Privacy Policy

Last updated: September 7, 2026

This Privacy Policy explains how Rivasyst (“we,” “us,” or “our”) collects, uses, and protects your information when you use ChatRwD, our AI-powered Bible study assistant, available on the web at chatrwd.appand as a mobile application (collectively, the “Service”). By using the Service, you agree to the practices described in this policy.

Information We Collect

Account information

When you create an account, we collect your email address, account ID, and profile name. Our authentication provider stores a password hash when you use email and password sign-in. If you sign in using a third-party provider (Google, Apple, or Facebook), we receive your name, email address, and profile picture from that provider, as permitted by your privacy settings with them. We do not receive or store your social account password, and we do not post to your social accounts.

Content you provide

We collect the messages, questions, and conversations you submit to the Service, along with any feedback, ratings, or search queries you make. These are stored so you can revisit your conversation history.

You may also submit images, files, and documents as chat attachments. Authorized publishers can upload photos, videos, and voice recordings to the community feed; recordings may be transcribed. We process this media and its associated filenames and captions to provide these features.

Community posts, comments, profile names, and avatars are visible to other people who can access the feed, including visitors. We store likes, replies, notifications, content reports, and block preferences. Reports and AI feedback are available to authorized moderators, not displayed publicly. Avoid posting private contact details or sensitive information. We also record the community-rule version you accept and the time of acceptance to manage participation and enforce these rules.

Usage and device information

We collect limited technical information such as device type, operating system, app version, diagnostic and crash data, and—if you opt in to notifications—a push notification token. Notification delivery can also use installation identifiers and app-version information. This helps us operate, secure, and improve the Service.

How We Use Your Information

  • To create and authenticate your account.
  • To provide the core Service, including generating AI responses to your questions and saving your conversation history.
  • To send you notifications you have opted in to receive.
  • To respond to your support requests and feedback.
  • To monitor, secure, debug, and improve the Service and prevent abuse.
  • To comply with legal obligations.

How AI Responses Are Generated

To answer your questions, the content of your messages is processed by third-party AI and search service providers acting on our behalf. Please do not submit sensitive personal information (such as financial, health, or government identification details) in your messages.

OpenAI processes questions, relevant conversation context, selected attachments, retrieved study material, and voice recordings when transcription is requested. We use automated content checks and review reports to improve safety. Pinecone stores search representations of conversations so you can find your own past messages. Generated answers can be inaccurate; verify them against the cited material.

Service Providers

We share information with trusted third-party service providers who process data on our behalf, only as needed to operate the Service:

  • OpenAI — AI answers, attachment processing, voice transcription, and automated content moderation.
  • Pinecone — semantic search and retrieval, including account-linked conversation search.
  • Supabase — authentication and database (stores your account, profile, conversation, community, and moderation data), plus storage for uploaded media and conversation records.
  • Vercel — application hosting and delivery.
  • Sentry — error and crash diagnostics.
  • Expo — delivery of mobile push notifications.
  • Google Firebase Cloud Messaging — Android push-token registration and notification delivery, including installation-related identifiers and app information. Native Android Firebase Analytics collection is disabled.
  • PostHog — where enabled, product-usage analytics linked to account IDs and app interactions. New server-side event collection is disabled by default in the native Android release configuration; previously collected analytics may still require provider-side erasure.
  • Google, Apple, and Facebook — optional sign-in providers, when you choose to use them.

We do not sell your personal information, and we do not share it for third-party advertising.

Data Retention and Deletion

We retain your information for as long as your account is active. You may request deletion of your account and associated data at any time. See our Data Deletion page for instructions.

Account deletion covers conversation records and search indexes, uploaded files held for your account, profiles, authored community content, feedback, and notification tokens. Provider cleanup can require retries; the app reports success after its automated cleanup completes and account-linked analytics deletion requests are accepted. PostHog processes associated event and recording erasure asynchronously. For historical provider records or a failed deletion, use the email request on our Data Deletion page so we can complete the remaining work.

Restricted operational deletion receipts, security logs, and legally required records may remain after deletion. Provider backups and abuse monitoring records follow the applicable provider retention settings. These records are not used to restore an active account. Contact us for the retention period applicable to a specific record or deletion request.

Data Storage and International Transfers

Your information is stored and processed on servers located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed there.

Security

We use industry-standard safeguards, including encryption in transit and access controls, to protect your information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us so we can remove it.

Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below or use our Data Deletion page.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or your data, contact us at hello@rivasyst.com.