Privacy Policy
This policy explains what data Rivarise ("we", "us") collects when you use rivarise.com and app.rivarise.com (the "Service"), why we collect it, where it is processed and what rights you have. The short version: we collect what is needed to run an AI visibility tracker for you, we do not sell data, and you can delete your account and its data at any time.
1. Data we collect
Account data
- Email address, name and password hash (we never store plain-text passwords).
- Organization name, plan and billing status.
Configuration data
- The domains, prompts, competitors and alert rules you configure.
Tracking results
- AI engine responses to your prompts, citation details, sentiment scores and derived metrics such as your PPS score. Retention follows your plan's history window.
Payment data
- Payments are processed by Stripe. We never see or store full card numbers; we keep the subscription status, plan and invoice references Stripe provides.
Usage and technical data
- Standard logs (IP address, browser, pages viewed) and error reports, used for security and to fix problems.
2. What we use it for
- Operating the Service: running your tracking jobs, computing your metrics, showing your dashboard.
- Sending your prompts to the AI engines on your plan; prompts are sent without your identity attached beyond what the engine APIs technically require.
- Transactional email: alerts you configured, billing receipts, important account notices.
- Support, fraud prevention and legal compliance.
We do not sell your personal data, and we do not use your prompts or results to advertise to anyone.
3. Processors we rely on
We use a small set of processors, each bound by their own data processing terms:
- Supabase: database, authentication and storage.
- Stripe: payments and subscription management.
- Resend: transactional email delivery.
- AI engine providers (OpenAI, Perplexity, Google, DeepSeek, xAI, Together AI, Microsoft Azure, Anthropic): receive the prompt text of checks run on your behalf.
- Vercel and DigitalOcean: application hosting and background workers.
- Sentry: error monitoring.
4. Cookies
The app uses strictly necessary cookies for authentication and session state. The marketing site sets no advertising or cross-site tracking cookies.
5. Retention and deletion
- Tracking history is retained according to your plan (7 days on Free up to unlimited on Business and Agency).
- Account data is kept while your account exists.
- Deleting your account removes your configuration and tracking data from production systems within 30 days; encrypted backups roll off on their own schedule within 90 days.
- Invoices and records we are legally required to keep are retained for the mandated period.
6. Security
Data is encrypted in transit and at rest. Access to production data is limited, logged and protected. API keys you connect are stored hashed or encrypted; alert webhooks are signed. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you without undue delay.
7. Your rights
Depending on where you live (including under GDPR and similar laws), you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. You can exercise most of these directly in the app; for anything else, email support@rivarise.com and we will respond within 30 days. You also have the right to complain to your local data protection authority.
8. International transfers
Our processors operate globally, so your data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses provided by the processors listed above.
9. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
10. Changes and contact
If this policy changes materially, we will notify you by email or in the app before the change takes effect. Privacy questions: support@rivarise.com.