Privacy for self-hosted Riffbase
Last updated 3 October 2026. The repository has the same policy in docs/PRIVACY.md.
This applies when you install Riffbase yourself: with the Docker image, the Windows installer, or an Android build. In that case, you are the one running the installation. For the website and workspaces hosted in the cloud, see the privacy notice.
Who’s behind it
Riffbase is developed by Andrea Osma Rafael (andreaosma.com). If you install it yourself, there is no Riffbase server collecting anything: your installation doesn’t depend on a central server.
Where your data is
Everything (songs, lyrics, scores, recordings, setlists, calendar, accounts, and settings) is stored in a SQLite database you control: in the Docker volume you mount or, with the Windows installer, in %LOCALAPPDATA%\Riffbase\. Riffbase’s developer has no access to it, no copy, and no way to see it. How to back it up and restore it is in docs/DOCKER.md and docs/RUNBOOK.md in the repository.
Who is responsible for the data
Whoever runs the installation is the data controller for the people who use it, and that is who any request to access, correct, or delete data should go to. Riffbase’s developer cannot handle those requests because there is no access to the data. If you run Riffbase for other people, such as a school or another band, you may need your own privacy notice for them.
Optional outside services
They only turn on if you set them up with your own credentials, in environment variables or in Settings. None of them are needed for songs, scores, setlists, or the calendar.
- Resend (password reset). If you set
RIFFBASE_RESEND_API_KEY, “Forgot your password?” emails go out from your own Resend account. If not, no email is sent and you can change the password with flask reset-password. - External SSO or a reverse proxy (Authelia, Authentik, oauth2-proxy, Tailscale Serve, Cloudflare Access, and the like). Riffbase trusts a header your proxy adds; the proxy does the sign-in.
- Cloudflare Access (member sync). Only if you set
CF_ACCESS_ACCOUNT_ID and CF_ACCESS_API_TOKEN to sync your own member directory. Your token is used. - Instagram. Only if you set
META_APP_ID and META_APP_SECRET and connect an account. The tokens stay in your database. - Google Drive. Only if you connect it in Settings. The tokens stay in your database.
Stats, sharing, and deleting
There are no third-party stats, no ads, and nothing that sends information to Riffbase’s developer. Data only goes out to the services you switched on yourself.
To delete everything, remove the SQLite file or the Docker volume, or uninstall the app. Riffbase is not meant for children.
Contact
Questions about this policy: open a security advisory on the repository, or use the contact on andreaosma.com.
Privacidad de Riffbase autoalojado
Última actualización: 3 de octubre de 2026. El repositorio recoge lo mismo en docs/PRIVACY.md.
Esto aplica cuando instalas Riffbase tú: con la imagen de Docker, el instalador de Windows o una build de Android. En ese caso, quien gestiona la instalación eres tú. Para la web y los espacios alojados en la nube, mira el aviso de privacidad.
Quién está detrás
Riffbase lo desarrolla Andrea Osma Rafael (andreaosma.com). Si lo instalas por tu cuenta, no hay ningún servidor de Riffbase recogiendo nada: tu instalación no depende de un servidor central.
Dónde están tus datos
Todo (canciones, letras, partituras, grabaciones, setlists, calendario, cuentas y ajustes) se guarda en una base de datos SQLite que controlas tú: en el volumen de Docker que montes o, con el instalador de Windows, en %LOCALAPPDATA%\Riffbase\. Quien desarrolla Riffbase no tiene acceso a ella, ni copia, ni forma de verla. Cómo hacer copias y restaurarlas está en docs/DOCKER.md y docs/RUNBOOK.md del repositorio.
Quién responde de los datos
Quien gestiona la instalación es el responsable del tratamiento de los datos de las personas que la usan, y es a quien hay que dirigir cualquier petición para acceder a los datos, corregirlos o borrarlos. Quien desarrolla Riffbase no puede atender esas peticiones porque no tiene acceso a los datos. Si gestionas Riffbase para otras personas, como una academia u otra banda, puede que necesites tu propio aviso de privacidad para ellas.
Servicios externos opcionales
Solo se activan si los configuras tú con tus propias credenciales, en variables de entorno o en Ajustes. Ninguno hace falta para usar canciones, partituras, setlists o el calendario.
- Resend (restablecer la contraseña). Si defines
RIFFBASE_RESEND_API_KEY, los correos de «¿Olvidaste tu contraseña?» salen desde tu cuenta de Resend. Si no, no se envía ningún correo y puedes cambiar la contraseña con flask reset-password. - SSO externo o un proxy inverso (Authelia, Authentik, oauth2-proxy, Tailscale Serve, Cloudflare Access y parecidos). Riffbase se fía de una cabecera que añade tu proxy; el inicio de sesión lo hace el proxy.
- Cloudflare Access (sincronizar miembros). Solo si defines
CF_ACCESS_ACCOUNT_ID y CF_ACCESS_API_TOKEN para sincronizar tu propio directorio de miembros. Se usa tu token. - Instagram. Solo si defines
META_APP_ID y META_APP_SECRET y conectas una cuenta. Los tokens se quedan en tu base de datos. - Google Drive. Solo si lo conectas desde Ajustes. Los tokens se quedan en tu base de datos.
Estadísticas, datos compartidos y borrado
No hay estadísticas de terceros, ni anuncios, ni nada que envíe información a quien desarrolla Riffbase. Los datos solo salen hacia los servicios que hayas activado tú.
Para borrarlo todo, elimina el archivo SQLite o el volumen de Docker, o desinstala la app. Riffbase no está pensado para niños.
Contacto
Si tienes dudas sobre esta política, abre un aviso de seguridad en el repositorio o usa el contacto de andreaosma.com.