Privacy notice
This notice explains what personal data Riven processes, why, for how long, and which rights you have — whether you use the service with an account or appear in it as the owner of a public professional profile.
Last updated 31 August 2026
In short
- Account holders: we store what you give us to run your account and workspace (email, name, password hash, sign-in sessions, workspaces, shortlists, briefs, invitations and responses).
- Specialists who have not joined: we show only eligible public professional information from public Instagram profiles, record where each field came from, keep contact details away from guests, and honour correction, suppression and removal requests.
- No advertising, no tracking cookies, no sale of data. Only the cookies needed to keep you signed in.
- During the alpha, profile pages are available to signed-in, invited users only and are excluded from search engines.
Who is responsible
The controller for the processing described here is the operator of Riven:
Operator details are not configured for this deployment.
The responsible legal entity, postal address and contact address are supplied through the RIVEN_LEGAL_* environment values and appear here once set.
Use the contact address above for privacy requests. Requests about a specialist profile can also be made without an account through the correction and removal form.
Data of account holders
What we process
- Account: email address, optional name, a password hash (never the password), email verification status, sign-in sessions and session cookies. If you choose Google sign-in, Google provides your email and name and we store the sign-in tokens Google issues for your account.
- Workspace activity: brand workspaces and their members and roles, shortlists, project briefs, invitations you send and the responses you receive, collections and exports, and the Notion connection you may set up yourself.
- Specialist journey: profile claims, the ownership challenge (stored as a hash only), vetting submissions (portfolio links, services, languages, availability), the identity verification method and an opaque reference. We never ask for, nor store, identity documents.
- Security and audit records: trust-affecting actions (claims, vetting decisions, suppressions, approvals) are logged with timestamps; rate limits record request counts per account and IP address.
Why and on which basis
- To provide the service you asked for — creating and securing your account, operating your workspace, delivering invitations and responses (performance of a contract, Art. 6(1)(b) GDPR).
- To keep the service safe and to prevent abuse — rate limits, verification, audit trails (legitimate interests, Art. 6(1)(f) GDPR).
- To send transactional email you triggered — email verification, invitations, response notifications. We do not send marketing email.
Public specialist profile data
What we collect and from where
Riven helps brands find social-media specialists. To do that we assemble profiles from publicly available professional information: the public parts of Instagram profiles located through web search (handle, display name, biography, public follower and engagement figures, stated location, and a business email or website if the profile publishes one). The source and retrieval time of every field are stored with it. Collection runs through a data collection provider acting on our instructions (see below).
Why and on which basis
We process this data so that businesses can identify suitable specialists and contact them through a professional channel they themselves made public. We rely on our legitimate interests and those of the businesses using the service (Art. 6(1)(f) GDPR), balanced by the safeguards below. You can object at any time (see “Your rights”).
Safeguards
- Guests see masked previews only — no handle, email or website — and small result sets are hidden so nobody can be singled out.
- Full profiles are visible only to signed-in, invited alpha users with a confirmed email address, inside an authenticated workspace; profile pages carry
noindexand are not listed for search engines. - A profile that has not been claimed is labelled Unclaimed. We do not describe any profile as vetted, in any state: we check who controls an account, not the quality of anyone's work.
- Correction, suppression and removal requests are reviewed by a person. An approved suppression immediately removes the profile from search, profile pages, shortlists, invitations, claims and future refreshes, and is recorded in an immutable audit log.
- Invitations to specialists are rate-limited per sender and per profile, and delivery stops automatically for suppressed or opted-out profiles.
Recipients and processors
We use the following categories of service providers, bound by data processing agreements and acting on our instructions:
- Hosting and database infrastructure. Data is stored in the databases and logs of these providers.
- Public data collection — Apify (Apify Technologies s.r.o., Czech Republic) runs the web-search and public-profile retrieval described above on our instructions.
- Location normalisation — the place names you type into a search are sent to OpenStreetMap Nominatim to resolve them to a city and country. We do not send account data with that request.
- Transactional email — Resend (Resend, Inc., USA) delivers verification, invitation and notification emails.
- Google sign-in — only if you choose it; Google then processes your sign-in according to its own privacy policy.
- Notion — only if you connect your own Notion workspace; collection data then flows into your Notion pages under your account.
Where a provider processes data outside the EU/EEA, we rely on the European Commission's adequacy decisions or standard contractual clauses. Businesses using Riven see the specialist data they search for, shortlist or invite within their own workspace.
How long we keep data
- Account data: until you delete your account or ask us to delete it.
- Search runs and their frozen results: 90 days; Notion sync logs: 180 days; access audit events: 365 days.
- Correction, suppression and removal requests: 365 days after submission, so we can prove how a request was handled.
- Email verification links: 24 hours. Profile-claim invitation links: 7 days. Alpha access invitations: 14 days. Delivered emails have their links removed from our outbox once sent.
- Public profile data: for as long as it is relevant to the service and not suppressed; suppressed profiles are excluded from all surfaces and future refreshes.
- Trust and security audit records are kept for the life of the related profile or workspace because they document decisions about ownership and vetting.
Your rights
You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, to data portability where applicable, and to lodge a complaint with a supervisory authority.
- Account holders can change their profile and delete their account under Account → Security.
- Owners of a public professional profile can claim it, request a correction, or ask for suppression or removal through the correction and removal form or directly from the profile page. You do not need an account.
- For anything else, contact the controller at the address above. We respond within the statutory deadlines.
Changes to this notice
We will update this notice when the service changes — for example when new features, providers or regions are added — and show the date of the last revision at the top of this page.