All policies

Privacy Policy

What personal data we handle, why, and what you can do about it. · Last updated 2026-09-28

This policy covers two different sets of people, and the difference matters. Users are the people with rivomi accounts: we are the controller of their data. Prospects are the LinkedIn users our customers research and contact: our customer is the controller and we are their processor. This policy describes both.

Data about users (we are the controller)

  • Account: name, email address, hashed password or Google account identifier, and the workspaces you belong to. Basis: performance of our contract with you.
  • Session and security: IP address, user agent, sign-in timestamps, rate-limit counters. Basis: legitimate interest in keeping accounts secure.
  • Usage: which pages you visit and features you use, how you found us (referrer and campaign parameters), errors you hit, and what your workspace costs us to run. Basis: legitimate interest in operating and improving the Service.
  • Support and email: messages you send us, and whether our transactional emails were delivered. Basis: performance of our contract.

Data about prospects (our customer is the controller)

When a customer configures rivomi to watch a LinkedIn page, post or search term, the Service collects information that LinkedIn shows publicly about the people who engage with it: name, profile URL, headline, job title, employer, location, public profile text, and the public comment or reaction that triggered the collection. If the customer connects a LinkedIn account and sends messages, we also store those messages and any replies.

  • We do not attempt to access anything that is not publicly visible, and we do not bypass authentication or access controls to get it.
  • We do not sell prospect data, and we do not use one customer's prospect data for another customer or to train models.
  • Each customer's data is isolated. Every record carries the workspace it belongs to and every query is filtered by it.

Automated decision-making

The Service scores prospects using a large language model and drafts messages with one. The score is advisory: it ranks who a customer might contact and orders a review queue. It produces no legal or similarly significant effect on the person scored, and a human approves every message before it is sent unless the customer has explicitly turned that requirement off in Settings.

Who we share it with

Only the sub-processors listed below, each for the purpose stated. We do not sell personal data and we do not share it for advertising.

International transfers

Some sub-processors are outside the UK/EEA. Where that is the case, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with the supplementary measures described in our Data Processing Addendum.

How long we keep it

  • Account data: for as long as the account exists, then 30 days.
  • Workspace data including prospects: until the customer deletes it, or 30 days after the workspace is deleted.
  • Audit log: for the life of the workspace — it is the record of who changed what, and pruning it would defeat the purpose.
  • Backups: rolling 30 days (Cloudflare D1 Time Travel) plus weekly snapshots retained for 90 days.

Your rights

If you are a user, you can access, correct, export or delete your data in the app, or write to [privacy@yourdomain]. If you are a prospect whose data is in a customer's workspace, the customer is the controller and you should contact them; if you contact us we will pass the request on within 5 working days and help them action it. You can also ask us directly to suppress a LinkedIn profile URL across a workspace, and we will do so.

Cookies

rivomi sets two first-party cookies. The session cookie is HTTP-only and required to stay signed in. The analytics cookie (PostHog, named ph_…_posthog, kept for a year) holds a random visitor identifier so we can count visits, see how people find us and what they use, and link that to your account once you sign in. It is sent only to our own domain, which forwards the events to PostHog; replays mask what you type and the prospect data in your workspace. We use no advertising cookies and do not share analytics with ad networks. You can block or clear the analytics cookie in your browser without affecting the Service.

Changes

We may update this document. Material changes are announced in the product and by email to workspace owners at least 14 days before they take effect. The date at the top is the version in force.

Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Questions about this document: [legal@yourdomain].

Sub-processors

Everyone we send customer data to, and why. Changes are announced 30 days in advance.

ProviderPurposeLocationData
CloudflareApplication hosting, database (D1), object storage, CDN, DDoS protectionGlobal (edge)All service data
UnipileLinkedIn account connection, invitations, messages, inbox syncEU (France)LinkedIn account credentials/session, message content, contact identifiers
ApifyPublic LinkedIn profile and post data collectionEU (Czechia) / USPublic profile URLs and the profile data returned
ScrapeCreatorsPublic LinkedIn post metadata and profile enrichmentUSPublic profile and post URLs and the data returned
Google (Vertex AI / Gemini)Scoring prospects, drafting messages, reading company websitesUS / EUProspect profile text, your company profile, post text
ResendTransactional and notification emailUS / EUAccount email addresses and message content
PostHogWebsite and product analytics, session replay, error reportsUSPages viewed, clicks, referrer and campaign parameters, device and approximate location, account and workspace identifiers; replays with form inputs and workspace data masked