Privacy Policy
Effective date: July 31, 2026
1. Introduction
Riven Inc. ("Riven," "we," "us," or "our") is the data controller responsible for your personal data when you use our products, services, websites, and applications (collectively, the "Services"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over that data. We are committed to protecting your privacy and being transparent about our data practices.
2. Data We Collect
- Account data: Your name, email address, and authentication credentials when you create or manage an account.
- Usage data: How you interact with the Services, including features used, session duration, and product activity.
- Billing data: Pseudonymous billing identifiers processed by Stripe; we do not receive your full card number.
- Technical data: IP address, browser type, operating system, and device identifiers collected for security and operational purposes.
- AI conversation content: The prompts, messages, and files you submit to AI models, retained to provide responses and your session history.
3. What We Do Not Collect
- Raw card numbers: Payment details are handled entirely by Stripe and never touch our servers.
- Biometric data: We do not collect fingerprints, facial geometry, voiceprints, or other biometric identifiers.
- Special categories under GDPR Art. 9: We do not intentionally collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, or data concerning sex life or sexual orientation.
4. We Do Not Train on Your Prompts
We do not use your prompts, conversations, or content to train AI models. Your data is processed only to generate responses and operate the Services. We will not use your data for model training without your explicit opt-in consent. When you select a frontier cloud model, your prompt content is sent to that provider under API terms where providers do not train on API traffic.
5. How We Use Your Data
We process your personal data for the following purposes, each with a corresponding legal basis under GDPR Article 6:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Contractual necessity (GDPR Art. 6(1)(b)) |
| Billing, invoicing, and payment processing | Contractual necessity and legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Aggregated, anonymized product analytics | Legitimate interests (Art. 6(1)(f)) |
| Transactional and account-related email communications | Contractual necessity (Art. 6(1)(b)) |
| Marketing and promotional email | Consent (Art. 6(1)(a)) |
6. Data Retention
- Account data: Retained for the life of your account plus 90 days following deletion.
- AI conversation content: Retained only for the duration of your session by default; saved conversations persist until you delete them.
- Usage logs: Retained for 12 months.
- Billing records: Retained for 7 years as required for tax and accounting compliance.
- Security logs: Retained for 90 days.
You may request deletion of your data at any time, subject to our legal retention obligations. We complete full account deletion within 30 days of a verified request.
7. Data Sharing
We do not sell your personal data. We share data with subprocessors that help us operate the Services, each under data processing agreements (DPAs):
- Stripe — payment processing; card data never touches our servers.
- Cloudflare — DNS, CDN, TLS termination, DDoS protection, and web application firewall.
- Microsoft Azure — cloud hosting and GPU compute in United States regions.
- Microsoft 365 — transactional and support email delivery.
We may also disclose your data when required by law, court order, or valid government request, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Riven, our users, or others. In the event of a merger, acquisition, or sale of all or substantially all of our assets, we will provide notice before your data is transferred to a successor and becomes subject to a different privacy policy.
8. International Transfers
Our infrastructure is based in the United States. If you access the Services from the European Economic Area (EEA), the United Kingdom, or other regions with data protection laws that differ from those in the United States, your data may be transferred to and processed in the United States. For transfers of personal data out of the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs). For transfers out of the United Kingdom, we rely on the UK International Data Transfer Addendum to the SCCs.
9. GDPR Rights (EEA/UK)
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectify: request correction of inaccurate or incomplete data.
- Erase: request deletion of your personal data, subject to legal exceptions.
- Restrict: request that we restrict processing of your data in certain circumstances.
- Port: request your data in a structured, machine-readable format and transfer it to another provider.
- Object: object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: withdraw consent at any time where we rely on it as a legal basis.
- Complain: lodge a complaint with your local data protection supervisory authority.
To exercise these rights, contact [email protected]. We will respond within 30 days of receiving your request.
10. CCPA Rights (California)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Know: request the categories and specific pieces of personal data we collect and how we use them.
- Delete: request deletion of your personal data, subject to exceptions.
- Correct: request correction of inaccurate personal data.
- Limit use of sensitive data: direct us to limit the use and disclosure of sensitive personal information.
- No selling: we do not sell your personal data and have not sold it in the past 12 months.
- Non-discrimination: we will not discriminate against you for exercising your rights.
11. Cookies
We use strictly necessary session cookies that are essential for the Services to function, as well as preference cookies that remember your settings (such as theme). We also use Google Analytics 4 (GA4) for analytics, enabled via the NEXT_PUBLIC_GA_MEASUREMENT_ID environment variable. GA4 uses first-party cookies to collect aggregated, anonymized analytics about how the marketing site is used. We do not use third-party advertising cookies. You can opt out of analytics and non-essential cookies through your browser settings at any time.
12. Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: all data is encrypted using TLS 1.3.
- Encryption at rest: stored data is encrypted using AES-256.
- Access controls: role-based access control (RBAC) limits access to data on a need-to-know basis.
- Password hashing: user passwords are protected with cryptographic hashing.
- Breach notification: in the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
13. Children
The Services are not intended for or directed to individuals under 18 years of age, and we do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will delete that data as soon as practicable. If you believe we have collected such data, please contact [email protected].
14. Data Processing Agreement
Enterprise customers who require a formal data processing agreement (DPA) to meet their regulatory obligations may execute a separate DPA with us. To request a DPA or discuss enterprise data processing terms, contact [email protected].
15. Changes to Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide at least 30 days' notice before the changes take effect, either by email or by posting a prominent notice within the Services. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
16. Contact
For privacy inquiries or to exercise your rights, contact [email protected].