Our VisionDocsBlogCareersOpen Console ↗
Effective September 17, 2026

Privacy Policy

Plain language summary

This Privacy Policy explains what personal information we collect when you use our Services as defined in the Beta Tester Agreement (“Agreement”), why we collect it, who we share it with, how long we keep it, and the choices and rights you have. Where local laws (such as the California Consumer Privacy Act and the EU/UK General Data Protection Regulation) require additional disclosures, those appear in the Region-specific notices section below. This policy does not apply when we process data on behalf of a business customer — for example on our API or enterprise plan — in which case a Data Processing Addendum would apply.

At a glance

  • We are River AI Inc., a Nevada corporation with business operations in San Francisco, California.
  • We do not sell personal information, do not share it for cross-context behavioral advertising, and do not make solely automated decisions about you with legal effect.
  • For our Services, we minimize the amount of data we collect about you, and we give you control to opt-in to features.
  • We collect some data for authentication, billing, and security, and providing you access to the Services.
  • If any User Information (such as your user inputs, user outputs, conversation history, the history of what actions your agents made, and similar items) as defined in the Agreement, is needed to be kept in order for the functionality of the Services to work, then it is kept on the device or system that you specify, such as your own laptop or your own chosen cloud provider. Only that device or system that was chosen by you, such as your own laptop or your own chosen cloud provider, stores that User Information; after ephemeral processing, we do not store User Information on our systems.
  • You can access, correct, delete, export, restrict, or object to processing at [email protected].

1. Who we are

River AI Inc. (“River AI”, “we”) is a Nevada corporation with business operations in San Francisco, California.

Privacy: [email protected]

2. Information we collect

Information you give us:

  • Account information (e.g., name, email, password, year of birth, country, profile image);
  • Payment information when required (payment card numbers are processed by our payment provider and are not stored by us);
  • Inputs and outputs (e.g., prompts, files, images, audio, video, code, and the resulting outputs, plus content from third-party services necessary to provide Services);
  • Identity and age verification information when required;
  • Communications and support tickets;
  • Feedback (e.g., thumbs up/down and the related conversation);
  • Other information you choose to provide.

Information we collect automatically:

  • Device and connection data (IP, OS, browser, identifiers, crash logs);
  • Usage data (features used, pages viewed, timestamps, referrers);
  • Approximate location from IP; precise location only with consent;
  • Cookies and similar technologies.

Information from third parties:

  • Single sign-on providers (e.g., Apple / Google / Microsoft / X) when you choose SSO;
  • If you choose to connect email, calendar, messaging, or other third-party services, we maintain information necessary to sign in and access those third-party services for as long as you remain opted in. Information from those third-party services (such as your email contents or your calendar) are not kept on our systems. After ephemerally processing your requests, any needed remnants of that information are kept on the system or device of your choice, such as your laptop or the cloud provider you choose – we don’t keep it.
  • If you choose to connect to Google services (like Google’s email or calendar) through our Services, the Google User Data Policy restricts using, transferring, or selling Google user data, including raw, aggregated or derived data, to create, train, or improve foundational or AI models.
  • Payment processors (transaction confirmations, fraud signals);
  • Identity verification, trust and safety vendors, sanctions and export control, and anti-fraud vendors;
  • Analytics partners.

Sensitive data. We do not ask for and ask you not to submit sensitive data (government IDs except for verification, biometrics, health data, racial or ethnic origin, religion, political views, sexual orientation, trade-union membership, genetic data, or financial-account credentials). We do not use sensitive data to infer characteristics about you.

Minimum Age. The minimum age for using the Services is 18 years old, unless older as required by your local laws. We do not ask for and ask you not to submit information regarding anyone under the minimum age.

3. How we use information

We use personal information to:

  • Provide and operate the Services, including authenticating you, processing your prompts, and delivering features;
  • Support and communicate with you;
  • Maintain safety, security, and abuse prevention, including automated and human review where appropriate;
  • Comply with law and legal process;
  • Research and improve the Services
  • Send marketing, with consent where required and an unsubscribe option in every message; and
  • Conduct corporate transactions.

We may aggregate or de-identify data and use it for any lawful purpose; we will not try to re-identify it. We do not “sell” or “share” personal information for cross-context behavioral advertising, do not engage in targeted advertising, and do not make solely automated decisions producing legal or similarly significant effects about you. Generating content in response to your prompt is not “automated decision-making” within the meaning of GDPR.

Legal bases (EEA, UK, Switzerland)

  • Legitimate interests: for processing prompts, providing Services, security and abuse prevention, service announcements, research and product improvement, and corporate transactions; balanced against your rights and freedoms.
  • Contract: to deliver the Services and process payments.
  • Legal obligation: for tax, accounting, sanctions screening, and lawful requests.
  • Consent: for marketing where required, precise location, and other features expressly flagged.

4. How we share information

We share personal information only as needed for the purposes in Section 3 (“How we use information”), with:

  • Service providers and processors (cloud, model serving, analytics, payments, support, identity verification, fraud and trust-and-safety);
  • Affiliates under common control;
  • Connected services and third parties you direct (e.g., when you log in via an identity provider, when you share an output, when you request information provided by a connected service or a third party, or when you invite a collaborator);
  • Authorities to comply with law, enforce the terms of our Agreement, prevent fraud, and protect rights and safety;
  • Successors in a merger, acquisition, restructuring, or asset sale;
  • Anyone else with your direction or consent.

5. International transfers

We are headquartered in the United States and use service providers located primarily in the United States. When we transfer personal information from the EEA, UK, or Switzerland, we rely on EU adequacy decisions where available and otherwise on the EU Standard Contractual Clauses with the UK International Data Transfer Addendum and the Swiss equivalent, supplemented by encryption, strict access controls, vendor due diligence, and procedures to challenge improper government-access requests.

6. Retention

Category Default retention
Account & Authentication data Active account, then up to 30 days
Conversations, inputs, and uploaded data After ephemeral processing, we do not store these. You store it on your own device or your own cloud system of choice.
Payment and tax records Up to 7 years (varies by law)
Server, security, and audit logs Up to 5 years; longer if needed for investigations
Marketing contacts Until you unsubscribe, and then up to 30 days

When data is no longer needed, we delete or de-identify it.

7. Security

We maintain a written information security program with administrative, physical, and technical safeguards reasonably designed to protect personal information — encryption in transit and at rest, identity and access management with least privilege, network segmentation, vulnerability management, third-party assessments, employee training, and a documented incident-response process. We test against recognized frameworks such as SOC2, Type II. No system is perfectly secure; please use a strong, unique password and protect your devices. If you believe your account has been compromised, contact [email protected].

8. How we use data to develop our products and services

We may use aggregated or de-identified information (disassociated from your account), including telemetry, to improve and operate our Services.

We may employ automated systems and trained safety reviewers for the safety of our customers and our employees.

9. Cookies and tracking

We and our service providers use essential cookies and similar technologies to operate the Services, remember preferences, secure accounts, measure performance, and improve features. We do not respond to “Do Not Track” because there is no consensus standard.

10. Your rights and choices

Subject to local laws, you have the following rights. We will not discriminate against you for exercising them. You may have the right to access, correct, delete, port, restrict, or object to processing of your personal information; to withdraw consent; to lodge a complaint with a supervisory authority; to be free from retaliation; and to appeal a denial. Exercise rights through [email protected]. We are required to verify your identity and may require additional verification for sensitive requests. Authorized agents must present signed written permission and proof of identity. We respond within the timelines required by your local law.

11. Updates to this policy

We may update this policy from time to time by posting updated versions with a new effective date. If changes are material, we will give advance notice if required.

12. Region-specific notices

The following notices add to or modify this policy for users in specific regions. For any questions, please contact [email protected].

12.1 California

  • CCPA notice at collection: In the past 12 months we collected the categories in Section 2 — using the CCPA statutory categories of identifiers; customer records; commercial information; internet/network activity; geolocation; audio/visual; professional or employment-related (only if you provide it); inferences; and sensitive personal information as described in Section 2 — from the sources in Section 2, for the purposes in Section 3, and disclosed them to the recipients in Section 4.
  • No sale, no sharing, no targeted advertising: We do not sell personal information and do not share it for cross-context behavioral advertising. Any sensitive personal information would be used only for purposes permitted by CCPA Reg. § 7027(m); the right to limit is preserved.
  • Your rights: California residents have rights to access, correct, delete, port, opt out, limit, be free from retaliation, and appeal. You may contact [email protected]; and we will respond within 45 days, extendable once by 45 days. Authorized agents must present signed written permission and proof of identity.
  • Shine the Light (Cal. Civ. Code § 1798.83): We do not share personal information with third parties for their direct marketing.

12.2 EEA, United Kingdom, and Switzerland

  • River AI does not have operations in the EEA, UK, or Switzerland
  • Your Rights: You have rights of access, rectification, erasure, restriction, portability, objection (including to legitimate-interests processing and direct marketing), withdrawal of consent. Contact [email protected].
  • No automated decisions: We do not make decisions producing legal or similarly significant effects about you using only automated processing.
  • Transfers: EU SCCs with the UK Addendum and Swiss equivalent.
  • Required data: Some categories (e.g., email, date of birth) are required to enter into and perform our contract with you; without them we cannot provide the Services.
  • Complaints: Your local SA.
  • Overseas transfer: Our operations and systems are in the United States. You may refuse the transfer; in that case we may not be able to provide the Services.

12.3 Canada

  • Consent: We rely on consent, contractual necessity, legal obligation, and other bases permitted by Canadian privacy law. You may withdraw consent subject to legal/contractual restrictions and reasonable notice; this may affect our ability to provide the Services.
  • Cross-border processing: Your personal information may be processed outside Canada (in the United States) and is subject to the laws of those jurisdictions, including lawful access by foreign governments. We use safeguards and security controls consistent with Canadian standards.
  • Complaints: Canadian residents may complain to their respective Information and Privacy Commissioners. We comply with applicable breach notification and recordkeeping. For questions, contact [email protected].
Intelligence that flows with you

Product

  • Platform
  • Documentation
  • Changelog

Company

  • Our Vision
  • Blog
  • Careers
  • Support
  • Security
  • Contact

Connect

  • Discord
  • X
  • LinkedIn
© 2026 River AI Inc.
≈