Ravivo

The Spanish version prevails / La versión en español prevalece: Español

Privacy Policy

Last updated: 2026-10-04

This Privacy Policy explains what personal data Ravivo collects, why, on what legal basis, who receives it, how long we keep it, and what rights you have. It applies to the public website https://ravivo.app (the "Website") and to the Ravivo application at https://app.ravivo.app, including its MCP endpoint (https://app.ravivo.app/mcp) (the "App"), which we operate both; together they are the "Service". It has special sections on TikTok (section 3), data deletion (section 9) and cookies (section 10). It follows Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). This Policy is published in Spanish and English. The Spanish version is binding and prevails if there is any difference. The English version, and any other translation we publish, is provided for convenience and is not binding.

1. Who is responsible for your data

The data controller is Volodymyr Tanygin, an individual acting as a self employed professional (autónomo), who operates the Ravivo service under the name "Ravivo" ("Ravivo", "we", "us").

Address: calle De la Rosa 100, P01C, Estepona, Málaga, Spain. Contact for privacy questions and to exercise your rights: privacy@ravivo.app, or the contact form at https://ravivo.app/en/contact. Full identification details required by Spanish law are in the Legal Notice: https://ravivo.app/en/legal-notice.

We have not appointed a data protection officer, because this is not required for our activity under Article 37 GDPR and Article 34 LOPDGDD. You can contact us at the address above for any data protection question.

Ravivo is a platform for managing content and communication. Users plan, approve, schedule and publish content to the social media accounts they connect, and can use an AI assistant. The Service is in private beta and registration requires an invitation code. It is offered to businesses and to individuals.

2. Data we collect

Account data. Name or brand name you enter, email address, password (stored only as a cryptographic hash), invitation code, workspace name, language and settings.

Connected account data. When you connect a social account, we receive from the platform the identifiers and profile details allowed by the permissions you approve. We store a connection reference (connection ID, platform, display name, status). Access and refresh tokens for the connection are held by the integration provider that runs the connection (see section 5), not by your browser.

Content data. Text, images and videos you upload or create in the Service, captions and titles, post settings (for example privacy level and schedule), and the result of each publish attempt (post ID, status, error messages).

Usage and device data. Server logs with IP address, timestamps, pages or API calls, browser and device type, used for security, abuse prevention and troubleshooting.

Payment data. The beta is free and there are no active paid plans at present. If paid features are offered in the future, payments will be handled by Stripe: card details are entered directly into Stripe and we do not store them. We receive from Stripe the payment status and basic billing data (customer ID, plan, amount, date).

Communications. Messages you send to us by email or through the contact form (name, email address, message), for example support requests, and notices about illegal content. The contact form is protected by Cloudflare Turnstile.

Acceptance record. Date and time, version of the Terms and Policy you accept, your account ID, as proof of your acceptance. At sign-up your IP address and user agent are not stored; if you later accept an updated version of the documents again, your full IP address and user agent are stored as well.

Voice. If you use dictation or voice chat, the audio is sent to a speech recognition provider (section 5) to be converted into text. Ravivo does not keep the audio: it is processed temporarily and only the resulting text is returned; whether the provider keeps it depends on the provider's terms.

External AI clients. If you connect an AI client through MCP (section 13), we store the connection (client, permissions you grant, dates) and, for security, we keep a log of the requests the App receives, including those to the MCP endpoint (with the IP address they come from), and an audit log of the write actions performed through it.

Cookies and local storage. Only those that are strictly necessary or exempt from consent, see section 10.

We do not collect special categories of personal data on purpose. Do not upload them unless you have a lawful reason to do so. If Your Content contains personal data of other people, you are responsible for having a lawful basis and for informing those people. For that data we act as your processor, and you act as the controller.

We collect the data directly from you, from the platforms you connect, and from your browser or device.

3. TikTok data

If you choose to connect a TikTok account, the connection is made through our integration provider Zernio (section 5): Ravivo redirects you to TikTok to authorize access, TikTok returns the authorization to Zernio, which handles it and stores the tokens on our behalf, and you return to the App. The TikTok authorization screen shows the name of the TikTok app used for this connection. We use only the following TikTok permissions (scopes), and only for these purposes:

ScopeData or actionPurpose
user.info.basicTikTok open ID, display name, avatarShow which TikTok account is connected and which account will receive a post
video.publishPublish a video you prepared to your TikTok profile. Before posting we also read your posting options from TikTok (nickname, available privacy levels, comment, duet and stitch settings, maximum video length) and the status of the postDirect Post after you review the post and press publish
video.uploadSend a video to your TikTok inbox as a draftLet you finish and publish the post inside TikTok

What we do not do:

For the TikTok profile data we receive through the TikTok API, we are an independent controller, and TikTok is an independent controller for its own processing under the TikTok Privacy Policy. If TikTok requires us to delete TikTok data, for example when our access to the TikTok API ends, we delete it.

You can withdraw TikTok access at any time, in Ravivo by disconnecting the account (Settings, Integrations), or in TikTok under Settings and privacy, Security and permissions, Apps and services. When you disconnect, we stop using that connection in Ravivo and ask our integration provider to delete the connection and the tokens; the related data is deleted under sections 7 and 9.

4. Why we use data and on what legal basis

PurposeDataLegal basis under GDPR
Provide the Service: accounts, media library, scheduling, publishing to connected accounts at your requestAccount, connected account, content dataPerformance of a contract, Article 6(1)(b)
Security, fraud and abuse prevention, troubleshootingUsage and device dataLegitimate interests, Article 6(1)(f)
Bot protection at sign-up, login and on the contact form (Cloudflare Turnstile)IP address, TLS fingerprint, user agentLegitimate interests in security, Article 6(1)(f)
Charging for paid plans (when they exist)Payment and billing dataPerformance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c)
Connection of an external AI client (MCP) that you authorizeData you allow to be read or requested with the access you grantPerformance of a contract, Article 6(1)(b)
Service messages, support, notices about changesAccount data, communicationsPerformance of a contract and legitimate interests
Handling notices about illegal content and complaintsCommunications, content data concernedLegal obligation, Article 6(1)(c), and legitimate interests
Keeping proof that you accepted the Terms and the PolicyAcceptance recordPerformance of a contract, Article 6(1)(b), and legitimate interests in proving the contract and defending legal claims, Article 6(1)(f)
Tax, accounting and other legal obligations, and defence of legal claimsData needed for the specific obligationLegal obligation, Article 6(1)(c), and legitimate interests
AI features you use, to produce suggestions from the content and brand information you provideContent data you submit to the featurePerformance of a contract

We do not send marketing emails without your prior consent, and we do not sell personal data. We do not take decisions based solely on automated processing that produce legal effects on you. AI output is a suggestion that you review.

5. Who receives data

We share data only with providers that process it on our behalf, with the platforms where you ask us to publish, with the external AI clients you connect, and where the law requires it. Processing by our providers is governed by data processing contracts that meet Article 28 GDPR and, where data leaves the European Economic Area, by the safeguards described in section 6. Our current categories and providers are:

RecipientPurpose and dataWhereTransfer safeguard
Hetzner Online GmbHOur own server where the database and the App logic run: all account, content and connection dataEuropean Union (Germany)Article 28 GDPR processor contract; processing takes place in the European Union
Vercel Inc.Hosting and delivery of the App's web interface; requests between your browser and the API pass through its network (content and account data in transit) and its access logsUnited States and global networkArticle 28 GDPR processor contract; EU-U.S. Data Privacy Framework or standard contractual clauses for the transfer
Cloudflare, Inc.DNS and a secure tunnel to our server; storage of uploaded media files (R2); bot protection (Turnstile); forwarding of mail to privacy@ravivo.app. Data: files, IP address, trafficUnited States and global network; media files (R2) in the EU jurisdictionData Privacy Framework and standard contractual clauses in its data processing addendum
StripePayments, only if paid features are offered. Data: email, billing data, card data (which you enter directly into Stripe)Ireland and United States, depending on the Stripe entity providing the serviceArticle 28 GDPR processor contract; Data Privacy Framework or standard contractual clauses for the transfer
Zernio Software S.L.Publishing, statistics and the message inbox for social networks such as TikTok. It stores the tokens of those connections. Data: identifiers and profile of the connected account, content you publish, platform messagesAccording to the information provided by the providerArticle 28 GDPR processor contract; standard contractual clauses if data is transferred outside the EEA
Composio (Sampark, Inc.)Connection of Facebook Pages (stores the tokens of those connections and technical logs of calls). Not used for TikTokUnited StatesArticle 28 GDPR processor contract and standard contractual clauses
External AI model providers, if the corresponding feature is enabled (through a model gateway, LiteLLM, which runs on our server)Process the content and brand information you send to an AI feature and return a result. Providers such as OpenAI, Anthropic or Google may be involved, depending on the models enabled. If an own key from an AI provider has been configured for your account, the request is made with that keyUnited States and others depending on the providerArticle 28 GDPR processor contract; standard contractual clauses in their data processing terms. We access the models through their API; according to OpenAI, data sent to its API is not used to train models by default
Speech recognition providerConverts the audio of dictation or voice chat into textIn the European Union or, if outside the EEA, with the safeguards of Chapter V GDPRArticle 28 GDPR processor contract; standard contractual clauses or the Data Privacy Framework if data is transferred outside the EEA
Tavily (AlphaAI Technologies Inc.)Web search by the AI agent, if that feature is enabled: it receives the text of the search query. It must not include personal dataUnited StatesArticle 28 GDPR processor contract; standard contractual clauses
Email sending providerSending service emails, such as sign-up confirmation and password reset. Data: email address and message contentIn the European Union or, if outside the EEA, with the safeguards of Chapter V GDPRArticle 28 GDPR processor contract; standard contractual clauses or the Data Privacy Framework if data is transferred outside the EEA
Google (mail service)The mailbox that receives messages sent to privacy@ravivo.app and sends our replies from that addressUnited States and EUData Privacy Framework and standard contractual clauses in Google's terms
External AI clients you connect (for example ChatGPT or Claude)Receive the data you allow them to read through MCP (section 13), at your initiativeDepends on the client's providerSet by the AI client's provider under its own terms; we are not its processor
TikTok and other platforms you connectReceive the content and settings you choose to publish and the authorization you grantLocation of the platformThe platform acts as an independent controller under its own policy
Authorities and advisersWhere the law requires it or to protect rightsSpainNot applicable

If the Service is reorganized or transferred, data may pass to the successor with the same safeguards.

6. International transfers

Some providers are established in the United States or process data outside the European Economic Area. When data leaves the EEA we rely on the adequacy decision of the EU-U.S. Data Privacy Framework for certified providers, or on the standard contractual clauses approved by the European Commission, together with additional safeguards where appropriate. External AI clients you connect (section 13) process data under the safeguards set by their own provider. You can ask for a copy of the safeguards at privacy@ravivo.app.

7. How long we keep data

8. Your rights

Under the GDPR and the LOPDGDD you can ask us to:

To use these rights write to privacy@ravivo.app from the email address of your account, or use the contact form at https://ravivo.app/en/contact. We may ask you to verify your identity. We answer within one month, which can be extended by two further months for complex requests, and we will tell you if that happens. Exercising your rights is free, except for manifestly unfounded or excessive requests.

You can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or to the supervisory authority of your habitual residence or place of work.

9. Data deletion

You can delete your data from Ravivo at any time.

Disconnect a connected account (TikTok or another platform). Sign in to the App (https://app.ravivo.app), open Settings, Integrations tab, and choose Disconnect next to the account. The procedure is the same for all platforms. Ravivo deactivates the connection, stops all publishing to that account and asks its integration provider to delete the connection and the tokens; if the provider is unavailable at that moment, the connection stays deactivated in Ravivo anyway and the deletion at the provider may be delayed. The stored TikTok profile data (open ID, display name, avatar) is deleted within 30 days.

Remove access in TikTok. Open TikTok, go to Settings and privacy, Security and permissions, Apps and services, and remove the app. After that Ravivo can no longer act on your TikTok account.

Delete your Ravivo account and all data. For now the account cannot be deleted from inside the App; you request it by email. Write to privacy@ravivo.app from your account email with the subject "Delete my data". Say whether you want to delete the whole account or only the data related to TikTok. We may ask you to confirm your identity.

We reply within one month. We delete or anonymize your personal data and revoke all connections within 30 days from when we confirm your request, except data we must keep by law or to defend legal claims (for example the acceptance record), which we keep blocked and only for the legal period. Backups are removed on the regular cycle (section 7).

What is deleted: account data (name, email, settings, invitation record); connection references and stored tokens; uploaded content, descriptions, schedules and post results; TikTok profile data; connections of external AI clients. Technical logs at our providers are deleted when the periods in section 7 end.

Posts you already published on TikTok stay on TikTok. You delete them in TikTok. Deleting data in Ravivo does not delete them.

10. Cookies

The Service uses only cookies and local storage that are necessary to provide the service you request: signing in and keeping you signed in, protecting access, and remembering the language you choose. Under Article 22(2) of Law 34/2002 (LSSI-CE) and the Spanish Data Protection Agency's Guide on the use of cookies, these uses are exempt from consent. We list them for transparency. We do not use advertising, tracking or analytics cookies, nor third-party analytics, error-tracking or font tools. The language is stored only when you choose it in the language selector or already have it saved in your account.

NameWhere set (host)PurposeDuration
__Secure-next-auth.session-tokenapp.ravivo.app (that host only)Keeps you signed inUp to 24 hours
__Host-next-auth.csrf-tokenapp.ravivo.app (that host only)Protects sign-in forms against forged requestsBrowser session
__Secure-next-auth.callback-urlapp.ravivo.app (that host only)Remembers which page to return to after sign-inBrowser session
ravivo_localeapp.ravivo.app (that host only)Remembers the language you chose1 year
ravivo_td_tenant (browser local storage)app.ravivo.app (that host only)"Trusted browser": only if you expressly choose to remember this browser (checkbox when entering the second verification factor), it avoids asking for that second factor again30 days
nextauth.message (browser local storage)app.ravivo.app (that host only)Technical storage of the sign-in component to keep the session in sync between browser tabs. Not sent to any third partyUntil you delete it
Other interface data in the browser (local or session storage: language, notices you closed)app.ravivo.app (that host only)Remember the state of the interface. Not sent to any third partyUntil you delete it or the session ends

All these cookies are first-party and strictly necessary. The sign-in and forged request protection cookies are set by the App, on its own host (app.ravivo.app). The public Website (https://ravivo.app) does not use analytics, advertising or tracking cookies and, apart from the strictly necessary ones described in this section, sets no other cookies of its own.

Cloudflare Turnstile. On the sign-up and login pages, the App loads a Cloudflare script (challenges.cloudflare.com) that checks that the request comes from a person and not a robot. Cloudflare receives your IP address, the TLS fingerprint, the user agent and the site key with its origin. It is the only third-party script the App loads. It is a security measure against abuse that we consider necessary to provide the service, so we do not ask for consent. According to the Turnstile privacy addendum, Cloudflare acts as our processor to protect the site and as an independent controller to improve its bot detection. Turnstile does not create cookies on the App host (app.ravivo.app); any technical storage Cloudflare uses for this check serves only this security purpose.

If we add cookies that are not strictly necessary, for example analytics, we will first ask for your consent with an Accept button and a Reject button of equal visibility, let you change your decision at any time and update this section. You can block or delete cookies in your browser settings. If you block the necessary cookies, signing in will not work.

11. Security

We protect data with encryption in transit (TLS), encryption of stored credentials and tokens, hashed passwords, role based access control, and limited access to systems. No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and, where required, you.

12. Children

The Service is for adults. You must be at least 18 years old to use it. We do not knowingly collect data from minors. In Spain, a person under 14 cannot give consent to data processing without the consent of a parent or guardian, and we do not accept registrations from them. If you believe a minor has given us data, contact us and we will delete it.

13. AI features and external AI clients

Ravivo AI agent. The Service includes an AI agent ("AI Agent") and other AI features. The agent identifies itself as an AI system in every chat interface of the App, so you know you are not talking to a person (Article 50 of Regulation (EU) 2024/1689). In addition, each chat offers a button to contact a person through support. We send to AI model providers only the content and brand information you send to the feature and the context needed to answer. If an own key from an AI provider has been configured for your account, requests are made with that key under your contract with that provider. For TikTok data, see section 3. AI output is a suggestion that you review before use.

External AI clients (MCP). You can connect to your account, at your own initiative, a third-party AI client that you choose (for example ChatGPT, Claude or another MCP-compatible client) through the App's MCP endpoint (https://app.ravivo.app/mcp). Ravivo acts as the OAuth authorization server: before granting access you see a consent screen where you choose the permissions (reading your data, sending tasks to the Ravivo AI agent, reports) and whether the access covers all accounts of your workspace or only one. With that access the client can read data of your workspace (for example connected accounts and your role, content and texts, posts (including TikTok posts) with platform, link, date and status, reports and actions awaiting confirmation) and ask the Ravivo AI agent to perform actions, such as uploading files or preparing content and posts. Actions that change something or publish are submitted to you for confirmation inside Ravivo, unless you have turned on the agent's fully autonomous mode. The data the client reads leaves Ravivo at your initiative and falls under the terms and privacy policy of that client's provider (for example OpenAI or Anthropic, usually in the United States). You are responsible for choosing the client and for complying with its terms; Ravivo is not responsible for how the client processes that data. We store the connection and, for security, we keep a log of the requests the App receives (including those to the MCP endpoint) and an audit log of write actions. You can revoke access at any time in the App, under Settings, External agents; after you revoke it, the client cannot renew access. You can also remove it from the client itself. When you use an external client, the conversation with the AI takes place in that client's interface, and it is the client that informs you that you are interacting with an AI system.

14. Changes

We may update this Policy. For material changes we will notify you by email or in the Service before they take effect. The date at the top shows the latest version.

15. Contact

Volodymyr Tanygin, Ravivo Address: calle De la Rosa 100, P01C, Estepona, Málaga, Spain Email: privacy@ravivo.app Contact form: https://ravivo.app/en/contact Legal Notice: https://ravivo.app/en/legal-notice