Privacy Policy
Last updated: October 2026
About this policy
This Privacy Policy explains how Viralinx LLC, a Wyoming limited liability company (“Viralinx”, “we”, “us”, “RISR”), handles personal information when you use RISR: the RISR Studio apps for iPhone, iPad, Mac, Windows and Android, the risr.app website, and RISR's online services (accounts, cloud storage, sharing, the Assistant and remote access). It works alongside our Terms of Service and End User License Agreement.
In short
- Your work starts on your device. Projects, recordings and settings are stored locally. They reach our servers only when you use a cloud feature: saving to the cloud, syncing, sharing a link or a file, or asking the hosted Assistant.
- We do not sell or share your personal information, show ads, or track you across other apps and websites.
- We don't use your work to train AI models without your permission.
- You can delete your account from the app or the website at any time.
1. Who is responsible
Viralinx LLC is the controller of the personal information described here. Contact: [email protected].
When you buy RISR on our website or in the Mac and Windows apps, Paddle (Paddle.com Market Limited, or Paddle.com Inc. for buyers in the United States) is the merchant of record and sells it to you. Paddle is a separate controller of the payment and tax information it collects; see Paddle's privacy notice. When you buy in the App Store or Google Play, Apple or Google processes your payment under their own privacy policies.
2. What we do not collect
Today, we do not collect the following. If that changes, we'll update this policy first and, where the law requires, ask you.
- product-usage analytics: how, when or how often you use the apps;
- advertising identifiers, or data for advertising or profiling;
- your browsing behaviour on other sites;
- your contacts, location, or health data (RISR does not ask for location or health access on any platform);
- the contents of your projects, unless you save them to the cloud, share them, or send them to the Assistant (section 3.4–3.6);
- the audio, MIDI, video and sensor signals RISR processes while you play. These stay on your device, or travel only to devices and software you connect yourself.
3. What we collect, why, and for how long
3.1 Your account
| What | Why | Legal basis | Kept |
|---|---|---|---|
| Email address, display name, account ID; if you sign in with Apple, Google or Microsoft, the name and email they share with us (Google also shares a profile photo address, which we don't use) | Create and secure your account, sign you in on your devices | Contract | Until you delete your account (section 7) |
| Password (stored as a hash by Google Firebase Authentication), two-factor (TOTP) enrolment if you turn it on | Sign-in security | Contract | Until you delete your account |
| Your agreement to the Terms and your privacy choices (which version, when) | Show what you agreed to; honour your choices | Contract; legal obligation | Until you delete your account |
| Devices linked to your account: an installation ID, the device name, platform, operating-system and app version, when it was last seen. On Windows the device name is the computer's name, which may include your name | Show and manage your devices; security notices (“new device added”) | Contract; legitimate interest (security) | Until you delete your account; removed devices are marked removed |
| Password-reset and sign-in requests: email address (hashed for rate limiting) and IP address | Stop abuse of password reset | Legitimate interest (security) | Up to 24 hours |
3.2 Subscriptions and purchases
| What | Why | Legal basis | Kept |
|---|---|---|---|
| Subscription status, product, store (App Store, Google Play, Paddle), renewal date, entitlement records; store transaction identifiers; the notifications Apple, Google and Paddle send us when a subscription starts, renews, changes or is refunded (including the full notification Paddle sends) | Give you the features you paid for on every device | Contract | While your account exists; then a de-identified copy for tax and accounting (section 7) |
| AI credit balance and usage (tokens, cost, model, device, session) | Run and bill the Assistant | Contract | While your account exists; then a de-identified copy |
| Your approximate country (from your IP address or store storefront) at checkout | Show the right price and tax | Contract; legal obligation | Not stored by us |
We never receive your full card details. Our former payment processor, Stripe, still holds records for customers who bought before we moved to Paddle.
3.3 Things you save to the cloud
When you save a project to the cloud, upload audio or media, create a template, or sync preferences, we store:
| What | Where | Why | Kept |
|---|---|---|---|
| Projects (structure and contents), audio and media files with their file names, templates, synced settings | Google Cloud Firestore and Cloudflare R2 | Store and sync your work across your devices | Until you delete them. Deleted items stay in the trash for a limited time (currently 30 days), then are permanently deleted |
| When your storage plan ends | — | — | Files above the free allowance may be deleted 90 days after the plan ends; we email you first |
3.4 Sharing
- Public links. When you share a file or template by link, anyone with the link can open it until you stop sharing, delete the file, or delete your account. Links don't expire on their own.
- Sharing with a person. When you share with someone by email, we store their email address and account so they can open it. Both of you can see the share.
3.5 The Assistant
RISR's Assistant can work in two ways:
- RISR's hosted Assistant (uses RISR credits). What you send (your messages, images you attach, screenshots and project details the Assistant reads to help you) goes to our servers and from there to our AI provider OpenRouter, which passes it to the AI model that answers (models and providers change over time). Today we don't store the content of your conversations on our servers; we keep usage records such as the number of tokens and the cost. Our AI providers process the content to produce the answer, under their own terms and retention. We don't use your conversations or projects to train AI models without your permission. Conversations are kept on your device with your project.
- Your own provider. If you connect your own AI service (for example a local model, or your own account with an AI company), the app sends your messages directly from your device to that service, using your key. We store the connection's name, address and model in your account so it appears on your other devices; we never receive or store your key. That service's own privacy policy applies.
Dictation in the Assistant chat uses your device's speech recognition. On iPhone, iPad and Mac it runs on the device. On Android and Windows, your operating system may send the audio to Google or Microsoft, depending on your device settings.
3.6 Remote access (MCP)
RISR can let AI tools and other software control the app through the Model Context Protocol (MCP). It is off for other devices by default: only the device itself can connect, with a security token. If you turn on access from other devices (RISR Pro), devices on your network can connect with the token. If you use RISR's remote relay (mcp.risr.app), requests and replies pass through our relay on Cloudflare. The tools you connect receive whatever project and app data you let them read; their own terms apply.
3.7 Email
- Service email about your account and subscription (verification, password reset, receipts, renewal and billing, new or removed devices, account deletion). Sent under our contract with you, not marketing.
- Marketing email (product news and tips) only if you opt in, at sign-up, on the website newsletter form, or later in Settings → Privacy. Every marketing email has a one-click unsubscribe. We keep a suppression list so we don't email you again after you unsubscribe.
- Newsletter sign-up without an account: your email, the consent text you agreed to and when. You can unsubscribe from any email, or write to us to have it deleted.
- Support email: when you write to us, we keep your message, your contact details and, if you have an account, a snapshot of your subscription and devices so we can help. We keep it as long as we need it to help you and keep a record of our support (currently up to 2 years).
We send all email through Twilio SendGrid, which also tells us whether an email was delivered, bounced or opened.
3.8 Crash and error reports
When something goes wrong, the app can send a report to our error-monitoring provider Sentry (Functional Software, Inc., USA): the error and stack trace, which part of the app was active, app version, device and operating-system or browser details, your IP address, and a short trail of recent app events. We use reports only to find and fix problems. Legal basis: legitimate interest (keeping RISR working), or your consent where the law requires it. Sentry keeps reports for a limited period under our retention settings.
3.9 Feedback
If you rate or comment on a building block in the app, we store your rating, words and note with your account so our team can improve RISR. Kept until you delete your account.
3.10 Technical data and logs
Like any online service, our servers and providers see your IP address and basic device and browser information when your app or browser connects. We use this to deliver the service and keep it secure:
- Hosting: our website runs on Vercel and Cloudflare; our servers on Google Cloud (Firebase). They keep standard request logs for a limited period.
- Server logs: our Cloud Functions logs may include your account ID or email when something about your account is processed; kept for a limited period (currently about 30 days).
- Security checks: we use Google reCAPTCHA Enterprise (Firebase App Check) to check that requests come from a genuine app or browser; Google receives browser and device signals for this.
- Downloads the app makes: app updates and interface updates (from risr.app and
cdn.risr.app), the in-app news feed, the app's fonts from Google Fonts, and, for some camera features, machine-learning models from public content networks. These servers see your IP address; we send no account information with them. - Mac and Windows updates include only the platform, release channel and app version; not your account.
Cookies and browser storage
The risr.app website does not use analytics or advertising cookies. It keeps you signed in using your browser's storage. On the checkout page, our merchant of record Paddle uses its own cookies and storage to run the payment; see Paddle's notice. Your theme choice is remembered in your browser.
4. Permissions on your device
RISR asks for these permissions only when you use a feature that needs them. Everything here is processed on your device unless the table says otherwise.
| Permission | Used for | Platforms |
|---|---|---|
| Microphone | Audio input, voice-to-MIDI, dictation | iPhone, iPad, Mac, Windows, Android |
| Camera | Video input; face, hand, body and object tracking as control signals; photos for the Assistant (sent only if you attach them, section 3.5) | iPhone, iPad, Mac, Windows, Android |
| Face and body tracking (ARKit) | Face expressions and body position as control signals | iPhone, iPad |
| Speech recognition | Dictation (on-device on Apple; may use Google/Microsoft on Android/Windows) | All apps |
| Motion and pressure sensors | Movement and air pressure as control signals | iPhone, iPad, Android |
| Local network | Finding and connecting to your other RISR devices and RISR Link, lighting and OSC equipment you set up | All apps |
| MIDI, USB and game controllers | Connecting instruments and controllers | All apps |
| Photos | Choosing a photo for the Assistant | iPhone, iPad, Mac |
| Notifications | App notices | Android |
Local network details. To find your other devices, RISR announces itself on your local network with the device's name (on Windows, the computer's name), a device ID, and a security key fingerprint. Devices signed in to the same RISR account can connect to each other without a pairing prompt. Data you route between devices travels on your network, not through us.
Android backup. Android may include your RISR projects and settings in your Google device backup, under Google's terms. Your sign-in keys are excluded.
5. Who we share personal information with
We share personal information only with the providers that run RISR for us (processors), under contracts that limit their use to providing their service, and with the stores and Paddle as described above. Our current providers are listed below; we update this list when they change.
| Provider | What for | Location |
|---|---|---|
| Google (Firebase Authentication, Firestore, Cloud Functions, Cloud Logging, reCAPTCHA Enterprise, Google Fonts) | Accounts, database, servers, logs, security checks, fonts | USA |
| Cloudflare (R2 storage, network, relay) | Storing your cloud files, delivering downloads, website network, remote-access relay | USA / global |
| Vercel | Website hosting | USA / global |
| Twilio SendGrid | USA | |
| Sentry (only if you opt in) | Crash reports | USA |
| OpenRouter and the AI model provider it routes to | The hosted Assistant | USA and other countries |
| Paddle | Merchant of record for web, Mac and Windows purchases | UK / USA |
| Apple, Google | App Store and Google Play purchases, sign-in with Apple/Google | USA |
| Microsoft | Sign-in with Microsoft | USA |
| Stripe | Former payment processor (records of earlier purchases) | USA |
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business (you would be told).
People at RISR. Staff who need it can see account, subscription, device and support information to help you and keep RISR running. Access is limited by role and protected by two-factor sign-in.
6. International transfers
We are based in the United States, and our providers process data in the United States and other countries. Where the law of your country requires it (for example the EEA, the UK and Switzerland), we rely on the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses.
7. How long we keep it, and deleting your account
We keep personal information only as long as we need it for the purposes above, or as the law requires.
Deleting your account. You can delete your account in the app's account settings or on risr.app/account. Your account stays recoverable for a short period (currently 30 days); sign in during that time to cancel. After that we permanently delete your account, your cloud files and templates, your shared links and shares, your devices, your consent and preference records, your email and newsletter records, and your Assistant and credit records. A subscription bought on the website or in the Mac or Windows app is cancelled; App Store and Google Play subscriptions must be cancelled in the store. Data stored on your devices stays there until you delete the app.
Backups. Copies may remain in encrypted backups for up to 90 days, used only for disaster recovery.
What we keep after deletion. Transaction, billing, tax and invoice records are kept as tax and accounting law requires, in a form that no longer identifies your account where possible. We also keep security and administrative audit logs with your personal details removed, and a one-way code that shows an account was deleted. Paddle, Apple and Google keep their own records of your purchases.
8. Your rights and choices
- Choices in the app: marketing email (Settings → Privacy, or risr.app/account); stop sharing any link; delete files; disconnect devices; turn remote access off; delete your account.
- Your rights: depending on where you live (including the EEA, UK, Switzerland and California), you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to processing, and to withdraw consent at any time. Email [email protected]; we respond within the time the law requires and may need to verify it's you. You can download your cloud files from the app; for a full copy of your account data, email us.
- California: we do not sell or share personal information (as those words are defined in the CCPA) and do not use sensitive personal information to infer characteristics.
- Complaints: if you are in the EEA or UK, you can complain to your data-protection authority.
9. Security
We use reasonable security measures, such as encrypted connections to our services, encryption at rest by our providers, and restricted staff access. No system is perfectly secure; if a security incident affects your data, we will tell you as the law requires.
10. Children
RISR is not directed to children under 13 (or the higher age the law sets where you live), and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
11. Changes
We'll update this policy when RISR changes. For material changes we'll give you notice (for example by email or in the app) and, where the law requires, ask for your consent. The date at the top shows the latest version.
12. Contact
Viralinx LLC · [email protected]
RISR is a product of Viralinx LLC, a Wyoming limited liability company. © Viralinx LLC. RISR is a trademark of Viralinx, LLC.