
- Track publishing jobs, failures, retries, and service usage so you can manage your campaign.
Enabling Fully Automatic Mode authorizes background publishing for your campaigns. Connecting YouTube alone does not enable this mode. Campaign optimization can adjust eligible future posting times, hooks, captions, and hashtags. Analytics currently use video statistics from the YouTube Data API; they do not include a complete YouTube Studio analytics report.
Storage and protection
OAuth access and refresh tokens are encrypted before storage using Fernet and a server-configured encryption key. Tokens are decrypted on the server only when needed to authorize Google API requests. Channel details, campaign records, video identifiers, statistics, optimization history, and job status are stored in the application database. Authorization checks restrict account and artist records to their owners.
Audio and video files are stored on the server or in configured object storage such as Cloudflare R2, with temporary local copies used during processing or publishing. Media delivery can use public storage URLs. Anyone with such a URL may access the file, so do not treat a shared media URL as private. Google API requests use HTTPS. These protections reduce risk but cannot guarantee that every system or transmission is completely secure.
Sharing and AI-assisted features
We send uploads and their publication metadata to Google/YouTube to carry out the publishing features you authorize. Hosting, database, storage, and processing providers handle information needed to operate Riffzen. Google handles information it receives under its own Privacy Policy.
Riffzen uses Anthropic to generate campaigns and optimization recommendations. Campaign context and performance evidence, including video statistics or measures derived from them, post age, captions, hooks, hashtags, artist name, and campaign name, can be sent to Anthropic for these user-facing features. OAuth tokens are not included in these AI prompts. Uploaded songs are sent to OpenAI for transcription to produce timed lyrics. These processing providers receive the information needed for the requested feature; their processing is subject to their applicable service terms.
We do not sell Google or YouTube user data, use it for advertising or credit decisions, or use it to train generalized AI models. We limit transfers to providing the features you authorize, security needs, legal requirements, or a business transfer with your prior consent. Human access to Google user data is limited to your affirmative permission, necessary security or legal purposes, or permitted aggregated internal operations.
Google API Services Limited Use
Riffzen follows the Google API Services User Data Policy, including its Limited Use requirements, when using or transferring information received from Google APIs.
Retention, revocation, and disconnecting
Connection credentials are retained while your channel remains connected. Campaign records, uploaded media, statistics snapshots, and optimization history remain stored for your campaign features until removed. The current application does not automatically purge all historical campaign analytics when you disconnect or revoke access.
You can revoke Riffzen's access at Google Account connections. Revoking prevents further authorized access but does not by itself erase data already stored in Riffzen. The authenticated Riffzen disconnect endpoint, DELETE /artists/{artist_id}/automate/youtube/connection, deletes that artist's connection record, including stored OAuth tokens, channel details, and automatic publishing setting. Use the deletion contact below if you need help disconnecting or removing other stored data. Logging out is not the same as revoking access.
Pause or cancel campaigns to stop future Riffzen work. Disconnecting, revoking access, or pausing a campaign does not delete a YouTube video or cancel a publication already scheduled on YouTube. Use YouTube Studio to change or delete those uploads.
Requesting deletion or asking a privacy question
Privacy and deletion contact: boohooyou143@gmail.com.
Request removal of your Google/YouTube connection data, stored video identifiers, analytics snapshots, optimization evidence, campaign records, uploaded media, or your account. Include your account email and the connected channel or artist name, and say which information you want removed. Do not send passwords or OAuth tokens. We may verify account ownership before acting on the request.
Deletion of Riffzen's records does not delete copies held by YouTube or files you downloaded or shared. Where deletion is handled by the operator, it must include related database records and stored media rather than only the connection record. Records that must be kept for legal, billing, fraud prevention, or security reasons may be retained for those purposes. Provider logs and backups may persist under the provider's retention arrangements; this application has no automated backup-erasure feature.
Policy changes
We will update the date on this page when this policy changes. If a change introduces a new use of Google user data, we will explain it and obtain any required consent before that use begins.