Home / PrivacyLegal

Privacy Policy

Last updated: 25 July 2026  ·  Effective: 25 July 2026
In short — Rieva collects the information it needs to do your tasks and remember you, uses trusted providers to run the AI, never sells your data or trains third-party foundation models on it, keeps you in control with human approval before it acts, and lets you access, correct, or delete your data — including your memory — at any time.

Introduction

Rieva (“Rieva”, “we”, “us”, or “our”) provides an AI assistant that helps you get work done across your connected tools, on the web and on WhatsApp. This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, and the choices and rights you have. It applies to our websites, apps, and services (together, the “Services”).

For the purposes of the EU and UK GDPR, Rieva is the “controller” of the personal information described here, except where we act as a “processor” on your behalf for content you route through connected apps. If you have any questions, contact us at [email protected].

Information we collect

We collect the following categories of personal information, depending on how you use Rieva:

Information you give us

  • Account & profile — name, email address or phone number, password or login credentials, and your settings.
  • Content — the messages, prompts, files, and instructions you send to Rieva.
  • Payment information — if you buy a paid plan, billing details processed by our payment provider (we don’t store full card numbers).
  • Communications — messages you send us for support, feedback, or enquiries.

Information from your connected apps

When you connect a third-party account (for example email, calendar, documents, or messaging), you authorize Rieva to access data in that service to perform the tasks you request. We access only the data covered by the permissions (scopes) you grant, use it only to carry out your instructions, and you can revoke access at any time.

Information we collect automatically

  • Usage & log data — features used, actions taken, and timestamps.
  • Device & connection data — IP address, browser and operating system, and similar identifiers.
  • Approximate location — derived from your IP address.
  • Cookies & similar technologies — as described below.

Information from other sources

We may receive information from authentication or one-time-passcode providers when you sign in, and from partners or publicly available sources where permitted by law.

How & why we use it

We use personal information to:

  • provide, operate, and maintain the Services;
  • understand your requests, plan steps, and carry out tasks across your connected apps;
  • personalize the Services and remember your preferences, people, and projects (see Memory);
  • process transactions and manage your account;
  • communicate with you about service updates, security, and support — and, with your consent where required, about new features;
  • keep the Services secure, prevent fraud and abuse, and debug problems;
  • comply with our legal, tax, and regulatory obligations.

We do not sell your personal information, and we do not use your content to train third-party foundation models.

Legal bases for processing (EEA/UK)

Where the GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing the Services you requestPerformance of a contract — Art. 6(1)(b)
Security, fraud prevention, and understanding and improving how the Services are usedOur legitimate interests — Art. 6(1)(f)
Optional features, certain cookies, and marketing where requiredYour consent — Art. 6(1)(a), withdrawable at any time
Meeting legal and regulatory obligationsLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we weigh them against your rights and freedoms. You can object to this processing as described in Your privacy rights.

AI processing & training

How your content is processed

To generate responses and complete tasks, Rieva sends relevant content (such as your messages and connected-app data) to large-language-model (“LLM”) providers and to our tool-integration layer. These providers process the content on our behalf under contracts that limit their use of it to providing the service to us.

Model training

We do not use your content, files, or connected-app data to train third-party foundation models, and our model providers are contractually restricted from using data we send them to train their own models. We may use aggregated or de-identified data — and limited content where you have given consent — to maintain and improve the Services (for example, to fix errors and improve quality). Where we use personal data to train or fine-tune our own models, we will disclose it and obtain consent where the law requires.

Memory & automated decisions

Your memory

Rieva keeps a memory — an evolving profile and a searchable archive of durable facts — so it can remember your preferences, people, and projects across conversations. You can view, edit, or delete any memory at any time from the Memory screen; deletions remove the underlying data from our stores.

Automated decision-making

Rieva does not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Actions that affect you or others — such as sending a message or changing data in a connected app — are subject to your review and approval, so a human (you) stays in the loop. Where automated processing is used to personalize the Services, you can adjust or turn off the relevant features and contact us to object.

Cookies & tracking technologies

We and our providers use cookies and similar technologies to keep you signed in, remember preferences, secure the Services, and understand usage. You can control cookies through your browser and, where offered, our cookie settings. We honor Global Privacy Control (GPC) and similar opt-out signals where required by law.

How we share information

We share personal information only as described below. We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as defined by California law.

  • Service providers & sub-processors who host, secure, process, and operate the Services on our behalf, under contract and confidentiality obligations.
  • Third-party apps you connect — to carry out the actions you direct in those services.
  • At your direction — when you ask Rieva to send, post, or share information on your behalf.
  • Legal & safety — to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and property of Rieva, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, with notice where required.

Service providers & sub-processors

We rely on a limited set of trusted sub-processors, including:

CategoryPurpose
Cloud hosting & infrastructureRunning and storing the Services
LLM / AI model providersGenerating responses and completing tasks
Tool-integration layerSecurely connecting to third-party apps
Databases, vector search & cachingStoring memory and conversation data
Analytics & error monitoringReliability and product improvement
Email, messaging & OTPLogin, notifications, and support
Payment processorBilling, for paid plans

We maintain a current list of sub-processors and will provide it on request at [email protected]. We require sub-processors to protect personal information and to use it only to provide services to us.

Where your data is stored

We store your personal information in the region that matches where you are: data for users in the United States is stored in the US, for users in the European Union in the EU, and for users in India in India. Where information is transferred across regions — for example, to a service provider or model provider — we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (with the UK Addendum) and rely on adequacy decisions or other lawful mechanisms where available. Contact us at [email protected] to learn more about the safeguards we use.

Data retention

We keep personal information for as long as your account is active and as needed to provide the Services, then retain or de-identify it only as necessary for legitimate business purposes such as security, dispute resolution, and legal compliance. You can delete conversations, memories, or your entire account at any time; we then delete or de-identify the associated data, except where we are required to keep it.

Security

We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure; we work to protect your information and will notify you and regulators of material breaches where required by law.

Your privacy rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you and receive a copy;
  • Correct inaccurate or incomplete information;
  • Delete your information;
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Data portability — receive your data in a portable, machine-readable format;
  • Withdraw consent at any time, without affecting processing done beforehand;
  • Opt out of the sale or sharing of personal information and limit the use of sensitive personal information (see the California notice below);
  • Non-discrimination — you won’t be treated differently for exercising your rights.

You can exercise many of these rights directly in the app, or by emailing [email protected]. We will verify your request and respond within the timeframes required by law (generally within 30–45 days). You may authorize an agent to make a request for you. If you disagree with our decision, you may appeal by replying to our response, and you may lodge a complaint with your local data protection authority.

Region-specific notices

EEA & UK

Rieva is the controller of your personal information; you can reach us at [email protected]. You have the right to complain to your local supervisory authority (in the UK, the ICO).

California (CCPA/CPRA)

In the past 12 months we collected the categories of personal information described in “Information we collect” (identifiers, customer records, commercial information, internet/network activity, approximate geolocation, and content you provide), for the purposes described in “How & why we use it”, and disclosed them to the providers and parties described in “How we share information”. We do not sell or share personal information for cross-context behavioral advertising, and not for anyone we know to be under 16. California residents have the rights to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information, and to be free from discrimination. To exercise them, contact [email protected]; authorized agents may submit requests with proof of authorization.

Other US states & India

Residents of states such as Virginia, Colorado, Connecticut, and Texas have similar rights to access, correct, delete, and opt out of targeted advertising, sale, and certain profiling; exercise them as described above, with a right to appeal. If you are in India, we handle personal data consistent with the Digital Personal Data Protection Act, 2023 as applicable; you may contact us at [email protected].

Children’s privacy

The Services are not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you (for example by email or in-app) and update the “Last updated” date above. Your continued use of the Services after an update means you accept the revised policy.

Contact us

Questions, requests, or complaints? Contact us at [email protected]. For privacy-rights requests, please put “Privacy Request” in the subject line.