Rize by LOL Studio Inc.

Provider: LOL Studio Inc. ("LOL Studio", "we", "us")

Product: Rize — voice-first AI alarm, morning briefing, and family companion app

Availability: United States and Canada only

Last updated: [DATE — set on publish]

Privacy contact: support@rizealarm.ai · LOL Studio Inc. [COUNSEL: mailing address]


1. Summary (the short version)

on-device where your phone supports it; when on-device recognition is unavailable or fails,

the audio may be sent to Apple or OpenAI (Whisper) to be turned into text. Command audio

and transcripts are discarded after your request is parsed.

family — not to build advertising profiles. We do not sell your personal information, and we

do not sell or share children's personal information for any commercial purpose.

2. Information we collect

We collect only what a feature you use requires:

CategoryExamplesWhySource
Accountemail address and password, or your Apple Sign-In identifiercreate/secure your accountyou
Profile & settingsname/nickname, timezone, voice choice, briefing section prefs, quiet hourspersonalize the appyou
Alarms / reminders / timerstimes, labels, recurrencerun the core featuresyou
Journal entriestext transcribed from your speech (see §3 — on-device by default; cloud transcription only if you choose the standard privacy level)your private journal + recallyou (voice → transcript)
User-to-user (U2U) voice messagesrecorded or synthesized voice clips, recipient, delivery statusdeliver a message you send to a contactyou
Location-derived dataa named place (e.g. "Work") and a one-time foreground fix for ETA/trafficcommute/smart-wake features you enabledevice, with permission
Contactscontact names/numbers you pick for U2U or quick-contactssend a message to someone you choosedevice, with permission
Family dataparent-owned child/pet profiles (first name, age band, content prefs), family reminders, "proud moments"run the shared household experiencethe parent/guardian
Diagnostics & analyticsapp events, crash reportskeep the app working; measure the productdevice

What we do NOT do: no background/continuous location tracking (named places + one-time

foreground fixes only — no people-tracking); no building of voice-training datasets from user or

child speech; no advertising SDKs ship in the app.

3. Voice data (how we handle the thing people worry about)

tries your phone's on-device recognizer first. If on-device recognition is unavailable or fails

before producing text, Rize retries through Apple's speech service, and if that also fails it

records a short clip and sends it to OpenAI Whisper for transcription. The audio and transcript

are used to parse your request and then discarded; neither is stored by Rize. We do not describe

Rize as "on-device only."

on-device recognition and every cloud fallback is disabled — if your phone cannot transcribe

on-device, the entry simply is not captured rather than uploaded. If you switch journaling to the

standard privacy level, the same Apple/OpenAI fallbacks as voice commands may be used for

journal dictation. Journal text is stored in your private account; audio is not retained.

private, access-controlled store, and are subject to a 90-day retention limit.

or explicitly approved. Any voice cloning (making a message sound like the sender) ships only

with the explicit consent of the person whose voice is used. [Counsel: voiceprints may be

regulated biometric identifiers under BIPA (IL), CUBI (TX), and WA — confirm consent capture +

retention before enabling.]

4. How we use your information

To provide and operate the features you use; to personalize your experience; to send you the

notifications and messages you enable; to secure accounts and prevent abuse; to diagnose problems

and improve the product; and to comply with law. We do not use your content to serve ads.

5. Service providers (subprocessors)

We share data with providers only as needed to run Rize, under contract:

[Confirm the exact, final subprocessor list and each one's data-handling terms before publishing.]

We do not sell your personal information, and we do not share it for cross-context behavioral

advertising.

6. Payments

Subscriptions are billed by Apple [and Google Play if Android ships]. We receive

purchase/entitlement status from [RevenueCat] to unlock features; we do not receive or store your

full payment card details.

7. Children's privacy (COPPA / family plan)

This mirrors §B.6 of the Terms/EULA and LEGAL-REVIEW-T8-KID-DATA.md:

data is the parent's data about their own child (first name, age band, content prefs).

transcribed on-device with transcripts discarded, no retained child voice recordings, and no

voice datasets built from child speech; this section will be updated with the verified behavior

before the feature ships.

outside-family messaging in kid mode.

offered a data export and children's personal information is deleted 30 days after

dissolution (enforced by an automated purge). A parent may request deletion of an individual

child's data at any time via the in-app remove-child flow (Family → member → Remove) or by

emailing support@rizealarm.ai; removal takes effect immediately in the app and the underlying

data is permanently purged by the same automated process within 30 days.

explicit consent mechanism, before kid features ship.

[Counsel to confirm Law 25 minors' specifics.]

8. Your rights & choices

Account, or email support@rizealarm.ai.

Settings; denying a permission disables the related feature but not the whole app.

do not sell/share as defined, but a "Do Not Sell or Share My Personal Information" control is

provided in-app. [Wire + enforce it — see R9; a dead control is a liability.]

9. Data retention

We keep data while your account is active and as needed to provide features: U2U messages

90 days; family/child data deleted 30 days after dissolution; diagnostics and product analytics

events are retained for up to 12 months.

On account deletion we delete or de-identify your personal information within [30] days, except

where retention is legally required.

10. Security

Access is protected by per-user database row-level security; auth tokens are stored in the device

secure keystore; U2U media is kept in private, access-controlled storage. No system is perfectly

secure, but we design for least-privilege access. [Confirm encryption-at-rest/in-transit

statements with counsel + infra.]

11. International & data location

Rize is offered in the U.S. and Canada; data is processed and stored on infrastructure located

in the United States (AWS us-west-2, Oregon). If you use Rize from Canada, your personal

information is transferred to and stored in the United States, where it is subject to U.S. law and

may be accessible to U.S. authorities under lawful process. By using Rize you consent to this

transfer; the protections described in this policy apply wherever the data is processed.

12. Changes to this policy

We will post changes here and update the "Last updated" date; material changes will be notified

in-app or by [email].

13. Contact

support@rizealarm.ai · LOL Studio Inc. [COUNSEL: mailing address]. Canadian users may contact our [privacy

officer — Law 25 may require naming one].


Open items for Drew + counsel (privacy-specific)


*Draft prepared 2026-07-21 by Hermy (engineering) from the shipped app behavior. Not legal advice.

For Drew and licensed counsel to review, complete, and approve before any public use.*

© LOL Studio Inc. · Rize is available in the U.S. and Canada. · Contact