Retroactive Consent: The Riverside Case Study
What Happens When You Actually Ask a Vendor the Question
Introduction:
Most people never read a platform's privacy policy. This piece is what happened when someone did. Then they asked a direct written question about what it actually meant.
Two Documents, Two Different Answers
Riverside is a popular recording platform. Podcasters, coaches, and consultants all use it. Riverside's own materials say two different things, depending on where you look.
A Help Center article makes a simple claim. It says customer content isn't used for training. Only metadata about how customers edit their content gets used, according to that page.
The Privacy Policy says something broader. It defines “Content Data” to include recordings, transcripts, and AI-feature outputs. It states that Riverside can use Content Data to train Riverside's own AI models. It also says opt-out is only available to Business-tier customers. And only through a written agreement.
A help page isn't a binding legal document. A privacy policy is. That gap was worth resolving directly. In writing. Rather than guessing which one actually governs.
The Question, Framed Carefully
A direct written question went to Riverside's team. It was framed as an ordinary vendor check. The kind any consultant runs before recommending a tool to clients. Not as an accusation.
The email asked five specific things. Does Riverside use recordings or transcripts to train its own AI models? Is that limited to editing metadata, or does it include the actual audio and video? Is any opt-out available to Pro plan users, or only Business plan? Is data shared with any outside company beyond the listed subprocessors? Do specific AI features create any extra rights beyond making that one output?
What Riverside Actually Said
The answer came back in writing. It settled the central question. Yes, Riverside's Privacy Policy governs. Content Data is used to train Riverside's own AI models. This applies to Riverside's own models. It's separate from any outside processors.
On the second question, Riverside gave no clear answer. Whether the training use is limited to metadata, or covers the full audio and video, would need a separate written agreement. That level of detail sits at the Business-plan tier only.
On opt-out, here's what Riverside described for Pro-plan users. Simply don't use Riverside's AI features. That's the whole opt-out. Business-plan customers can do more. They can turn off certain tools and negotiate their own terms.
On third parties, the news was genuinely good. Data goes only to listed subprocessors. Those subprocessors cannot use customer data to train their own models. That's a real, clear answer.
The Part Worth Sitting With
Here's where two of Riverside's own answers don't line up. The first answer says Content Data gets used to train Riverside's models. That's recordings and transcripts. The Privacy Policy doesn't say this depends on using any specific AI feature.
But the opt-out offered is exactly that: don't use the AI features. If the first answer is accurate, skipping a feature doesn't seem to change whether your recordings still count as Content Data. Read side by side, Riverside's own two answers describe two different levels of protection.
This isn't proof that Riverside acted in bad faith. It's a real example of what a company's own answers can reveal. But only once someone actually asks, in writing. Instead of assuming the help page tells the whole story.
What This Means for Anyone Using Riverside, or Any Similar Tool
Say you use Riverside on the Pro plan. Your recordings are very likely training Riverside's own AI models right now. That's true under the current Privacy Policy. Simply continuing to use the plan is what the policy treats as enough basis for that. Not any specific choice you made about AI.
The same gap between a help page and a privacy policy could exist at any recording or meeting platform. Not just Riverside. This series built a checklist in an earlier piece. It's based directly on the exact steps used here.
Where This Fits
This is one piece in a larger series about Retroactive Consent. It's the pattern of old terms being stretched to cover new AI uses. Riverside's Privacy Policy existed before anyone asked this question out loud. Once asked, the answer was already sitting there in writing. It just needed a close read.
Where This Goes Next
Retroactive Consent doesn't stop at recording platforms. The same structure — old terms, stretched to cover a use never named — shows up anywhere a platform, a vendor, or a client-recording tool sits between a person and their own voice, face, or written work. This series will keep applying that same pattern, case by case, to:
● Voice actors, audiobook narrators, and broadcasters — the same BIPA suits referenced in this series, examined through each profession's specific contracts and exposure.
● Face-forward creators — fitness, cooking, and lifestyle creators whose likeness is the product itself.
● Coaches, consultants, and service providers — where the exposure isn't personal biometrics but client data and vendor liability.
● Musicians, authors, and visual artists — where the same argument Google is making about a 2019 YouTube clause is already being tested against record labels, publishers, and stock-photo archives.
Each of those segment breakdowns will follow the same discipline this one does: state plainly what's confirmed, what's attributed to a source rather than independently verified, and what remains an open question — and end with what actually helps, not just what to be afraid of, so you're clear on what action you can take if it doesn't sit well with you.