Provider: LOL Studio Inc. ("LOL Studio", "we", "us")
Product: Rize — voice-first AI alarm, morning briefing, and family companion app
Availability: United States and Canada only
Last updated: [DATE — set on publish]
Privacy contact: support@rizealarm.ai · LOL Studio Inc. [COUNSEL: mailing address]
on-device where your phone supports it; when on-device recognition is unavailable or fails,
the audio may be sent to Apple or OpenAI (Whisper) to be turned into text. Command audio
and transcripts are discarded after your request is parsed.
family — not to build advertising profiles. We do not sell your personal information, and we
do not sell or share children's personal information for any commercial purpose.
We collect only what a feature you use requires:
| Category | Examples | Why | Source |
|---|---|---|---|
| Account | email address and password, or your Apple Sign-In identifier | create/secure your account | you |
| Profile & settings | name/nickname, timezone, voice choice, briefing section prefs, quiet hours | personalize the app | you |
| Alarms / reminders / timers | times, labels, recurrence | run the core features | you |
| Journal entries | text transcribed from your speech (see §3 — on-device by default; cloud transcription only if you choose the standard privacy level) | your private journal + recall | you (voice → transcript) |
| User-to-user (U2U) voice messages | recorded or synthesized voice clips, recipient, delivery status | deliver a message you send to a contact | you |
| Location-derived data | a named place (e.g. "Work") and a one-time foreground fix for ETA/traffic | commute/smart-wake features you enable | device, with permission |
| Contacts | contact names/numbers you pick for U2U or quick-contacts | send a message to someone you choose | device, with permission |
| Family data | parent-owned child/pet profiles (first name, age band, content prefs), family reminders, "proud moments" | run the shared household experience | the parent/guardian |
| Diagnostics & analytics | app events, crash reports | keep the app working; measure the product | device |
What we do NOT do: no background/continuous location tracking (named places + one-time
foreground fixes only — no people-tracking); no building of voice-training datasets from user or
child speech; no advertising SDKs ship in the app.
tries your phone's on-device recognizer first. If on-device recognition is unavailable or fails
before producing text, Rize retries through Apple's speech service, and if that also fails it
records a short clip and sends it to OpenAI Whisper for transcription. The audio and transcript
are used to parse your request and then discarded; neither is stored by Rize. We do not describe
Rize as "on-device only."
on-device recognition and every cloud fallback is disabled — if your phone cannot transcribe
on-device, the entry simply is not captured rather than uploaded. If you switch journaling to the
standard privacy level, the same Apple/OpenAI fallbacks as voice commands may be used for
journal dictation. Journal text is stored in your private account; audio is not retained.
private, access-controlled store, and are subject to a 90-day retention limit.
or explicitly approved. Any voice cloning (making a message sound like the sender) ships only
with the explicit consent of the person whose voice is used. [Counsel: voiceprints may be
regulated biometric identifiers under BIPA (IL), CUBI (TX), and WA — confirm consent capture +
retention before enabling.]
To provide and operate the features you use; to personalize your experience; to send you the
notifications and messages you enable; to secure accounts and prevent abuse; to diagnose problems
and improve the product; and to comply with law. We do not use your content to serve ads.
We share data with providers only as needed to run Rize, under contract:
[Confirm the exact, final subprocessor list and each one's data-handling terms before publishing.]
We do not sell your personal information, and we do not share it for cross-context behavioral
advertising.
Subscriptions are billed by Apple [and Google Play if Android ships]. We receive
purchase/entitlement status from [RevenueCat] to unlock features; we do not receive or store your
full payment card details.
This mirrors §B.6 of the Terms/EULA and LEGAL-REVIEW-T8-KID-DATA.md:
data is the parent's data about their own child (first name, age band, content prefs).
transcribed on-device with transcripts discarded, no retained child voice recordings, and no
voice datasets built from child speech; this section will be updated with the verified behavior
before the feature ships.
outside-family messaging in kid mode.
offered a data export and children's personal information is deleted 30 days after
dissolution (enforced by an automated purge). A parent may request deletion of an individual
child's data at any time via the in-app remove-child flow (Family → member → Remove) or by
emailing support@rizealarm.ai; removal takes effect immediately in the app and the underlying
data is permanently purged by the same automated process within 30 days.
explicit consent mechanism, before kid features ship.
[Counsel to confirm Law 25 minors' specifics.]
Account, or email support@rizealarm.ai.
Settings; denying a permission disables the related feature but not the whole app.
do not sell/share as defined, but a "Do Not Sell or Share My Personal Information" control is
provided in-app. [Wire + enforce it — see R9; a dead control is a liability.]
We keep data while your account is active and as needed to provide features: U2U messages
90 days; family/child data deleted 30 days after dissolution; diagnostics and product analytics
events are retained for up to 12 months.
On account deletion we delete or de-identify your personal information within [30] days, except
where retention is legally required.
Access is protected by per-user database row-level security; auth tokens are stored in the device
secure keystore; U2U media is kept in private, access-controlled storage. No system is perfectly
secure, but we design for least-privilege access. [Confirm encryption-at-rest/in-transit
statements with counsel + infra.]
Rize is offered in the U.S. and Canada; data is processed and stored on infrastructure located
in the United States (AWS us-west-2, Oregon). If you use Rize from Canada, your personal
information is transferred to and stored in the United States, where it is subject to U.S. law and
may be accessible to U.S. authorities under lawful process. By using Rize you consent to this
transfer; the protections described in this policy apply wherever the data is processed.
We will post changes here and update the "Last updated" date; material changes will be notified
in-app or by [email].
support@rizealarm.ai · LOL Studio Inc. [COUNSEL: mailing address]. Canadian users may contact our [privacy
officer — Law 25 may require naming one].
PrivacyInfo.xcprivacy*Draft prepared 2026-07-21 by Hermy (engineering) from the shipped app behavior. Not legal advice.
For Drew and licensed counsel to review, complete, and approve before any public use.*