The short version
This summary is for orientation only. The numbered sections below are the policy.
- We collect what running the product requires: your account details, your workspace configuration, billing records held by Stripe, and technical logs.
- We do not sell or share your personal information, and we run no advertising, no ad pixels and no cross-context behavioral tracking.
- We do not use your prompts or results to train models that serve anyone else.
- Your prompts are sent to the AI engines on your plan, because that is how the measurement works. Do not put confidential or personal data in prompt text.
- You can access, correct, export and delete your data at any time, from the application or by emailing us. We honor Global Privacy Control signals.
Rivarise LLC, a Wyoming limited liability company ("Rivarise," "we," "us"), respects the confidence you place in us when you hand over data. This policy explains what personal information we collect, why we collect it, who processes it on our behalf, how long we keep it, and the rights you have over it.
1. Scope and who we are
This policy applies to rivarise.com, app.rivarise.com, and the Rivarise application and related services (the "Service"). It does not apply to third-party websites or AI engines you may reach through us, each of which has its own policy.
Two different roles apply depending on the data:
- We are the controller of account and billing data, meaning we decide why and how it is processed. Examples: your name, email, workspace name, plan and support correspondence.
- We are a processor or service provider for the content of your workspace, meaning we act on your instructions. Examples: the prompts you write, the domains you track and the results we generate for you.
If you are an employee of a customer organization, that organization decides what goes into its workspace, and requests about workspace content should go to it first.
2. Notice at Collection
California law requires us to tell you, at or before collection, what categories of personal information we collect, why, and how long we keep them. The table below is that notice, and it also serves users in every other state.
| Category | Examples | Why we collect it | Retention |
|---|---|---|---|
| Identifiers | Name, email address, account and workspace ID, IP address | Create and secure your account, authenticate you, send service email, prevent abuse | Life of account, then 30 days |
| Customer records | Company or workspace name, job role if you provide it, support messages | Provide and support the Service, understand who we are serving | Life of account, then 30 days |
| Commercial information | Plan, subscription status, invoices, payment history, refunds | Bill you, honor the refund policy, meet tax and accounting duties | 7 years (tax law) |
| Internet and network activity | Pages viewed, features used, timestamps, browser and device type, referring page, error diagnostics | Keep the Service working, diagnose failures, measure product usage, detect fraud | Up to 12 months |
| Approximate location | City or region inferred from IP address | Security, fraud prevention and tax determination. We do not collect precise GPS location | Up to 12 months |
| Workspace content | Domains, prompts, competitor names, engine results and stored answer text | Run the measurement you asked for and produce your dashboard and reports | Per plan retention, then 30 days |
| Payment information | Card details, billing address | Collect payment. Handled entirely by Stripe. We never receive or store your full card number | Held by Stripe, not by us |
Sensitive personal information. We do not intentionally collect sensitive personal information as defined by California law, such as government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, health data, biometric data or the contents of your private communications. We do not use or disclose any such information for purposes requiring a right to limit. Please do not enter this kind of information into prompt text or support messages.
3. What we collect, in detail
3.1 Information you give us
- Account information: your name, email address and a securely hashed password, or the identifier supplied by a sign-in provider you choose. We never see or store your plaintext password.
- Workspace configuration: the domains you track, prompts you write, competitors you name, alert destinations such as a Slack or webhook URL, and team members you invite.
- Billing details: submitted directly to Stripe. We receive a customer token, the last four digits, card brand, expiry and billing country so we can show you your own invoices.
- Communications: what you write to support, including any attachments.
3.2 Information collected automatically
- Log and usage data: IP address, browser and operating system, pages and features used, timestamps, and referring URLs.
- Diagnostics: error reports and performance traces, captured through Sentry, which may include the URL where an error occurred and your account identifier so we can reproduce the failure.
- Cookies: as described in section 6.
3.3 Information from third parties
- Payment and fraud signals from Stripe, such as whether a charge succeeded or was disputed.
- Sign-in details from an identity provider if you use one, limited to your email address and basic profile.
- Referral attribution if you arrived through an affiliate link, limited to the referring affiliate ID.
- Publicly available answer content returned by AI engines in response to your prompts. This is content about brands and websites, not about you.
4. How we use information
We use personal information only for the purposes below, and we do not use it for purposes that are incompatible with the ones disclosed at collection:
- to create, authenticate and secure your account and workspace;
- to run the tracking you configured and deliver results, alerts and reports;
- to process payments, manage subscriptions and apply the refund policy;
- to provide support and respond to what you ask us;
- to send service messages such as security notices, billing receipts, plan-limit warnings and material changes to these policies, which you cannot opt out of while you hold an account;
- to send product and marketing email, which you can opt out of at any time using the unsubscribe link in any such message;
- to monitor stability, debug failures and improve the Service;
- to detect, investigate and prevent fraud, abuse and security incidents;
- to comply with law and to establish, exercise or defend legal claims.
Where we rely on legal bases under the GDPR or UK GDPR, they are: performance of a contract for providing the Service; legitimate interests for security, product improvement and direct business communications; consent for optional cookies and marketing email where required; and legal obligation for tax and accounting records.
5. We do not sell or share your personal information
Rivarise has never sold personal information and does not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act, or by any comparable state law. We have not done so in the preceding twelve months, including with respect to anyone under 16 years of age.
We run no advertising network, no third-party ad pixels, no retargeting tags and no data brokerage. Because there is nothing to opt out of, there is no "Do Not Sell or Share My Personal Information" link on this site. That is not an omission, it is the absence of the practice.
6. Cookies and similar technologies
We keep this deliberately minimal. The Service uses:
| Type | Purpose | Can you refuse it |
|---|---|---|
| Strictly necessary | Keep you signed in, maintain your session, protect against cross-site request forgery, remember your workspace | No, the Service cannot function without these |
| Preference | Remember interface choices such as selected date range or theme | Yes, by clearing cookies. Some settings will reset |
| Referral attribution | Credit an affiliate for a referral for a limited window | Yes, by clearing cookies before signing up |
We do not use advertising cookies, third-party trackers or social media pixels. Most browsers let you refuse or delete cookies through their settings. Blocking strictly necessary cookies will prevent you from signing in.
7. Prompts, results and the AI engines
This is the part of the product most worth understanding, so we state it plainly.
To measure whether an AI engine mentions a brand, Rivarise has to ask that engine a question. The prompts in your workspace are therefore transmitted to the operators of the engines included in your plan, which may include OpenAI, Perplexity, Google, DeepSeek, xAI, Meta, Microsoft and Anthropic. Once a prompt reaches an engine operator, that operator's own privacy policy and data-retention practices govern what happens to it.
- We send only prompt text and the parameters needed to run the query. We do not send your name, email address, account identifier or billing details to any AI engine.
- Because prompt text leaves our systems, treat it as public. Do not include trade secrets, personal information about identifiable people, credentials, or anything regulated such as health or financial records.
- The answers we receive are stored in your workspace, under your plan's retention period, so you can inspect exactly what an engine said rather than trusting a score.
- We do not use your prompts, answers or results to train our own models or any model that serves another customer.
8. Service providers and subprocessors
We disclose personal information to vendors who process it on our behalf, under written contracts that limit them to our instructions and forbid them from selling it or using it for their own purposes. We keep this list short on purpose.
| Provider | Function | Data involved |
|---|---|---|
| Supabase | Database, authentication and storage | Account details, workspace content, results |
| Stripe | Payment processing and subscription billing | Payment details, billing address, transaction history |
| Vercel | Application hosting and content delivery | Request logs, IP address |
| DigitalOcean | Background job workers that run tracking checks | Workspace content during processing |
| Resend | Transactional and alert email delivery | Email address, message content |
| Sentry | Error monitoring and performance diagnostics | Error traces, IP address, account identifier |
| Hostinger | Hosting for the rivarise.com marketing site | Web server request logs |
| AI engine operators | Answer generation for the engines on your plan | Prompt text only, as described in section 7 |
We may also disclose information when required by law, subpoena or court order; to protect the rights, property or safety of Rivarise, our customers or the public; to enforce our Terms of Service; or to professional advisers such as lawyers and accountants bound by confidentiality. Where legally permitted, we will notify you of a demand for your data before responding to it.
9. How long we keep information
| Data | Retention period |
|---|---|
| Account and profile | For as long as the account is open, then deleted within 30 days of closure |
| Workspace results and answer text | Your plan's history window: 7 days on Free, 30 days on Starter, 90 days on Growth, unlimited on Business and Agency |
| Prompts and configuration | Until you delete them or close the account, then 30 days |
| Billing and tax records | 7 years, as required by United States tax law, even after account closure |
| Server and security logs | Up to 12 months |
| Support correspondence | Up to 24 months |
| Encrypted backups | Rolling 30-day window, after which deleted records fall out of backup naturally |
Deletion means removal from active systems within 30 days and expiry from backups within the backup window. We may retain the minimum information needed to enforce a suspension, resolve a dispute, or comply with a legal obligation.
10. How we protect information
No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can tell you is what we actually do:
- all traffic is encrypted in transit with TLS, and data at rest is encrypted by our hosting providers;
- every record is scoped to a workspace and enforced at the database layer with row-level security, so one customer's queries cannot reach another customer's rows;
- tenancy is derived from server-side authentication claims, never from values a browser can modify;
- API keys are stored only as hashes, so a database disclosure would not reveal usable keys;
- passwords are hashed by our authentication provider and are never visible to us;
- administrative access is limited to those who need it, and internal endpoints fail closed rather than open;
- dependencies are patched on an ongoing basis and errors are monitored continuously.
If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay and within the timeframes required by applicable law. Report a suspected vulnerability to support@rivarise.com; we welcome good-faith reports and will not pursue researchers who follow responsible disclosure.
11. Your privacy rights
11.1 Rights available to everyone
Regardless of where you live, we extend these rights to every Rivarise user:
- Know and access: learn what we hold about you and get a copy.
- Correct: fix inaccurate personal information.
- Delete: have your personal information erased, subject to legal retention duties.
- Portability: receive your data in a portable, machine-readable format.
- Opt out of marketing: unsubscribe from promotional email at any time.
- Non-discrimination: we will never deny service, charge a different price, or reduce quality because you exercised a privacy right.
11.2 California residents (CCPA as amended by CPRA)
In addition to the above, California residents have the right to know the categories and specific pieces of personal information collected, the categories of sources, the business purposes, and the categories of third parties to whom it is disclosed, all of which are set out in sections 2, 3 and 8. You have the right to opt out of sale or sharing, which we address in section 5 by not engaging in either, and the right to limit the use of sensitive personal information, which does not arise because we do not collect it. You may use an authorized agent, who must provide written permission signed by you, and we may still ask you to verify your own identity. California's "Shine the Light" law permits you to request information about disclosures to third parties for their direct marketing purposes; we make no such disclosures.
11.3 Other United States state privacy laws
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island, have rights to confirm processing, access, correct, delete and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale and profiling with legal or similarly significant effects. We do not engage in targeted advertising, sale or such profiling, so those opt-outs have nothing to act on, but the access, correction, deletion and portability rights all apply and are handled as described below.
Appeals. Several of these laws give you the right to appeal a refused request. If we decline your request, we will explain why, and you may appeal by replying to that decision or emailing support@rivarise.com with the subject line "Privacy Appeal." We will respond within 45 days with our decision and reasoning. If we deny the appeal, you may contact your state attorney general.
11.4 Nevada
Nevada residents may direct us not to sell certain personal information. We do not sell personal information, so this right has nothing to act on, but you may still submit a request and we will confirm our practice in writing.
12. How to exercise your rights
Most requests are faster to satisfy yourself: your profile, workspace data, prompts, invoices and account deletion are all available directly in the application under Settings, and deleting your account there triggers the deletion process described in section 9.
Otherwise, email support@rivarise.com with the subject line "Privacy Request" and tell us what you want. We will:
- acknowledge your request within 10 business days;
- verify your identity, normally by confirming control of the email address on the account, and for sensitive requests by asking for information only the account holder would know. We do not ask for government identification;
- respond substantively within 45 days, and if we need more time, tell you why and take no more than 45 additional days;
- charge nothing, unless a request is manifestly unfounded or excessive, in which case we will say so before doing any work.
If your data sits inside an organization's workspace and that organization is the controller, we will refer your request to them and assist them in answering it.
13. Do Not Track and Global Privacy Control
There is no industry consensus on browser Do Not Track signals, so we do not respond to them. We do honor Global Privacy Control (GPC) signals. Since we neither sell nor share personal information, a GPC signal changes nothing about how we treat you: the protection it requests is already the default here.
14. International users and data transfers
Rivarise is operated from the United States, and our infrastructure providers process data in the United States and other countries where they operate. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
Where we transfer personal information of individuals in the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we apply supplementary technical measures including encryption in transit and at rest. Individuals in those regions also have the rights to object to and restrict processing, to withdraw consent at any time without affecting prior processing, and to lodge a complaint with their local supervisory authority. Contact us first and we will try to resolve it directly.
15. Children's privacy
The Service is a business tool intended for people aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18, nor do we knowingly sell or share the personal information of anyone under 16. If we learn that we have collected personal information from a child, we will delete it promptly. A parent or guardian who believes a child has provided us with personal information should contact support@rivarise.com.
16. Third-party links and services
The Service links to third-party sites, including the AI engines we track and the sources cited in their answers. We do not control those sites and are not responsible for their content or privacy practices. Read their policies before providing them with information.
17. Business transfers
If Rivarise is involved in a merger, acquisition, financing, reorganization or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this policy for information transferred, and we will notify you by email or in the application before your information becomes subject to a materially different policy, so that you can delete your account first if you prefer.
18. Changes to this policy
We may update this policy to reflect changes in our practices or the law. The effective date at the top always shows the current version. For material changes we will give notice by email or in the application at least 14 days before they take effect. Continued use after that date means you accept the updated policy.
19. How to contact us
Rivarise LLC, a Wyoming limited liability company. For any privacy question, request or appeal, email support@rivarise.com. Please put "Privacy Request" or "Privacy Appeal" in the subject line so it reaches the right place quickly. A human answers, normally within one business day.
Quick answers
Related: Terms of Service and Refund Policy.