Privacy Policy
RioStudio is an app that turns a topic into a short narrated video. It is operated by RioReply ("we"). This policy explains what the app and our server collect, why, who helps us process it, and how to delete it. Questions: info@rioreply.app.
No account
RioStudio has no sign-up. The app creates a random identifier (an "install ID") the first time it runs and keeps it in your device's Keychain. It is not linked to your name, email address or Apple ID, and it is how our server knows which videos and credits are yours.
What we collect
- Install ID, sent with every request, to keep your library and credits.
- What you create: the topics you enter, the scripts we write or you edit, your choices (style, voice, language, length, audio and motion), and the images, audio and video rendered for you.
- Credits: a record of credits granted and spent (welcome credits, rewarded ads, subscription allowance, renders and refunds).
- Purchase status: when you subscribe, the app sends the signed purchase record that Apple gives it. We verify it with Apple's signature to see whether you have RioStudio Pro and which plan. We never see your payment details.
- Push token: if you allow notifications, your device's Apple push token, so we can tell you when a video is ready or could not be made.
- IP address: used in memory to limit request rates, and stored only as a keyed one-way hash to limit how many new installs get free credits from one network. We do not store the raw address.
- Ads (free users): Google AdMob shows ads and rewarded ads. Google may collect device and usage data according to your iOS tracking choice and Google's policies. When you finish a rewarded ad, Google tells our server your install ID and an ad transaction ID so we can grant the credit.
Our server logs record events such as "render failed" with video IDs and error codes. They do not contain your topics or scripts, your push token or your purchase records.
Photos you upload
When you use Restore & colorize or Bring it to life, the photo you choose is uploaded to our server and processed on our GPU servers (RunPod) to restore, colorize, upscale or animate it. The original you uploaded is deleted as soon as its restore finishes or fails. The results (the restored photo, a small "before" copy for the comparison slider and any animation) are kept in your library until you delete them; deleting a photo deletes its files. Your photos are never used to train AI models.
Who processes it for us
- Anthropic (Claude) writes scripts from your topic and reviews edited scripts for safety.
- Google (Gemini text-to-speech) voices narration in languages other than English. AdMob serves ads.
- RunPod provides the GPU servers that render images, voice and video and process the photos you upload.
- Apple handles purchases, subscriptions and push notifications.
- Our API server and the stored files run on Amazon Web Services (Lightsail).
They receive only what their task needs (for example, the script text for voicing, not your install ID). We do not sell your data or share it for anyone else's advertising.
How long we keep it
- Videos stay in your library until you delete them. Deleting a video deletes its rendered images and video file at once. A short record of the deleted video (its topic and script) stays in our database, marked deleted, so daily limits and abuse checks keep working; email us to have it erased completely.
- Credit records and the install record are kept while the app is in use, so your balance is correct.
- Your push token is removed when the app turns notifications off or Apple tells us it is no longer valid.
Deleting your data
Delete any video in the app to remove its files. For anything else (all your videos, credit history, push token, install records), email info@rioreply.app with your install ID (Settings → Copy install ID in the app) and we will erase it within 30 days. Deleting the app does not delete server data by itself, because we cannot tell who you are without the install ID.
Children
RioStudio is not directed at children under 13, and we do not knowingly collect data from them. If you think a child has used the app, contact us and we will delete the related data.
Security
Connections use HTTPS. Media links are signed and expire. Access to the server is restricted to the operator.
Changes
If this policy changes, we will update this page and its date. Material changes will also be shown in the app.