Privacy and cookies
How Risetive handles account information, public research, website diagnosis and website usage, including your data rights and privacy requests.
Who is responsible
Olena Holub, operating Risetive from Ireland, is the data controller for the personal data processed to run this service. The Risetive team handles requests on her behalf; authorised technical staff carry out the necessary account and data operations.
For privacy requests, contact support@trovestep.com, +353 830091396, or 2 Hume Street, Dublin 2, Ireland. You do not need to find or contact an individual developer.
Research access and current availability
Public research pages and the independent website diagnosis tool remain available. Website diagnosis processes the address you submit and public website material; research and diagnosis may use AI service providers.
Agent chat is currently available at no charge to signed-in accounts. The MCP guide is public, but MCP client access and dependent plugin integrations are not currently available. Neither is included in the planned Pro offer.
Information we process
Account and session information: Clerk handles sign-in identifiers, email addresses and other profile information you provide through sign-in, together with authentication and session data. Our application uses your sign-in state and user identifier to control account access.
Website and security information: requests expose technical information such as an IP address, requested URL, browser details and errors to the infrastructure serving them. We use Cloudflare Web Analytics for aggregate cookie-free page usage and performance measurements.
Optional Google Analytics information: after you accept analytics, Google receives a restricted public page location and title, device and regional information, a limited source or campaign attribution, and a randomly generated analytics identifier. We remove unapproved query values and fragments, do not send external referrer paths, and do not send account identifiers, email addresses, search or chat text, credentials, or private project content.
Support information: if you email us, we receive your email address, message and any information you choose to include. Share only what is needed for the request. We do not currently collect card details or operate checkout.
Public research data: our product corpus contains publicly available information about products, websites, markets and their growth evidence. It is separate from user account data. Public material may sometimes identify an individual operating a product; those individuals can also contact us about their personal data.
Why we use it
We process account information and the inputs you submit to provide the software service you request and manage your account. The legal basis is performance of that service agreement, or steps you ask us to take before entering it.
We rely on legitimate interests to protect the service from abuse, diagnose faults, understand cookie-free aggregate performance and maintain useful public product research, while considering the rights and reasonable expectations of affected people. You may object to processing based on legitimate interests.
Google Analytics is optional and is used only with your consent to understand visits to public pages, broad acquisition sources, regions and devices. Refusing does not affect product access. You can reopen Cookie settings and withdraw consent at any time.
We do not currently connect to users' Google Search Console or Google Analytics accounts. The project's own search-performance reporting is not a user-authorised integration. Your account data is not added to the public product corpus.
Service providers and recipients
Clerk provides identity and session services. Render hosts the web service and PostgreSQL database in Frankfurt.
Cloudflare supplies DNS and Web Analytics. If you consent, Google supplies Google Analytics for public page and acquisition measurement. Google Fonts serves the interface font, so your browser contacts Google to request the font resources. Google also handles support correspondence sent to our Gmail address. Necessary technical request information is processed when using these services.
Authorised people supporting Risetive may access information needed to respond to a request or maintain the service. Information may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.
AI service providers process public website material for research, website diagnosis and signed-in Agent requests. MCP client access is not currently available; this does not stop processing in the remaining tools and data pipelines.
Cookies and browser storage
Clerk uses authentication and session storage when sign-in is activated. These mechanisms are needed to keep an account signed in and protect access. The Clerk interface is loaded for signed-in users or when you explicitly open sign-in or sign-up. Authentication infrastructure may also set security cookies when its resources are requested, before you sign in.
Cloudflare describes Web Analytics as cookie-free and says it does not use browser storage or fingerprinting to identify visitors. A cookie-free analytics service does not mean all infrastructure requests are free of technical information.
Google Analytics remains unloaded until you accept it. After acceptance, Google Analytics may set first-party `_ga` cookies used to distinguish visits. Risetive stores your accepted or rejected analytics choice in browser storage. Rejecting creates no Google Analytics cookie or request.
You can reopen Cookie settings to change your choice. Withdrawal stops later Google Analytics events and removes the Google Analytics cookies Risetive can address. Browser or provider records already received are governed by their retention and deletion arrangements.
Retention and international processing
Account information is used while your account remains active and is reviewed for deletion when you close it or exercise your rights. Support correspondence is kept only as needed to resolve the request and meet any applicable legal obligations or claims. Retention depends on the type of record, its purpose and the obligations that apply.
Infrastructure logs, provider records and backup copies have separate retention arrangements and may not disappear when a page session ends.
Although our application database is hosted in Frankfurt, providers including Google and authorised support may process information in other countries, including outside the EEA. Such transfers are subject to applicable GDPR requirements. The applicable mechanism depends on the recipient and destination, such as an adequacy decision or appropriate safeguards including standard contractual clauses.
You may request the relevant recipient, destination, retention information and applicable transfer safeguards through support@trovestep.com. We will explain the arrangements relevant to your data. A Frankfurt database does not mean all processing stays in the EEA.
Your rights and our response times
Subject to the GDPR conditions that apply, you may request access, correction, erasure, restriction and portability of your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on it. Erasure is not an unconditional right to remove every record, for example where retention is legally required or needed for legal claims.
Send your request to support@trovestep.com. We will reply within 3 working days and delete personal data eligible for erasure within 7 working days of receiving your request. Working days are Monday to Friday, excluding Irish public holidays. These are our service commitments, not a statement of the GDPR's standard response period.
We may need proportionate information to confirm your identity before releasing or deleting account data. We will ask promptly, explain what is needed and keep you informed. If a record must be retained, or provider or backup handling affects completion, we will explain the reason, scope and next steps rather than claim deletion is complete.
Under the GDPR, requests must be handled without undue delay and normally within one month. Where the law permits an extension for complexity or the number of requests, we must explain it within the first month; the extension can be up to two further months. These statutory rules are not a routine replacement for our faster service commitments.
Privacy requests are handled by people, not an automated deletion portal. We do not normally charge for a rights request. If we cannot act on a request, we will explain why and your complaint and judicial remedy options.
You can complain to the Irish Data Protection Commission or another competent supervisory authority. Visit dataprotection.ie for the Irish authority's current contact and complaint information.
Changes to this notice
We will update this notice when the service or its data processing changes and show the revision date. Material changes will be communicated as required.
Contact the Risetive team
Supervisory authority: Irish Data Protection Commission.