DistroRigRIG 01
Legal · Rig 01

Privacy
Policy

What we collect, why we collect it, who else sees it, and how to get it back or have it deleted. No dark patterns, no data sales.

Last updated · 14 September 2026
Controller · Rivvs LLC

01The short version

We collect your email, your app’s public store details, the video the rig makes, the tokens you grant us for your social and store accounts, and how you use the product. We use it to run the service you are paying for.

We do not sell your data. We do not share it for advertising. We do not train models on your footage. You can export or delete everything at any time.

This policy covers distrorig.com and the DistroRig application. The data controller is Rivvs LLC, New York, United States. Contact: support@distrorig.com.

02What we collect

You give us

Account
Email address. That is the whole sign-up: we use magic links, so there is no password to store.
Billing
Name, billing address and card details go directly to Stripe. We receive a customer ID, subscription status, the last four digits and the card brand. We never see or store a full card number.
Your apps
Store URLs, bundle identifiers, app name, icon and screenshots, plus anything you upload: builds, footage, logos, fonts.
Content
Hooks, captions, hashtags, schedules and approvals you create in the rig.
Support
Whatever you send us by email, including attachments and any diagnostic information you choose to include.

We generate

  • Recorded footage of your app running on a simulator we drive, and the composed video made from it.
  • Job records: what the rig captured, composed, scheduled and published, and when.
  • Performance data: views, watch time, saves and shares pulled back from platforms, and install counts pulled from Apple and Google, joined to the post that preceded them.

Collected automatically

  • Product analytics through PostHog: pages viewed, features used, buttons clicked, errors hit, approximate location derived from IP, browser and device type.
  • Server logs: IP address, timestamp, request path, user agent, response status. Kept for security and debugging.

We do not collect special category data, we do not ask for your government ID, and we do not run trackers on the marketing site beyond what is described in section 06.

03Why we collect it

Under UK and EU data protection law, our lawful bases are:

Contract
Running your account, capturing and composing video, publishing posts, reporting installs, taking payment. Without this data there is no service to deliver.
Legitimate interests
Keeping the service secure, preventing abuse, debugging, understanding which features get used, and improving the product. We balance this against your interests and keep the data minimal.
Consent
Marketing email and any non-essential analytics cookies. Withdraw it at any time; the unsubscribe link is in every marketing email.
Legal obligation
Tax records, accounting, and responding to lawful requests.

Transactional email — magic links, receipts, publish failures, security notices — is sent on the contract basis and cannot be unsubscribed from while your account is open.

04Connected platform data

When you connect TikTok, Instagram, Facebook, YouTube, App Store Connect or Google Play Console, you authorise us through that platform’s own flow. We receive an access token and the scopes you approved.

  • Tokens are encrypted at rest and used only to perform the actions you asked for: publishing a post you approved, and reading back metrics.
  • We request the narrowest scopes that let the rig work. We do not read your direct messages, your contacts, or content unrelated to the posts we published.
  • Install and revenue data from Apple and Google is read at aggregate level. We do not receive the identity of individual people who installed your app, and we have no interest in it.
  • Disconnecting an account from your dashboard revokes the token on our side and deletes it. Revoke on the platform’s side too if you want belt and braces.

Each platform has its own privacy policy governing what it does with the posts we publish for you. Those are worth reading; they are not ours to speak for.

05Who else touches it

We use a small number of sub-processors. Each is bound by a data processing agreement and may only act on our instructions.

Vercel
Website and application hosting, edge network, logs. United States.
Supabase
Database, authentication and file storage for your footage and video. United States.
Fly.io
Container workers that capture and compose video. United States.
Stripe
Payments and subscription management. Stripe is an independent controller for payment data.
PostHog
Product analytics and error tracking.
Resend
Transactional and marketing email delivery.

We will also disclose data where we are legally required to, or to protect our rights, safety or property. If DistroRig is ever sold or merged, your data moves with it and you will be told before anything changes.

We have never sold personal data, and we will not. We do not share it with advertisers, data brokers, or anyone building a marketing profile of you.

06Cookies and analytics

  • Essential cookies keep you signed in and protect forms from abuse. These cannot be turned off without breaking the product.
  • Analytics cookies from PostHog tell us which features get used. Non-essential, consent-based in regions that require it, and refusing them changes nothing about what the product does for you.

We do not run advertising cookies or third-party ad pixels on the application. Campaign traffic arriving from paid ads is measured with URL parameters, not by a tracker following you around.

We honour Global Privacy Control and browser Do Not Track signals as an opt-out of non-essential analytics.

07How long we keep it

Account data
While your account is open, then 30 days after closure, then deleted.
Raw footage
90 days after capture, unless you pin a clip to keep it.
Published video
While your account is open, so your post history stays intact.
Platform tokens
Until you disconnect or close your account, then deleted immediately.
Analytics
12 months, then aggregated and stripped of identifiers.
Server logs
30 days.
Invoices
7 years, because tax law requires it.

Encrypted backups roll off on a 35-day cycle, so deleted data can persist there briefly.

08How we protect it

  • Everything travels over TLS, and is encrypted at rest by our infrastructure providers.
  • Platform tokens and store credentials get an additional layer of application-level encryption.
  • Row-level security in the database means one account’s queries cannot reach another account’s rows.
  • Magic-link sign-in means there is no password of yours for us to leak.
  • Access to production is limited, logged, and protected by multi-factor authentication.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator without undue delay, and within 72 hours where that applies.

09Your rights

Wherever you are, you can ask us to:

  • Access a copy of the personal data we hold about you.
  • Export it in a portable, machine-readable format.
  • Correct anything inaccurate.
  • Delete your account and its data.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent for marketing or analytics at any time.

Most of this you can do yourself from the dashboard. For anything else, email support@distrorig.com and we will respond within 30 days. We do not charge for this, and we will not make your product worse for exercising a right.

If you are in the EU or UK

You may lodge a complaint with your local supervisory authority, or the UK Information Commissioner’s Office. We would rather you came to us first.

If you are in California

You have rights under the CCPA and CPRA to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the rights above are yours and are exercised the same way.

10International transfers

We operate from the United States and our sub-processors are primarily United States based. If you are in the EEA, UK or Switzerland, your data is transferred there under the European Commission’s Standard Contractual Clauses, plus the UK addendum where it applies, together with the technical measures in section 08. A copy of the relevant clauses is available on request.

11Children

DistroRig is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, email us and we will delete it.

12Changes and contact

We update this policy as the product changes. For material changes we email every account holder at least 14 days ahead and update the date at the top. Past versions are available on request.

Rivvs LLC
New York, United States
support@distrorig.com

For how these promises sit alongside the rest of the agreement, see the terms of service.