This Privacy Policy explains how RIVEL Companies International LLC ("RIVEL," "we," "us," "our") collects, uses, shares, and protects personal information when you use our websites, products, and services (collectively, the "Services"), including our web application and any related experiences, content, and features.
Contact: info@rivelcompanies.com
01Who we are (Data Controller)
The data controller for the Services is:
- Legal name: RIVEL Companies International LLC
- Entity type: Limited Liability Company (LLC)
- Jurisdiction: State of Wyoming, United States of America
- Date of formation: May 18, 2026
- Principal office & mailing address: 5830 E 2nd St, Ste 7000 #35827, Casper, WY 82609, USA
- Registered agent: Republic Registered Agent LLC, 5830 E 2nd St, Ste 7000, Casper, WY 82609, USA
- Privacy contact: privacy@rivelcompanies.com (or info@rivelcompanies.com)
If you need to exercise your privacy rights or have questions about how we handle your data, please contact us at the addresses above.
02Scope
This Policy applies to:
- our website(s) and landing pages,
- the RIVEL web application,
- any community, research, content, and communications we provide in connection with the Services.
It does not apply to third-party services you use independently (e.g., Stripe, Google, Apple, social networks). Those services have their own privacy policies.
03Information we collect
We collect information in four ways: (A) you provide it, (B) we collect it automatically, (C) we receive it from integrations you enable, and (D) payments (handled by Stripe).
A) Information you provide
- Account & profile: name, email, username, password (stored using hashing), profile settings, preferences.
- Content you create: notes, tasks, missions, OKRs, messages, journal entries, knowledge base entries, files you upload, and other content you submit within the Services.
- Communications: messages and information you send to us (support, contact forms, feedback, survey responses).
- Business information (if you engage with RIVEL services): company name, role, goals, and details you choose to share for delivery.
B) Information we collect automatically
- Usage data: pages/screens visited, features used, clicks, session duration, actions taken in the Services.
- Device & technical data: IP address, browser type, device type, OS, language, and approximate location derived from IP.
- Log data: diagnostic data to maintain security and reliability.
C) Information from integrations you enable
If you connect third-party tools (e.g., calendar, email, CRM, web services), we may receive and process the data necessary to provide that integration as authorized by you. You can disconnect integrations at any time.
D) Payments (Stripe)
If you purchase paid Services, payments are processed by Stripe. We typically receive limited payment-related information such as billing details and payment status. We do not store full payment card numbers; they are handled by Stripe.
04Sensitive data and wellbeing-related information
RIVEL may include features related to wellbeing and personal tracking (e.g., mood/energy/habits/reflections). This information can be sensitive depending on jurisdiction and context.
- You choose whether to provide this information.
- We treat wellbeing-style data as sensitive in practice and apply additional protections (see Security).
- RIVEL is not a medical service or medical device and does not provide medical advice.
05How we use your information
We use personal information to:
- Provide and operate the Services (create accounts, authenticate users, store your content, enable features).
- Personalize and improve the experience (recommendations, templates, organization, and helpful guidance).
- Power AI-assisted features (e.g., drafting, summarizing, suggesting next actions) based on the content and context you provide within the Services.
- Maintain safety and security (fraud prevention, abuse detection, account protection).
- Provide support and respond to inquiries.
- Analytics and product improvement (understanding usage to improve performance and reliability).
- Legal compliance (tax, accounting, enforcing terms, responding to lawful requests).
- Communications (service updates and announcements; marketing communications only where permitted or with consent—unsubscribe anytime).
We do not sell your personal information.
Legal basis for each purpose
If you are in the European Union, the United Kingdom or Switzerland, this is the ground we rely on for each thing we do:
- Answering a form you sent us: steps taken at your request before a contract, GDPR article 6(1)(b).
- Keeping the site online, secure and in your language: our legitimate interest in running a working website, GDPR article 6(1)(f).
- Counting visits without cookies: our legitimate interest in knowing which pages work, GDPR article 6(1)(f). No cookie is set, so no consent is required for the storage either.
- Meta pixel and Conversions API: your consent, GDPR article 6(1)(a) and article 5(3) of the ePrivacy Directive.
- Keeping a record of what you chose about cookies: our legal obligation to be able to prove it, GDPR articles 5(2) and 7(1).
- Invoices and accounting: legal obligation, GDPR article 6(1)(c).
- Running the product for a paying customer: performance of the contract, GDPR article 6(1)(b).
Where we rely on legitimate interest you can object at privacy@rivelcompanies.com, and we will stop unless we have a reason we can defend in writing.
06AI processing
RIVEL may provide AI-assisted features. Important notes:
- Your control: AI outputs depend on what you choose to input and request.
- No medical decisions: We do not use AI to provide medical diagnoses or treatment decisions.
- No “solely automated” significant decisions: We do not use AI to make decisions producing legal or similarly significant effects about you without appropriate human involvement.
07How we share information
We share information only as needed:
A) Service providers (processors)
We rely on a small set of carefully selected third-party vendors to host and operate the Services. Each provider acts as a data processor on our behalf under a Data Processing Agreement (DPA) and processes personal data only on documented instructions:
- Vercel Inc. — web hosting, edge runtime, and content delivery (USA).
- Supabase, Inc. — PostgreSQL database, authentication, storage, and realtime services (USA, EU regions available).
- Resend Inc. — transactional email delivery (USA).
- Stripe, Inc. — payment processing and billing (USA / global).
- Google LLC — Google Cloud infrastructure behind some of the services we use. This website no longer runs Google Analytics and no longer loads any Google tag.
- Anthropic, PBC and OpenAI, OpenCo. LLC — large-language-model APIs powering Axiom, the intelligence layer inside RIVEL OS. We use providers with zero-data-retention agreements where available.
- Vercel Inc. — also counts visits for us. It sets no cookie, it runs on our own domain, it never follows you to another site, and the result is a page count, not a profile.
The list of subprocessors may evolve. The current list is available on request. We require each provider to maintain confidentiality, implement appropriate security measures, and assist us with data-subject requests.
A-bis) Advertising partner (independent controller)
Meta is not our processor, and putting it on the list above was wrong. When you accept marketing cookies, Meta Platforms, Inc. decides on its own account what it does with the data it receives, so it acts as an independent controller and, for the collection that happens on this site, as a joint controller with us under the Meta Business Tools terms. That is a different legal relationship from the providers above, which is why it is described separately.
- What your browser sends Meta once you accept marketing: the address of the page you are on, the cookies
_fbpand_fbc, a random visitor number we generate (rivel-vid), your IP address and your browser user agent. - What our server sends Meta when you submit a form: the same page address, the same
_fbp,_fbcand visitor number, your IP address, your browser user agent, and your email address and first name turned into an irreversible SHA-256 fingerprint. Meta never receives your email or your name in readable form. - Why: to know whether an ad brought you here, and to stop paying for ads that bring nobody.
- Legal basis: your consent. If you reject marketing, or if your browser sends a do not sell signal, none of this happens. Not in your browser and not from our server. Our server checks your choice before it sends anything, which is the part most websites forget.
- Where: the United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, and we also rely on Standard Contractual Clauses.
- How to withdraw: use Cookie preferences in this policy. One click, effective immediately.
B) Payment processing
Stripe processes payments for paid Services.
C) Integrations you enable
We share information with third-party services only when you choose to connect them and only as required for that integration.
D) Legal and safety
We may disclose information if required by law or to protect rights, safety, and security (e.g., to respond to lawful requests, prevent fraud or abuse).
E) Business changes
If we undergo a business transition (e.g., incorporation, merger, acquisition, reorganization), information may be transferred as part of that process subject to appropriate protections.
08Data retention
We retain personal information only as long as necessary to:
- provide the Services,
- comply with legal obligations,
- resolve disputes,
- enforce agreements.
How long we keep each thing:
- Messages sent through a form on this site: 24 months from your last message, then deleted automatically by a scheduled job, not by someone remembering.
- Your cookie choice and its proof: 5 years, because that is how long we may need to demonstrate it.
- Email in our inbox: 24 months.
- Server logs: 30 days.
- Account data: while your account is active, then 90 days.
- Your content inside the product: until you delete it or ask us to, subject to legal requirements.
- Backups: up to 35 days after deletion, for disaster recovery only.
- Invoices: as long as tax law requires.
09Security
We implement safeguards designed to protect personal information, such as:
- access controls and least privilege principles,
- encryption in transit and, where applicable, at rest,
- monitoring for abuse and suspicious activity,
- separation of environments and secure secrets management.
No system can be guaranteed 100% secure. If we become aware of a security incident affecting your data, we will notify you and regulators as required by applicable law.
10International data transfers
We are a US-incorporated company (Wyoming) and primarily process personal data in the United States and the European Union. Personal data may be transferred to and processed in jurisdictions outside your country of residence.
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards including:
- the European Commission's Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Addendum, where applicable;
- supplementary technical and organisational measures (encryption in transit and at rest, access controls, audit logging).
For transfers from Mexico, we comply with the principles of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) and require equivalent contractual protections from recipients.
11Your privacy rights
Depending on where you live, applicable privacy law (including the EU/UK GDPR, the California CCPA/CPRA, and the Mexican LFPDPPP) gives you the following rights regarding your personal information:
- Access your personal information
- Correct inaccurate information
- Delete personal information
- Restrict or object to certain processing
- Port your data (where applicable)
- Withdraw consent (where processing is based on consent)
- Opt out of certain uses in jurisdictions that provide those rights
To exercise any of these rights, email privacy@rivelcompanies.com with:
- the email address associated with your account (if any),
- the request you are making,
- any relevant details to help us verify identity and locate the data.
We may need to verify your identity before fulfilling certain requests.
Do Not Sell or Share My Personal Information
We do not sell personal information for money. We do share it: when you accept marketing cookies, the Meta pixel and our Conversions API send Meta the data described in section 7, and California law calls that a share for cross-context behavioral advertising.
To stop it, use the control below, or Cookie preferences in this policy, or write to privacy@rivelcompanies.com. We also honor the Global Privacy Control signal automatically, browser by browser, with no account and no verification needed. We do not discriminate against anyone who opts out: nothing on this site is priced differently, gated or degraded because you said no.
Do Not Sell or Share My Personal Information
12Cookies and tracking technologies
Nothing that is not strictly necessary runs before you say yes. The first time you land here, no advertising script has been downloaded and no advertising cookie has been written. You choose first, rejecting takes exactly as many clicks as accepting, and if you reject, those scripts are never requested at all.
We ask again after 180 days, and any time we change what the categories do.
Essential. Always on.
- rivel-lang, set by rivelcompanies.com. Remembers whether you read the site in English or Spanish so we do not send you to the wrong version. 1 year.
- rivel-consent, set by rivelcompanies.com. Stores what you chose here, and a random reference number so we can prove you chose it. 180 days. A copy stays in this browser so we do not ask again if the cookie is cleared too soon.
Counting visits. No cookie at all.
We measure how many people read which pages using Vercel Web Analytics. It writes nothing to your browser, it runs on our own domain, it cannot follow you to any other website, and it is never used to build a profile or to target an ad. Because there is no storage on your device, this needs no consent, and it keeps working whether you accept marketing or refuse it.
This site no longer runs Google Analytics. If your browser still holds a _ga or _ga_* cookie from before, we delete it on your next visit.
Marketing. Only if you accept.
- _fbp, written by the Meta pixel on rivelcompanies.com. Identifies this browser to Meta so a conversion can be tied to an ad. 90 days.
- _fbc, written on rivelcompanies.com. Stores the click identifier of the ad you arrived from. 90 days.
- rivel-vid, set by rivelcompanies.com. A random number, tied to no name, that lets our server and your browser report the same visit once instead of twice. 180 days.
- rv_first and rv_last, set by rivelcompanies.com. Which campaign or link first brought you here and which one brought you back, so we can tell useful advertising from wasted advertising. 180 and 90 days.
- fr, set by facebook.com. Meta's own advertising cookie, placed by the pixel on Meta's domain, not ours.
What happens when you reject or withdraw
We delete the marketing cookies we set from this browser, the scripts stop being loaded, and our server stops sending your form submissions to Meta. Cookies that Meta holds on its own domain, like fr, sit outside our reach: only your browser settings or Meta can remove those, and we say so rather than promise a deletion we cannot perform.
Change your mind at any time with Cookie preferences, on this page. Browser settings work too, and if your browser sends a Global Privacy Control signal we treat it as a rejection of marketing without asking you anything.
13Children’s privacy
The Services are not intended for children under 13 (or under 16 where required by local law). We do not knowingly collect personal information from children. If you believe a child has provided information, contact info@rivelcompanies.com.
14Third-party links
Our Services may include links to third-party sites. Their practices are governed by their own policies, and we are not responsible for them.
15Changes to this Privacy Policy
We may update this Policy from time to time. If changes are material, we will provide notice (e.g., in-app or email notice) and update the “Last updated” date.
16Contact
For questions or requests regarding this Privacy Policy:
- Email: privacy@rivelcompanies.com
- Mail: RIVEL Companies International LLC, 5830 E 2nd St, Ste 7000 #35827, Casper, WY 82609, USA
EU/EEA residents may also lodge a complaint with their local supervisory authority. UK residents may contact the Information Commissioner's Office (ICO). California residents may contact the California Privacy Protection Agency (CPPA). Mexican residents may contact INAI.