RIVYL

Privacy Policy

Effective date: 2026-08-02 Last updated: 2026-08-14


1. Introduction

This Privacy Policy explains how RIVYL ("RIVYL", "we", "our", or "us") collects, uses, stores, shares, and protects information when you use our website, application, and services (collectively, the "Service").

RIVYL is an AI-powered platform that helps direct-to-consumer ("DTC") brands plan, draft, analyze, and launch advertising campaigns across Meta, Google, TikTok, and other connected platforms.

By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.


2. Who we are

RIVYL is a product of RIVYL Inc., a Delaware corporation. References to "RIVYL", "we", "our", or "us" mean RIVYL Inc.

For privacy questions, contact us at:

  • Email: privacy@rivyl.xyz

3. What information we collect

We collect the following categories of information.

3.1 Account information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a salted hash, never in plain text)
  • Company name and role
  • Billing information (processed by Stripe; we do not store full card numbers)

3.2 Connected platform information

When you connect a third-party platform via OAuth (Meta, Google Ads, TikTok, Shopify), we receive and store:

  • Access tokens and refresh tokens (encrypted at rest)
  • The list of ad accounts, pages, stores, or properties you grant access to
  • The scopes you authorized
  • Profile information returned by the connected platform (name, email, account ID)

3.3 Ad performance and creative data

When you connect an ad account, we collect on your behalf:

  • Campaigns, ad sets, ad groups, and individual ads
  • Daily performance metrics (spend, impressions, clicks, conversions, ROAS, video engagement, etc.)
  • Creative assets (images, videos, ad copy, headlines)
  • Audience definitions and targeting metadata
  • Account-level metadata (currency, timezone, billing details)

3.4 Shopify and store data

When you connect Shopify or a similar store platform, we collect:

  • Product catalog (titles, descriptions, prices, images, variants)
  • Order summaries (volumes, AOV, top SKUs; we do not retain individual customer PII unless required)
  • Theme content (copy, fonts, colors used for brand voice extraction)
  • Inventory levels (when relevant to recommendations)

3.5 Usage and interaction data

We collect data about how you use the Service:

  • Pages visited, features used, agent prompts you submit
  • Outputs generated by our AI agents and which you approved or rejected
  • Time spent and click patterns

3.6 Technical data

We automatically collect:

  • IP address, browser type, device type, operating system
  • Session timing and referral URLs
  • Cookies and similar tracking technologies (see Section 11)

3.7 Communications

We retain support tickets, chat messages, and emails you exchange with us.

3.8 Permissions we request from connected platforms

We request only the permissions needed to operate the Service on your behalf. You can review and revoke these at any time (see Section 9).

Meta (Facebook and Instagram):

  • ads_read: read your campaigns, ad sets, ads, and performance metrics so we can analyze and report on them
  • ads_management: create, edit, and (with your approval) launch or pause campaigns on your ad account
  • business_management: identify and access the ad accounts and assets you choose to connect
  • pages_show_list, pages_read_engagement: identify the Pages your ads run from
  • instagram_basic: run and report on Instagram placements
  • public_profile: identify you when you sign in

Google:

  • https://www.googleapis.com/auth/adwords: read your Google Ads account data and, with your approval, create and manage campaigns

We do not request permissions we do not use, and we use the data each permission provides only to deliver the Service to you.


4. How we collect information

  • Directly from you when you sign up, fill in forms, or contact support.
  • From third-party platforms via OAuth when you authorize a connection.
  • Automatically via cookies, analytics, and server logs.
  • From service providers such as Stripe (billing events) or platform webhooks.
  • From the RIVYL browser extension if you choose to install it (see Section 15).

5. Why we collect information (legal basis)

We process your information for the following purposes:

PurposeLegal basis (GDPR)
Providing the Service (account, agent execution, campaign management)Contractual necessity
Improving the Service and our AI agents (using product-usage analytics and publicly available advertising data, never data from your connected ad accounts)Legitimate interest
Sending transactional emails (receipts, alerts, security notices)Contractual necessity
Sending marketing emails (only with consent or where permitted)Consent or legitimate interest
Complying with legal obligations (tax, fraud prevention, lawful requests)Legal obligation
Securing the platform (detecting abuse, debugging)Legitimate interest

6. How we share information

We share information only as described below. We do not sell your data.

6.1 Service providers (subprocessors)

We use the following subprocessors to operate the Service:

ProviderPurposeLocation
SupabasePrimary database hostingUnited States
Cloudflare R2Creative asset storageGlobal edge
VercelApplication hostingUnited States
StripePayment processingUnited States
AnthropicLLM inference for AI agentsUnited States
Google (Gemini via Vertex AI)LLM inference for AI agentsUnited States
OpenAILLM inference for selected agentsUnited States
Postmark / ResendTransactional emailUnited States
PostHogProduct analyticsUnited States
SentryError monitoringUnited States

A full and current list is available on request. These providers have contractual obligations to process data only as instructed and to maintain appropriate security.

6.2 LLM providers and subprocessor obligations

We send data to LLM providers (Anthropic, OpenAI, and Google via Vertex AI) only to generate outputs for you. Each provider is engaged under a written agreement, on an enterprise or paid API tier, that requires it to process your data solely on our instructions and only to provide the service to us, and not for the provider's own purposes, including training or improving the provider's models. We do not use the free or consumer tiers of these services for your data.

6.3 Connected platforms

We send your authorized instructions (campaign drafts, edits, launches) to the platforms you connect, on your behalf. We do not share your data across customers.

6.4 Legal compliance

We may disclose information if required by law, court order, or to protect the rights, property, or safety of RIVYL, our users, or others.

6.5 Business transfers

If we are involved in a merger, acquisition, or asset sale, your information may be transferred to the acquiring party, subject to the same protections.

6.6 Compliance with platform data policies (Meta and Google)

Data we obtain from your connected advertising accounts is used solely to provide the Service to you: to analyze, optimize, report on, and (with your authorization) manage your own campaigns. We keep each customer's connected-account data logically separated from other customers'. We do not use data obtained from Meta or Google APIs to train or improve our own AI or machine-learning models, to build cross-customer benchmarks, or for any purpose other than operating the Service for you. Any comparative or benchmark features we offer are derived only from publicly available advertising data, never from data obtained through your connected accounts.

The same applies to anything our browser extension collects (see Section 15): we use it only to provide the Service to you, never to train our models and never to build benchmarks across customers.

RIVYL's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Our use of data obtained through the Meta platform complies with the Meta Platform Terms and Developer Policies. You can request deletion of data we hold from your connected accounts at any time (see Section 9). We delete it promptly and revoke the associated tokens with the source platform.


7. International data transfers

If you are in the European Economic Area, United Kingdom, or other regions with data export restrictions, your data may be transferred to and processed in the United States. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards to legitimize transfers.


8. Data retention

  • Active account data: retained for the duration of your account.
  • Ad performance data: retained for the duration of your account, plus 90 days after closure for export and recovery.
  • Browser extension data: saved ads are retained for the duration of your account (see Section 15).
  • Connected access tokens: deleted within 7 days of disconnection or account closure; tokens are also revoked with the source platform.
  • Aggregated product-usage metrics (how the Service itself is used, excluding data from your connected ad accounts): retained for product analytics.
  • Billing and tax records: retained as long as required by law (typically 7 years).
  • Support communications: retained for 3 years.

You can request earlier deletion under Section 9.


9. Your rights

Depending on your location, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (subject to legal retention obligations)
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent at any time where consent is the legal basis
  • Lodge a complaint with your local data protection authority

To exercise any right, contact privacy@rivyl.xyz. We respond within 30 days.

You can also revoke any third-party OAuth grant directly with that platform:

  • Meta: https://www.facebook.com/settings?tab=business_tools
  • Google: https://myaccount.google.com/permissions
  • TikTok: in your TikTok Business account settings
  • Shopify: in your Shopify admin under Apps

9.1 How to delete your data (data deletion instructions)

You can request deletion of the data we hold from your connected accounts at any time by any of these methods:

  • Disconnect the platform in your RIVYL settings, which revokes our access tokens and stops further sync, or
  • Email privacy@rivyl.xyz with the subject line "Data deletion request," or
  • Revoke RIVYL's access directly with the platform using the links above.

On a verified request, we promptly delete the associated data, revoke the relevant tokens with the source platform, and confirm completion. We retain only the limited records described in Section 8 where required by law. This section also serves as our data deletion instructions for the Meta platform.


10. AI processing and training disclosure

Because RIVYL is an AI-powered platform, we want to be explicit about how AI is used:

10.1 Per-customer AI processing

When you use a RIVYL agent, your data (ad metrics, creatives, brand profile, prompts) is sent to one or more LLM providers (Anthropic, OpenAI, and Google via Vertex AI) for inference. These providers do not train on your data and process it solely on our instructions, per the contractual obligations described in Section 6.2.

10.2 Our own model improvement

We do not use data from your connected advertising accounts (data obtained through Meta or Google APIs) to train or improve our AI models, or to build cross-customer benchmarks.

Where we improve the Service and our AI agents, we do so using product-usage analytics (how the Service itself is used) and publicly available advertising data. We do not train AI models that re-output your specific creatives, copy, or campaigns to other customers, and we keep each customer's connected-account data separated from other customers'.

10.3 No automated decisions with legal effect

RIVYL agents propose campaigns, drafts, and recommendations. All consequential actions (publishing campaigns, changing budgets, launching ads) require your explicit approval. We do not make solely-automated decisions that produce legal or similarly significant effects on you.


11. Cookies and tracking

We use cookies and similar technologies for:

  • Strictly necessary: authentication, security, load balancing
  • Functional: remembering preferences and account state
  • Analytics: PostHog and similar to understand usage and improve the product
  • No third-party advertising cookies on rivyl.xyz

You can manage cookies via your browser settings. Refusing strictly necessary cookies will limit functionality.


12. Children's privacy

The Service is not intended for individuals under 16 in the European Economic Area, or under 13 in the United States. We do not knowingly collect data from anyone in those age groups. If we discover such data, we delete it promptly.


13. Security

We implement industry-standard safeguards:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest for sensitive fields (access tokens, passwords)
  • Principle of least privilege for internal access
  • Regular dependency and infrastructure audits
  • Incident response plan in case of a breach

No system is perfectly secure. If a breach affecting your data occurs, we will notify you and the relevant authorities as required by law.


14. California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what categories of personal information we collect, use, disclose, and sell
  • Request deletion of personal information
  • Opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising)
  • Limit the use of sensitive personal information
  • Non-discrimination for exercising your rights

Contact privacy@rivyl.xyz to exercise these rights.


15. Browser extension

We offer a RIVYL browser extension for Chrome. This section applies only if you choose to install it. The extension works across the sites you visit so it can recognize stores and ads, and Chrome tells you this when you install it.

  • Saved ads: when you save an ad from the Meta Ad Library, we store an image of it and its public details in your account. This happens only when you click save, and the image occasionally includes a little more of the page than the ad itself.
  • Store lookups: when you open the extension on a site, it sends us that site's domain so we can return information about the store, along with platform and product details that are already public on the page. We do not send the pages you visit, and the extension does not track or record your browsing.

Both of these happen only when you act: when you click save, or when you open the extension. The extension does not collect anything in the background.

Everything the extension collects belongs to your account and is used only to provide the Service to you. We do not sell it, and we never share it with other RIVYL customers or use it to build benchmarks (see Section 6.6).

Saved ads are kept while your account is open, and you can delete any of them at any time. You can request deletion at any time under Section 9, and removing the extension from Chrome stops all further collection immediately.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.


16. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to active account holders at least 14 days before they take effect. The "Last updated" date at the top will always reflect the most recent revision.


17. Contact

Questions, requests, or complaints about privacy:

  • Email: privacy@rivyl.xyz

You also have the right to lodge a complaint with your local data protection authority.

© 2026 RIVYL Inc.
Privacy PolicyTerms of Service