Privacy Policy
Last updated: July 6, 2026
This page is provided for general information and should be reviewed by legal counsel before production use.
1. Introduction
This Privacy Policy explains what information Rivethink collects, how it is used, when it may be processed by service providers, and the choices and rights available to users.
2. Data We Collect
Account data
We collect the username and email address you provide when creating an account. Your password is stored as a password hash rather than as plain text.
Login and security data
We may record login timestamps and related security information needed to authenticate users, protect accounts, investigate errors, and prevent misuse.
Portfolio and imported data
We process broker account details, uploaded CSV/import data, transaction records, and portfolio analytics generated from those transactions. Imports currently support file uploads from XTB, Revolut, and the Rivethink custom CSV format.
Journal data
We store the Journal entries you create, including entries connected to a portfolio, stock, or transaction.
AI analysis data
When AI analysis is used, we may process the portfolio, transaction, Journal, prompt, stock, and market context needed to generate the requested analysis. Inputs and outputs may be stored so you can review previous analyses.
Technical logs
The service may create technical logs containing timestamps, request details, errors, and security events. These logs are used for operation, debugging, reliability, and abuse prevention.
3. Data We Do Not Collect
Rivethink does not currently ask for or collect:
- Broker passwords or direct broker account login credentials.
- Bank login credentials.
- Payment card or other payment data.
- Your real name, address, or phone number.
Rivethink does not connect directly to broker accounts. Transaction imports are performed through CSV or other supported file uploads.
4. How We Use Data
We use collected data to:
- Create, authenticate, and secure user accounts.
- Import, validate, and process transaction files.
- Calculate FIFO positions and portfolio metrics.
- Display portfolio analytics, exposure, charts, and transaction markers.
- Store and display Journal entries.
- Generate AI portfolio or stock analysis when requested.
- Maintain security, diagnose errors, and prevent abuse.
- Understand and improve how the service operates.
5. AI Analysis
AI analysis may process portfolio data, transaction data, Journal entries, user prompts, and stock-related context. AI inputs and outputs may be retained to provide analysis history and operate the feature.
Do not enter unnecessary sensitive personal information in Journal entries or AI prompts. Information sent for AI processing may be handled by an AI service provider when required to generate the response.
AI analysis is informational only. It may be incomplete or inaccurate and is not financial, investment, tax, or legal advice.
6. Data Sharing
We do not sell user portfolio data or publish identifiable portfolio data. Individual holdings, transactions, broker accounts, and Journal entries are not shared publicly.
Data may be processed by hosting, infrastructure, logging, market data, or AI service providers when needed to operate Rivethink. These providers receive only the information needed for the relevant service.
7. Anonymous Aggregated Insights
Future features may present aggregated or anonymized community metrics. These insights will be designed not to identify individual users. Individual holdings, transactions, broker accounts, and Journal entries will not be displayed publicly as part of these features.
8. Data Retention
Account data is generally kept while your account exists. Imported transactions and Journal entries are kept until you delete them, delete the related data where that option is available, or request account deletion.
Technical logs may be retained for a limited period for security and debugging. Backups may temporarily retain deleted information until the relevant backup is replaced or expires.
9. Security
Passwords are stored as hashes rather than plain text, and application data access is scoped to the authenticated user. HTTPS should be used when Rivethink is deployed in production.
No online system is perfectly secure. Users should use a strong, unique password and protect access to their email account and devices.
10. User Rights
Depending on where you live and the applicable law, you may request:
- Access to the personal data associated with your account.
- Correction of inaccurate or incomplete data.
- Deletion of your data.
- Export of data you provided.
- Restriction of or objection to certain processing, where applicable.
Requests can be submitted using the contact address below. We may need to verify that the request relates to your account.
11. Cookies
Rivethink may use essential cookies for login, session handling, security, and core application functionality. If analytics or advertising cookies are introduced later, this policy and any required cookie controls should be updated.
12. International Processing
Depending on the hosting and service providers used, information may be processed on servers located outside your country. The privacy and data protection rules in those locations may differ from those in your country.
13. Changes to This Policy
This Privacy Policy may be updated as Rivethink changes. The date at the top of the page identifies the latest revision. Material changes should be communicated through an appropriate service notice.
14. Contact
Privacy questions or requests can be sent to office@rivethink.com.