Privacy Policy
Effective August 10, 2026
In short: We collect what the product needs to work: your account details, the positions you enter, and basic security records. We do not sell personal information, and we never see your card number. This summary is for orientation only — the sections below are the agreement.
This policy explains what Riviy collects, why, who else touches it, and what you can ask us to do about it. It applies to riviy.com and the Riviy application.
1. What we collect
Account information. Your name and email address. If you sign in with Google, we also receive your profile picture. Passwords are stored only as a hash — we cannot read yours, and nobody at Riviy can tell you what it is.
What you enter about your investments. The symbols, share counts, average cost, opening dates, and any notes you add. This is the product, and it is the most sensitive thing we hold.
Security records. Sign-in sessions, each with the IP address and browser user agent it was created from; whether two-factor authentication is enabled and when it was last used; and rate-limiting counters. These exist so you can see and end your own sessions, and so we can resist password guessing.
Billing records.Your subscription status and the identifier Stripe assigns you. Card numbers, expiry dates, and security codes are entered on Stripe’s own pages and never reach Riviy’s servers.
Operational records.A log of emails we sent you and whether our provider accepted them for delivery, and an audit log of privileged administrative actions such as a change to an account’s role.
We do not use advertising trackers, and we do not build a profile of you for marketing.
2. Why we collect it
To run your account and keep it secure; to show you what your holdings are worth; to send you the emails the service requires (verification, password reset, and — if you subscribe — notice that The Riviy Portfolio has changed); to take payment; and to meet our legal and accounting obligations.
We do not use your holdings for any purpose other than showing them to you.
3. Who else handles it
These are the only third parties involved, and each one receives the minimum it needs:
- Amazon Web Services — hosting, database, and outbound email. Your data is stored in the United States.
- Stripe — payment processing. Stripe holds your payment details under its own privacy policy; we hold only your subscription status.
- Google — only if you choose to sign in with Google, and only to confirm your identity.
- A market-data provider — market prices. We send ticker symbols and nothing that identifies you. The provider is not told whose portfolio a symbol belongs to, or that it belongs to a portfolio at all.
We do not sell or share your personal information as those terms are defined by the California Consumer Privacy Act, and we have not done so in the preceding twelve months.
4. How long we keep it
Your account data is kept while your account exists. An account that never verifies its email address is deleted automatically after seven days.
When you close your account we delete your positions, sessions, and account record. Records we must keep for accounting or legal reasons — invoices, and the administrative audit log — are retained separately for as long as the law requires.
5. How it is protected
Traffic is encrypted in transit. Passwords are hashed. Database connections use TLS with a pinned certificate authority. Two-factor authentication is available to every account and required for accounts with administrative access, and privileged actions are written to an append-only audit log.
No system is perfectly secure. If a breach affects your personal information we will notify you as the law requires.
6. Your rights
You may ask us to:
- tell you what personal information we hold about you, and why;
- give you a copy of it;
- correct anything that is wrong;
- delete your account and the information in it.
California residents have these rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. Because we do not sell or share personal information, there is nothing to opt out of — but you may still make any of the requests above.
Access and deletion are in the product, under Settings → Data & privacy. Downloading needs no request and no waiting: you are already signed in, which is the identity check. Deleting asks you to type a confirmation and tells you exactly what goes and what is retained.
For anything the screens do not cover — a correction, or a question about what we hold — email privacy@riviy.com from your account address. We verify the request is genuinely yours before acting on it, and respond within the time the law allows.
7. Cookies
Riviy sets cookies only to keep you signed in and to protect the sign-in process. There are no advertising or analytics cookies. Blocking these cookies will prevent you from signing in.
8. Children
Riviy is not intended for anyone under 18 and we do not knowingly collect information from children. If you believe a child has created an account, email us and we will delete it.
9. Changes to this policy
We may update this policy. For material changes we will give notice by email or in the product before they take effect, and the date at the top of this page always reflects the version in force.
10. Contact
Privacy questions: privacy@riviy.com. For the agreement governing use of the service, see the Terms of Service.