Riviso← Home

Privacy Policy

Effective date: 27 September 2026
In short: we collect what's needed to run your projects and publish your content, we encrypt the credentials you connect (WordPress, Shopify, Google), we never sell your data, and you can export or permanently delete your account at any time. If you're looking for India-specific rights under the Digital Personal Data Protection Act, see our Data Privacy Policy.

This Privacy Policy explains how Riviso (“Riviso”, “we”, “us”, “our”) collects, uses, discloses, and protects information when you use the Riviso application, website, and related services (the “Service”). It applies to visitors, registered users, and their end customers where relevant. By using the Service you agree to the practices described here. If you do not agree, please do not use the Service.

This policy is written to be accurate to how Riviso actually works today. Where a feature or integration is optional (for example, connecting WordPress or Google Search Console), the related data collection only happens if you choose to enable it.

1. Information we collect

1.1 Account information

  • Email address, and password (stored only as a salted Argon2id hash — we never store or can recover your plain-text password).
  • Optional profile details you provide: full name, phone number, timezone.
  • Subscription/plan tier and usage counters (e.g. articles generated this month) used to enforce your plan's limits.

1.2 Project and integration data

You choose what to connect. We only collect the following when you set it up:

  • WordPress: site URL, WordPress username, and an Application Password you generate in your own WordPress admin. The Application Password is encrypted at rest and used only to publish/update posts you initiate.
  • Shopify: your store domain and the OAuth access token / API credentials Shopify issues when you authorize the connection. Encrypted at rest; used only for the store actions you initiate (e.g. publishing a blog article).
  • Google Search Console: if you connect a property, we request read/management access (the Google “webmasters” scope) to show performance data and, where you request it, to submit a URL for indexing after you publish. OAuth tokens are encrypted at rest. Our use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
  • Website URL and platform choice for projects you create, including projects you choose to leave unconnected while trying Riviso out.

1.3 Content you create

  • Article drafts, titles, metadata, and generated or uploaded images.
  • Prompts and prompt templates you write or customize (writing prompts, image prompts).
  • Keywords, topic clusters, and research inputs you provide or that our tools derive from a website you connect.

1.4 Technical and usage data

  • IP address, browser/device information, and request metadata — used transiently for security, rate-limiting, and abuse prevention, not for advertising.
  • Application logs and error reports (see “Third-party processors” below regarding our error-monitoring provider).
  • Authentication session identifiers stored in secure, HTTP-only cookies (see our Cookie Policy).

2. How we use information

  • To provide the Service: generating, editing, scheduling, and publishing content you request.
  • To operate integrations you enable (WordPress, Shopify, Google Search Console) strictly for the actions you initiate.
  • To send transactional email: email verification codes, password reset links, and account/plan notifications.
  • To enforce plan limits and prevent abuse of the Service.
  • To maintain, secure, debug, and improve the Service (including via the error-monitoring tool described below).
  • To comply with legal obligations and respond to lawful requests.

We do not sell your personal information, and we do not use your account or content data to train third-party AI models beyond what is strictly needed to generate the content you request in the moment.

3. AI-generated content

Riviso uses OpenAI's API to generate article text and images from the prompts, keywords, and settings you provide. The text/prompts sent to generate your content are transmitted to OpenAI for that purpose under OpenAI's own API data-use terms, which (at the time of writing) do not use API-submitted content to train their models by default. You are responsible for reviewing AI-generated content before publishing it — see our Disclaimer.

4. Third-party processors

We use a small number of service providers to operate Riviso. Each only receives the data necessary to perform its function:

ProviderPurposeData involved
OpenAIArticle/image generationPrompts, keywords, generation settings you submit
Google (Search Console API)Performance data, indexing requestsOAuth token, the property you connect
WordPress (your own site)Publishing content you requestApplication Password, published content
Shopify (your own store)Publishing content you requestOAuth token, published content
MongoDB AtlasPrimary database hostingAll account, project, and content data described above
Hosting providers (Vercel, our VPS host)Running the applicationRequest/traffic data necessary to serve the Service
SentryError monitoring / crash reportingTechnical error context (e.g. stack traces); we configure it to avoid sending passwords or credentials
Email delivery (SMTP provider)Verification and account emailsYour email address and the message content

These providers are contractually or by policy restricted to using data only to provide their service to us, not for their own independent purposes.

5. Data security

  • Passwords are hashed with Argon2id — never stored or logged in plain text.
  • Sensitive connection credentials (WordPress application passwords, Shopify tokens, Google OAuth tokens) are encrypted at rest.
  • Authentication uses short-lived, HTTP-only, secure session cookies rather than tokens exposed to page scripts.
  • Outbound requests you configure (e.g. to a WordPress/Shopify URL) are checked against known internal/private network ranges to prevent server-side request forgery.
  • No method of transmission or storage is 100% secure; we work to protect your information but cannot guarantee absolute security.

6. Data retention

We retain your account and project data for as long as your account is active. If you deactivate your account, your projects and articles are retained so you can reactivate later with your data intact. If you permanently delete your account (available any time from your Profile settings, or by emailing support@riviso.com), we erase your projects, articles, scheduled jobs, and subscription records. Some records may be retained where required by law (e.g. billing/tax records, security logs) for the period required by the applicable regulation.

7. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent at any time. You can exercise most of these directly in the app (Profile settings), or by contacting support@riviso.com. Indian users: see our Data Privacy Policy for Digital Personal Data Protection Act, 2023 specific rights and our Grievance Redressal process. EU/UK users have rights under the General Data Protection Regulation (GDPR); California residents have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale of personal information — we do not sell personal information as defined by the CCPA.

8. International data transfers

Our infrastructure and service providers may process data outside your home country (for example, our database and hosting providers may operate servers in other regions). Where we transfer personal data internationally, we rely on the transfer mechanisms recognized under applicable law (such as standard contractual clauses under GDPR) and take steps to ensure an equivalent level of protection.

9. Children's privacy

Riviso is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact support@riviso.com and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above; continued use of the Service after a change constitutes acceptance of the revised policy.

11. Contact us

Questions about this policy or your data: support@riviso.com.
Grievance Officer (India): grievance@riviso.com — see Grievance Redressal for details.
Registered address: [Registered business address to be added]

Privacy PolicyData Privacy Policy (DPDP Act)Terms & ConditionsCookie PolicyDisclaimerRefund & Cancellation PolicyGrievance Redressal