Privacy Policy
Last updated · September 24, 2026
1. Introduction
Rive ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, and how we handle it when you use our website and workspace.
By using Rive or creating an account, you agree to the practices described in this policy.
2. Information we collect
We collect the following types of information:
- Email addresses — When you create an account, use the workspace, or contact us.
- Account and workspace data — Information you enter in Rive, such as clients, projects, invoices, expenses, and calendar events.
- Google account data — If you sign in with Google or connect Google Calendar. Details are in section 4.
- Usage analytics — First-party page and product events, including the route visited, a browser-session identifier, acquisition tags, referrer origin and path, browser user agent, and the signed-in account ID when applicable. These records are not advertising profiles and are not shared with advertisers.
- Browser and device information — Browser and device category derived from the user agent, for product compatibility purposes.
- Cookies — See our Cookie Policy for details.
We do not collect payment details or government IDs. Synced calendar events can include the titles, times, and details you or others put on those events.
3. How we use your information
We use the data we collect solely to:
- Provide, secure, and improve the workspace and its features.
- Understand onboarding, activation, workflow depth, and feedback so we can improve the product.
- Respond to support requests or inquiries sent to us.
- Detect and prevent spam, abuse, or unauthorized access.
We never sell your data or share it with third-party advertisers.
Service emails. We send a small number of account-related emails. Some are required to run your account and cannot be turned off: email verification, password reset, and security notices when your password changes or two-factor authentication is turned on, turned off, or given new recovery codes. Others are optional: a login-alert notice each time your account is signed in to, and, only if you turn it on, a weekly business summary sent Monday mornings in your local time. None of these are marketing email. The optional ones can be turned off from Settings → Notifications; the weekly summary can also be turned off from the unsubscribe link in the email itself.
4. Google user data
If you choose to sign in with Google or connect Google Calendar, Rive accesses Google user data only with your consent, only for the feature you turned on, and only to the extent that feature needs.
Sign in with Google and Google Calendar are separate. Connecting Calendar is optional. Sign-in does not grant Calendar access.
Google sign-in. When you sign in with Google, we request OpenID, email, and profile access. We receive your Google account identifier, email address, and name so we can create or authenticate your Rive account. We do not keep Google sign-in access or refresh tokens after that sign-in request finishes. We store the Google account identifier so later sign-ins can recognize the same account.
Google Calendar. When you connect Google Calendar from the workspace, we request read-only access to your calendar list and access to calendar events (create, read, update, and delete) on the calendars you connect. We use that access so Rive can list those calendars and keep workspace events in sync with Google Calendar for your business workflow. We store the connected account email, the calendars you select, synced event data in your workspace, and the OAuth tokens needed to keep that connection working.
We use Google user data only to provide and improve these user-facing sign-in and calendar features. We do not use Google user data for advertising, personalized ads, retargeting, interest-based ads, selling to data brokers, credit-worthiness, lending, or any other unrelated purpose. We do not use Google user data to develop, improve, or train generalized or third-party AI or machine-learning models.
We do not sell Google user data. We do not share, transfer, or disclose Google user data to third parties for purposes other than providing the Service, except where required by law. Infrastructure we use to host the Service (see section 8) may process that data on our behalf under confidentiality terms, solely to run Rive.
Rive's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Emails we send to your clients on your behalf
When you use invoice reminders or paid receipts, Rive sends automated emails to your clients using the client contact details you enter. These emails cover: a scheduled reminder about an unpaid invoice (on the schedule you choose — up to 3 days before the due date and 1, 7, or 14 days after), and a receipt confirming an invoice has been paid in full. Both are off by default and only send if you turn them on.
For this purpose, Rive acts as a data processor on your behalf: we send the message using the invoice and client data already in your workspace, we do not use it for any other purpose, and we do not sell it. You are responsible for the accuracy of the client contact details you provide and for having the right to contact that client — see our Terms of Service.
Every automated reminder email includes an unsubscribe link that is specific to that client. Using it stops future reminder emails to that client from your account; it does not affect the original invoice-sent email, a paid receipt, or any other correspondence. Reminders are also capped: at most four per invoice, and a daily limit per account.
6. How we protect your data
Security procedures are in place to protect the confidentiality of your data, including Google user data stored in Rive's environment rather than only inside Google.
- Encryption in transit — The website, APIs, and database connections use TLS (HTTPS in the browser; TLS required to the database).
- Encryption at rest — Workspace data is stored in a private, encrypted PostgreSQL database that is not publicly reachable. Google Calendar OAuth access and refresh tokens are encrypted at rest with AES-256-GCM using a dedicated application key, separate from session secrets.
- Access limited to the feature — Google data is used only to provide sign-in or calendar sync. Authenticated workspace queries are scoped to the signed-in account. The database is private, the application host does not accept inbound SSH, and operator access uses authenticated AWS sessions recorded in the AWS audit trail.
- Account credentials — Passwords are stored as salted scrypt hashes, not in plain text. Sessions use signed HttpOnly cookies (Secure in production, SameSite restrictions) rather than tokens exposed to page scripts.
- Two-factor authentication — If you turn on two-factor authentication, your authenticator secret is encrypted at rest with the same AES-256-GCM scheme used for connected-account credentials. Recovery codes are stored only as hashes, never in a form that alone could sign you in.
No method of transmission or storage is perfectly secure. We apply these controls as a small SaaS operating on AWS; we do not claim third-party security certifications in this policy.
7. Data retention
We retain account and workspace information for as long as you use the Service or as needed for legitimate business, security, and legal purposes. You can request access, correction, or deletion at any time by emailing hello@rive.work.
If you disconnect Google Calendar in the workspace, we revoke Rive's Google grant and delete the stored connection tokens and calendars imported from that connection. You can also revoke Rive's access in your Google Account permissions. If you ask us to delete your Rive account, we delete the account and associated workspace data, including any Google account identifier and remaining Google Calendar connection data, unless a longer retention period is required or permitted by law.
8. Third-party services
We use privacy-respecting infrastructure providers for web hosting and database management. These services process data on our behalf under strict confidentiality terms. Production hosting and the encrypted database run on Amazon Web Services.
Usage analytics are first-party and stored on Rive's AWS infrastructure; no third-party analytics service processes them.
If you sign in with Google or connect Google Calendar, Google provides those APIs under Google's terms. Rive then stores and protects the Google user data described in sections 4 and 6 in order to provide the feature you enabled.
9. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise these rights, email us at hello@rive.work.
10. Children's privacy
Rive is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@rive.work.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date at the top of this page. For significant changes, we will notify account holders through the Service or by email.
Your continued use of Rive after any changes constitutes acceptance of the updated policy.
12. Contact us
For any privacy-related questions, requests, or concerns — including Google user data — email hello@rive.work.
Email: hello@rive.work
Response time: Within 72 hours