Privacy
Last updated: September 2026
This notice explains the product-level privacy approach for Riyan AI Growth OS. The exact data processed depends on the workspace features and integrations a customer chooses to authorize.
Information we may process
RIYAN may process account and workspace information, authentication and security events, configuration data, authorized integration data, campaign and performance metrics, store or lead outcomes, support communications, public inquiries and technical usage information needed to provide and secure the service.
Trial eligibility and abuse-prevention signals
To enforce limited free-trial eligibility and reduce automated or repeated fake registrations, RIYAN may use verified account information together with security signals such as a first-party HttpOnly trial-device token, network information and payment-processor card fingerprint signals. Where implemented, RIYAN stores one-way keyed hashes of trial email, network, device-token and processor-fingerprint signals rather than using those values as advertising profiles. These security records may be retained as needed to enforce one-trial policies, investigate abuse and protect the service. Network or IP information is not treated as a sole permanent identity because offices and shared networks may contain legitimate separate customers.
Payment information
Card collection is hosted by the payment processor. RIYAN is designed not to store raw card PAN or CVV. A payment processor may provide tokenized references, limited card metadata and a card fingerprint that can be used for billing operations, fraud prevention and trial-eligibility enforcement.
Connected services
External advertising, commerce, CRM, search and analytics systems are connected only through customer-authorized access. Credentials and OAuth tokens are handled server-side and are not intended to be exposed in the customer interface or Growth Brain context.
How information is used
Information may be used to provide the service, normalize authorized data, generate analytics and recommendations, maintain security, diagnose incidents, support customers, enforce workspace permissions, manage subscriptions and comply with applicable obligations.
AI and minimum necessary context
Growth Brain is designed to receive the minimum workspace evidence needed for the requested assistance. Raw card PAN/CVV, passwords, recovery-code values, payment tokens, processor identifiers and provider secrets are not intended to be injected into AI context.
Workspace isolation and access
Customer-owned records are workspace-scoped. Access is controlled by authentication, roles and server-side authorization. Privileged support and administrative access should be limited, scoped and auditable.
Retention, export and deletion
Retention requirements may vary by data type, customer configuration, security need, connected provider and applicable law. RIYAN supports controlled data export and deletion workflows rather than silent cross-workspace reuse.
Public inquiries
Information submitted before login through the Contact page is stored so the RIYAN team can respond. Do not submit passwords, payment-card details, API keys or provider secrets through public inquiry forms.
Your choices
Customers control which supported systems they connect and can revoke authorized connections subject to provider behavior and contractual or legal retention requirements. Marketing communications are optional and separate from service/security communications.
Contact
Privacy inquiries can be sent through the Riyan AI Contact page.