Privacy Policy
Last updated September 10, 2026
1. Information we collect
We collect information you provide directly — such as your name, email address, and organization details when you create an account or contact us.
We also collect information automatically when you use Roiva, including usage data, log data (IP address, browser type, pages visited), and cookies necessary for the service to function.
When you connect third-party integrations (e.g. HubSpot, Salesforce), we store OAuth credentials and sync data from those platforms on your behalf. We do not access that data for any purpose other than providing the service to you.
2. How we use your information
We use the information we collect to:
- Provide, operate, and improve Roiva
- Authenticate your account and keep it secure
- Send transactional emails (invitations, notifications, receipts)
- Respond to support requests
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use your data to train AI models.
3. Data storage and security
Your data is stored on servers in the United States (AWS). We use encryption in transit (TLS) and at rest. Sensitive credentials — integration tokens, API keys, OAuth client secrets, and SAML signing keys — are encrypted at the field level using AES-256.
External auditor access links are stored as a one-way SHA-256 digest, never as the original token. The full URL is shown to your administrator once at creation and cannot be retrieved again afterwards. If an auditor loses their link, your administrator regenerates a new one.
No method of transmission or storage is 100% secure. We take reasonable measures to protect your information but cannot guarantee absolute security.
4. Data retention and deletion
We retain your account data for as long as your account is active. You can delete your data at any time using the in-app controls:
- Delete your user. Profile → Security → Delete account. This permanently removes your sign-in credentials, two-factor secret, assistant chat history, notifications, and personal activity, and removes you from every account you're a member of.
- Delete a workspace account (Owner only). Settings → Account → Delete account. This permanently removes the workspace and every initiative, value entry, integration, document, and report it contained.
Both flows are irreversible. We recommend exporting any reports or data you want to keep before initiating either deletion.
When you delete an account or user, we retain a single audit-log entry recording that the deletion happened — the date, an aggregate count of what was destroyed, and (for user deletions) a one-way SHA-256 hash of the email address so support can answer a future "did this person ever have an account" query without storing the email itself. No other personal information is retained. This entry exists so the deletion itself stays auditable.
Financial records inside your workspace — accounting periods, journal entries, allocation rules — are deleted with the rest of the account data. We rely on your prior export of those records to satisfy your own tax and audit retention duties, in line with GDPR Article 17(3)'s recognition that erasure rights and financial-records obligations can coexist provided the data subject has been given the opportunity to preserve their own copy. Our own books (revenue from you, in our accounting system and Stripe) are retained separately under the retention period required by applicable tax law.
If you can't sign in and need help exercising your deletion right, contact us at hello@roiva.ai .
5. Third-party services
We use the following sub-processors to operate the service:
- AWS — cloud infrastructure and storage
- Stripe — payment processing
- Sentry — error monitoring
- Sidekiq / Redis — background job processing
- Anthropic — large-language-model inference for the in-app assistant and for AI-generated initiative estimates and document analysis. Content you send to the assistant, and initiative and document text we analyze on your behalf, are processed by Anthropic's API. Anthropic does not use this content to train its models. See Anthropic's privacy policy for details.
- PostHog — product and usage analytics across both our marketing pages and the signed-in application. In-browser tracking only loads after you accept the analytics cookie banner; a limited set of account events (described in Section 6) is also sent from our servers. See PostHog's privacy policy for details.
- HubSpot — demo scheduling on our public booking page. If you book a demo, the name, email address, and meeting details you enter are submitted to HubSpot. The booking widget is an embedded HubSpot page; it does not set cookies or other storage on our own site. See HubSpot's privacy policy for details.
- Google Analytics 4 — usage analytics (only loaded after you accept the analytics cookie banner). See Google's privacy policy for details.
Each sub-processor is contractually required to handle data in accordance with applicable privacy law.
6. Cookies and analytics
Roiva uses two kinds of cookies and similar storage:
- Functional (always on). Session cookies for authentication, account context, and security. These are required for Roiva to work and are not optional.
- Analytics (opt-in). On our marketing pages and inside the signed-in application we use PostHog and Google Analytics 4 (GA4) to understand how people find and use Roiva. Neither tool loads in your browser until you click Accept on our cookie banner.
PostHog stores its identifier in both your browser's local storage and a first-party cookie. Once loaded it records pageviews, and — because autocapture is enabled — it also records interactions such as clicks on buttons and links, along with the element that was interacted with. PostHog only builds a stored person profile for users we have identified (in practice, signed-in users); visitors who are not signed in are counted without a persistent profile being created. We have configured our PostHog project to discard client IP addresses, so your IP address is not stored alongside these events; an approximate location is derived from it before it is discarded.
Google Analytics 4 sets its own cookies and records pageviews, on-site events, approximate location, and an anonymized IP address (IP anonymization is enabled in our configuration). We do not use GA4's advertising features, audiences, or remarketing.
Separately from the banner, when you are signed in our servers send a small, fixed set of product events to PostHog — such as completing signup or requesting an invite — together with your email address, account identifier, and account name. This is server-side processing we carry out to operate and improve the service; it does not involve cookies or storage in your browser, and it is not affected by your cookie banner choice.
You can decline analytics at any time by clicking Decline on the banner — your choice is stored in your browser's local storage. To change a previous choice, click Cookie preferences in the footer of any page; the banner will reappear and you can choose again.
We do not use advertising, retargeting, or third-party tracking cookies.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing.
The fastest way to exercise your erasure right (GDPR Article 17 and equivalents) is the in-app self-service flow described in Section 4 . For access, correction, objection, restriction, or any request you can't complete in-app, email us at hello@roiva.ai and we will respond within the timeframes required by applicable law.
8. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or by posting a notice in the application. Continued use of Roiva after changes take effect constitutes acceptance of the updated policy.
9. Contact
Questions about this policy? Email us at hello@roiva.ai .