RIVENLENS LEGAL
Back to RivenLens
Current effective document. Version 2026-10-10-v4. Please review this document carefully.

RivenLens Privacy Policy

Status: EFFECTIVE Version: 2026-10-10-v4 Effective date: October 10, 2026

RivenLens (“RivenLens,” “we,” “us,” or “our”) operates the Service and acts as the operator/controller for the information processing described in this Privacy Policy.

1. Our privacy commitments

RivenLens is designed to collect only information reasonably connected to operating, improving, securing, and responsibly funding the Service, and to explain those practices in understandable language.

Our current privacy commitments are:

2. Scope

This Privacy Policy explains how RivenLens collects, uses, stores, and shares information when you use the RivenLens website, software, closed beta, grading and pricing tools, account/profile features, saved-Riven libraries, marketplace listings and trade-coordination features, feedback systems, supporter-linked features, advertising/privacy settings, administrative or privacy-request features, and related services (collectively, “RivenLens” or the “Service”).

It does not govern independent third-party websites or services that have their own privacy practices.

3. Information we collect and why

A. Authentication and beta identity

For protected beta access, RivenLens receives the authenticated email address associated with the user's protected beta authentication session.

We use this information to:

Our hosting, security, and authentication providers may separately process network, device, authentication, and security information when delivering and protecting the Service.

B. Beta agreement and electronic-signature records

When a beta tester electronically accepts the RivenLens Beta Tester NDA & Limited Competitive-Use Agreement, RivenLens stores a legal audit record that can include:

RivenLens uses this information to form and administer the beta agreement, verify that the current agreement was accepted, maintain evidence of the transaction, protect confidential beta access, and establish, exercise, or defend legal rights.

RivenLens does not intentionally store the tester's raw IP address in the beta agreement database record.

C. Product analytics

RivenLens collects limited product-usage analytics to understand whether the Service works, whether users return, and how the grading-to-valuation experience performs.

Analytics can include:

The RivenLens product-analytics store is intentionally designed not to store the tester's authenticated email, raw IP address, raw user-agent string, screenshot contents, or free-text feedback.

The persistent analytics browser identifier is stored in browser local storage and is designed to rotate after approximately 395 days (about 13 months). Session and evaluation identifiers use browser session storage and ordinarily expire with the browser session/tab. Users can clear browser storage sooner using their browser controls.

RivenLens server-side analytics events are automatically pruned after approximately 395 days.

Because the browser identifier can recognize the same browser over time during that period, these analytics are pseudonymous rather than fully anonymous.

On the production Service, when the Google/IAB consent framework reports that GDPR applies, RivenLens' first-party product analytics are designed to wait for the required consent signals before creating the persistent analytics identifier or sending product-analytics events. The current production consent gate requires consent for IAB TCF Purposes 1, 8, 9, and 10 for this analytics processing. If that consent is refused or withdrawn, RivenLens stops this product analytics and clears the RivenLens analytics identifiers stored in local/session browser storage. This consent gate does not disable grading, pricing, marketplace, profile, or other substantive Service features.

D. Normal grading, comparable analysis, and pricing requests

When you grade or value a Riven, RivenLens processes the information necessary to generate the requested output, such as:

The protected grading, comparable-analysis, and pricing engines process these requests to return a result. RivenLens does not currently maintain a separate named-user history table containing every grading or pricing request.

Reduced pseudonymous product-analytics events may be stored separately as described above.

E. Screenshot scanning and generated images

When you select a Riven screenshot for the normal screenshot scanner, RivenLens processes the image in your browser using on-device OCR and browser image/canvas features. The screenshot bytes are not uploaded to RivenLens merely because you select or scan the image.

If you separately choose to attach a screenshot to a feedback report, the browser re-encodes the image to remove embedded metadata before uploading it to private feedback-attachment storage. Attaching a screenshot is optional and requires an explicit file selection in the feedback form.

If you generate a shareable RivenLens image, the image is composed locally in the browser unless a feature specifically tells you otherwise. If you choose to share or save that image through your device or another service, the destination you choose may process it under that destination's own privacy policy.

When screenshot OCR is used, the browser may need to download software or language resources required for OCR. Section 7 describes the relevant category of technical provider without publishing an internal infrastructure map.

F. Feedback, bug reports, and diagnostic information

If you intentionally submit feedback, a bug report, accuracy response, or feature request, RivenLens stores the information you provide, which can include:

To reproduce beta bugs and investigate grading/pricing disagreements, RivenLens may automatically attach technical context available at the time of submission, including:

RivenLens minimizes this information before storage. In particular, RivenLens removes query strings and URL fragments from the stored feedback page URL and removes the selected screenshot's filename and file last-modified timestamp before the report is written to the feedback store.

The screenshot image itself is not uploaded as part of the automatic diagnostic package. If the user explicitly adds a screenshot through the feedback form, RivenLens stores the re-encoded image privately with the report, without retaining its original filename or embedded image metadata. Screenshot attachments are accessible only through the protected feedback-admin workflow and are not included in privacy-safe text exports.

Free-text fields may contain personal information if you choose to include it. Please avoid including passwords, authentication tokens, financial-account information, or other sensitive information that is not necessary to explain the issue.

G. Feedback resolutions and in-app notifications

When RivenLens closes a beta report, RivenLens may store an in-app tester-facing resolution, creation timestamp, and read timestamp so the submitting tester can see what happened to the report. RivenLens does not currently use an email provider to send these beta report-resolution notifications.

H. Security and anti-abuse information

RivenLens processes security information needed to operate protected endpoints, including protected authentication/session information, request identifiers, request origin/security headers, and connecting IP information supplied by infrastructure/security services for rate limiting and abuse prevention.

The RivenLens application currently uses the connecting IP address in a short-lived in-memory beta rate-limit key rather than intentionally writing that IP address into the RivenLens analytics, feedback, or beta-agreement application stores.

Infrastructure and security providers may independently maintain delivery, security, authentication, or access logs according to RivenLens' configuration and the provider's applicable service practices.

I. Browser storage and privacy signals

RivenLens uses browser storage and authentication technology for purposes such as:

RivenLens may read a browser/device privacy signal such as Global Privacy Control (GPC) where exposed and legally applicable. The RivenLens Privacy Center no longer stores or changes a separate personalized-advertising ON/OFF preference. With Google AdSense active, site-level advertising consent and opt-out choices are handled through Google Privacy & messaging / the applicable Google-certified CMP, which may use cookies, local storage, TCF or GPP consent/opt-out strings, or similar mechanisms according to Google's implementation, the user's choices, and applicable law. For supported U.S. state messages, Google Privacy & messaging can use the IAB Global Privacy Platform (GPP) to communicate sale, sharing, and targeted-advertising opt-out choices to participating advertising partners.

J. User accounts, profiles, saved Rivens, marketplace, messaging, and reputation

RivenLens currently provides account/profile features that allow a user to create and sign in to a RivenLens account, maintain a profile, save graded Rivens to a personal library, publish selected Rivens as marketplace listings, upload a profile picture, set a presence state, use direct marketplace messaging, block or report users, record user-confirmed trades, and leave reputation reviews after an eligible confirmed trade. Warframe in-game-name verification is currently marked Coming soon on the production Service; prerelease or beta channels may use separate verification tooling.

For RivenLens accounts, a third-party account/identity provider currently handles email-and-password authentication, email verification, password recovery, and authentication-session issuance. RivenLens receives the authenticated account identity and maintains the RivenLens username/account linkage needed to operate the Service. RivenLens does not intentionally store a user's plaintext account password in the RivenLens application database. Prerelease or beta channels may also use an additional access/security layer as a legacy authenticated identity bridge for authorized testers.

Depending on the final implementation, RivenLens may process or store information such as:

Authenticated email addresses and account passwords are not displayed publicly merely because a user creates a profile or marketplace listing. Depending on the user's settings and feature state, a public trading profile can display information such as the RivenLens username, Warframe in-game name, platform, cross-play setting, verification status, public presence state, profile picture, supporter badge/flair or permanent public achievement, confirmed-trade count, reputation summary, published reviews, and active marketplace listings. A user's Appear Offline selection is presented publicly as offline rather than exposing the private label itself.

The planned marketplace is a listing/discovery/trade-coordination service. Every actual Riven transfer will occur directly between users inside Warframe. RivenLens does not plan to take custody of in-game inventory, hold a Riven or Platinum in escrow, transfer the item between users, process settlement for the in-game trade, or maintain payment-card data merely to facilitate ordinary Riven marketplace listings. A listing or trade-coordination status may become stale if a user changes plans or completes a trade elsewhere in Warframe.

These account, profile-picture, saved-Riven, marketplace, messaging, reporting, trade-confirmation, reputation, and moderation features are implemented in the current RivenLens service architecture, with prerelease-only functionality isolated from production. The deployed authentication flow, database/storage schema, public/private field boundaries, authorization controls, account-deletion behavior, marketplace moderation/security controls, and privacy-request coverage have been reviewed against the production implementation. RivenLens continues to review these controls as the Service changes.

K. Supporter memberships, advertising, and sponsorships

RivenLens offers optional supporter memberships through Patreon and provides optional Patreon account linking so a RivenLens user can verify an active membership tier and receive the corresponding supporter benefits. Google AdSense advertising is active on eligible public production pages. Ad delivery can include targeted/personalized advertising where permitted, or contextual, non-personalized, limited, or restricted advertising where applicable. An ad request may remain unfilled, and applicable ad-free supporter benefits suppress RivenLens ad requests. Sponsorships are not currently active.

If a user chooses to link Patreon to a RivenLens account, RivenLens receives or stores the limited information reasonably necessary to recognize and administer supporter benefits. Depending on the authorization response and membership state, this can include:

The supporter platform may independently process information such as the supporter's email, legal/billing information, payment method, transaction history, tax information, and other account information under its own privacy policy. Patreon authorization may return account identity information such as an email address or display name as part of the authorized identity response. The current RivenLens Patreon-link record does not separately persist the Patreon account email or full name; it links the membership to the user's existing RivenLens account and stores provider identifiers instead. RivenLens does not intend to receive or store full payment-card numbers merely because a user supports RivenLens through Patreon or another supporter platform.

RivenLens encrypts stored Patreon OAuth access and refresh tokens at rest. If a user disconnects Patreon from RivenLens, the stored Patreon link record—including those encrypted OAuth credentials—is deleted and recurring Patreon-derived entitlements are marked inactive. Permanent achievements that were expressly granted as permanent recognition, such as an eligible Founding Supporter achievement, are not automatically revoked merely because Patreon is later disconnected or the recurring membership ends.

When personalized advertising is active, an advertising provider may process identifiers, cookies or similar technologies, approximate location, device/browser information, and activity or inferred-interest information used to select, measure, limit, or report ads, depending on the provider and the user's privacy treatment. Non-personalized or contextual ads may still use limited technologies for purposes such as frequency capping, aggregated reporting, fraud prevention, or coarse/contextual ad selection.

RivenLens does not intend to provide an advertiser with an authenticated RivenLens email address or Patreon/supporter status merely to personalize advertising. Sponsors do not receive RivenLens user personal information merely because they sponsor RivenLens.

Before adding another advertising provider or activating sponsorship integrations, RivenLens will review the resulting data flows and update this Policy if they materially expand the information collected, shared, or retained. RivenLens will likewise review changes to existing Google AdSense and Patreon implementations and update this Policy when required.

4. How we use information

RivenLens uses information for purposes including:

RivenLens will not repurpose personal information for a materially incompatible purpose without providing any notice or consent required by applicable law.

5. Advertising choices, sale/share disclosures, and sponsorships

RivenLens does not sell authenticated account identity, such as a user's RivenLens email address, to advertisers for money.

RivenLens uses targeted/personalized advertising where legally permitted, and Google-managed contextual, non-personalized, limited, or restricted advertising treatments when applicable. Declining personalized advertising does not by itself disable ordinary advertisements. Some privacy laws define sale, sharing, or targeted advertising broadly enough that certain disclosures or uses by personalized advertising providers can fall within those terms even when RivenLens does not receive money for a list of users. If a RivenLens advertising implementation falls within those definitions, RivenLens will make the legally required disclosure and provide the applicable opt-out mechanism.

Google AdSense and advertising cookies

RivenLens has selected Google AdSense as its intended launch advertising provider. Google AdSense ad serving is active on eligible public production pages; the closed beta and protected account, communication, legal, and privacy-request screens do not carry RivenLens ad placements. Ad availability depends on provider fill, consent and privacy requirements, and applicable ad-free membership benefits. When AdSense is activated, third-party vendors, including Google, may use cookies or similar technologies to serve ads based on a user's prior visits to RivenLens or other websites. Google's use of advertising cookies enables Google and its partners to serve ads to users based on visits to RivenLens and/or other sites on the Internet.

Users may opt out of personalized advertising provided through Google by visiting Google Ads Settings at https://adssettings.google.com/. RivenLens provides Privacy and cookie settings through the account-free Advertising Privacy Choices page at https://rivenlens.com/privacy-choices, linked from the Privacy Center at https://rivenlens.com/privacy-center. Google's native regional consent or opt-out controls appear when applicable and available. RivenLens does not promise that a dialog will appear for every location, visitor, or existing preference. RivenLens does not maintain a second independent personalized-advertising toggle. If RivenLens later enables additional third-party ad vendors or ad networks, RivenLens will identify them or provide access to the applicable provider list and privacy controls before those vendors are activated where required.

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, RivenLens will not request personalized Google ads unless the required consent has been obtained through a Google-certified Consent Management Platform (CMP) integrated with the IAB Transparency and Consent Framework (TCF). Where required, users will be able to review or change consent choices through the applicable Google CMP/privacy interface.

U.S. state privacy opt-outs and restricted data processing

For U.S. states supported by Google Privacy & messaging, RivenLens has configured a launch privacy message targeted to all current and future supported U.S. states. When published, eligible visitors can use Google's Do Not Sell or Share My Personal Information link and confirmation flow to opt out of sale, sharing, and targeted advertising as represented through the Google/IAB implementation.

Google's U.S. state privacy message supports the IAB Global Privacy Platform (GPP). When a visitor opts out through that message, the applicable GPP fields can communicate opt-out choices for sale, sharing, and targeted advertising to Google and participating advertising partners. RivenLens will not maintain a second conflicting local advertising opt-out toggle.

Where Google's U.S. state framework or applicable law calls for restricted treatment, Google may use Restricted Data Processing (RDP) and serve only non-personalized ads for the affected Google ad request. Non-personalized ads may still be selected using contextual information, coarse location, and other permitted non-behavioral signals. RivenLens does not intend to force RDP on all U.S. traffic where it is not required, because eligible users who have not opted out may receive the personalized advertising treatment otherwise permitted by law and provider policy.

Google states that for users in applicable U.S. states it can receive qualifying Global Privacy Control (GPC) signals directly and trigger RDP for those ad requests. RivenLens will honor qualifying universal opt-out signals where legally required and will not treat a prior provider-managed opt-in or consent state as overriding a legally binding universal opt-out signal.

Where applicable law permits an opt-out model, Google Privacy & messaging and the applicable provider settings will govern the user's site-level advertising choice. If a user opts out of sale, sharing, targeted advertising, or personalized advertising where applicable, RivenLens and Google will apply the corresponding contextual, non-personalized, limited, restricted-data-processing, or otherwise legally required ad treatment supported by the integration. Users may still see ordinary advertisements unless an ad-free supporter benefit or another feature removes them.

Where applicable law requires prior consent before personalized advertising, cookies, local identifiers, or similar technologies are used, RivenLens will request the required consent before enabling the affected processing.

RivenLens will honor legally required universal or browser/device opt-out preference signals where applicable. A qualifying signal such as GPC may require restricted processing independently of a prior provider-managed choice.

RivenLens does not intend to collect date of birth merely to determine advertising treatment. The general-audience Service remains intended for users age 13 and older. If RivenLens, a responsible RivenLens representative, or an advertising provider actually knows that a particular user is a child or teenager entitled to additional advertising protections, RivenLens will apply the required protected treatment. The advertising provider may independently apply its own child/teen protections based on information available to it.

RivenLens may display clearly identified sponsorships or sponsored placements. A sponsor does not receive RivenLens user personal information merely by sponsoring the Service, and sponsorship status does not influence RivenLens grading or valuation output.

6. When information is shared

RivenLens may disclose information in the following circumstances:

Service providers and infrastructure

RivenLens may provide information to service providers that process it on RivenLens' behalf to host, secure, operate, maintain, or support the Service. RivenLens expects providers handling personal information on its behalf to use appropriate confidentiality and security protections consistent with their role and applicable law.

Marketplace/public profile information

When a user intentionally publishes profile or marketplace information, RivenLens may display it to other users or the public as indicated by the feature. This can include a RivenLens username, Warframe in-game name, platform, cross-play setting, verification status, public presence state, profile picture, supporter badge/flair or public achievement, listed Riven details, asking price or trade terms, listing status, confirmed-trade count, reputation summary, and published review content. Authenticated account email is not intended to become public merely because the user creates a profile or listing.

Supporter platforms

If you choose to support RivenLens through Patreon or another supporter platform, RivenLens and the supporter platform may exchange limited membership or entitlement information where necessary to recognize your optional supporter benefits. The provider independently handles information it needs for its own account, billing, tax, fraud-prevention, and payment purposes under its policies.

Advertising providers

Google AdSense is the active production advertising provider on eligible public pages. Google may select contextual or non-personalized inventory instead of personalized ads based on applicable privacy choices and law; no particular ad impression is guaranteed. When advertising is enabled, RivenLens may allow Google or another disclosed advertising provider to process information necessary to select, serve, measure, limit, secure, or report advertisements. Depending on the user's privacy treatment, this may include contextual information or information used for permitted personalized advertising. RivenLens will use provider-managed consent/opt-out controls and configure supported providers to respect legally required privacy signals to the extent required and technically supported.

RivenLens does not intend to provide authenticated RivenLens email addresses or supporter membership status to advertising providers merely for ad personalization.

Sponsors

RivenLens may work with sponsors to fund the Service. A sponsor does not receive RivenLens user personal information merely because it sponsors RivenLens. If a future sponsored feature requires a separate data disclosure, RivenLens will disclose that before the data is provided.

Legal and safety reasons

RivenLens may preserve or disclose information when reasonably necessary to comply with law, court orders, subpoenas, or other valid legal process; protect rights or safety; investigate fraud, abuse, or security incidents; or establish, exercise, or defend legal claims.

Business transactions

If RivenLens undergoes a financing, reorganization, merger, acquisition, sale, or transfer of all or part of the business or assets, information may be transferred as part of that transaction, subject to applicable law and appropriate protections.

At your direction

RivenLens may disclose information when you intentionally direct the Service to share/export content to another destination.

7. Categories of third parties and external data services

RivenLens uses third-party services and public/external data sources to operate, secure, improve, and support the Service. The public Privacy Policy identifies these parties by category so users can understand what types of organizations may receive information without publishing an unnecessary map of RivenLens' internal infrastructure or data-supply architecture.

Depending on the feature used, relevant categories can include:

Hosting, database, security, and authentication providers

These providers help deliver the website and APIs, store application information, authenticate protected users, maintain sessions, prevent abuse, cache content, and protect the Service. They may process ordinary network, device, request, authentication, and security information necessary to perform those functions.

Account and identity providers

RivenLens currently uses an account/identity provider for public-account sign-up, email-and-password authentication, email verification, password recovery, and authentication-session issuance. That provider may process account identifiers, email address, authentication credentials, verification/recovery events, session/cookie information, and security metadata under its own terms and privacy practices. RivenLens receives the authenticated identity/session information necessary to operate the account and links it to the user's locked RivenLens username and RivenLens application records. The production configuration and applicable provider and data-processing arrangements remain subject to periodic review as the public Service evolves.

Public game and market-data services

RivenLens uses public, community, market, or official game information to support weapon/catalog mapping, grading, valuation, comparable analysis, and marketplace-related features. Some requests may be made server-to-server; when the user's browser communicates directly with an external source, that source can receive ordinary connection/request metadata such as IP address and browser/device information.

Software, content-delivery, and technical dependency providers

Some browser features may download approved software libraries, language resources, or other technical dependencies from external delivery services. Those providers can receive ordinary network/request metadata when the resource is downloaded. Local screenshot OCR does not intentionally transmit the selected Riven screenshot to such a provider merely because the OCR software or language resource is downloaded.

Supporter and membership providers

RivenLens currently supports optional Patreon membership recognition and account linking. Patreon independently processes its own account, billing, payment, tax, fraud-prevention, and transaction information under its privacy practices. RivenLens receives only the authorized identity/membership information and OAuth credentials described in this Policy that are needed to link the account, verify current membership state, and administer RivenLens supporter benefits.

Advertising providers

RivenLens has selected Google AdSense for launch advertising. When activated, Google and its advertising partners may process identifiers, cookies or similar technologies, approximate location, browser/device information, page or activity information, inferred interests, fraud/security signals, and ad measurement/reporting information, depending on the user's legally applicable privacy treatment. Site-level consent and opt-out choices will be managed through Google Privacy & messaging / the applicable Google-certified CMP rather than a separate RivenLens personalization toggle. For supported U.S. state traffic, Google's message may communicate sale, sharing, and targeted-advertising opt-out choices through the IAB GPP framework, and Google may apply restricted data processing when an applicable opt-out or qualifying GPC signal requires it. Google Ads Settings at https://adssettings.google.com/ provides an additional Google-level control for personalized advertising.

Sponsors and business partners

RivenLens may work with sponsors or other business partners. Sponsorship alone does not entitle a sponsor to RivenLens user personal information. If a particular partnership requires a separate disclosure of personal information, RivenLens will disclose that practice before the information is provided where required.

RivenLens maintains a more detailed internal privacy/data inventory for security, compliance, vendor review, and engineering purposes. The internal inventory may identify specific vendors, storage products, endpoints, or technical data paths that are not necessary to publish in the consumer-facing Privacy Policy.

8. Data retention

RivenLens retains information according to its purpose, sensitivity, legal significance, and whether the information remains necessary.

Product analytics

Pseudonymous product-analytics event rows are automatically pruned after approximately 395 days (about 13 months). The persistent browser analytics identifier is designed to rotate on the same approximate schedule and may be cleared sooner by the user through browser storage controls. Where the production consent gate applies, refusing or withdrawing the required analytics consent clears the RivenLens analytics identifiers stored in local/session browser storage and stops new first-party analytics events from being sent until the required consent is present again.

Advertising privacy choices

The RivenLens Privacy Center does not maintain a separate personalized-advertising ON/OFF preference. When Google Privacy & messaging / the applicable Google-certified CMP is activated, Google or participating consent technology may store consent or opt-out state through cookies, local storage, TCF or GPP strings, or similar mechanisms as necessary to operate the privacy choice. RivenLens may also read legally applicable universal opt-out signals such as GPC at request time, and Google may receive qualifying GPC signals directly for supported U.S. state ad requests. Provider-maintained choice records are governed by the provider's applicable implementation and retention practices, subject to RivenLens' legal obligations.

Feedback and diagnostic records

RivenLens retains active feedback while it is needed to investigate and resolve the report. For a closed ticket, detailed report/diagnostic information, including an optional screenshot attachment, is retained for up to approximately 12 months after the ticket's most recent closure. After that period, the screenshot is deleted and detailed diagnostic context is removed or minimized while the basic report, resolution, and essential ticket history may be retained for up to approximately 24 months after the most recent closure. After approximately 24 months, the remaining ticket record is deleted unless a security, fraud, dispute, legal-hold, or other lawful retention exception applies.

Account, profile-picture, saved-Riven, marketplace, messaging, and reputation records

These records are retained while reasonably necessary to provide the applicable account, profile, saved-Riven, marketplace, messaging, moderation, trade-confirmation, and reputation features. Replacing a profile picture deletes the previously referenced image object on a best-effort basis, and using the profile-picture removal control deletes the current image record/object. Removing a public listing or profile field is intended to remove it from ordinary public display, while limited records may need to remain for security, fraud prevention, moderation, abuse investigations, disputes, legal obligations, or privacy-request administration.

RivenLens does not publish a fixed ordinary deletion period for account records, marketplace conversations/messages, trade-confirmation history, reviews, or moderation records because retention needs vary by feature and lawful purpose. Production account-deletion and privacy-request behavior has been verified against the deployed Service. Where a deletion request applies, RivenLens removes or minimizes ordinary account/product data subject to limited retention that is reasonably necessary for security, fraud prevention, moderation, disputes, legal obligations, or other lawful exceptions.

Agreement and electronic-signature records

Beta agreement/electronic-signature records are legally significant. RivenLens may retain them for as long as reasonably necessary to prove the agreement, enforce or defend legal rights, resolve disputes, comply with law, or maintain required business records. They are not treated as ordinary disposable analytics records and may be retained after an account or ordinary user data is deleted where a lawful retention reason applies.

Supporter membership records

While Patreon remains linked, RivenLens retains the Patreon link and encrypted OAuth credentials needed to verify membership and administer supporter benefits. Disconnecting Patreon deletes the stored Patreon link record and encrypted OAuth credentials and marks recurring Patreon-derived entitlements inactive. RivenLens may retain limited entitlement-status history as reasonably necessary for administration, security, fraud prevention, disputes, required business records, or legal obligations. Permanent achievements that are expressly designed to survive cancellation or disconnection, such as an eligible Founding Supporter achievement, remain recorded unless deletion is required by law or otherwise approved through a privacy request subject to lawful exceptions.

Security and infrastructure records

Application-level rate-limit IP keys are short-lived in memory. Infrastructure/security logs are retained according to RivenLens' configuration and the applicable service provider's practices.

Legal holds and exceptions

RivenLens may suspend deletion or retain specific records longer when reasonably necessary for litigation, legal process, fraud/security investigation, regulatory obligations, accounting obligations, or another lawful purpose.

RivenLens will not claim a fixed retention period in the effective Policy unless the Service is configured to support that commitment.

9. Your privacy rights and advertising choices

RivenLens intends to provide the following core rights to users regardless of where they live, subject to identity verification and lawful exceptions:

Choosing non-personalized, contextual, limited, or otherwise restricted advertising treatment will not reduce the substantive grading or valuation functionality available to a free user. Ordinary ads may remain unless the user has an applicable ad-free supporter benefit.

RivenLens will not unlawfully discriminate against a user for exercising a privacy right.

Some information may be exempt from deletion or other requests, including information reasonably necessary to comply with law, protect security, prevent fraud, complete a transaction, maintain legally significant agreement records, establish or defend legal claims, or exercise another lawful exception.

10. How to submit a privacy request or manage advertising choices

The public Service provides a Privacy Center at https://rivenlens.com/privacy-center through which authenticated account holders may submit an access, correction, export, deletion, or other privacy request. Anyone, including a visitor without an account, may contact [email protected] for privacy-related assistance. Separate protected beta features may offer additional authenticated support channels.

RivenLens does not maintain a separate personalized-advertising ON/OFF toggle. For site-level Privacy and cookie settings, visit the account-free Advertising Privacy Choices page at https://rivenlens.com/privacy-choices, accessible from the Privacy Center and website footer. This simplified page loads Google's native Privacy & messaging controls when available to the visitor; it does not itself submit an opt-out or guarantee a dialog on every visit. For Google-account-level personalization, use Google Ads Settings at https://adssettings.google.com/. If a regional control does not appear, contact [email protected] for assistance.

For eligible visitors in supported U.S. states, Google's published Privacy & messaging message may display its native Do Not Sell or Share My Personal Information control and confirmation flow on the Advertising Privacy Choices page. Only a visitor's affirmative selection to opt out through Google's dialog submits that choice; merely opening the page does not opt them out. Google can encode the resulting sale, sharing, and targeted-advertising choices using the IAB GPP framework. Where a qualifying GPC signal is legally applicable, RivenLens will honor that signal as required independently of a provider-managed choice; Google states that it can receive qualifying GPC signals directly and trigger restricted data processing for applicable U.S. state ad requests.

For users in the EEA, United Kingdom, and Switzerland, the applicable Google-certified CMP will provide the required consent controls and a way to review or change consent choices when AdSense is activated.

RivenLens may need to verify the requester's identity before disclosing, correcting, exporting, or deleting information. Verification is designed to prevent a person from using privacy rights to obtain or alter someone else's information.

RivenLens will respond within the timeframe required by applicable law and intends to use 45 days as the ordinary maximum response target for verified requests unless a shorter period applies or a lawful extension is available and communicated.

If RivenLens denies a request that applicable law gives the requester a right to appeal, RivenLens will provide a reasonable appeal method with the decision. Where Delaware law applies and an appeal is denied, the appeal response will also provide a method for contacting the Delaware Department of Justice as required by applicable law.

The RivenLens Privacy Center is the current request mechanism for authenticated users. Privacy-related questions or requests may also be sent to [email protected]. RivenLens will update these request methods if additional contact options are required by applicable law or changes to the Service.

11. Delaware and other U.S. state privacy rights

RivenLens voluntarily provides the core access/correction/export/deletion rights above broadly rather than limiting them only to residents of a particular state.

Where the Delaware Personal Data Privacy Act or another applicable U.S. state privacy law provides additional targeted-advertising, sale/sharing, profiling, appeal, authorized-agent, or universal opt-out rights, RivenLens will honor those requirements to the extent they apply.

RivenLens has configured Google's U.S. state privacy message for all current and future U.S. states supported by Google Privacy & messaging, rather than Delaware only. Where applicable and displayed, eligible visitors may use Google's native Do Not Sell or Share My Personal Information control via https://rivenlens.com/privacy-choices. Google currently supports transmission of relevant U.S. state privacy choices through the IAB GPP framework.

If RivenLens processes personal data for legally defined targeted advertising, the Service will clearly disclose that practice and provide the applicable provider-managed opt-out method. Where a qualifying universal opt-out preference signal is legally binding, RivenLens will treat that signal as an opt-out for the processing to which it applies. Google may apply restricted data processing to applicable ad requests after an eligible user opts out or where a qualifying GPC signal requires that treatment.

12. Children and teenagers

The public RivenLens Service and separate contractual beta are intended for users 18 years of age or older. Users represent they are adults under the Terms of Service. RivenLens does not routinely verify visitor ages or require government identification. This stated audience does not establish that all visitors are adults or waive protections required when RivenLens actually knows that a visitor is a minor.

RivenLens does not routinely collect birth dates solely for advertising treatment or require a date of birth to view the public Service. If an underage user is identified, RivenLens will assess appropriate account participation and legally required advertising protections instead of assuming the 18+ audience statement resolves them.

RivenLens does not knowingly collect personal information from children under 13 through account, beta, feedback, or other personal-data features. If RivenLens learns that it has collected personal information from a child under 13 in circumstances where parental consent is required and was not obtained, RivenLens will take appropriate steps to delete the information and disable the affected participation, subject to legal requirements.

If RivenLens actually knows or is legally treated as knowing that a user is a teenager entitled to additional targeted-advertising protections, RivenLens will apply the required age treatment. RivenLens may also rely on an advertising provider's own child/teen protections when those protections are based on information available to the provider.

Parents or guardians who believe a child under 13 has provided personal information to RivenLens may use the Privacy Center/contact method identified in this Policy.

13. International users

RivenLens and its service providers may process information in the United States and other countries where infrastructure or providers operate. Privacy and data-protection laws may differ between countries.

Where applicable law requires prior consent before personalized advertising or related nonessential storage/tracking technologies are used, RivenLens will request the required consent before enabling the affected processing. For Google AdSense traffic in the EEA, United Kingdom, and Switzerland, RivenLens uses Google's Privacy & messaging consent framework intended to operate with a Google-certified CMP and the IAB TCF, and must verify the applicable consent treatment before requesting personalized ads. Users who do not provide the required consent may receive contextual, non-personalized, limited, or otherwise restricted advertising where legally and technically permitted.

Where applicable law requires a particular transfer mechanism, notice, contractual protection, or legal basis for an international transfer, RivenLens will implement the required measure before relying on that transfer.

14. Legal bases where required

Where a jurisdiction requires RivenLens to identify a legal basis for processing, the basis may include:

The applicable basis depends on the specific data and context.

15. Security

RivenLens uses technical and organizational measures intended to protect information, including protected server-side functionality, protected access controls for the closed beta, same-origin controls, rate limits, no-store response controls for sensitive endpoints, restricted owner/admin APIs, and data minimization.

No internet service can guarantee absolute security. Users should protect their own authentication methods and promptly report suspected unauthorized access or security vulnerabilities.

16. Changes to this Privacy Policy

RivenLens may update this Privacy Policy when the Service, providers, law, monetization model, or data practices change. Each version will include a version identifier and effective date.

For material privacy changes, RivenLens will provide reasonable notice. If a new processing activity requires consent under applicable law, RivenLens will request that consent rather than treating publication of a revised Privacy Policy by itself as consent.

Historical versions may be retained for transparency, legal, and audit purposes.

17. Contact

Privacy or legal questions may be sent to [email protected]. Authenticated users can also submit privacy requests through the RivenLens Privacy Center. Authorized beta participants may use additional authenticated support/help channels in prerelease environments.

Document fingerprint (SHA-256): a947214cfd0c3d60678da26349ee23c2e3ca24f3473286112ae922d37c518f15