RiffHubWorkspace

Privacy policy

How RiffHub handles account, private workspace, public publication, and visitor request data.

2026-07-26

Data we process

RiffHub processes account identity, private repository and collaboration records, uploaded assets, product preferences, and creator-approved public publication data.

Public access requests

Visitors provide a name, email address, intended use, optional message, consent record, and an abuse-prevention fingerprint. Contact data is available only to the relevant work owner and is scheduled for deletion after 90 days.

Cookies and authentication

Strictly necessary Supabase Auth cookies maintain sessions. Language and theme cookies store non-sensitive product preferences for up to one year. Google is used only for identity when the user selects Google sign-in; RiffHub does not request Drive, contacts, calendar, or offline Google access.

Sharing and processors

Data is processed by the hosting, database, authentication, email, security-verification, and observability providers required to operate RiffHub. RiffHub does not sell personal data.

Your choices

Creators control whether a checkpoint is published and may unpublish it. Visitors may ask the work owner to close an access request. Account deletion is available after repository ownership and immutable-history requirements are resolved.

Contact and changes

Material changes will be dated on this page before they take effect. Use the product support channel associated with your RiffHub account for privacy requests.