PRIVACY POLICYLast updated: July 26, 20261. Data ControllerIn accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Data Protection and Digital Rights Guarantee (LOPDGDD), the User is informed that personal data will be processed by:
Data Controller: Galina Egorova NIE: Address: Alicante, Spain Email:
support@rivapsy.comHereinafter, "RIVA," "RIVA PSY," "the App," "the Service," or "we."
2. ScopeThis Policy governs the processing of personal data of users of the RIVA PSY mobile app, the official website (rivapsy.com), and any associated digital service.
By using the App or website, the User declares having read and understood this Policy and agrees to the processing of their data under the terms described here. If you disagree, please refrain from using the Service.
3. Definitions- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (collection, recording, storage, consultation, use, disclosure, erasure, etc.).
- User: any natural person using the App or website.
- Processor: a natural or legal person that processes data on behalf of the Controller.
- Third-party services: technology services from external companies necessary for the Service to operate.
4. Data Minimization PrincipleRIVA PSY is designed around the principle of data minimization: we collect only what is strictly necessary to provide the service, and we avoid access to sensitive information by design wherever technically possible. In particular:
- The content of your emotional journal (SMER entries: situation, thoughts, emotions, body, actions) is stored exclusively on your device (local storage), and RIVA never has access to this content.
- Voice recordings (the "Talk it out" feature) are created and stored exclusively on your device. They are never transmitted to, processed by, or stored on our servers.
5. Personal Data We Collect5.1 Data provided directly by the User- Email address
- Username
- Age
- Gender (when the User chooses to provide it)
- Preferred language
- Subscription/plan status
- Information voluntarily submitted when contacting support (suggestions, error reports)
5.2 Data collected automatically- IP address
- Device identifiers
- Operating system version and device model
- Firebase identifiers
- Technical logs and crash/error data
- Push notification token (Firebase Cloud Messaging)
5.3 Authentication dataWhen logging in, we may process information from Firebase Authentication, Google Sign-In, or Sign in with Apple. Passwords are never stored by RIVA in plain text; authentication is handled through Firebase Authentication's secure mechanisms.
6. Data We Do NOT CollectRIVA does not request or collect:
- The content of your emotional journal or voice recordings (they remain on your device, see Section 4)
- Biometric or genetic data
- Identity documents
- Full bank account details or card numbers
- Special categories of data under Art. 9 GDPR, unless the User voluntarily enters such information in free-text fields of the App, in which case it will be processed solely to provide the requested service and, if it is journal content, will likewise remain on the User's device.
7. Purposes of Processing- Create and manage the User's account
- Authenticate the User and recognize subscription status across devices
- Provide the App's functionality
- Send notifications and reminders when enabled by the User
- Facilitate backups when the User explicitly activates that feature
- Respond to support inquiries
- Improve performance, stability, and security of the App
- Detect technical errors and prevent fraudulent use
- Comply with applicable legal obligations
8. Legal Basis for Processing- Performance of a contract or the requested service (Art. 6(1)(b) GDPR)
- User consent (Art. 6(1)(a) GDPR), revocable at any time
- Compliance with legal obligations (Art. 6(1)(c) GDPR)
- Legitimate interest of the Controller in ensuring security and continuous improvement (Art. 6(1)(f) GDPR)
9. Third-Party Services9.1 Firebase (Google LLC)We use Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging (FCM), and Firebase Storage (for recommendation/meditation audio files, not for the User's journal). Firestore stores only the account and subscription data described in Section 5 — never journal content.
Firebase may process: email address, unique identifiers, device identifiers, IP address, technical device information, logs, and push notification tokens.
RIVA does not currently use Firebase Analytics
.9.2 Google Sign-InWhen signing in with Google, we only access information the User has authorized (name, email, unique identifier). RIVA never has access to the Google account password.
9.3 Sign in with AppleApple may provide a unique identifier, email address (real or private, depending on the User's configuration), and name. This is used solely to manage authentication.
9.4 Google Drive API (Backups)RIVA lets the User create and restore backups generated and controlled by the User themselves, via their Google Drive account. Access:
- is only requested after an explicit User action;
- is used solely to create or restore the backup generated by the App;
- does not allow access to, viewing, modification, or deletion of any other files in the User's account.
RIVA does not perform automatic or scheduled backups without User action. The User is responsible for managing and retaining their own backups.
9.5 Payments (processed via the website)Paid subscriptions are purchased and processed through our website (rivapsy.com), via a specialized external payment provider (currently being integrated). RIVA does not collect or store full card numbers, CVV/CVC codes, or financial credentials. RIVA only receives information about payment status, transaction ID, and payment date, in order to activate the corresponding access on the User's account.
10. International Data TransfersSome technology providers may process data outside the European Economic Area (EEA), including the United States. Where this occurs, RIVA will implement safeguards equivalent to those required by the GDPR (adequacy decisions, Standard Contractual Clauses, and/or additional technical measures including encryption where appropriate).
11. Data RetentionData type | Retention period |
User account (email, subscription) | While the account remains active |
Journal content / voice recordings | Not applicable — stays exclusively on the User's device |
Google Drive backups | Under the User's exclusive control, until deleted by them |
Technical logs | Up to 24 months, unless a longer period is required for security reasons |
Payment information | For the period required by applicable tax and accounting law |
Support inquiries | Up to 24 months from the last communication |
12. Security of InformationWe apply appropriate technical and organizational measures, including: encrypted communications via HTTPS/TLS, secure authentication via Firebase Authentication, least-privilege access control, security rules for Cloud Firestore and Firebase Storage, and internal incident management procedures.
In the event of a security breach affecting Users' rights, RIVA will act in accordance with Articles 33 and 34 of the GDPR.
13. MinorsRIVA's services are intended exclusively for individuals over 18 years of age, or the applicable digital age of consent in their country of residence. We do not knowingly collect data from minors. If we become aware that we have collected data from a minor without verifiable parental/guardian consent, we will delete it promptly.
14. Future Use of Artificial IntelligenceRIVA does not currently use generative AI features. In the future, we may introduce an optional conversational AI assistant feature. When available, you will be specifically informed before it is activated, its use will be optional, and it will be governed by a dedicated AI Transparency Notice, available on our website.
15. CookiesThe rivapsy.com website uses cookies. For more information, see our separate Cookie Policy. The mobile App does not use browser cookies, though the third-party SDKs described in Section 9 may use equivalent technical identifiers.
16. User RightsUnder the GDPR, Users may exercise: the right of access, rectification, erasure, restriction of processing, objection, data portability, withdrawal of consent, and the right not to be subject to decisions based solely on automated processing that produce significant legal effects.
Exercising these rights is free of charge. Requests may be sent to
support@rivapsy.com. RIVA may request additional information to verify the requester's identity and will respond within a maximum of one (1) month.
17. Right to Lodge a ComplaintUsers may file a complaint with the Spanish Data Protection Agency (AEPD), or with the competent data protection authority of their habitual EU country of residence.
18. Changes to This PolicyWe may update this Policy periodically. The updated version will be published on this page along with the last-updated date. We recommend reviewing this page periodically.
19. ContactFor any questions regarding this Privacy Policy:
support@rivapsy.com