Legal
Privacy Policy
Rtriv does not sell personal data or use it for targeted advertising. Some data is disclosed to providers strictly necessary to operate, secure, bill for and enrich the service, as detailed below.
1. Controller
The controller is Benoit Gainnier, individual entrepreneur (EI), trading as Rtriv. Privacy and rights contact: contact@rtriv.io.
2. Account and authentication
Data: email, account ID, sign-in method, Apple Sign in or Google Sign-In data and security information. Purposes: create and secure the account, authenticate you and send service communications. Legal basis: contract; legitimate interests for security. Recipients: Rtriv, Supabase, Apple or Google depending on the method selected. Retention: account lifetime, then up to 30 days for active-system deletion, unless law or security requires longer.
3. Profile and social features
Data: display name, profile picture, bio, follows, interactions, shares, blocks and reports. Purposes: social functions, profile personalisation and moderation. Basis: contract; legitimate interests in preventing abuse; legal duty where applicable. Recipients: users you select, Rtriv, Supabase and necessary moderation providers. Retention: account lifetime; reports and enforcement records up to 3 years where needed for evidence and abuse prevention.
4. Saves, URLs, notes, collections and screenshots
Data: URL, title, metadata, notes, tags, collections, screenshots and sharing settings. Purposes: save, organise, retrieve, sync and share as you choose. Basis: contract. Recipients: Rtriv, Supabase, extraction and enrichment providers; other users only under your settings. Retention: until item or account deletion, followed by active-system erasure within 30 days.
5. Enrichments, summaries and transcripts — AI
Data: URL, accessible source content, metadata and required instructions; depending on media, audio or text to transcribe. Purposes: extract, transcribe, summarise, classify and enrich a save. Basis: contract when you request the feature. Recipients: OpenAI, Supadata, GetXAPI, Brave Search and Rtriv, depending on the source and feature used. A notice in the three-dot menu indicates when content is AI-generated. More information is available in the app’s Legal Centre.
Automated outputs may be wrong. Rtriv does not intentionally send account identity when unnecessary and does not use your content to train its own models. Avoid unnecessary sensitive data.
6. One-time location and search
Data: location requested at that moment or searched place. Purposes: geographic search or enrichment. Basis: consent through system permission or performance of your request. Recipients: Rtriv, Supabase when the result is saved, and the system geocoding service used by the app. Retention: raw location is not continuously tracked; a place added to a save follows that save’s retention.
7. Selected photos
Data: only photos or screenshots you choose through the system picker. Purposes: create or illustrate a save and perform requested analysis. Basis: your request and system permission. Recipients: Rtriv, Supabase and OpenAI if analysis is requested. Retention: until item or account deletion.
8. Notifications and technical data
Data: push token, preferences, device, app version, IP and technical logs. Purposes: selected notifications, compatibility, troubleshooting and security. Basis: consent for notifications; legitimate interests for reliability and security. Recipients: Expo, Apple, Supabase and Sentry. Retention: tokens while valid; logs and diagnostics generally up to 90 days, longer only where an incident requires it.
9. Subscriptions and purchases
Data: product, status, dates, transaction IDs and technical receipt; Rtriv does not receive full card details. Purposes: enable Rtriv+, verify and restore purchases and provide support. Basis: contract and accounting duties. Recipients: Apple and RevenueCat. Retention: subscription lifetime and then the legally required transaction-evidence period, generally up to 10 years for accounting records.
10. Product events, diagnostics, security and abuse
Data: features/screens used, timestamps, errors, technical identifiers, IP, reports and fraud signals. Purposes: understand product operation without targeted advertising, fix errors, protect accounts and prevent abuse. Basis: legitimate interests; legal duty where applicable. Recipients: Rtriv, Supabase, Sentry and authorities following a valid request. Retention: product events and diagnostics up to 13 months unless aggregated; security records up to 3 years where necessary.
11. Contacts
Address-book access is optional and requires your iOS permission. To find people already registered, the app reads contacts’ email addresses only, normalises them (lowercase and trimmed), then computes their SHA-256 fingerprints locally. Only those fingerprints are sent to Supabase for matching; plain-text addresses and the complete address book are neither transmitted nor retained by Rtriv. The fingerprints are used for the matching request and are not stored in a dedicated table. You can withdraw permission at any time in iOS Settings.
12. Website, cookies and Screen Time Receipt
The website uses two strictly functional cookies, “locale” and “currency”, to remember the selected or detected language and currency for 12 months. These cookies are not used for targeted advertising.
To secure generation routes and limit abuse, the IP address and technical request data are processed by Vercel and Upstash Redis. Rate-limit counters use one-minute windows; associated rate-limit analytics are retained for the period configured by Upstash and are used only for security and diagnostics.
Screen Time Receipt processes, in your browser and on the server when generating or sharing, the selected apps, entered durations, language and currency. A shared URL encodes the apps and durations in its address: anyone who has that URL can view the receipt. Rtriv does not save these inputs to an account; they may nevertheless appear temporarily in Vercel and Upstash technical logs under their retention periods, and remain in your browser history or bookmarks until you delete them.
13. Providers and transfers outside the EEA
Some providers may process data outside the EEA. Depending on provider and destination, transfers rely on adequacy decisions (including the Data Privacy Framework where applicable), European Commission Standard Contractual Clauses and supplementary measures. Request details or a copy of safeguards at contact@rtriv.io.
- Supabase: authentication, database and storage.
- OpenAI: AI enrichments and analysis.
- Supadata: supported-content extraction and transcription.
- GetXAPI: supported-content extraction.
- Brave Search: web search used for certain enrichments.
- Sentry: diagnostics and error monitoring.
- RevenueCat: subscription and purchase status.
- Apple: sign-in, payments, notifications and system services.
- Google: account sign-in when Google Sign-In is selected.
- Expo: application infrastructure and notifications.
- Vercel: website hosting and technical logs.
- Upstash Redis: rate limiting and related security analytics.
- System geocoding services used by a feature.
14. Retention, account deletion and backups
Unless specified above, active systems retain data for the account lifetime. A deletion request disables the account and starts active-data erasure within 30 days. Encrypted residual copies may remain in rotating backups for up to 90 additional days and are not restored to production except for security recovery. Evidence may be isolated longer where law or legal claims require it.
Deleting an account does not automatically cancel an Apple subscription; cancel it in App Store settings.
15. Your rights
You may request access, correction, deletion, restriction, objection to legitimate-interest processing and portability of data you provided where legal conditions apply. You may withdraw consent at any time without affecting earlier processing.
Email contact@rtriv.io. Identity evidence is requested only where there is reasonable doubt. Rtriv normally responds within one month. You may complain to the CNIL (cnil.fr) or your habitual-residence supervisory authority.
16. Security, children and changes
Rtriv uses proportionate technical and organisational safeguards, including access controls, encryption in transit, backups and logging. No system is entirely secure. The service is not intended for children under 13. Material policy changes will be appropriately notified and renewed consent requested where required.