How we handle your data.
Written in plain English, structured for UK GDPR and EU GDPR compliance. Last reviewed by us, not generated by a wizard.
Optional product emails
Product updates, tool tips, and offers are optional. We ask you to choose the topics you want and confirm your email subscription. Signing in, accepting our terms, or having a paid plan does not automatically subscribe you.
For subscribers, we use your selected topics, account plan, signup date, and tool activity to choose relevant messages. We record delivery failures, complaints, and link clicks. When you are signed in, we may attribute a return visit, completed server tool job, or paid-plan activation to your latest email click within seven days. We do not use email open-tracking pixels in these templates.
Our configured email delivery provider (SMTP2GO or Resend) processes recipient addresses, message content, and delivery events to send these emails. We keep subscription choices and a record of consent, and suppress addresses that unsubscribe, hard-bounce, or report spam. You can change topics or unsubscribe through any marketing email, without signing in, or in account settings. Withdrawing marketing consent does not affect essential account notices.
Who we are
Rivo Tools is operated by Yeema Holdings LTD (company number 15809333), a company registered in England and Wales. Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom.
We are the data controller for personal data we collect about you when you use Rivo Tools. That means we are responsible for deciding how and why your data is used. You can reach us about anything in this notice at tyrese@yeema.co.
We are not affiliated with Cfx.re, FiveM, Rockstar Games, or Take-Two Interactive. Trademarks and game content remain the property of their respective owners.
The short version
We try not to collect more than we need to run the service. Concretely:
- Sign-in uses a third-party identity service connected to your community account. We never receive that account's password.
- Files you upload are kept in encrypted object storage, processed by our worker, and deleted automatically.
- Payments are handled by a regulated payment processor. We never see your full card number.
- AI tools send the prompt or source image you provide to the selected third-party AI provider to generate an image or 3D model. Administrators can also request AI-assisted announcement drafts.
- With your permission, we use usage analytics and sampled, masked session replay to improve the service.
- You can ask us to delete everything we hold about you at any time.
What data we collect
We collect a small set of categories:
We do not ask for, and do not knowingly collect, special category data (health, political views, ethnicity, etc.) or government IDs.
Why and how we use it
Under the UK GDPR and EU GDPR, we must have a lawful basis for every use of your personal data. Here's what we do and why:
We do not sell your personal data. We do not run advertising on Rivo Tools, and we do not share your data with advertising networks.
Two things happen automatically on our side: free-tool access pauses while your connected account is not a member of our community server (and restores itself when you rejoin), and clear patterns of free-tier abuse (such as repeated leave/rejoin cycling) can automatically suspend an account. Both are reversible, and you can always ask a human to review an automated action by contacting us. Beyond that, we do not make automated decisions that produce legal or similarly significant effects about you (no automated profiling for hiring, credit, eligibility, etc.).
Optional Discord messages and your choices
With your explicit consent, we send personal broadcast DMs through the Rivo bot for the categories you choose: service and account notices, and factual release notes about app functionality. Each category starts off and remains off unless you select it. Linking Discord, joining our server, accepting our Terms, or purchasing a plan does not enable broadcast DMs. We do not use these broadcasts for advertising or promotions.
For this feature we store your account identifier, authentication identifier, linked Discord ID, selected categories, the wording and version of the consent request, when you changed your choices, and whether you used the connection screen or Settings. We keep per-recipient delivery records containing the account and Discord IDs, display name, DM channel ID where available, delivery status, time, and error or skip reason. Administrators can view delivery outcomes to operate and troubleshoot broadcasts.
Our basis for sending optional broadcast DMs is consent (Article 6(1)(a)). We retain preference and consent records to demonstrate and respect your choices, and limited delivery records to diagnose failures and prevent abuse, based on our legitimate interests in operating the service responsibly (Article 6(1)(f)). Consent and preference records are kept while your account exists and are removed during account deletion. Per-recipient delivery records are scheduled for deletion after 30 days by a daily cleanup job; aggregate broadcast totals can remain.
You can withdraw consent for either category at any time in Settings or follow the preferences link in a broadcast DM. This does not affect your plan, tool access, or the lawfulness of earlier processing. Queued and scheduled messages are checked against your current preference before delivery; an in-flight message may still arrive. We disable both categories if Discord rejects DMs as closed or blocked. A new Discord account requires a new opt-in.
When delivering a DM we send Discord your recipient ID and the message and attachments, which may include your display name or plan label. Discord processes messages under its own Privacy Policy. Deleting our records or turning DMs off does not delete messages already held by Discord. Contact tyrese@yeema.co to report unwanted messages or exercise your data rights.
How long we keep it
The shortest period we can get away with. Where retention is open-ended, you can ask us to delete it earlier (see Your rights).
Service providers
We use a small number of carefully chosen processors to run the service. We describe them by function rather than brand. Each processes data only for the stated purpose and under appropriate contractual terms.
Sign-in, connected-account authentication, and session management.
UK, EEA, and other safeguarded processing regions
Accounts, jobs, subscriptions, realtime application data, and service operation.
UK, EEA, and other safeguarded processing regions
Uploaded files, generated outputs, short-lived download links, and edge delivery.
Global infrastructure with contractual transfer safeguards
Image and 3D generation, plus administrator-requested announcement drafting through OpenRouter and its configured model provider. Only the inputs needed for the requested generation are sent for processing.
International processing with contractual transfer safeguards
Card payments, subscriptions, receipts, refunds, and fraud prevention. Full card details do not reach our servers.
International processing with regulated and contractual safeguards
Aggregate usage analytics, product improvement, error reporting, and performance monitoring. We do not use these services for advertising.
Primarily UK/EEA, with safeguards where international processing occurs
If the categories or purposes of our processors change, we will update this section. Material changes will be announced in our changelog and, where required, by email.
International transfers
Some of our processors are based outside the UK and the EEA, most commonly in the United States. Where personal data is transferred outside the UK or the EEA, we rely on one or more of the following:
- The European Commission's Standard Contractual Clauses (SCCs).
- The UK International Data Transfer Addendum (IDTA) to the SCCs.
- The EU-US Data Privacy Framework where the receiving organisation is certified, and the UK Extension where applicable.
You can ask us for a copy of the safeguards in place for any specific transfer by emailing tyrese@yeema.co.
Your rights
Under the UK GDPR and EU GDPR, you have the following rights over personal data we hold about you:
- Access. Ask for a copy of the personal data we hold about you.
- Rectification. Ask us to correct data that is inaccurate or incomplete.
- Erasure. Ask us to delete your personal data. We will, unless we are required to keep it (for example, for tax records).
- Restriction. Ask us to limit how we use your data while a dispute is resolved.
- Portability. Ask for a machine-readable export of data you have provided to us.
- Objection. Object to processing we do on the basis of legitimate interests.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Complain. Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or with your local EU supervisory authority. We would appreciate the chance to address your concern first, but it is your right to skip that step.
To exercise any of these rights, email tyrese@yeema.co from the address linked to your account. We will respond within 30 days. We may need to verify your identity before disclosing personal data.
Security
We take security seriously and apply commercially reasonable measures to protect your data:
- TLS for all traffic to and from the site and the worker pool.
- Encryption at rest for uploaded files and database storage.
- Least-privilege access controls for staff and worker tokens.
- Short-lived presigned URLs for downloads.
- Automatic deletion of inputs and outputs on the schedule above.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where required, you.
Children
Rivo Tools is intended for people aged 13 or over, in line with the minimum age for our connected account service. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided data to us, email tyrese@yeema.co and we will delete it.
In some EU jurisdictions, the age of consent for processing under the GDPR is higher than 13. If you live somewhere with a higher age of consent and you are under that age, please have a parent or guardian get in touch.
Changes to this notice
We may update this notice from time to time as the service evolves or the law changes. The date at the top reflects the most recent version. Material changes will be highlighted in our changelog and, where appropriate, notified by email.
Contact and complaints
Privacy questions, data subject requests, or complaints: tyrese@yeema.co.
Post: Yeema Holdings LTD, 128 City Road, London, EC1V 2NX, United Kingdom.
You can also complain to the UK Information Commissioner's Office at ico.org.uk or, if you are based in the EU, to your local supervisory authority.