Trust & privacy

This page is maintained by RhyReel to answer common security and privacy questions about the app. It describes current practices — it is not a certification or an independent audit.

Accounts & access

Accounts are protected by email + password or Google sign-in. Role-based access is enforced server-side; client-supplied role claims are ignored.

Listener, creator, and admin permissions live in a dedicated roles table and are checked on every privileged request.

Data protection

All traffic between your device and RhyReel is encrypted in transit (HTTPS/TLS). Your database is hosted on a managed backend with encryption at rest provided by the platform.

Row-level security is enabled on every user-facing table. Wallet balances, credit transactions, and support payments can only be written by trusted server-side functions — never directly from the client.

What we store

Your profile (name, handle, avatar), the tracks and covers you upload, comments, likes, follows, and a record of credit top-ups and supports you send or receive.

Audio, cover art, and video files are kept in private storage buckets and served through short-lived signed URLs.

Payments

Card payments are processed by Stripe. RhyReel never sees or stores your full card number — Stripe handles card data directly under their PCI-compliant infrastructure.

Stripe Connect identifiers used for artist payouts are stored in a private table that is not readable from the client.

Privacy requests & contact

To request a copy of your data, delete your account, or report a security issue, contact support@rhyreel.com.

Please do not include passwords or payment details in your message.

Last updated · 7/22/2026