The engine never sees the name.


Rivalta’s architecture decides what we can know about a household before any policy does. The professional’s machine is the only place where the real names, addresses, account numbers, and Social Security numbers live. A synthetic-identifier vocabulary maps to them locally. What leaves the browser, and what Rivalta’s servers receive, is raw numbers, role labels, and pseudonyms — a substrate that is structurally insufficient to constitute a household-identifying record.

This is the operative privacy fact. The policy below describes how Rivalta handles the data that does reach us — the professional’s account, billing, and operational telemetry — under that architectural ceiling.


Account information. Name, work email, firm name, professional license category (advisor, CPA, attorney, insurance, real estate), and the credentials you use to sign in. This is data about you, the professional — not about a household you serve.

Billing information. Tier, seat count, credit balance, invoice history, and a tokenized reference to the payment method held by our payment processor. Rivalta does not store card numbers.

Pseudonymized engagement data. The substrate Rivalta reasons over: numeric facts, role labels, household composition, and synthetic identifiers. This data is the product of your browser’s local mapping. We see the structure; we do not see who it belongs to.

Operational telemetry. Page loads, feature usage, performance metrics, and error reports. Error reports are scrubbed for the pseudonymized substrate above — we retain stack traces and request shapes, not their contents.

Communications. Email you send us, support tickets, and any feedback you choose to share.


Client names, postal addresses, dates of birth, Social Security numbers, account numbers at custodians or carriers, photographs of documents, and any free-text fields you might type into a competing product. Rivalta’s ingress refuses these on principle, and the architecture makes the refusal enforceable: there is no place on our servers where this data could land, because the API does not accept it.

The same rule applies to the pre-customer sandbox at try.rivalta.co. Documents you upload there are parsed in your browser, exactly as in the paid product; only pseudonymized structured data leaves the device. The sandbox runs on separate hardware with no network route to the paid environment, and the pseudonymized data is deleted within 7–14 days or on upgrade. The full posture is on /security.

We do not train models on your engagement data. We do not sell data. We do not run advertising. We do not enrich your records against third-party data brokers.


To run the engine on your behalf, render its output, bill your subscription, send the operational email that the platform generates (receipts, security notices, the occasional product announcement), respond to your support requests, and improve the product through anonymized usage analysis.

The decision substrate stays in the engagement it belongs to. Cross-customer pooling, training-set construction, and aggregate-statistics work happens only on data stripped of the pseudonyms that link it back to your account.


Rivalta uses a short list of third-party services to run the platform. Each operates under a written agreement that restricts their use of your data to the service they provide:

Hosting. The main Rivalta platform runs on bare-metal infrastructure in Zürich, Switzerland (Tier III facility, NTS Workspace AG); your pseudonymized engagement data for production accounts lives there. The pre-customer sandbox at try.rivalta.co — described in the Terms — runs on separate infrastructure hosted in Germany, in the European Union. The two environments do not share data and have no network route between them; both run the same browser-side anonymization, so only pseudonymized structured data reaches either set of servers.

Payment processing. A PCI-compliant processor handles card capture and recurring billing. They hold the card data; Rivalta holds a token.

Error monitoring. A monitoring vendor receives scrubbed stack traces and performance data. They do not receive the pseudonymized substrate or its contents.

Reasoning providers. The engine routes specific reasoning steps to upstream model providers (Anthropic, OpenAI, Google, xAI, and an inference aggregator). Calls are scoped, logged, and carry only the pseudonymized substrate — no household identifiers reach upstream providers.

A current subprocessor list is available on request to [email protected].


When you send a Sealed Findings Handoff to another professional, the bundle is already de-identified by the time it leaves the engine. Rivalta returns a single-use link, scoped to one recipient and one expiry window. You forward that link through your own email or messaging channel. Rivalta is not in the email path; we do not see who you sent it to until they open it.

The receiving professional imports the bundle under their own local pseudonym vocabulary. No shared workspace is created. No joint record is created.


Production accounts. Your engagement data lives for as long as your subscription is active. After cancellation, we retain it for ninety days so that reactivation restores the work, then we delete it from live systems. Encrypted backups expire on a rolling schedule and are fully purged within twelve months.

Pre-customer sandbox. Data submitted to the sandbox at try.rivalta.co follows a shorter timeline matched to the inflow path. A dossier engagement expires seven days after creation. A Sealed Findings Handoff recipient engagement expires fourteen days after the recipient first opens the link, with a sixty-day hard cap from the date the sender created the handoff. Expired sandbox engagements are deleted from live systems within seven days of expiry; encrypted backups follow the same rolling-purge schedule as production data. Sandbox data is never moved to a production account.

Billing and operations. Billing records are retained for seven years to meet tax and accounting requirements. Operational logs and telemetry are retained for thirteen months.


You can ask us to show you what we hold about you, correct it, export it, or delete it. The architectural rule means there is very little to show: your account record, your billing record, and the pseudonymized substrate keyed to your account.

California residents have rights under the CCPA / CPRA; European residents have rights under the GDPR. To exercise any right, write to [email protected] from the email address on your account. We will respond within thirty days.

Because Rivalta’s engine never receives household identifiers, the data-subject rights of the people you advise do not flow through Rivalta. They flow through your firm, which is where their identifiable record lives.


The application uses session cookies to keep you signed in. We do not run third-party analytics, advertising pixels, or cross-site trackers on the application surface.

The marketing site at rivalta.co sets no cookies. It collects anonymous usage analytics through PostHog — pages viewed, links clicked, and session replays with every form field masked — so we can see how these pages are read. The analytics identifier lives in your browser’s local storage, is never tied to a name or an email, and is never joined with application data. No advertising pixels, no cross-site tracking.


Rivalta is a professional tool. Accounts are limited to licensed practitioners eighteen years and older. We do not knowingly collect information from minors.


When we revise this policy materially, we will email account owners and update the revision date at the top of this page. The current revision date governs.