// LEGAL
PRIVACY POLICY
Last updated 9 September 2026.
0. DATA CONTROLLER
// OPERATOR / LEGAL ENTITY
- Operator
- SIA "RIZZ GROUP" (Sabiedrība ar ierobežotu atbildību · Latvian limited liability company)
- Registration No.
- 40203589324 — registered 18.09.2024 in the Commercial Register (Komercreģistrs) of Latvia
- VAT No.
- LV40203589324 (VAT-registered, active from 06.08.2025)
- SEPA identifier
- LV26ZZZ40203589324
- Registered address
- Strēlnieku iela 1A · 7, Rīga, LV-1010, Latvia
- Contact
- yes@rizzgroup.org
Governing law & jurisdiction: these terms and any use of the service are governed by the laws of the Republic of Latvia. Disputes are subject to the courts of Rīga, Latvia. Mandatory EU consumer-protection law continues to apply to consumers, including the right to bring proceedings in their country of residence.
1. WHAT WE STORE
- Account data — email, display name, password hash (via our auth provider), notification preferences.
- Uploaded audio files and any reference images / brand assets you provide.
- Lyrics — either transcribed from your audio or supplied by you.
- AI-generated assets — cover art, motion loops, lyric video, social crops, merch mockups, captions, campaign schedule.
- Analysis-derived data — BPM, key, mood tags, genre, sentiment, visual brief, style manifest, and (for ERA) your Visual Genome DNA profile.
- Payment metadata — Stripe customer id, price ids, subscription state. We do NOT store card numbers.
- Custom fonts and any Printful API keys you connect (encrypted at rest).
2. HOW WE USE IT
To analyse your audio, generate visuals and campaign assets, deliver your release pack, process payments, send transactional emails (release ready, campaign reminders you opt into), and improve the product's model routing.
3. PROCESSORS AND SUBPROCESSORS
Audio, prompts, images, and text are sent to the following providers strictly to fulfil generation and platform requests, grouped by purpose:
Platform & infrastructure
- Supabase — database, storage, authentication, server functions.
Payments & fulfilment
- Stripe — payments, billing portal, and artist payouts via Stripe Connect.
- Printful — merch production and fulfilment (only if you connect your account).
AI — language, analysis & critique
- Managed AI gateway — routing layer for our language and vision model calls.
- Google (Gemini) — audio/lyric analysis, art direction, critique, captions.
- OpenAI — language lanes and some image lanes.
- xAI (Grok) — language and image lanes.
AI — image generation
- fal.ai — image hosting/inference (FLUX, Ideogram, and fallback lanes).
- Pika — primary image host for several model lanes.
- ByteDance Seedream, Recraft, Ideogram, Stability AI, Google Imagen — image models routed through the hosts above.
AI — video & audio
- Runway, Luma, Kling, Pika — motion loops, canvas and film clips.
- ElevenLabs — lyric transcription, voiceover and sound effects.
- OpenAI (Whisper) — fallback transcription.
- Creatomate — video rendering (when configured).
Communications
- Resend — transactional email delivery (when configured).
Each subprocessor has its own privacy policy and its own retention behaviour. We send them only what a request needs. We cannot guarantee on their behalf how quickly they erase content they have processed, and we do not claim to control their internal copies. We also do not claim that a deletion or zero-retention option is switched on for our account with any particular provider: where such a setting exists we intend to use it, but unless we say otherwise for a named provider you should treat their published retention terms, not ours, as what applies to content they process.
4. RETENTION
Uploaded audio and generated assets are retained for the life of your account, so you can revisit past releases. Delete your account and we remove them (see section 6). Payment and invoice records are kept after account deletion for the period applicable accounting and tax law requires of us as a Latvian company.
Two operational records outlive an asset on purpose: an internal file-ownership record (which order a stored object belonged to, so that a file can never be re-claimed by someone else) and the consent timestamp recording that you asked for immediate delivery at checkout. Both are records about a transaction, not content, and both are needed to keep the system honest.
5. YOUR RIGHTS (GDPR / CCPA)
You have the right to access, correct, export, and delete your personal data. Access, correction, and export can be handled by emailing support with the address on file. Deletion is self-service (see below).
6. DELETING YOUR DATA
Go to Account settings → "DELETE MY ACCOUNT & DATA". Deletion runs in four checked stages, in this order: any active subscription is cancelled at our payment provider first; then the files you own are removed from storage — uploaded audio, generated artwork, video, published copies and their folders; then your records — orders, asset rows, campaign schedules, review links, render and generation jobs, custom fonts, artist DNA, Printful key, subscription rows, API keys, profile; and finally your login.
The stages run in order, so if one of them cannot finish, the ones before it have already happened. We will not pretend otherwise: a cancelled subscription is not reinstated, and files or records already removed are gone and cannot be restored. What we do instead is stop rather than continue blindly, keep your login working where the login stage has not run yet, tell you which stage failed, and put individual objects a storage call refused on a retry list to be attempted again. If a run stops part-way, some of your data is deleted and the rest still needs another attempt or a hand from support — we report that plainly rather than claiming either a clean sweep or an untouched account. Payment invoices are retained only where required by law.
One honest limitation: an artwork or video link you published yourself may stay readable for up to a minute after you unpublish it or delete your account, because our delivery layer caches a public release page that briefly. After that, every request is re-checked and refused.
7. INTERNATIONAL TRANSFERS
Our subprocessors operate in the EU and the United States, so some of your data is processed outside the EEA. For those transfers we rely on the transfer mechanism each provider publishes in its own data processing terms — commonly the European Commission's Standard Contractual Clauses, and in some cases the EU-US Data Privacy Framework. We name the providers above so you can read those terms yourself. We do not state which mechanism a given provider applies to our specific account, and we do not claim to have negotiated bespoke terms with any of them.
8. COOKIES
We use only strictly necessary cookies for authentication and session persistence. No advertising cookies, no third-party trackers embedded in the app itself.
9. CONTACT
Data requests: yes@rizzgroup.org. Operator / controller details are in section 0.