Privacy Policy
Last updated: August 18, 2026
Rivet Gaming, Inc. (“Rivet”, “we”, “us”) builds open-source infrastructure for stateful backends. This policy explains what personal information we collect across the rivet.dev website and Rivet Cloud, why we collect it, who we share it with, and the choices you have. We have written it to be read, not skimmed past.
Who We Are and What This Policy Covers
Rivet Gaming, Inc., 2261 Market Street STE 22704, San Francisco, CA 94114, United States, is the company responsible for the personal information described in this policy. Where data protection law distinguishes roles, we are the controller of that information unless this policy says otherwise.
This policy covers:
- The rivet.dev website, including our documentation and blog.
- The Rivet Cloud dashboard at https://dashboard.rivet.dev and the managed services behind it.
- Related interactions with us, such as sales inquiries and support.
This policy does not cover:
- Self-hosted Rivet. Rivet is open source, and you can run the control plane and your workers entirely on your own infrastructure. Your application data in a self-hosted deployment stays on your infrastructure and is outside this policy. One exception: by default, the open-source control plane sends crash reports to our error-tracking service; you can turn this off by setting
telemetry.enabled: falsein its configuration. - Data our customers’ applications process about their own end users. See Customer Content: Our Role as a Processor below.
- Third-party sites we link to. Their privacy policies govern what they collect.
Your use of the services is also governed by our Terms of Service and Acceptable Use Policy.
Information We Collect
We collect information in three ways: information you give us directly (such as account details and form submissions), information collected automatically when you use the website or Rivet Cloud (such as analytics events and request logs), and information we receive from the service providers listed later in this policy. The subsections below describe each source in plain terms.
Account information
When you create a Rivet Cloud account, we collect your email address, name, organization or team details, and authentication data needed to sign you in and keep your account secure.
Billing information
Payments are handled by our payment processor, which receives your payment details directly. We never store full card numbers. We keep your billing contact details, your plan, and usage and metering records (for example, awake actor hours, storage, reads and writes, egress, and compute time) so we can bill you accurately.
Service usage data
When you use Rivet Cloud, we collect operational data about your use of the service itself:
- API request logs, including the identity of the account and credentials making each request.
- Resource usage measured for metering and billing, such as awake actor hours, state storage, reads and writes to persisted state, egress, and compute time.
- Diagnostic logs that help us detect failures, debug problems, and keep the service running.
This is data about your use of Rivet Cloud. The data your workloads themselves store and process is Customer Content, covered separately below.
Website analytics and diagnostics
When you visit rivet.dev, the following tools run:
- Google Analytics collects usage and device data about your visit.
- Ahrefs Analytics collects usage data about your visit.
- PostHog, served through our own subdomain (ph.rivet.gg), records page views, interaction events, and in-page feedback you submit, and sets
ph_cookies. - Sentry monitors the site for errors. Error reports may include your IP address, request headers, and cookies.
- Docs search is powered by Typesense. Your search queries and IP address go directly from your browser to Typesense’s servers to return results.
- GitHub API calls are made from your browser to fetch repository star counts.
- Google Fonts load on pages under /learn.
- YouTube embeds run in privacy-enhanced mode (youtube-nocookie).
Contact and sales forms
If you submit a contact-sales or talk-to-an-engineer form, we collect your name, email, company, role, and message. These submissions are stored in PostHog and Sentry, which serve as our storage and notification systems for these forms.
Support and community
If you email support@rivet.dev, we receive your email address and whatever you include in your message. Our Discord server and GitHub repositories are independent platforms governed by their own privacy policies.
Job applicants
Our careers page embeds Y Combinator’s Work at a Startup. Applications you submit there are submitted to and processed by Y Combinator under its privacy policy.
Signed-in docs experience
If you are logged in to Rivet Cloud, documentation pages fetch your projects, namespaces, and API tokens from Rivet Cloud using your existing session so we can prefill code examples for you. Your project and namespace selections are kept in your browser’s localStorage; tokens are not persisted there.
Customer Content: Our Role as a Processor
Customers run workers — processes running their own code with the Rivet SDK — on their own infrastructure, while Rivet Cloud hosts the control plane and storage. In that arrangement, Rivet Cloud persists data on the customer’s behalf. We call that data “Customer Content”. It includes:
- Persisted actor state and per-actor SQLite databases.
- Messages, schedules, and logs.
- Container images customers supply for managed container deployment, and the logs those containers produce while running on Rivet-managed infrastructure.
- agentOS session data, including files, command history, and network activity within an agentOS workload — which may include credentials, such as model-provider API keys, that the customer configures.
For Customer Content, the customer is the controller and Rivet is a processor (or “service provider” under US state privacy laws) acting on the customer’s instructions. We access Customer Content only to provide, secure, and support the service, or as required by law. We do not use Customer Content for advertising, and we do not sell it.
If you are an end user of an application built on Rivet, the developer of that application decides what data it collects and why. Please direct privacy requests about that application to the developer; if a request reaches us instead, we will assist and redirect it as appropriate.
Self-hosted deployments do not send Customer Content to us.
How We Use Information
We use the information described above to:
- Provide, operate, and maintain the services.
- Meter usage and bill you.
- Respond to your inquiries, support requests, and sales requests.
- Secure, debug, and monitor the services and the website.
- Understand how the product and site are used so we can improve them.
- Comply with legal obligations, such as tax and accounting requirements.
- Enforce our Terms of Service and Acceptable Use Policy.
Where the GDPR or similar laws apply, our legal bases for processing are:
- Performance of a contract — accounts, billing, and delivering the services you signed up for.
- Legitimate interests — analytics, securing the services, and responding to business inquiries, balanced against your rights and interests.
- Legal obligation — tax and accounting records we are required to keep.
- Consent — where the law requires it, in which case you may withdraw consent at any time.
Cookies, Analytics, and Local Storage
The cookies actually set on rivet.dev are:
| Cookie | Set by | Purpose |
|---|---|---|
_ga and _ga_ prefixed | Google Analytics | Distinguishes visitors for website analytics |
ph_ prefixed | PostHog | Distinguishes visitors for product analytics and in-page feedback |
The Ahrefs script and the Sentry SDK also run on our pages. We do not use advertising or retargeting cookies.
We use your browser’s localStorage for functional preferences only: theme, sidebar state, dismissed banners, feedback flags, and your selected project and namespace in the docs. No authentication tokens are persisted in localStorage.
Your choices. You can block or delete cookies in your browser settings. For Google Analytics specifically, Google offers an opt-out browser add-on. Blocking analytics does not affect core site functionality.
Do Not Track and Global Privacy Control. Our site does not currently respond to Do Not Track or Global Privacy Control signals. That said, we do not sell or share personal information regardless of any signal.
How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information with the service providers below, each for the purpose listed.
| Provider | Purpose | Data involved |
|---|---|---|
| Google (Analytics) | Website analytics | Usage and device data |
| Ahrefs | Website analytics | Usage data |
| PostHog | Product analytics and contact-form storage | Usage data, form submissions |
| Sentry | Error monitoring and form feedback | Error context including IP, headers, cookies |
| Typesense | Docs search | Search queries, IP |
| Railway | Website hosting | Server request logs |
| Cloudflare | Asset delivery | IP, request data |
| Our payment processor | Payments and billing | Payment and billing details |
| GitHub | Code hosting, community | Public activity, IP on browser API calls |
| Discord | Community | Per Discord’s policy |
| Y Combinator (Work at a Startup) | Job applications | Application data |
| Google (YouTube, Fonts) | Embedded video and fonts | IP, embed interaction |
We may also share information:
- For legal compliance. To comply with law or respond to lawful requests from public authorities, such as a court order or subpoena.
- To protect rights, safety, and the service. To enforce our agreements, investigate abuse, or protect the rights, property, or safety of Rivet, our customers, or others.
- In business transfers. If Rivet is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
- With your consent. For any other purpose you agree to.
International Data Transfers
Rivet is a United States company, and the information described in this policy is processed in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to a country whose data protection laws differ from those of your home jurisdiction. Where such transfers require a legal mechanism, we rely on appropriate safeguards such as the Standard Contractual Clauses.
Data Retention
We keep personal information for as long as we need it for the purposes described above and to meet our legal obligations, then delete or de-identify it. In practice:
- Account data is retained until you close your account or make a verified deletion request.
- Billing and metering records are retained as needed for invoicing, disputes, and tax and accounting obligations.
- Customer Content is retained per the customer’s instructions and deleted following account termination; see the Terms of Service for the export window.
- Analytics and log data are kept for shorter operational periods appropriate to their purpose.
Residual copies may persist in backups for a limited period before deletion completes.
Security
We use reasonable technical and organizational measures to protect personal information, including:
- TLS encryption for data in transit.
- Access controls on our systems and on the Rivet Cloud dashboard.
- Least-privilege access to Customer Content, limited to providing, securing, and supporting the service.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and API keys confidential; secret keys and Cloud API tokens should never be exposed client-side (publishable keys are the only credential class designed for that).
If you believe you have found a security issue in our services, please report it to legal@rivet.dev.
Your Rights
EEA, UK, and Switzerland
If the GDPR or UK or Swiss data protection law applies to you, you have the right to:
- Access the personal information we hold about you and receive a copy of it.
- Rectify inaccurate or incomplete personal information.
- Erase your personal information where there is no good reason for us to keep processing it.
- Restrict our processing of your personal information in certain circumstances.
- Receive a portable copy of information you provided to us, in a structured, commonly used, machine-readable format.
- Object to processing based on our legitimate interests, and to any direct marketing.
- Withdraw consent at any time where we rely on consent, without affecting processing that already happened.
- Complain to a supervisory authority in your country of residence or place of work.
US state privacy laws
If you live in California or another state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Texas), you may have the right to:
- Know and access the personal information we have collected about you.
- Correct inaccurate personal information.
- Delete personal information we collected from you.
- Receive a portable copy of your personal information.
- Opt out of sale, sharing, and targeted advertising. These rights exist under those laws; as described above, we do not sell or share personal information, and we do not use it for targeted advertising.
We do not use personal information for profiling that produces legal or similarly significant effects.
Non-discrimination. We will not discriminate against you for exercising any of these rights — we will not deny you services, charge you different prices, or provide a different level of service because you made a privacy request.
Appeals. If we deny a request, we will explain why. You may appeal by replying to our decision, and we will review the appeal and respond as required by your state’s law. If we deny your appeal, you may contact your state attorney general.
Authorized agents. An authorized agent may submit a request on your behalf with proof of authorization; we may still need to verify your identity directly.
Exercising your rights
Email legal@rivet.dev to exercise any of these rights. To protect your information, we will verify your identity before acting on a request — typically by confirming control of the email address associated with your account or your original submission. We respond within the timeframes required by applicable law. If a request concerns Customer Content processed on behalf of one of our customers, we will refer the request to that customer and assist them in responding.
Children
Our services are business tools intended for users 18 and older. They are not directed to children under 18, and we do not knowingly collect personal information from children. We do not sell the personal information of any consumer, including consumers under 16 years of age. If you believe a child has provided us with personal information, contact legal@rivet.dev and we will delete it.
Links and Embedded Content
Our site links to and embeds third-party content, including:
- Our status page, which is hosted by a third party and is informational.
- YouTube videos, embedded in privacy-enhanced mode.
- Community platforms such as Discord and GitHub.
- Y Combinator’s Work at a Startup on our careers page.
Those parties’ privacy policies govern any data they collect when you interact with their content. We encourage you to review them.
Changes to This Policy
We may update this policy from time to time. We will post updates on this page and revise the “Last updated” date at the top. If a change is material, we will flag it with a prominent notice on the site.
Contact Us
For privacy questions or to exercise your rights: legal@rivet.dev.
For general support: support@rivet.dev or /support.
By post: Rivet Gaming, Inc., 2261 Market Street STE 22704, San Francisco, CA 94114, United States.