Privacy Policy

Version v1.0 · Effective: 2026-07-22 · Last updated: 2026-07-22

This Privacy Policy is issued by the Rivo API team ("we", "us") and explains how we collect, use, store, and protect your information when you use the Rivo API platform — including the website, the console, and the API relay service (the "Service"). Please read this Policy carefully before using the Service. By registering an account or using the Service, you acknowledge that you have read and agree to this Policy.

1. Scope

This Policy applies to all features of the Service, including account registration and sign-in, console operations, top-ups and billing, and model calls made through the API gateway.

Once your request is forwarded to a third-party upstream model provider, that provider processes the data under its own privacy policy, which is outside the scope of this Policy (see Sections 3 and 6).

2. Information We Collect

To provide the Service, we collect the following information:

  • Account information: the email address and username you provide at registration, and the credentials required to sign in.
  • Top-up and transaction records: top-up amounts and timestamps, order identifiers returned by payment providers, and balance/usage ledger entries.
  • API request metadata: the model name invoked, input and output token counts, request timestamps, the originating IP address, and response status. This data is used for billing, invoice reconciliation, and abuse-prevention (risk control).

3. How API Request Content Is Handled

The content you send through the Service (e.g. prompts, conversation messages, text or images to be processed) is processed only transiently, to the extent necessary to relay it, and is forwarded to the upstream model provider you selected in order to generate and return a response.

We do not use your request content or model responses to train any model.

4. Cookies and Local Storage

We use cookies and browser local storage to keep you signed in and to remember interface preferences such as your language and currency settings. This information is used solely to improve your experience. If you disable cookies in your browser, some features (such as staying signed in) may not work properly.

5. Data Retention

Account information is retained for as long as your account exists. API request logs (the metadata described in Section 2) are retained for a reasonable period as needed for billing and invoice reconciliation.

After you close your account, we will delete or anonymize personal information associated with it within a reasonable period, except where retention is required by law or necessary to settle outstanding transactions.

6. Sharing with Third Parties

We share information with the following third parties only to the extent necessary to provide the Service:

  • Upstream model providers: they receive your request content in order to generate model responses (see Section 3).
  • Payment providers: they process your top-up transactions; we do not store your full payment account details.

Beyond the above and cases required by applicable law, we do not sell or rent your personal information to any third party.

7. Data Security

We take reasonable technical and organizational measures to protect your information, including TLS encryption in transit, encrypted storage of sensitive credentials, and internal access controls following the principle of least privilege.

Please understand that no method of transmission or storage over the Internet is absolutely secure. If a data-security incident occurs that may affect your rights, we will notify you as required by applicable law.

8. Your Rights

You may access and correct your account information, and you may request deletion of your personal information or closure of your account. To exercise these rights, email [email protected] or submit a ticket in the console. We will process your request within a reasonable period after verifying your identity.

9. Cross-Border Transfers

The servers for the Service are located in the United States. When you use the Service, your account information and request data are transferred to and stored on servers in the United States. By continuing to use the Service, you acknowledge and consent to such cross-border transfers.

10. Minors

The Service is intended for users with full legal capacity and is not directed at minors under 18 years of age (or the age of majority in your jurisdiction). If we learn that we have collected personal information from a minor without guardian consent, we will delete that data promptly.

11. Changes to This Policy

We may revise this Policy from time to time. Revised versions will be published on this page with an updated "Last updated" date; for changes that materially affect your rights, we will additionally provide prominent notice such as an on-site announcement. Continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.

12. Contact

If you have any questions, comments, or complaints about this Policy or our handling of personal information, please contact the Rivo API team at [email protected].