Privacy
Last updated 18 July 2026
This is the short, human version, because that's the only kind worth reading. Riffle is a small task app, currently in a 30-person founding beta. This page covers what we collect, why, where it lives, and the control you have over it. The short story: we keep the data we need to run Riffle and nothing more, and we never sell or trade any of it.
Who we are
Riffle is operated by AgileTask OÜ (Estonia). Questions, requests, anything at all: support@agiletask.ai.
What we collect
- Your account email, so you can sign in and we can reach you.
- Display names and initials you set, so teammates recognise you.
- The text of your throws and cards: this is the app itself; it's the work you put in.
- Emails of teammates you invite, so we can send them an invite link.
- Standard server logs (IP address, timestamps, error traces), to keep the service running, fix bugs, and spot abuse.
We never store voice audio. Speech-to-text runs on your own device, so only the resulting text ever reaches us. The audio itself never leaves your phone or laptop. No ads, no selling your data, no third-party trackers. We run zero analytics right now, and if that ever changes we'll say so here first.
Where it lives
Everything sits in a Supabase PostgreSQL database hosted in the EU region. That's the home of your account and your work.
Who processes it
A few trusted services help us run Riffle. They only ever handle your data to do their job for us:
- Supabase: EU hosting, authentication, and the database itself.
- Anthropic: the text of a throw is sent to its API so it can be parsed into cards. Under Anthropic's commercial terms, API inputs and outputs are not used to train their models.
- OpenAI: when you hold to talk, the audio clip is sent to its API for transcription, then discarded. We never store audio. Under OpenAI's API terms, inputs and outputs are not used to train their models.
- Fly.io: web hosting, in its Amsterdam (EU) region.
Anthropic and OpenAI are US-based, so a little processing happens there under their standard data-processing terms. Your data at rest stays in the EU.
Why we're allowed to (legal basis)
Two reasons under the GDPR. Contract: we need this data to actually provide the service you signed up for: no email, no account; no card text, no app. And legitimate interest: a small amount, purely to keep things secure and to limit abuse of the beta.
How long we keep it
As long as your account exists. Delete your account in-app and your data cascades out with it. You don't have to email us to make that happen, though you're welcome to. Deletion completes fully within 24 hours; during beta an operator step finalizes the underlying auth records, which is what accounts for the gap.
Your rights
Under the GDPR you can ask us to give you a copy of your data (access), fix it if it's wrong (rectification), delete it (erasure), hand it over in a portable form (portability), and object to certain uses. Just email support@agiletask.ai and we'll sort it out, quickly. You also have the right to lodge a complaint with a data protection supervisory authority. For us that would be Estonia's, but you can also go to the one where you live.
Teammates
Only invite people who expect to collaborate with you. They sign in themselves through a link. We don't create accounts on anyone's behalf.
Changes
We'll note any changes right here. Beta means things move fast, so if something material changes we'll email you too.
Riffle · AgileTask OÜ (Estonia) · support@agiletask.ai