RIYAN AIGrowth OS
LEGAL

Privacy

Last updated: September 2026

This notice explains the product-level privacy approach for Riyan AI Growth OS. The exact data processed depends on the workspace features and integrations a customer chooses to authorize.

Information we may process

RIYAN may process account and workspace information, authentication and security events, configuration data, authorized integration data, campaign and performance metrics, store or lead outcomes, support communications, public inquiries and technical usage information needed to provide and secure the service.

Trial eligibility and abuse-prevention signals

To enforce limited free-trial eligibility and reduce automated or repeated fake registrations, RIYAN may use verified account information together with security signals such as a first-party HttpOnly trial-device token, network information and payment-processor card fingerprint signals. Where implemented, RIYAN stores one-way keyed hashes of trial email, network, device-token and processor-fingerprint signals rather than using those values as advertising profiles. These security records may be retained as needed to enforce one-trial policies, investigate abuse and protect the service. Network or IP information is not treated as a sole permanent identity because offices and shared networks may contain legitimate separate customers.

Payment information

Card collection is hosted by the payment processor. RIYAN is designed not to store raw card PAN or CVV. A payment processor may provide tokenized references, limited card metadata and a card fingerprint that can be used for billing operations, fraud prevention and trial-eligibility enforcement.

Connected services

External advertising, commerce, CRM, search and analytics systems are connected only through customer-authorized access. Credentials and OAuth tokens are handled server-side and are not intended to be exposed in the customer interface or Growth Brain context.

How information is used

Information may be used to provide the service, normalize authorized data, generate analytics and recommendations, maintain security, diagnose incidents, support customers, enforce workspace permissions, manage subscriptions and comply with applicable obligations.

AI and minimum necessary context

Growth Brain is designed to receive the minimum workspace evidence needed for the requested assistance. Raw card PAN/CVV, passwords, recovery-code values, payment tokens, processor identifiers and provider secrets are not intended to be injected into AI context.

Workspace isolation and access

Customer-owned records are workspace-scoped. Access is controlled by authentication, roles and server-side authorization. Privileged support and administrative access should be limited, scoped and auditable.

Retention, export and deletion

Retention requirements may vary by data type, customer configuration, security need, connected provider and applicable law. RIYAN supports controlled data export and deletion workflows rather than silent cross-workspace reuse.

Public inquiries

Information submitted before login through the Contact page is stored so the RIYAN team can respond. Do not submit passwords, payment-card details, API keys or provider secrets through public inquiry forms.

Your choices

Customers control which supported systems they connect and can revoke authorized connections subject to provider behavior and contractual or legal retention requirements. Marketing communications are optional and separate from service/security communications.

Contact

Privacy inquiries can be sent through the Riyan AI Contact page.