Privacy Policy

This policy explains what personal data Rileva collects, why we process it, who receives it, how long we keep it, and the rights you have. Rileva does not use your conversations, prompts, files, images, memories or outputs to train AI models.

Effective and last updated: 19 September 2026 · Rileva is operated by SOUNDTECH INVEST PROSTA SPÓŁKA AKCYJNA.

1. Who we are

Rileva is operated by SOUNDTECH INVEST PROSTA SPÓŁKA AKCYJNA, ul. Sławęcińska 10, 05-850 Macierzysz, Poland (KRS 0000971111, NIP 1182241482, REGON 521991622). Rileva is the trading name of the product available at rileva.ai.

We are the controller of the personal data described in this policy. For any privacy question or request, write to privacy@rileva.ai. We have not appointed a Data Protection Officer; privacy requests are handled by our team at that address.

2. Scope

This policy covers the Rileva website, the Rileva workspace (chat, Council, search, files, images, projects, memory and settings), account and billing processes, and support communications. It applies to consumers and to people using Rileva on behalf of a business. Rileva is available worldwide and is intended only for people aged 18 or over.

Linked third-party websites and services have their own privacy policies, which apply to your use of them.

3. What data we process

  • Account and profile data: your email address, the authentication identifiers issued by our authentication provider, and — if you sign in with Google — the name and profile picture Google returns for your account.
  • Temporary workspaces: if you start using Rileva before creating an account, we create an anonymous account so your workspace can exist. It is stored on our systems and can later be claimed by signing up.
  • Your content: prompts and chat messages, uploaded files and the text extracted from them, generated images, model outputs, projects, saved memories and custom instructions.
  • Settings and preferences: appearance, default routing mode, model-label and notification preferences, memory settings, and your selected image engine.
  • Billing and subscription data: plan, subscription status, billing period, credit balance and usage records, and the identifiers and events we receive from our payment processor. We never receive or store full card numbers.
  • Technical and security data: request, error and operational logs generated when you use the service, including technical metadata such as timestamps, request identifiers, device/browser information and network address data processed by our hosting and infrastructure providers for delivery and security.
  • Support communications: the content of messages you send us and our replies.
  • Connected-service data: if and when you authorise a connected service, only the data that service returns under the permissions you grant. Connections are not yet available in Rileva; this applies only once the feature is enabled and you connect an account.

4. Where the data comes from

  • Directly from you: what you type, upload, configure and send us.
  • Automatically from your use of the service: technical, usage and security records.
  • From our payment processor: subscription and payment status events.
  • From your identity provider: if you sign in with Google, the profile information Google shares with us.
  • From a connected service, once you have authorised it.

5. Why we process data, and our legal bases

  • To provide the service — creating your account, running your requests through the selected model or models, storing your chats, projects and files, and keeping everything available across your devices. Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)).
  • To process payments, subscriptions and credits. Legal basis: performance of a contract, and legal obligation for invoicing and tax records (Art. 6(1)(b) and (c)).
  • To keep Rileva secure and reliable — abuse prevention, rate and usage enforcement, debugging, and protecting our systems and users. Legal basis: our legitimate interests (Art. 6(1)(f)).
  • To improve and operate the product — diagnosing failures and understanding aggregate reliability and cost. Legal basis: legitimate interests (Art. 6(1)(f)). This does not include training AI models on your content.
  • To provide optional features you switch on, such as memory and chat history recall, and to store non-essential preferences where consent is required. Legal basis: your consent (Art. 6(1)(a)), withdrawable at any time in Settings.
  • To respond to support requests and to handle legal claims and obligations. Legal basis: legitimate interests and legal obligation (Art. 6(1)(f) and (c)).

6. How your content reaches AI providers

This is the most important part of this policy, so we state it plainly. To produce an answer, Rileva sends your prompt together with the relevant conversation and project context, any relevant files or text extracted from them, and the settings for that request, to the AI provider selected for that request — either automatically by Auto, or by you.

When you use Council, the relevant content is sent to several selected providers at the same time, and their answers are then sent to the provider that produces the synthesis. Image generation sends your prompt to the applicable image provider. Web search sends your query, and where relevant your prompt, to the applicable search provider or tool, which may fetch page content from the open web.

Rileva does not use your conversations, prompts, files, images, memories or outputs to train AI models. We use providers' API or commercial services to return results for your request. Their contractual terms, product settings and applicable law govern their handling of data. We cannot promise that no third party retains anything: providers operate their own systems and may retain data briefly for delivery, abuse prevention or legal reasons, and their practices may differ and may change.

For that reason, please do not submit unnecessary sensitive, confidential, medical, financial, authentication, government-ID, trade-secret or third-party personal information. Upload only content you own or are authorised to share, and make sure you have a lawful basis or permission for any personal data about other people.

7. Who receives your data

We share personal data with service providers and other recipients only as necessary to run Rileva. Depending on the service and the context, they may act as our processors or subprocessors, or as independent controllers. By category, and naming the services confirmed in our current setup:

  • Cloud platform, database, authentication and file storage: Supabase.
  • Application hosting and infrastructure: Lovable and its underlying hosting infrastructure.
  • Payments and subscriptions: Stripe (which acts as an independent controller for payment data it collects).
  • AI model providers, used for the models you or Auto select: OpenAI, Anthropic, Google (Gemini), xAI (Grok), Mistral and Perplexity.
  • Search and web-retrieval tooling: Firecrawl, and the built-in web search / grounding capabilities of OpenAI and Google.
  • Authentication provider for social sign-in: Google, if you choose to sign in with Google.
  • Connected services: only those you explicitly authorise, once that feature is available.

We may also disclose data to professional advisers, or to authorities and courts where we are legally required to do so, or to establish, exercise or defend legal claims. We do not sell personal data and we do not share it for advertising.

8. International transfers

Some of the providers above process data outside the European Economic Area, including in the United States. Where that happens, we rely on the appropriate safeguards available under Chapter V of the GDPR — most commonly the European Commission's Standard Contractual Clauses, or an adequacy decision where one applies to the recipient.

We do not claim any certification, seal or audit standard for Rileva. You can ask us for information about the safeguards applying to a specific transfer by writing to privacy@rileva.ai.

9. How long we keep data

  • Chats, projects, memories, custom instructions, files, generated images and account data: kept while your account exists, or until you delete them.
  • Account deletion or a deletion request: removed from our active systems within 30 days, subject to legal, fraud-prevention, security and dispute-preservation requirements.
  • Encrypted backups and security or operational logs: may persist for up to 90 days.
  • Billing, transaction and tax records: kept for the period required by Polish and EU law.
  • Temporary guest workspaces: a workspace created before sign-up is stored under an anonymous account and remains until it is claimed or deleted. A guest gets two demo answers; guest chats are not carried between different browsers or devices, because the temporary session lives only in the browser you used.
  • De-identified or aggregated information may be kept longer where it can no longer reasonably identify you.

10. Cookies and local storage

Rileva uses storage that is necessary to make the service work, plus optional advertising measurement only if you accept it. The essential storage is:

  • Your sign-in session, stored by our authentication provider in your browser so you stay logged in.
  • A small cookie remembering whether the sidebar is open, and local preferences such as your appearance (light/dark) and image-engine choice.
  • A short-lived local entry used to carry a guest workspace over when you sign up.
  • Security and load-balancing measures applied by our hosting infrastructure while serving requests.

Optional: Google Ads measurement. We load Google's tag (gtag.js) on every page with all consent signals — ad storage, analytics storage, ad user data and ad personalization — set to denied. Only if you choose "Accept all" in our cookie banner do we allow Google to set advertising cookies and let us report, to Google Ads, that a visit led to a paid subscription (the invoice ID, amount and currency; no name, email or card details). This helps us measure which ads work. If you choose "Reject non-essential", nothing is stored for advertising and no purchase is reported. We keep a record of your choice (accepted or rejected, and when) in your browser. You can change or withdraw your choice at any time via "Cookie settings" in the site footer or on the pricing page; withdrawal applies to anything reported afterwards.

11. Security

We take reasonable technical and organisational measures appropriate to the risk: encryption in transit, access controls and row-level authorisation rules so your data is only reachable by your account, restricted administrative access, and separation of secrets from application code.

No online service can be guaranteed completely secure. We make no certification claims for Rileva and encourage you to keep your email account secure, since sign-in links are delivered there.

12. Your rights

If the GDPR applies to you, you have the right to access your data, to have inaccurate data corrected, to have data deleted, to restrict processing, to data portability, to object to processing based on our legitimate interests, and to withdraw a consent at any time without affecting processing already carried out.

You can exercise some of these rights directly in Rileva — you can edit or delete the items the product lets you manage, such as chats, projects, files, images, memories and instructions. Account deletion, and any right that is not available in the product, must be requested by writing to privacy@rileva.ai. We may need to verify your identity, and we will reply within the statutory deadline. Once we process a deletion, your data is removed from our active systems within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw. You may also complain to the authority in your country of residence.

13. Automated decisions

Rileva selects a model automatically and may route a request between providers. This is a technical product function that affects which model answers you; it is not a decision producing legal effects concerning you or similarly significantly affecting you. We do not carry out automated decision-making of that kind, and we do not profile you for advertising.

14. Age

Rileva is for adults. You must be at least 18 years old to create an account or use the service. We do not knowingly collect data from children; if you believe a minor has used Rileva, contact privacy@rileva.ai and we will delete the account.

15. Changes and contact

We may update this policy as the product changes. We will update the date at the top, and for significant changes we will notify you in the product or by email before they take effect.

Questions or requests: privacy@rileva.ai. General support: support@rileva.ai.