Privacy Policy

Last updated: March 23, 2026

1. Introduction

Riven AI, Inc. ("Company", "we", "us") operates the Riven AI platform at riven-ai.dev and app.riven-ai.dev. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.

2. Information We Collect

Information you provide

  • Account information: name, email address, and password when you create an account
  • Billing information: payment details processed by our payment provider (Paddle). We do not store credit card numbers directly.
  • Content: code, configuration, models, documents, and other data you upload to the Platform
  • Communications: messages you send to us via email or support channels

Information collected automatically

  • Usage data: pages visited, features used, and interactions with the Platform
  • Device information: browser type, operating system, and device identifiers
  • Log data: IP address, access times, and referring URLs
  • Cookies: session cookies for authentication and preference cookies for settings. See Section 7 below.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Send transactional communications (account verification, billing, security alerts)
  • Respond to support requests
  • Monitor and analyze usage patterns to improve the Platform
  • Detect and prevent fraud, abuse, and security incidents

We do not sell your personal information to third parties. We do not use your uploaded content (code, models, data) to train our own AI models.

4. Data Sharing

We may share your information with:

  • Payment processors: Paddle processes billing and subscription data on our behalf
  • Infrastructure providers: Amazon Web Services (AWS) hosts the Platform in the US East (N. Virginia) region
  • Analytics providers: to understand usage patterns (aggregated and anonymized where possible)
  • Legal obligations: when required by law, court order, or governmental authority

5. Data Storage and Security

Your data is stored on servers hosted by Amazon Web Services (AWS) in the US East (N. Virginia, us-east-1) region. We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control (RBAC)
  • Audit logging of administrative and sensitive actions
  • Regular security assessments

While we take reasonable measures to protect your data, no system is 100% secure. You are responsible for keeping your account credentials confidential.

6. Data Retention

We retain your account data for as long as your account is active. After account deletion, we retain your data for up to 30 days before permanent deletion, unless required by law to retain it longer. Usage logs are retained for up to 90 days. Billing records are retained as required by applicable tax and financial regulations.

7. Cookies

We use the following types of cookies:

  • Essential cookies: required for authentication and core functionality
  • Preference cookies: to remember settings like theme and language
  • Analytics cookies: to understand how users interact with the Service

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your personal data ("right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing activities

To exercise these rights, contact us at galgil39@gmail.com. We will respond within 30 days.

9. International Transfers

If you are located outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.

10. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use after changes take effect constitutes acceptance.

12. Contact

For privacy-related questions or requests, contact us at galgil39@gmail.com.