RiverX
Privacy

Privacy Policy

Effective: September 5, 2026Last updated: September 5, 2026Applies to: riverx.app and the RiverX application

This Privacy Policy explains how RiverX collects, uses, shares, transfers, retains, and protects personal data when you visit riverx.app, create an account, build projects with AI models, store data in a project database, or deploy a site through the Service. It also explains the rights you have over your data and how to exercise them.

This policy forms part of, and should be read with, our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms.

We do not sell your data

We do not sell or share personal data for cross-context behavioural advertising, and we run no advertising or third-party tracking cookies.

We do not train on your work

We do not use your prompts, code, or project content to train our own AI models. Model Providers you select apply their own policies.

You stay in control

You can access, correct, export, and delete your data from your account settings or by contacting us at any time.

We keep it lean

We collect what is needed to run the Service, secure it, bill accurately, and meet legal obligations — and we publish exactly how long we keep each category.

Contents

  1. Scope and who we are
  2. Our role: controller and processor
  3. Information we collect
  4. How we use information
  5. Legal bases for processing
  6. AI processing and model providers
  7. Cookies and similar technologies
  8. How we share information
  9. International data transfers
  10. How long we keep information
  11. How we protect information
  12. Your rights and choices
  13. Regional disclosures
  14. Data from your End Users
  15. Children’s privacy
  16. Automated decision-making
  17. Third-party links and integrations
  18. Changes to this policy
  19. Contact and grievance redressal

1. Scope and who we are

RiverX operates the Service and is responsible for the personal data described in this policy. You can reach us at support@riverx.app; our full contact details, including our Grievance Officer, are in Section 19.

This policy covers our own website and application. It does not cover sites and applications that our users build and deploy through the Service — those are operated by the users themselves, who set their own privacy practices (see Section 14) — nor third-party services you choose to connect, which are governed by their own policies.

2. Our role: controller and processor

Our role under data protection law depends on whose data is involved:

  • We are the controller (the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023) for data about you as our user — your account, billing, support, and usage of the Service. We decide why and how that data is processed, and this policy is our notice to you.
  • We are a processor (a “Data Processor”) for personal data that you or your End Users put into your Projects — prompts, project files, and project databases. We process that data on your instructions to provide the Service. You are the controller of it and are responsible for having a lawful basis, giving notice, and honouring rights requests.

Where we act as your processor, we will process the data only to deliver the Service and as your instructions and applicable law require; keep it confidential; apply the safeguards in Section 11; engage only the subprocessors listed in Section 8 under equivalent obligations; assist you with rights requests and security incidents so far as is reasonable; and delete or return the data as described in Section 10. If you require a separate written data processing agreement or standard contractual clauses, contact us at support@riverx.app.

3. Information we collect

Information you give us

  • Account data — email address, password credential (stored only as a salted hash by our authentication provider), display name, and avatar. If you sign in with Google, we receive your Google account identifier, email address, name, and profile picture from Google.
  • Project content — prompts and instructions you write, files and images you upload, code and configuration in your workspace, data you store in a project database, and repositories you connect.
  • Billing data — the amount you add to your Wallet, transaction identifiers, invoice records, and billing contact details. Card numbers are collected and stored by our payment processor, not by us; we receive only a token and limited metadata such as the card brand and last four digits.
  • Communications — the content of support requests, bug reports, and other messages you send us, along with your notification and marketing preferences.

Information we collect automatically

  • Usage and telemetry — features used, models selected, requests made, tokens and credits consumed, build and deployment events, error and diagnostic events, and timestamps.
  • Device and connection data — IP address, browser type and version, operating system, language, referring URL, and similar request headers, collected in server logs.
  • Cookies and local storage — strictly necessary session and security identifiers. See Section 7.

Information we receive from others

  • Authentication and identity confirmation from Google, where you use Google sign-in.
  • Payment status, refund, chargeback, and fraud-risk signals from our payment processor.
  • Deployment, domain, and delivery status from our hosting and infrastructure providers.
Sensitive data

We do not ask for, and ask that you do not submit, special or sensitive categories of personal data — government identifiers, financial account details, health or biometric data, precise geolocation, racial, religious, political, or sexual-orientation data — through prompts, project files, or project databases. If you do, you are responsible for having a lawful basis and appropriate safeguards, and you accept that the data will be processed through the third parties listed in Section 8. We do not use sensitive personal data to infer characteristics about you.

4. How we use information

  • Provide the Service — authenticate you, run workspaces, generate and edit code, produce previews, attach databases, publish deployments, and connect custom domains.
  • Bill accurately — meter usage, debit your Wallet, process top-ups, issue invoices, handle refunds and disputes, and prevent payment fraud.
  • Secure the platform — detect and investigate abuse, fraud, credential compromise, automated sign-ups, and violations of our Acceptable Use Policy; enforce usage limits; and protect our users, our providers, and the public.
  • Support you — respond to your questions, diagnose problems, and communicate about service issues, incidents, and changes to our terms.
  • Improve the Service — analyse aggregated and de-identified usage to understand reliability, performance, and which features are useful. We do not use your project content to train our own AI models.
  • Send communications — transactional and security emails you cannot opt out of while your account is open, and product or marketing emails you can turn off at any time in your settings.
  • Comply with law — meet tax, accounting, and record-keeping obligations, respond to lawful requests, and establish, exercise, or defend legal claims.

We will not use your personal data for a materially different purpose without first giving you notice and, where required, obtaining your consent.

5. Legal bases for processing

Where the EU or UK GDPR applies to you, we rely on the following legal bases. Where India’s Digital Personal Data Protection Act, 2023 applies, we rely on your consent or on legitimate uses recognised by that Act, including processing you have voluntarily provided data for and processing required by law.

PurposeLegal basis
Creating your account and providing the ServicePerformance of a contract with you
Processing payments and keeping financial recordsPerformance of a contract; compliance with a legal obligation
Security, abuse prevention, and enforcing usage limitsLegitimate interests in protecting the Service and its users
Service reliability, diagnostics, and product improvementLegitimate interests in operating and improving the Service
Marketing emails and optional product updatesConsent, withdrawable at any time
Responding to lawful requests and defending legal claimsCompliance with a legal obligation; legitimate interests

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to that processing as described in Section 12. Withdrawing consent does not affect processing carried out before withdrawal.

6. AI processing and model providers

When you use a generation or editing feature, we send the prompt you wrote and the parts of your project needed for context — such as relevant files, file structure, and recent conversation — to the Model Provider serving the model you selected, routed through our model gateway. The provider generates output and returns it to us, and we store it in your project.

What this means for you

We do not train our own models on your content, and we do not license your project content to anyone for model training.

Model Providers apply their own policies. Once your prompt reaches a provider, that provider’s privacy policy, retention period, and training terms apply in addition to ours. Retention and training practices differ between providers and can change. Where a provider offers a zero-retention or no-training configuration for the route we use, we prefer it, but we cannot guarantee the practices of every provider in a catalogue of hundreds of models.

Do not put anything into a prompt that you are not permitted to disclose to a third-party processor. That includes secrets, credentials, personal data you have no basis to share, and material covered by a confidentiality obligation.

Conversation history and workspace context are cached to make follow-up requests coherent and fast; that cache expires automatically on a rolling window of up to 30 days. We retain metered usage records — which model, how many tokens, what it cost — for billing and abuse prevention, as set out in Section 10.

We may review prompts and outputs manually in narrow circumstances: when you ask us to for support, when we are investigating a specific security or abuse signal, or when we are required to by law. Such access is limited to staff who need it and is logged.

7. Cookies and similar technologies

We use only strictly necessary cookies and equivalent browser storage. We do not run advertising networks, cross-site tracking pixels, or third-party analytics on riverx.app.

CategoryPurposeDuration
AuthenticationKeep you signed in and refresh your session securely. Set by our authentication provider on our domain.Session, and refresh tokens until sign-out or expiry
SecurityProtect against cross-site request forgery, session fixation, and automated abuse.Session
PreferencesRemember interface choices such as your last-used model or workspace layout.Stored locally in your browser until you clear it

Because these are strictly necessary to deliver a service you have requested, they do not require consent under the ePrivacy Directive or equivalent rules. You can block or delete cookies in your browser, but the Service will not work correctly without the authentication and security cookies. We honour Global Privacy Control and “Do Not Track” signals to the extent they are legally recognised; since we do not sell or share personal data or serve behavioural advertising, there is no tracking for them to disable.

Sites you deploy through the Service may set their own cookies. Those are your responsibility as the operator of that site — see Section 14.

8. How we share information

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose personal data only in the circumstances below.

Service providers and subprocessors

We rely on the categories of provider below to operate the Service. Each provider we engage is bound by contract to process personal data only on our instructions, keep it confidential, apply appropriate security, and delete or return it when our engagement ends. We engage subprocessors only where they are needed to deliver a feature you use.

Category of providerPurposeData involvedProcessing location
Authentication and identitySigning you in, securing sessions, and storing account recordsEmail address, authentication identifiers, profile name and avatarIndia, EU, or United States
Payment processingWallet top-ups, invoicing, refunds, and payment fraud checksPayment method tokens, amounts, billing identifiers (full card numbers never reach us)United States or global
AI model providers and routingGenerating output from the prompt and context you submit, using the model you selectPrompts, relevant project context, generated output, usage metadataVaries by provider and model
Cloud hosting and computeRunning our application, your workspace containers, and the sites you deployProject files, build and deployment logs, request and visitor dataIndia, EU, United States, or global edge networks
Databases and object storageProject databases you create and storage of uploaded or generated assetsWhatever you or your End Users store in a project database; uploaded files and assetsThe region you select, or a region we select
Caching and queueingShort-lived caching of conversation and workspace context so follow-up requests stay coherentConversation history and repository context, expiring on a rolling windowThe region we select
Code repository hostingOptional repository connection and code sync, only where you connect oneContents and metadata of repositories you choose to connectUnited States or global
Email deliverySending transactional, security, and (if enabled) product emailsEmail address, message content, delivery statusUnited States or global
Media and asset lookupFetching stock imagery when a project requests itImage search terms onlyGlobal
The named list

We maintain an up-to-date list naming every subprocessor in each category, along with its role and processing location. We provide that list on request — email support@riverx.app — including where you need it for your own compliance records, a vendor assessment, or a data processing agreement under Article 28 of the GDPR. If you have a data processing agreement with us, we will notify you of new subprocessors in advance and give you an opportunity to object, as that agreement provides.

Other disclosures

  • Legal and safety. We may disclose data where we believe in good faith that it is required by law, a valid court order, or a lawful request from a government or regulatory authority, or where disclosure is necessary to investigate suspected fraud or abuse, enforce our Terms, protect the rights, property, or safety of RiverX, our users, or the public, or defend legal claims. Where we are legally permitted, we will notify you before disclosing your data and will challenge requests we consider overbroad or unlawful.
  • Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, data may be transferred as part of that transaction, subject to the acquirer honouring this policy. We will notify you of any change in control affecting your data.
  • Professional advisers. Auditors, lawyers, accountants, and insurers, under confidentiality obligations.
  • With your direction. When you connect a third-party account, publish a project, or otherwise ask us to send data somewhere.
  • Aggregated and de-identified data. We may publish or share statistics that cannot reasonably be used to identify you, and we will not attempt to re-identify them.

9. International data transfers

We operate globally, and the providers listed above process data in India, the United States, the European Union, and other countries. This means your personal data may be transferred to and processed in a country whose data protection laws differ from those of your own.

Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate safeguard — an adequacy decision where one applies, or the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant) — together with a transfer risk assessment and, where appropriate, additional technical measures such as encryption in transit and at rest. Transfers out of India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified under it.

You can request a copy of the safeguards we rely on by emailing support@riverx.app.

10. How long we keep information

We keep personal data only for as long as we need it for the purpose we collected it, or for as long as the law requires. Our standard periods are below; where periods overlap, the longest applicable period governs.

CategoryRetention period
Account and profile recordsFor as long as your account is open
Projects, workspace files, and project databasesWhile the project exists; up to 30 days after account closure, then deleted
Conversation history and workspace context cacheUp to 30 days on a rolling window, then automatically expired
Prompts and outputs held by a Model ProviderGoverned by that provider’s own policy
Wallet, invoice, and transaction recordsAt least 8 years, as required by Indian tax, accounting, and company law
Security, access, and operational logsUp to 12 months
Support correspondenceUp to 24 months after the matter is closed
System backupsUp to 35 days on a rolling cycle
Records of consent, opt-outs, and rights requestsFor as long as needed to evidence compliance

When you delete a project or close your account, we begin deletion from active systems within 30 days. Copies may persist in encrypted backups for up to a further 35 days before being overwritten on our ordinary cycle, and we may retain the limited records we are legally required to keep — chiefly financial records — and anything needed to defend a live legal claim. Data that has been aggregated or de-identified so it can no longer be linked to you may be retained indefinitely.

11. How we protect information

  • Encryption in transit using TLS, and encryption at rest for stored data and backups.
  • Isolated, containerised workspaces so one user’s project cannot reach another’s, with row-level access controls on account and project records.
  • Least-privilege access for our staff, credential rotation, secret management, and logging of administrative access.
  • Payment data handled by a PCI-DSS compliant processor; we never store full card numbers.
  • Rate limiting, abuse detection, and monitoring of security and availability signals.

No system is perfectly secure, and we cannot guarantee absolute security. You play an essential part: use a strong, unique password, enable multi-factor authentication where available, keep credentials and API keys out of prompts and repositories, and tell us immediately at support@riverx.app if you suspect a compromise.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority — including, where applicable, the Indian Computer Emergency Response Team and the Data Protection Board of India — within the timeframes the law requires, and will notify affected users without undue delay, describing what happened, what data was involved, and what to do about it.

If you believe you have found a vulnerability, please report it to support@riverx.app rather than disclosing it publicly, and give us a reasonable opportunity to fix it. We will not pursue good-faith research that respects user privacy and avoids service disruption.

12. Your rights and choices

Subject to the law that applies to you, you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Correct data that is inaccurate, incomplete, or out of date.
  • Delete your data, subject to records we must keep by law.
  • Port data you provided to us in a structured, commonly used, machine-readable format.
  • Restrict or object to processing based on our legitimate interests, including profiling.
  • Withdraw consent at any time where processing is based on consent.
  • Nominate another individual to exercise your rights in the event of your death or incapacity, where the Digital Personal Data Protection Act, 2023 applies.
  • Complain to a supervisory authority, without prejudice to raising the matter with us first.

Exercising your rights

Many of these are available directly in your dashboard: update your profile, email address, and password in Settings, manage notification and marketing preferences there, and review billing history in Billing. For anything else, email support@riverx.app from the address on your account, or use the Support page.

We will verify your identity before acting — normally by confirming control of your account email, and for higher-risk requests by asking for additional confirmation. An authorised agent may act for you with written proof of authority. We respond within 30 days, or 15 days for grievances under Indian law, and will tell you if we need an extension the law permits. There is no charge unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline and explain why. We will never discriminate against you for exercising a privacy right.

You can unsubscribe from marketing email using the link in any such message or in your settings. We will still send transactional and security messages while your account is open.

13. Regional disclosures

India — Digital Personal Data Protection Act, 2023

We act as a Data Fiduciary for your account data and process it for the lawful purposes described in Section 4. You have the rights to access, correction, erasure, nomination, and grievance redressal set out in Section 12. Our Grievance Officer is the point of contact for grievances under the Act and under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and will acknowledge your complaint within 48 hours and resolve it within 15 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India. The Act requires you to provide authentic information and not to raise false or frivolous grievances.

European Economic Area, United Kingdom, and Switzerland — GDPR

Our legal bases are in Section 5 and our transfer safeguards in Section 9. You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office. We do not currently carry out processing that requires a designated Data Protection Officer; the contact in Section 19 handles all data protection enquiries. Where we act as your processor, Section 2 describes the terms that apply, and we will enter a separate data processing agreement on request.

California — CCPA/CPRA

In the twelve months before the date of this policy, we collected the categories of personal information described in Section 3 — identifiers, customer records, commercial information, internet activity, and the contents of your own submissions — for the business purposes in Section 4, and disclosed them to the service providers listed in Section 8. We have not sold personal information and have not shared it for cross-context behavioural advertising, including that of consumers under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. California residents have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination; exercise them as described in Section 12. You may appeal a decision by replying to our response.

Other United States state privacy laws

If you are a resident of a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — you have equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising or sell personal data. You may appeal a refused request by emailing support@riverx.app with “Privacy appeal” in the subject line; we will respond within 45 days and, if we deny the appeal, tell you how to contact your state Attorney General.

14. Data from your End Users

If you deploy a site or application through the Service and it collects personal data from visitors, customers, or other End Users, you are the controller of that data and we are your processor. We do not use it for our own purposes.

  • You must publish your own privacy notice on your site, describing what you collect and why, and identify yourself as its operator.
  • You must obtain any consent the law requires — including for non-essential cookies and marketing — and honour End User rights requests.
  • If an End User contacts us about data on your site, we will refer them to you and, where we are able, let you know.
  • You must not use the Service to process personal data in a way that would put us in breach of law, and you indemnify us for claims arising from your handling of End User data as set out in the Terms.

15. Children’s privacy

The Service is not directed to children. You must be at least 18 to hold an account in your own name; a person aged 13 to 18 may use the Service only through an account held and supervised by a parent or legal guardian who consents to this policy. We do not knowingly collect personal data from anyone under 13, and where India’s Digital Personal Data Protection Act, 2023 applies we do not knowingly process a child’s data without verifiable parental consent, do not track or profile children, and do not direct advertising at them.

If you believe a child has provided us with personal data, contact support@riverx.app and we will delete the account and its data promptly.

16. Automated decision-making

We use automated systems for fraud scoring, abuse detection, and enforcing usage limits — for example, automatically throttling or suspending an account whose activity matches abuse patterns. We do not make decisions producing legal or similarly significant effects on you solely by automated means without human involvement. If an automated control affects your account, you can ask a person to review it by contacting support@riverx.app, and you may contest the decision and express your point of view.

AI models generate output in response to your prompts; that is a content-generation process, not a decision we make about you. See the Terms for the limits of that output.

17. Third-party links and integrations

The Service links to and integrates with third-party websites and services, including code repositories, domain registrars, payment providers, and Model Providers. We are not responsible for their privacy practices, and this policy does not apply to them. Review their policies before connecting an account or sending them data. Disconnecting an integration stops future sharing but does not retrieve data already transferred.

18. Changes to this policy

We may update this policy as the Service, our providers, or the law change. We will revise the “Last updated” date above, and for material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give notice by email or in the product before the change takes effect, and obtain your consent where the law requires it. Previous versions are available on request.

19. Contact and grievance redressal

RiverX

Privacy enquiries and rights requests: support@riverx.app

Grievance Officer (Digital Personal Data Protection Act, 2023 and IT Rules, 2021): support@riverx.app

We acknowledge grievances within 48 hours and aim to resolve them within 15 days. You can also reach us through the Support page, and read the terms governing the Service in our Terms of Service.