What personal data we handle, why, and what you can do about it. · Last updated 2026-09-28
This policy covers two different sets of people, and the difference matters. Users are the people with rivomi accounts: we are the controller of their data. Prospects are the LinkedIn users our customers research and contact: our customer is the controller and we are their processor. This policy describes both.
When a customer configures rivomi to watch a LinkedIn page, post or search term, the Service collects information that LinkedIn shows publicly about the people who engage with it: name, profile URL, headline, job title, employer, location, public profile text, and the public comment or reaction that triggered the collection. If the customer connects a LinkedIn account and sends messages, we also store those messages and any replies.
The Service scores prospects using a large language model and drafts messages with one. The score is advisory: it ranks who a customer might contact and orders a review queue. It produces no legal or similarly significant effect on the person scored, and a human approves every message before it is sent unless the customer has explicitly turned that requirement off in Settings.
Only the sub-processors listed below, each for the purpose stated. We do not sell personal data and we do not share it for advertising.
Some sub-processors are outside the UK/EEA. Where that is the case, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with the supplementary measures described in our Data Processing Addendum.
If you are a user, you can access, correct, export or delete your data in the app, or write to [privacy@yourdomain]. If you are a prospect whose data is in a customer's workspace, the customer is the controller and you should contact them; if you contact us we will pass the request on within 5 working days and help them action it. You can also ask us directly to suppress a LinkedIn profile URL across a workspace, and we will do so.
rivomi sets two first-party cookies. The session cookie is HTTP-only and required to stay signed in. The analytics cookie (PostHog, named ph_…_posthog, kept for a year) holds a random visitor identifier so we can count visits, see how people find us and what they use, and link that to your account once you sign in. It is sent only to our own domain, which forwards the events to PostHog; replays mask what you type and the prospect data in your workspace. We use no advertising cookies and do not share analytics with ad networks. You can block or clear the analytics cookie in your browser without affecting the Service.
We may update this document. Material changes are announced in the product and by email to workspace owners at least 14 days before they take effect. The date at the top is the version in force.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Questions about this document: [legal@yourdomain].
Everyone we send customer data to, and why. Changes are announced 30 days in advance.
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Cloudflare | Application hosting, database (D1), object storage, CDN, DDoS protection | Global (edge) | All service data |
| Unipile | LinkedIn account connection, invitations, messages, inbox sync | EU (France) | LinkedIn account credentials/session, message content, contact identifiers |
| Apify | Public LinkedIn profile and post data collection | EU (Czechia) / US | Public profile URLs and the profile data returned |
| ScrapeCreators | Public LinkedIn post metadata and profile enrichment | US | Public profile and post URLs and the data returned |
| Google (Vertex AI / Gemini) | Scoring prospects, drafting messages, reading company websites | US / EU | Prospect profile text, your company profile, post text |
| Resend | Transactional and notification email | US / EU | Account email addresses and message content |
| PostHog | Website and product analytics, session replay, error reports | US | Pages viewed, clicks, referrer and campaign parameters, device and approximate location, account and workspace identifiers; replays with form inputs and workspace data masked |