The Spanish version prevails / La versión en español prevalece: Español
Privacy Policy
Last updated: 2026-10-04
This Privacy Policy explains what personal data Ravivo collects, why, on what legal basis, who receives it, how long we keep it, and what rights you have. It applies to the public website https://ravivo.app (the "Website") and to the Ravivo application at https://app.ravivo.app, including its MCP endpoint (https://app.ravivo.app/mcp) (the "App"), which we operate both; together they are the "Service". It has special sections on TikTok (section 3), data deletion (section 9) and cookies (section 10). It follows Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). This Policy is published in Spanish and English. The Spanish version is binding and prevails if there is any difference. The English version, and any other translation we publish, is provided for convenience and is not binding.
1. Who is responsible for your data
The data controller is Volodymyr Tanygin, an individual acting as a self employed professional (autónomo), who operates the Ravivo service under the name "Ravivo" ("Ravivo", "we", "us").
Address: calle De la Rosa 100, P01C, Estepona, Málaga, Spain. Contact for privacy questions and to exercise your rights: privacy@ravivo.app, or the contact form at https://ravivo.app/en/contact. Full identification details required by Spanish law are in the Legal Notice: https://ravivo.app/en/legal-notice.
We have not appointed a data protection officer, because this is not required for our activity under Article 37 GDPR and Article 34 LOPDGDD. You can contact us at the address above for any data protection question.
Ravivo is a platform for managing content and communication. Users plan, approve, schedule and publish content to the social media accounts they connect, and can use an AI assistant. The Service is in private beta and registration requires an invitation code. It is offered to businesses and to individuals.
2. Data we collect
Account data. Name or brand name you enter, email address, password (stored only as a cryptographic hash), invitation code, workspace name, language and settings.
Connected account data. When you connect a social account, we receive from the platform the identifiers and profile details allowed by the permissions you approve. We store a connection reference (connection ID, platform, display name, status). Access and refresh tokens for the connection are held by the integration provider that runs the connection (see section 5), not by your browser.
Content data. Text, images and videos you upload or create in the Service, captions and titles, post settings (for example privacy level and schedule), and the result of each publish attempt (post ID, status, error messages).
Usage and device data. Server logs with IP address, timestamps, pages or API calls, browser and device type, used for security, abuse prevention and troubleshooting.
Payment data. The beta is free and there are no active paid plans at present. If paid features are offered in the future, payments will be handled by Stripe: card details are entered directly into Stripe and we do not store them. We receive from Stripe the payment status and basic billing data (customer ID, plan, amount, date).
Communications. Messages you send to us by email or through the contact form (name, email address, message), for example support requests, and notices about illegal content. The contact form is protected by Cloudflare Turnstile.
Acceptance record. Date and time, version of the Terms and Policy you accept, your account ID, as proof of your acceptance. At sign-up your IP address and user agent are not stored; if you later accept an updated version of the documents again, your full IP address and user agent are stored as well.
Voice. If you use dictation or voice chat, the audio is sent to a speech recognition provider (section 5) to be converted into text. Ravivo does not keep the audio: it is processed temporarily and only the resulting text is returned; whether the provider keeps it depends on the provider's terms.
External AI clients. If you connect an AI client through MCP (section 13), we store the connection (client, permissions you grant, dates) and, for security, we keep a log of the requests the App receives, including those to the MCP endpoint (with the IP address they come from), and an audit log of the write actions performed through it.
Cookies and local storage. Only those that are strictly necessary or exempt from consent, see section 10.
We do not collect special categories of personal data on purpose. Do not upload them unless you have a lawful reason to do so. If Your Content contains personal data of other people, you are responsible for having a lawful basis and for informing those people. For that data we act as your processor, and you act as the controller.
We collect the data directly from you, from the platforms you connect, and from your browser or device.
3. TikTok data
If you choose to connect a TikTok account, the connection is made through our integration provider Zernio (section 5): Ravivo redirects you to TikTok to authorize access, TikTok returns the authorization to Zernio, which handles it and stores the tokens on our behalf, and you return to the App. The TikTok authorization screen shows the name of the TikTok app used for this connection. We use only the following TikTok permissions (scopes), and only for these purposes:
| Scope | Data or action | Purpose |
|---|---|---|
| user.info.basic | TikTok open ID, display name, avatar | Show which TikTok account is connected and which account will receive a post |
| video.publish | Publish a video you prepared to your TikTok profile. Before posting we also read your posting options from TikTok (nickname, available privacy levels, comment, duet and stitch settings, maximum video length) and the status of the post | Direct Post after you review the post and press publish |
| video.upload | Send a video to your TikTok inbox as a draft | Let you finish and publish the post inside TikTok |
What we do not do:
- We do not read your TikTok messages, followers, private videos or watch history, and we do not request permissions for them.
- We do not post, upload or change anything on TikTok unless you start that action in Ravivo.
- We do not sell TikTok data, use it for advertising, or build profiles of people from it.
- We use data received from TikTok only to provide the connection and posting features you asked for.
- We do not use TikTok user data to train AI models. Data about your TikTok posts (such as link and status, and publishing statistics) can be accessible to the Ravivo AI agent and, through MCP, to the external AI clients you connect (section 13), when you use those features and within the permissions you grant; we do not send it to AI model providers for any other purpose.
- We do not share TikTok data with anyone except the providers listed in section 5 that help us provide the Service.
For the TikTok profile data we receive through the TikTok API, we are an independent controller, and TikTok is an independent controller for its own processing under the TikTok Privacy Policy. If TikTok requires us to delete TikTok data, for example when our access to the TikTok API ends, we delete it.
You can withdraw TikTok access at any time, in Ravivo by disconnecting the account (Settings, Integrations), or in TikTok under Settings and privacy, Security and permissions, Apps and services. When you disconnect, we stop using that connection in Ravivo and ask our integration provider to delete the connection and the tokens; the related data is deleted under sections 7 and 9.
4. Why we use data and on what legal basis
| Purpose | Data | Legal basis under GDPR |
|---|---|---|
| Provide the Service: accounts, media library, scheduling, publishing to connected accounts at your request | Account, connected account, content data | Performance of a contract, Article 6(1)(b) |
| Security, fraud and abuse prevention, troubleshooting | Usage and device data | Legitimate interests, Article 6(1)(f) |
| Bot protection at sign-up, login and on the contact form (Cloudflare Turnstile) | IP address, TLS fingerprint, user agent | Legitimate interests in security, Article 6(1)(f) |
| Charging for paid plans (when they exist) | Payment and billing data | Performance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c) |
| Connection of an external AI client (MCP) that you authorize | Data you allow to be read or requested with the access you grant | Performance of a contract, Article 6(1)(b) |
| Service messages, support, notices about changes | Account data, communications | Performance of a contract and legitimate interests |
| Handling notices about illegal content and complaints | Communications, content data concerned | Legal obligation, Article 6(1)(c), and legitimate interests |
| Keeping proof that you accepted the Terms and the Policy | Acceptance record | Performance of a contract, Article 6(1)(b), and legitimate interests in proving the contract and defending legal claims, Article 6(1)(f) |
| Tax, accounting and other legal obligations, and defence of legal claims | Data needed for the specific obligation | Legal obligation, Article 6(1)(c), and legitimate interests |
| AI features you use, to produce suggestions from the content and brand information you provide | Content data you submit to the feature | Performance of a contract |
We do not send marketing emails without your prior consent, and we do not sell personal data. We do not take decisions based solely on automated processing that produce legal effects on you. AI output is a suggestion that you review.
5. Who receives data
We share data only with providers that process it on our behalf, with the platforms where you ask us to publish, with the external AI clients you connect, and where the law requires it. Processing by our providers is governed by data processing contracts that meet Article 28 GDPR and, where data leaves the European Economic Area, by the safeguards described in section 6. Our current categories and providers are:
| Recipient | Purpose and data | Where | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Our own server where the database and the App logic run: all account, content and connection data | European Union (Germany) | Article 28 GDPR processor contract; processing takes place in the European Union |
| Vercel Inc. | Hosting and delivery of the App's web interface; requests between your browser and the API pass through its network (content and account data in transit) and its access logs | United States and global network | Article 28 GDPR processor contract; EU-U.S. Data Privacy Framework or standard contractual clauses for the transfer |
| Cloudflare, Inc. | DNS and a secure tunnel to our server; storage of uploaded media files (R2); bot protection (Turnstile); forwarding of mail to privacy@ravivo.app. Data: files, IP address, traffic | United States and global network; media files (R2) in the EU jurisdiction | Data Privacy Framework and standard contractual clauses in its data processing addendum |
| Stripe | Payments, only if paid features are offered. Data: email, billing data, card data (which you enter directly into Stripe) | Ireland and United States, depending on the Stripe entity providing the service | Article 28 GDPR processor contract; Data Privacy Framework or standard contractual clauses for the transfer |
| Zernio Software S.L. | Publishing, statistics and the message inbox for social networks such as TikTok. It stores the tokens of those connections. Data: identifiers and profile of the connected account, content you publish, platform messages | According to the information provided by the provider | Article 28 GDPR processor contract; standard contractual clauses if data is transferred outside the EEA |
| Composio (Sampark, Inc.) | Connection of Facebook Pages (stores the tokens of those connections and technical logs of calls). Not used for TikTok | United States | Article 28 GDPR processor contract and standard contractual clauses |
| External AI model providers, if the corresponding feature is enabled (through a model gateway, LiteLLM, which runs on our server) | Process the content and brand information you send to an AI feature and return a result. Providers such as OpenAI, Anthropic or Google may be involved, depending on the models enabled. If an own key from an AI provider has been configured for your account, the request is made with that key | United States and others depending on the provider | Article 28 GDPR processor contract; standard contractual clauses in their data processing terms. We access the models through their API; according to OpenAI, data sent to its API is not used to train models by default |
| Speech recognition provider | Converts the audio of dictation or voice chat into text | In the European Union or, if outside the EEA, with the safeguards of Chapter V GDPR | Article 28 GDPR processor contract; standard contractual clauses or the Data Privacy Framework if data is transferred outside the EEA |
| Tavily (AlphaAI Technologies Inc.) | Web search by the AI agent, if that feature is enabled: it receives the text of the search query. It must not include personal data | United States | Article 28 GDPR processor contract; standard contractual clauses |
| Email sending provider | Sending service emails, such as sign-up confirmation and password reset. Data: email address and message content | In the European Union or, if outside the EEA, with the safeguards of Chapter V GDPR | Article 28 GDPR processor contract; standard contractual clauses or the Data Privacy Framework if data is transferred outside the EEA |
| Google (mail service) | The mailbox that receives messages sent to privacy@ravivo.app and sends our replies from that address | United States and EU | Data Privacy Framework and standard contractual clauses in Google's terms |
| External AI clients you connect (for example ChatGPT or Claude) | Receive the data you allow them to read through MCP (section 13), at your initiative | Depends on the client's provider | Set by the AI client's provider under its own terms; we are not its processor |
| TikTok and other platforms you connect | Receive the content and settings you choose to publish and the authorization you grant | Location of the platform | The platform acts as an independent controller under its own policy |
| Authorities and advisers | Where the law requires it or to protect rights | Spain | Not applicable |
If the Service is reorganized or transferred, data may pass to the successor with the same safeguards.
6. International transfers
Some providers are established in the United States or process data outside the European Economic Area. When data leaves the EEA we rely on the adequacy decision of the EU-U.S. Data Privacy Framework for certified providers, or on the standard contractual clauses approved by the European Commission, together with additional safeguards where appropriate. External AI clients you connect (section 13) process data under the safeguards set by their own provider. You can ask for a copy of the safeguards at privacy@ravivo.app.
7. How long we keep data
- Account and content data: while your account is active. After you delete your account we delete or anonymize it within 30 days.
- TikTok connection: until you disconnect it or delete your account. When you disconnect, we deactivate the connection in Ravivo and ask the integration provider to delete the connection and the tokens; if the provider is unavailable at that moment, the connection stays deactivated in Ravivo anyway and the external deletion may be delayed. We delete the stored TikTok profile data (open ID, display name, avatar) within 30 days.
- Post results (post IDs and statuses): while your account is active, then deleted with it.
- Server logs: kept with automatic size based rotation and deleted when rotated; we do not keep them longer than necessary for security, abuse prevention and troubleshooting.
- Integration provider logs: the connector service keeps technical logs of API calls under its own settings, for up to one year, and we ask it to delete connection data when you disconnect.
- Support messages and notices about illegal content: up to 2 years after the matter is closed, to defend legal claims.
- Accounting and tax records (when paid plans exist): for the period required by law, up to 6 years, blocked and used only for that purpose.
- Acceptance record of the Terms and the Policy: while your account exists and, after you delete it, blocked for up to 5 years (limitation period for personal actions, Article 1964.2 of the Spanish Civil Code), only to defend legal claims.
- Backups: kept for a limited time and then removed on the regular backup cycle.
8. Your rights
Under the GDPR and the LOPDGDD you can ask us to:
- give you access to your data and a copy of it;
- correct inaccurate data;
- delete your data (right to erasure);
- restrict processing, or object to processing based on legitimate interests;
- receive your data in a structured, commonly used format and have it transmitted (portability);
- withdraw consent at any time, where we rely on it, without affecting earlier processing.
To use these rights write to privacy@ravivo.app from the email address of your account, or use the contact form at https://ravivo.app/en/contact. We may ask you to verify your identity. We answer within one month, which can be extended by two further months for complex requests, and we will tell you if that happens. Exercising your rights is free, except for manifestly unfounded or excessive requests.
You can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or to the supervisory authority of your habitual residence or place of work.
9. Data deletion
You can delete your data from Ravivo at any time.
Disconnect a connected account (TikTok or another platform). Sign in to the App (https://app.ravivo.app), open Settings, Integrations tab, and choose Disconnect next to the account. The procedure is the same for all platforms. Ravivo deactivates the connection, stops all publishing to that account and asks its integration provider to delete the connection and the tokens; if the provider is unavailable at that moment, the connection stays deactivated in Ravivo anyway and the deletion at the provider may be delayed. The stored TikTok profile data (open ID, display name, avatar) is deleted within 30 days.
Remove access in TikTok. Open TikTok, go to Settings and privacy, Security and permissions, Apps and services, and remove the app. After that Ravivo can no longer act on your TikTok account.
Delete your Ravivo account and all data. For now the account cannot be deleted from inside the App; you request it by email. Write to privacy@ravivo.app from your account email with the subject "Delete my data". Say whether you want to delete the whole account or only the data related to TikTok. We may ask you to confirm your identity.
We reply within one month. We delete or anonymize your personal data and revoke all connections within 30 days from when we confirm your request, except data we must keep by law or to defend legal claims (for example the acceptance record), which we keep blocked and only for the legal period. Backups are removed on the regular cycle (section 7).
What is deleted: account data (name, email, settings, invitation record); connection references and stored tokens; uploaded content, descriptions, schedules and post results; TikTok profile data; connections of external AI clients. Technical logs at our providers are deleted when the periods in section 7 end.
Posts you already published on TikTok stay on TikTok. You delete them in TikTok. Deleting data in Ravivo does not delete them.
10. Cookies
The Service uses only cookies and local storage that are necessary to provide the service you request: signing in and keeping you signed in, protecting access, and remembering the language you choose. Under Article 22(2) of Law 34/2002 (LSSI-CE) and the Spanish Data Protection Agency's Guide on the use of cookies, these uses are exempt from consent. We list them for transparency. We do not use advertising, tracking or analytics cookies, nor third-party analytics, error-tracking or font tools. The language is stored only when you choose it in the language selector or already have it saved in your account.
| Name | Where set (host) | Purpose | Duration |
|---|---|---|---|
__Secure-next-auth.session-token | app.ravivo.app (that host only) | Keeps you signed in | Up to 24 hours |
__Host-next-auth.csrf-token | app.ravivo.app (that host only) | Protects sign-in forms against forged requests | Browser session |
__Secure-next-auth.callback-url | app.ravivo.app (that host only) | Remembers which page to return to after sign-in | Browser session |
ravivo_locale | app.ravivo.app (that host only) | Remembers the language you chose | 1 year |
ravivo_td_tenant (browser local storage) | app.ravivo.app (that host only) | "Trusted browser": only if you expressly choose to remember this browser (checkbox when entering the second verification factor), it avoids asking for that second factor again | 30 days |
nextauth.message (browser local storage) | app.ravivo.app (that host only) | Technical storage of the sign-in component to keep the session in sync between browser tabs. Not sent to any third party | Until you delete it |
| Other interface data in the browser (local or session storage: language, notices you closed) | app.ravivo.app (that host only) | Remember the state of the interface. Not sent to any third party | Until you delete it or the session ends |
All these cookies are first-party and strictly necessary. The sign-in and forged request protection cookies are set by the App, on its own host (app.ravivo.app). The public Website (https://ravivo.app) does not use analytics, advertising or tracking cookies and, apart from the strictly necessary ones described in this section, sets no other cookies of its own.
Cloudflare Turnstile. On the sign-up and login pages, the App loads a Cloudflare script (challenges.cloudflare.com) that checks that the request comes from a person and not a robot. Cloudflare receives your IP address, the TLS fingerprint, the user agent and the site key with its origin. It is the only third-party script the App loads. It is a security measure against abuse that we consider necessary to provide the service, so we do not ask for consent. According to the Turnstile privacy addendum, Cloudflare acts as our processor to protect the site and as an independent controller to improve its bot detection. Turnstile does not create cookies on the App host (app.ravivo.app); any technical storage Cloudflare uses for this check serves only this security purpose.
If we add cookies that are not strictly necessary, for example analytics, we will first ask for your consent with an Accept button and a Reject button of equal visibility, let you change your decision at any time and update this section. You can block or delete cookies in your browser settings. If you block the necessary cookies, signing in will not work.
11. Security
We protect data with encryption in transit (TLS), encryption of stored credentials and tokens, hashed passwords, role based access control, and limited access to systems. No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and, where required, you.
12. Children
The Service is for adults. You must be at least 18 years old to use it. We do not knowingly collect data from minors. In Spain, a person under 14 cannot give consent to data processing without the consent of a parent or guardian, and we do not accept registrations from them. If you believe a minor has given us data, contact us and we will delete it.
13. AI features and external AI clients
Ravivo AI agent. The Service includes an AI agent ("AI Agent") and other AI features. The agent identifies itself as an AI system in every chat interface of the App, so you know you are not talking to a person (Article 50 of Regulation (EU) 2024/1689). In addition, each chat offers a button to contact a person through support. We send to AI model providers only the content and brand information you send to the feature and the context needed to answer. If an own key from an AI provider has been configured for your account, requests are made with that key under your contract with that provider. For TikTok data, see section 3. AI output is a suggestion that you review before use.
External AI clients (MCP). You can connect to your account, at your own initiative, a third-party AI client that you choose (for example ChatGPT, Claude or another MCP-compatible client) through the App's MCP endpoint (https://app.ravivo.app/mcp). Ravivo acts as the OAuth authorization server: before granting access you see a consent screen where you choose the permissions (reading your data, sending tasks to the Ravivo AI agent, reports) and whether the access covers all accounts of your workspace or only one. With that access the client can read data of your workspace (for example connected accounts and your role, content and texts, posts (including TikTok posts) with platform, link, date and status, reports and actions awaiting confirmation) and ask the Ravivo AI agent to perform actions, such as uploading files or preparing content and posts. Actions that change something or publish are submitted to you for confirmation inside Ravivo, unless you have turned on the agent's fully autonomous mode. The data the client reads leaves Ravivo at your initiative and falls under the terms and privacy policy of that client's provider (for example OpenAI or Anthropic, usually in the United States). You are responsible for choosing the client and for complying with its terms; Ravivo is not responsible for how the client processes that data. We store the connection and, for security, we keep a log of the requests the App receives (including those to the MCP endpoint) and an audit log of write actions. You can revoke access at any time in the App, under Settings, External agents; after you revoke it, the client cannot renew access. You can also remove it from the client itself. When you use an external client, the conversation with the AI takes place in that client's interface, and it is the client that informs you that you are interacting with an AI system.
14. Changes
We may update this Policy. For material changes we will notify you by email or in the Service before they take effect. The date at the top shows the latest version.
15. Contact
Volodymyr Tanygin, Ravivo Address: calle De la Rosa 100, P01C, Estepona, Málaga, Spain Email: privacy@ravivo.app Contact form: https://ravivo.app/en/contact Legal Notice: https://ravivo.app/en/legal-notice