Legal
Privacy policy
Rilver reads your mail so that you can read it comfortably. That is a lot of trust, so this page says plainly what is collected, why, where it goes, and how to get rid of it.
The short version
- Only the newsletters in the one folder you nominate are read, and only to turn them into readable articles. Your inbox is not touched.
- Newsletter content is deleted after 90 days unless you save it.
- Your data is never sold, and never used for advertising.
- This website sets no cookies and runs no third-party trackers.
- You can delete your account, and everything with it, from inside the app.
What is collected, and why
| What | Why | Kept for |
|---|---|---|
| Your email address | To identify your account and send sign-in links | Until you delete your account |
| Sign-in tokens and sessions | To keep you signed in without a password | Sign-in links expire in minutes; sessions until you sign out |
| Mailbox access token | To fetch the newsletters in the folder you choose | Until you disconnect the mailbox or delete your account |
| Newsletter content and the original message | To render the article and let you re-read it | 90 days, unless you save the article |
| Pages you photograph | To turn them into readable text | Until you delete them or delete your account |
| Your colour and type settings | So a second device starts from something sensible | Until you change them or delete your account |
| Colour test answers | To produce your result, and to improve the test itself | Until you delete your account |
| Narration audio | So the same article is not paid to be spoken twice | Removed 90 days after nothing has played it |
| Subscription status | To know what your account is entitled to | Until you delete your account |
| Technical job records | To retry failed work and diagnose faults | 30 days |
Your mail
When you connect a mailbox, Rilver reads only the folder or label you pick, never your whole inbox. It looks for newsletters there, extracts the article out of the marketing layout, and stores the result so you can read it in your colours.
The newsletters found there — and nothing else — are sent to an artificial-intelligence provider to do that extraction: pulling out the article, its headline and its structure, and assigning it a category. They are processed only to return that result, and are not used to train models. Ordinary mail is never sent to it, because ordinary mail is never fetched.
Rilver never sends mail from your account, never modifies or deletes anything in your mailbox, and never reads mail outside the folder you nominated.
Your mailbox access token is encrypted before it is stored, with a key held separately from the database. Disconnecting the mailbox deletes it.
Gmail is the first mailbox Rilver supports and others will follow. None of this changes with the provider; where one requires its own disclosure on top, it is set out below.
What holds for every mailbox
- What it is used for: finding newsletters in the folder you choose and turning them into readable articles for you.
- What it is never used for: advertising, profiling, sale, or any purpose other than the reading features you can see in the app. It is never used to train or improve anyone's models, generalised artificial-intelligence models included.
- Who it is shared with: the processors listed below, and only to deliver those features. Nothing outside the folder you chose is ever fetched, so nothing outside it can be shared.
- How to stop it: disconnect the mailbox in the app and the stored credential is deleted straight away. You can also remove Rilver's access from your provider's own security settings.
Google user data
The promises above hold for a Gmail account like any other. Google also asks for them in its own terms, which is what this is.
Where you connect a Gmail account, Rilver's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- What is requested: read-only access to Gmail (
gmail.readonly), and nothing beyond it. - How to revoke it: disconnect the mailbox in the app, or remove access at myaccount.google.com/permissions.
Your colour test
The test runs on your device. It has to, because it needs your eye to stay adapted between choices and a network round trip per question would break that. The result and the individual answers are then stored on your account.
The answers are kept, not just the final colour, and it is worth being straight about why: repeatability in this area is genuinely poor, and the search will need improving against real answers rather than against assumptions. That is a use of your data beyond serving you personally. It is not shared, sold or published, and deleting your account deletes it.
Alongside a run, Rilver records the screen conditions it was taken in (brightness, and whether features that alter your screen's colour were switched on) and an identifier for the device model and screen type. A result measured on one screen does not transfer to another, so this is what tells the app whether your result still applies.
Read-aloud
Article text is sent to a speech synthesis provider to be spoken. The resulting audio is stored under a key derived from the text and the voice rather than under your name, so if two people ever narrate identical text in the same voice, it is synthesised once. Audio nothing has played for 90 days is deleted.
This website
No cookies. No advertising, no third-party trackers, no social widgets, and no fonts loaded from anyone else's server.
Your reading settings on this site (colour, text size, line spacing, typeface) are stored in your own browser and never sent anywhere. Clearing your browser storage removes them.
Visits are counted with a privacy-preserving analytics service, which records page views without cookies and without building a profile of you or tracking you between sites.
Who else processes your data
| Who | What they handle |
|---|---|
| Cloud hosting | Running the service, and the database and job queue behind it |
| Object storage and delivery | Narration audio, scanned pages, and this website |
| An artificial-intelligence provider | Extracting the article out of a newsletter message |
| A speech synthesis provider | Turning article text into audio |
| An email delivery provider | Sending sign-in links and service email |
| The app stores | Subscription payments and receipts, where you subscribe |
Rilver does not sell your data, does not share it for advertising, and does not pass it to anyone beyond the processors above. The companies currently filling those roles are named on request, from the contact address at the top of this page.
Rilver is run from the United Kingdom, and several of the processors above are based in the United States, so some of your data is handled outside the UK. Those transfers rely on the data protection terms in each processor's own agreement — the UK's International Data Transfer Addendum to the standard contractual clauses, or an adequacy decision where one covers them.
Why we are allowed to hold it
Under UK and EU data protection law the lawful bases are:
- Performance of a contract
- Your account, your mailbox connection, your articles, your settings and your subscription. Rilver cannot do what you asked without them.
- Legitimate interests
- Keeping the service secure and working, and improving the colour test against real answers. You can object to the second of these; see below.
- Legal obligation
- Records we are required to keep, such as those relating to payments.
Your rights
You can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask for it in a portable form, or object to processing based on legitimate interests. Write to privacy@rilver.app and you will get a reply within one month.
The quickest route for deletion is the app itself; see deleting your account.
If you are unhappy with how it is handled you can complain to the UK Information Commissioner's Office at ico.org.uk/concerns, or to your own country's supervisory authority.
Security
Mailbox tokens are encrypted at rest. Sign-in and session tokens are stored only as keyed hashes, so a copy of the database is not enough to impersonate anyone. Presenting a session refresh token twice ends the session, which is how a stolen one gets caught. Audio and scans are served over expiring links rather than public addresses.
No system is perfect. If you find a security problem, please write to the contact address at the top of this page before disclosing it publicly.
Children
Rilver is intended for adults and is not directed at children. It is not designed for classroom use and does not knowingly collect data from children.
Changes
If this policy changes in a way that affects what is collected or who it goes to, the date at the top changes and you will be told in the app before it takes effect.