Legal

Privacy policy

Effective 18 September 2026

1. Who we are

Rivilo ("Rivilo", "we", "us") tracks client requests for small teams: it reads the mailbox you connect, turns requests into cards on a board, drafts replies and documents for your approval, and keeps the context you ask it to remember.

Rivilo is a trade name of Future Ready Design B.V. The data controller for your account is:

  • Future Ready Design B.V. (trade name: Rivilo)
  • Raadhuisstraat 20-22, 1016 DE Amsterdam, The Netherlands
  • Chamber of Commerce (KvK): 92339867
  • Contact: getintouch@rivilo.app

This policy applies to the Rivilo application at app.rivilo.app, this website at rivilo.app, and related services. Where you use Rivilo on behalf of your organisation and Rivilo processes your clients' data on your instructions, we act as processor under the Data processing agreement.

2. What data we collect

a) Account and identity. When you sign in with Google or Microsoft, we receive your name, email address, profile photo and a unique account identifier from that provider. We never receive or store your Google or Microsoft password.

b) Google account data (Gmail, Calendar, Sheets APIs). With your explicit consent during setup, Rivilo requests these Google OAuth scopes:

  • gmail.readonly: read messages and metadata (senders, subjects, dates, content) to triage your inbox, summarise threads, turn requests into cards and prepare reply suggestions.
  • gmail.compose: create and update draft emails on your behalf.
  • gmail.modify: archive messages and manage labels, only where you enable it per board.
  • gmail.send: send emails on your behalf, only after you approve each one.
  • calendar.readonly and calendar.events: read availability and events for scheduling suggestions, and create events you approve.
  • spreadsheets.readonly: read Google Sheets you explicitly link to a board or document.

Some background features (assembling your approvals queue, syncing a mail-fed board, building your "current context") read only message metadata and headers (sender, subject, date, snippet), not message bodies, unless a feature you use needs the body.

c) Microsoft account data (Microsoft Graph). If you connect a Microsoft 365 work account, Rivilo requests Mail.Read (read your Outlook mailbox to turn requests into cards) and offline_access (keep the connection alive without signing in again). Rivilo does not currently request send permissions for Outlook, does not read Teams chats, and does not access shared mailboxes. Your tenant administrator may need to grant consent.

d) Slack, Microsoft Teams, Fireflies and other connections. If you connect them, Rivilo processes the messages, links and files in the channels or meetings you give it access to, to answer questions, create or update cards and post updates. It only reads channels it is invited to.

e) Content you create in Rivilo. Boards, cards, notes, documents, conversations with the assistant, approvals you review, files you upload, and the "learnings" Rivilo keeps about tone, preferences and decisions at your request.

f) Technical and usage data. Standard information needed to run and secure the service: logs, device data, timestamps and error reports.

We do not intentionally collect special categories of personal data and ask you not to store such data in Rivilo.

3. How and why we use your data (purposes and legal bases, GDPR Art. 6)

Purpose Legal basis
Provide the core service (account, boards, documents, request tracking, drafts, approvals) Performance of a contract (Art. 6(1)(b))
Access your Google or Microsoft data to power the features you enable Consent (Art. 6(1)(a)), given at connection, withdrawable at any time
Process your content with AI models to draft, summarise and suggest Performance of a contract
Secure, debug, prevent abuse and maintain the service Legitimate interests (Art. 6(1)(f))
Comply with legal obligations Legal obligation (Art. 6(1)(c))

We do not use your data for advertising and we do not sell your data.

4. AI processing (Mistral and Anthropic)

Rivilo's assistant features send relevant content, such as the email thread you are working on, a card's details or a document, to an AI model provider to generate summaries, drafts and suggestions. Rivilo runs these models under its own agreements; you do not need your own API key. Today the provider is Anthropic; Mistral is being added:

  • Mistral AI (France), processed in the European Union, once available for your account.
  • Anthropic, PBC (United States). Transfers to Anthropic are covered by the EU Standard Contractual Clauses.

Under both providers' commercial terms, data submitted through their APIs is not used to train their models. AI output can be imperfect; you review every reply, document or action before it is carried out.

5. Google API Services User Data Policy, Limited Use

Rivilo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not sell Google user data.
  • We do not use Google user data for advertising.
  • We do not use Google user data to train generalised or foundation AI models.
  • We do not transfer Google user data to third parties except as necessary to provide or improve these features, for security, or to comply with the law.
  • Humans do not read your Google user data, except with your explicit consent (for example support you request), for security or abuse investigations, to comply with the law, or where the data has been aggregated or anonymised.

6. Who we share data with (subprocessors)

Provider Purpose Location
Google Cloud / Firebase Authentication, database (Firestore), file storage, serverless functions, application hosting; Gmail, Calendar and Sheets APIs EU (europe-west1, Belgium)
Mistral AI AI processing, once available for your account EU
Anthropic, PBC AI processing (Claude) United States (Standard Contractual Clauses)
Microsoft Sign-in and Microsoft Graph, if you connect a Microsoft account EU / global, per your tenant
Slack Messaging, if you connect Slack Per your Slack workspace
Fireflies.ai Meeting transcripts, if you connect Fireflies United States
Resend Transactional email (notifications, sign-in messages) United States / EU
Netlify Hosting of this website and its contact form United States / global CDN
Google reCAPTCHA Spam protection on the early access form of this website United States / global

We require our subprocessors to protect your data and to process it only on our instructions, under a data processing agreement where applicable. We give customers 14 days notice by email before adding a subprocessor that handles their content.

7. Where your data is stored and international transfers

Your Rivilo account data, content and stored tokens are held in Google Cloud's EU region (europe-west1). AI processing via Anthropic, meeting transcripts via Fireflies and transactional email via Resend may involve transfer to the United States. Where personal data leaves the EEA we rely on the EU Standard Contractual Clauses or an applicable adequacy decision.

8. How long we keep your data

  • Account and content data: for as long as your account is active.
  • Mailbox content: read on demand from your mailbox; only the cards, drafts and learnings you keep are stored in Rivilo.
  • OAuth tokens and connection data: until you disconnect the integration or delete your account.
  • After account deletion: we delete or anonymise your personal data within 30 days, except where we must retain it to comply with a legal obligation.

9. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS); encryption at rest on Google Cloud; per-user OAuth tokens with least-privilege scopes; owner-scoped access rules enforced in the database; and EU-region hosting. Rivilo does not yet hold a SOC 2 or ISO 27001 certification. No method of transmission or storage is completely secure, but we work to protect your data and will tell you if something goes wrong.

10. Your rights (GDPR / AVG)

You have the right to access your data, rectify inaccurate data, request erasure, restrict or object to processing, data portability, and to withdraw consent at any time (which does not affect prior lawful processing).

To exercise these rights, contact getintouch@rivilo.app. You also have the right to lodge a complaint with your supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

11. Disconnecting and deleting your data

  • Disconnect Google or Microsoft: revoke Rivilo's access at any time in your Google Account permissions or Microsoft account settings, and in Rivilo's settings. Revoking mailbox access stops all inbox features.
  • Delete your account: email getintouch@rivilo.app and we will delete your account, stored content and tokens within 30 days.

12. This website

rivilo.app uses no analytics cookies and no third-party analytics. The early access form is processed by Netlify and delivered to us by email; we keep submissions, including a phone number if you give one, only to answer your request. To keep spam out, the early access form uses Google reCAPTCHA. The form is on the early access page and the pricing page. On those two pages Google loads a script, may set cookies and collects hardware and software information to tell people from bots. Google's privacy policy and terms apply to that data. No other page on this site loads it.

13. Children

Rivilo is intended for professional use by people aged 16 or older. We do not knowingly collect data from children.

14. Changes to this policy

We may update this policy. Material changes are communicated in-app or by email, and the effective date above changes.

15. Contact

Questions or requests: getintouch@rivilo.app · Future Ready Design B.V. · Raadhuisstraat 20-22, 1016 DE Amsterdam