Riggle
Sign in

Legal

Privacy Policy

Effective 31 July 2026 · Riggle

Riggle is the controller of the personal data described here. This policy covers the Riggle app at https://app.riggle.megasaleapp.com.

What we collect

Account
Your email address, your display name and the provider account id we receive from Google, Discord or Facebook when you sign in. We never see or store your password for those accounts.
Your models
The file you upload, the marks you place on the face, and everything derived from them — the face render, the preview stills and video, and the finished VRM.
Billing
A record of token purchases, grants and spends. Card details are handled by Dodo Payments and never reach our servers; we store the subscription and payment identifiers Dodo sends us.
Messages you send us
The email address, subject and text you submit through the contact form, plus which account was signed in when you sent it. We keep these so a refund or deletion request cannot be lost, and because we may have to show we answered it in time.
Technical
Server logs containing IP address, user agent, requested URL and timestamp, kept for security and debugging.

Why we use it, and on what basis

To provide the service you asked for and to bill for it (performance of a contract): your account, your models, your token ledger. To keep the service secure and working, and to prevent abuse (legitimate interests): server logs, rate limiting. To meet accounting and tax obligations (legal obligation): the record of what was purchased and when.

To tell you about Riggle (consent, or legitimate interests where the law allows us to email an existing customer about our own similar service): the product emails described below.

We do not sell or rent your data, we do not use it for third-party advertising, and we do not use your models or the avatars produced from them to train machine-learning models.

Email we send you

Service email — receipts, billing notices, security and account messages — comes with having an account and cannot be switched off while you have one.

Product email — new features, tips and offers — is on by default when you create an account, which we tell you on the sign-in page before you sign in. Turning it off takes one click, either from the Email switch on your account page or from the unsubscribe link at the bottom of every such email, and it takes effect immediately. We never pass your address to another company for their own marketing.

Who processes it for us

The Riggle marketing site at riggle.megasaleapp.com uses Google Analytics. The app itself carries no analytics and no advertising trackers.

International transfers

Our servers are in the United States. If you are in the EEA or the UK, your data is transferred there on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to each provider listed above.

How long we keep it

Nothing expires on a timer. We keep your models for as long as you want them, because deleting a customer's work on a schedule is a worse default than letting them decide.

We may remove content that breaks our terms or that we are legally required to remove, and we may contact you about a very long dormant account — but we will not delete your work without telling you first.

Cookies

The app sets two cookies, both strictly necessary: a session cookie that keeps you signed in, and a CSRF token that protects forms from cross-site submission. There are no analytics or advertising cookies in the app, which is why you are not asked to consent to any.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to our processing of it, or provide it in a portable form. Use the contact form and we will respond within 30 days. For deletion specifically, see Data deletion; to stop marketing email, use the switch on your account page — you do not need to write to us for that.

If you are in the EEA or the UK and think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.

Children

Riggle is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will remove it.

Security

Traffic is encrypted in transit (HTTPS). Your job files are served only to your signed-in account through authenticated views — there is no public media URL and no directory listing. Passwords for the providers you sign in with are never seen by us. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

Changes

If this policy changes, the effective date above changes with it and material changes are announced in the app.


Contact

Questions about this document: use the contact form and it reaches a person.