Privacy Policy
Last updated: May 21, 2026
River of Light is built by North Island Technologies, LLC (“we”, “us”, “our”). This policy describes what we collect when you use River of Light, how we use it, and the choices you have. It covers the River of Light mobile app, the web app at app.riveroflight.app, the River of Light Chrome extension, and related services (together, the “App”).
Information We Collect
Account information. We sign you in through Auth0. From your identity provider — most often Sign in with Apple — we receive a stable user identifier and an email address. If you use Sign in with Apple, that email may be Apple’s private relay address.
Music data you connect.
- Spotify. If you connect Spotify, we use OAuth to read your saved tracks, top artists and tracks, recently played tracks, currently playing track, and library and playlists. We also request permission to create and modify playlists — so we can write recommendations back as a river of light recs playlist — and to control playback from within the app. We store the access and refresh tokens needed to make these calls. You can revoke our access at any time at spotify.com/account/apps.
- YouTube Music. The optional River of Light Chrome extension reads your YouTube Music library from your existing browser session on music.youtube.com and sends it to River of Light so we can show and use it inside the app. The extension does not collect anything beyond what is needed to import that library.
Your activity in the App. Songs you rate, songs you mark as listened, playlists you create, sources you trust or hide, and the chat and recommendation queries you send.
Subscription state. Paid features are gated by RevenueCat, which receives a stable user identifier and your Apple-issued receipt and reports back whether your subscription is active. We do not see your payment card; Apple handles billing.
Device and diagnostic data. Standard logs (IP address, app version, OS version, timestamps) used to keep the service running and debug problems.
How We Use Your Information
- To run the product — rate, save, search, recommend, chat, and curate your library.
- To generate recommendations and chat replies. Your inputs and relevant library context are sent to AI models hosted on Amazon Bedrock (Anthropic Claude). Bedrock’s terms prohibit using your inputs to train those models.
- To deliver transactional email — such as a notice when a fresh batch of recommendations is ready — via Amazon SES.
- To keep the service safe and improve it: detect abuse, fix bugs, and measure usage.
What Other Users Can See
- Public profile pages. If you have a profile page, your handle and the library highlights you’ve chosen to make public are visible to anyone with the link. You control what is public from Settings.
- Friend graph. If you and another River of Light user are friends, certain library and rating signals are visible to each other to power friend-weighted recommendations.
Who We Share With
We share information only with the service providers we need to run the product:
- Auth0 — authentication.
- Amazon Web Services (Bedrock, SES, S3, RDS) — hosting, AI inference, email, storage.
- Spotify AB — when you connect Spotify, you authorize us to call the Spotify Web API on your behalf.
- Google LLC — only insofar as the Chrome extension reads your YouTube Music session in your own browser.
- RevenueCat, Inc. — subscription verification.
- Apple Inc. — App Store billing and Sign in with Apple.
We do not sell your personal information, and we do not run third-party advertising in the App.
Retention and Deletion
We keep your data while your account is active. You can delete your account and all associated data at any time from Settings → Delete account in the App, or by emailing support@riveroflight.app. Deletion removes your ratings, playlists, social connections, and your stored Spotify and YouTube Music credentials. Some operational logs may persist for a short period before automatic expiry.
Children’s Privacy
River of Light is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have, please contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. We will change the “Last updated” date above, and material changes will be announced in the App.
Contact
North Island Technologies, LLC
support@riveroflight.app