Introduction
Rieva (“Rieva”, “we”, “us”, or “our”) provides an AI assistant that helps you get work done across your connected tools, on the web and on WhatsApp. This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, and the choices and rights you have. It applies to our websites, apps, and services (together, the “Services”).
For the purposes of the EU and UK GDPR, Rieva is the “controller” of the personal information described here, except where we act as a “processor” on your behalf for content you route through connected apps. If you have any questions, contact us at [email protected].
Information we collect
We collect the following categories of personal information, depending on how you use Rieva:
Information you give us
- Account & profile — name, email address or phone number, password or login credentials, and your settings.
- Content — the messages, prompts, files, and instructions you send to Rieva.
- Payment information — if you buy a paid plan, billing details processed by our payment provider (we don’t store full card numbers).
- Communications — messages you send us for support, feedback, or enquiries.
Information from your connected apps
When you connect a third-party account (for example email, calendar, documents, or messaging), you authorize Rieva to access data in that service to perform the tasks you request. We access only the data covered by the permissions (scopes) you grant, use it only to carry out your instructions, and you can revoke access at any time.
Information we collect automatically
- Usage & log data — features used, actions taken, and timestamps.
- Device & connection data — IP address, browser and operating system, and similar identifiers.
- Approximate location — derived from your IP address.
- Cookies & similar technologies — as described below.
Information from other sources
We may receive information from authentication or one-time-passcode providers when you sign in, and from partners or publicly available sources where permitted by law.
How & why we use it
We use personal information to:
- provide, operate, and maintain the Services;
- understand your requests, plan steps, and carry out tasks across your connected apps;
- personalize the Services and remember your preferences, people, and projects (see Memory);
- process transactions and manage your account;
- communicate with you about service updates, security, and support — and, with your consent where required, about new features;
- keep the Services secure, prevent fraud and abuse, and debug problems;
- comply with our legal, tax, and regulatory obligations.
We do not sell your personal information, and we do not use your content to train third-party foundation models.
Legal bases for processing (EEA/UK)
Where the GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services you request | Performance of a contract — Art. 6(1)(b) |
| Security, fraud prevention, and understanding and improving how the Services are used | Our legitimate interests — Art. 6(1)(f) |
| Optional features, certain cookies, and marketing where required | Your consent — Art. 6(1)(a), withdrawable at any time |
| Meeting legal and regulatory obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we weigh them against your rights and freedoms. You can object to this processing as described in Your privacy rights.
AI processing & training
How your content is processed
To generate responses and complete tasks, Rieva sends relevant content (such as your messages and connected-app data) to large-language-model (“LLM”) providers and to our tool-integration layer. These providers process the content on our behalf under contracts that limit their use of it to providing the service to us.
Model training
We do not use your content, files, or connected-app data to train third-party foundation models, and our model providers are contractually restricted from using data we send them to train their own models. We may use aggregated or de-identified data — and limited content where you have given consent — to maintain and improve the Services (for example, to fix errors and improve quality). Where we use personal data to train or fine-tune our own models, we will disclose it and obtain consent where the law requires.
Memory & automated decisions
Your memory
Rieva keeps a memory — an evolving profile and a searchable archive of durable facts — so it can remember your preferences, people, and projects across conversations. You can view, edit, or delete any memory at any time from the Memory screen; deletions remove the underlying data from our stores.
Automated decision-making
Rieva does not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Actions that affect you or others — such as sending a message or changing data in a connected app — are subject to your review and approval, so a human (you) stays in the loop. Where automated processing is used to personalize the Services, you can adjust or turn off the relevant features and contact us to object.
Cookies & tracking technologies
We and our providers use cookies and similar technologies to keep you signed in, remember preferences, secure the Services, and understand usage. You can control cookies through your browser and, where offered, our cookie settings. We honor Global Privacy Control (GPC) and similar opt-out signals where required by law.
How we share information
We share personal information only as described below. We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as defined by California law.
- Service providers & sub-processors who host, secure, process, and operate the Services on our behalf, under contract and confidentiality obligations.
- Third-party apps you connect — to carry out the actions you direct in those services.
- At your direction — when you ask Rieva to send, post, or share information on your behalf.
- Legal & safety — to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and property of Rieva, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, with notice where required.
Service providers & sub-processors
We rely on a limited set of trusted sub-processors, including:
| Category | Purpose |
|---|---|
| Cloud hosting & infrastructure | Running and storing the Services |
| LLM / AI model providers | Generating responses and completing tasks |
| Tool-integration layer | Securely connecting to third-party apps |
| Databases, vector search & caching | Storing memory and conversation data |
| Analytics & error monitoring | Reliability and product improvement |
| Email, messaging & OTP | Login, notifications, and support |
| Payment processor | Billing, for paid plans |
We maintain a current list of sub-processors and will provide it on request at [email protected]. We require sub-processors to protect personal information and to use it only to provide services to us.
Where your data is stored
We store your personal information in the region that matches where you are: data for users in the United States is stored in the US, for users in the European Union in the EU, and for users in India in India. Where information is transferred across regions — for example, to a service provider or model provider — we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (with the UK Addendum) and rely on adequacy decisions or other lawful mechanisms where available. Contact us at [email protected] to learn more about the safeguards we use.
Data retention
We keep personal information for as long as your account is active and as needed to provide the Services, then retain or de-identify it only as necessary for legitimate business purposes such as security, dispute resolution, and legal compliance. You can delete conversations, memories, or your entire account at any time; we then delete or de-identify the associated data, except where we are required to keep it.
Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure; we work to protect your information and will notify you and regulators of material breaches where required by law.
Your privacy rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you and receive a copy;
- Correct inaccurate or incomplete information;
- Delete your information;
- Restrict or object to certain processing, including processing based on legitimate interests;
- Data portability — receive your data in a portable, machine-readable format;
- Withdraw consent at any time, without affecting processing done beforehand;
- Opt out of the sale or sharing of personal information and limit the use of sensitive personal information (see the California notice below);
- Non-discrimination — you won’t be treated differently for exercising your rights.
You can exercise many of these rights directly in the app, or by emailing [email protected]. We will verify your request and respond within the timeframes required by law (generally within 30–45 days). You may authorize an agent to make a request for you. If you disagree with our decision, you may appeal by replying to our response, and you may lodge a complaint with your local data protection authority.
Region-specific notices
EEA & UK
Rieva is the controller of your personal information; you can reach us at [email protected]. You have the right to complain to your local supervisory authority (in the UK, the ICO).
California (CCPA/CPRA)
In the past 12 months we collected the categories of personal information described in “Information we collect” (identifiers, customer records, commercial information, internet/network activity, approximate geolocation, and content you provide), for the purposes described in “How & why we use it”, and disclosed them to the providers and parties described in “How we share information”. We do not sell or share personal information for cross-context behavioral advertising, and not for anyone we know to be under 16. California residents have the rights to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information, and to be free from discrimination. To exercise them, contact [email protected]; authorized agents may submit requests with proof of authorization.
Other US states & India
Residents of states such as Virginia, Colorado, Connecticut, and Texas have similar rights to access, correct, delete, and opt out of targeted advertising, sale, and certain profiling; exercise them as described above, with a right to appeal. If you are in India, we handle personal data consistent with the Digital Personal Data Protection Act, 2023 as applicable; you may contact us at [email protected].
Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you (for example by email or in-app) and update the “Last updated” date above. Your continued use of the Services after an update means you accept the revised policy.
Contact us
Questions, requests, or complaints? Contact us at [email protected]. For privacy-rights requests, please put “Privacy Request” in the subject line.