Privacy Policy
Last updated August 31, 2026
We collect the minimum we need to run the Service: enough to log you in, charge you, send you alerts you ask for, and keep the system running. We do not sell your personal information.
1. Information we collect
We collect the following categories of information:
- Account data: email, name, and authentication identifiers, handled by our authentication provider.
- Billing data: your customer ID, subscription status, and payment metadata, handled by our payment processor. We do not store full card numbers on our servers.
- Alert preferences: categories, thresholds, daily caps, and delivery channels you configure.
- Delivery identifiers: chat IDs for any messaging channel you opt into.
- Trading data: wallet addresses, orders, positions, automated-copy records, and standing exit rules. If you connect an exchange account, its API credentials are encrypted at rest with AES-256-GCM and are never shown back to you or to anyone else.
- Developer API data: the API keys you issue, their scopes and spending limits, and request metadata such as which endpoint was called, when, and how much of your quota it used.
2. How we use it
- To authenticate you and provide the Service.
- To process subscription payments and prevent fraud.
- To deliver alerts to the channels you have enabled.
- To monitor performance, debug issues, and improve the product.
- To comply with legal obligations and enforce our Terms.
3. Sub-processors
We rely on a small set of reputable vendors to operate the Service. Each receives only the data necessary for its function:
- Authentication and user management, to create accounts and verify sessions.
- Payment processing: to handle subscription billing and prevent fraud.
- Database and runtime infrastructure: managed hosting for our application data and services.
- Frontend hosting and edge delivery, to serve the website to you reliably and quickly.
- Messaging and push providers: only if you opt into a given channel for alert delivery.
A current list of named sub-processors is available on request by emailing the address below.
4. We do not sell your data
We do not sell, rent, or trade your personal information. We may share limited information with service providers that help us operate, improve, and promote Rivo.
5. API and AI assistant access
Rivo offers a developer API and an MCP server, which let an AI assistant or an application you control call Rivo on your behalf using an API key you issue.
- Nothing reaches an assistant unless you connect it and supply your own key. You can revoke a key at any time from settings, which cuts off access immediately.
- What a key can reach is limited by the scopes you give it. Read scope returns market and account data; write scope changes account settings; trade scope can place orders. Keys default to read.
- Data returned to an assistant leaves our systems and is then handled by that assistant's provider under their privacy policy, not this one. We have no control over what they retain.
- Responses are filtered before they leave: venue-internal market identifiers and other traders' wallet addresses are stripped unless the key holds the scope that requires them.
6. Cookies
We use cookies and similar technologies that are strictly necessary to keep you logged in and operate the service. With your permission, we may also use optional cookies to understand usage and measure our marketing. You can opt out at any time, and declining optional cookies does not affect your access to Rivo.
7. Retention
We keep account, subscription, trading, and alert data for as long as your account is active. When you delete your account we cancel any live subscription, clear your display name and alert preferences, and delete your messaging links immediately.
A minimal billing record is deliberately retained after deletion. It is the only thing connecting a subscription to a person, and discarding it is how a closed account keeps getting charged with nobody able to trace it. We keep that record for seven years to meet tax and accounting obligations, and for no other purpose.
Market and trade data we collect from Polymarket and Kalshi is public exchange activity, is not personal information about you, and is retained indefinitely.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. Email privacy@rivo.markets to exercise any of these rights. You can also delete your account at any time from settings.
9. Security
We use industry-standard safeguards to protect your information, including encryption in transit, scoped access controls, and managed identity providers. No system is perfectly secure; we cannot guarantee absolute security.
10. Children
The Service is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.
11. International transfers
The Service is operated from the United States. If you access it from elsewhere, your information will be transferred to and processed in the United States and other countries where our sub-processors operate.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above.
13. Contact
Privacy questions? Email privacy@rivo.markets.