Privacy Policy
1. Scope
This Privacy Policy explains how Rikayne processes information when you use Rikayne Music Blueprints, its customer access system, and related Rikayne services that link to this policy (collectively, the “Service”). Contact: rikaynemusic@gmail.com.
2. Information we process
Google account information. When you choose Google sign-in, the Service receives a stable Google account identifier and may receive your email address and basic profile information under the scopes you approve. Rikayne does not receive your Google password.
Rikayne account and access information. We may process your Rikayne account identifier, product access, license or tester status, validity dates, feature eligibility, and saved service preferences.
License activation information. When you submit a Rikayne license code for activation or renewal, the Action temporarily processes the submitted code to verify eligibility for the authenticated Rikayne account. Rikayne does not store the reusable plaintext license code in ordinary database rows. The licensing database stores a one-way verifier, the last four display characters, license status and assignment metadata, and redemption or renewal history needed to provide and audit access.
Technical and security information. We may process request identifiers, timestamps, access decisions, errors, limited audit records, idempotency records, and per-account action-attempt counters needed to operate, secure, rate-limit, and troubleshoot the Service. Rikayne's application-level license-activation limiter does not require storing an IP address, although infrastructure providers may process network information as part of hosting and security operations.
Conversation content. Rikayne account and licensing Actions do not require or intentionally store ChatGPT prompts, generated lyrics, music, or creative output in the Rikayne customer database. If you type a license code into ChatGPT for activation, that credential is part of the request sent through ChatGPT to the licensing Action and is processed only as needed to perform that activation request.
3. How we use information
- authenticate and link the correct customer account;
- verify paid-license or authorized-tester access;
- activate or renew eligible paid or tester access;
- provide eligible features and saved preferences;
- prevent abuse, rate-limit activation attempts, investigate errors, and protect the Service;
- maintain auditability and improve reliability; and
- comply with applicable legal obligations.
4. OAuth tokens
Rikayne exchanges the short-lived Google authorization code on its server. The raw Google access token is used to obtain the verified Google account identifier. The Google ID token from the same verified exchange is passed to Supabase Auth so Supabase can create or resolve the corresponding Google identity and Rikayne account. Neither Google token is sent to ChatGPT or the Rikayne customer API, and Rikayne does not intentionally store either raw Google token. Rikayne then issues opaque, limited-purpose access and rotating refresh tokens for the Action. Only SHA-256 hashes of those Rikayne tokens are stored in the private authorization database.
ChatGPT sends the opaque Rikayne access token when it calls the customer API. The API validates that token, its client binding, approved scope, expiry, and revocation status before mapping the Google identifier to a Rikayne account. Raw OAuth access and refresh tokens are not stored in the Rikayne customer database.
You can review or revoke Google account access at Google Account permissions.
5. Service providers and data sharing
The Service relies on:
- Google, for account authentication;
- OpenAI and ChatGPT, for the GPT interface and Action requests;
- Supabase, for authorization, API hosting, account records, and logs; and
- Cloudflare, for hosting this public information page.
These providers process information under their own terms and policies. Rikayne does not sell or rent personal information and does not use customer account information for third-party behavioral advertising.
6. Data retention
Authorization transactions and one-time OAuth codes are retained briefly. Rikayne access-token hashes are retained until expiry, revocation, or routine cleanup. Refresh-token family records use a fixed session expiry, after which their hashes are removed by routine cleanup. Reusable plaintext license codes are not stored in ordinary database rows after issuance or submission; one-way verifiers, last-four display characters, license metadata, entitlement or tester records, and redemption history may be retained as operational or core account records. Short-lived idempotency records and compact per-account rate-limit state may also be retained as needed to prevent duplicate processing and abuse. Account-linking, entitlement, preference, and audit records are retained only as reasonably necessary to provide and secure the Service, resolve disputes, and meet legal obligations.
7. Your choices and requests
You may revoke Google access or disconnect the Action from ChatGPT. Depending on your location, you may also request access, correction, deletion, restriction, or a copy of certain personal information. Email rikaynemusic@gmail.com from the address connected to your Rikayne account. Reasonable verification may be required before a request is completed.
8. Data security
Rikayne uses access controls, short token lifetimes, one-time authorization codes, PKCE for the Google exchange, rotating refresh tokens, hashed token storage, one-way license-code verifiers, per-account activation rate limiting, and limited-purpose processing. No internet service can guarantee absolute security.
9. International processing
The Service and its providers may process information in countries other than where you live. Where required, we rely on safeguards provided by the relevant service providers or applicable law.
10. Children’s privacy
The Service is not directed to children under 13, and Rikayne does not knowingly collect personal information from children under 13.
11. Changes to this policy
We may update this Privacy Policy when the Service, legal requirements, or data practices change. The “Last updated” date indicates the latest revision.
12. Contact
Rikayne
Email: rikaynemusic@gmail.com
Official links:
linktr.ee/rikaynemusic