Rivet EstimatorConstruction estimating workspace
PlansCloudUser guideRelease notesFAQContactPrivacyRefundsSupportTermsDelete data
PRIVACY POLICY · EFFECTIVE SEPTEMBER 4, 2026

Your estimate data stays under your control

Rivet is local-first and Cloud sync is optional. Cloud project content is encrypted on your device before upload, protected by HTTPS in transit, stored encrypted at rest, and operated with KMS-protected workspace-key custody and limited server processing.

What Rivet handles

Rivet stores projects, plans, measurements, takeoffs, pricing, customer details, and estimate notes locally on the device where you create them. If you enable Rivet Cloud, the app encrypts workspace data before upload. The hosted service stores encrypted bytes plus the minimum metadata needed to connect devices, enforce licensed seats, detect revisions, and operate the service. Rivet also holds the workspace key in KMS-wrapped form. When a Cloud operation requires it, the authorized service may unwrap that key transiently in protected process memory to authenticate and decrypt synchronized entity records for validation, and to create encrypted key envelopes for permitted devices. Decrypted record content is not retained as a server-side plaintext record after that processing, and customer-support tools do not display project content or plaintext workspace keys.

Information you provide

  • Local profile information such as your display name and email.
  • For hosted accounts, your verified Rivet email/password identity or Google identity, optional display name, Rivet email-confirmation status, and delivery timestamps for confirmation and welcome messages. Single-use confirmation secrets are stored only as cryptographic hashes.
  • Purchase-request details submitted on Rivet's website, plus Stripe customer, Checkout, payment, subscription status, billing interval, and renewal references when you use Stripe. Card and bank credentials are collected and processed by Stripe, not Rivet.
  • Google Play subscription status, product, purchase token, order reference, region, and expiry when you subscribe or restore a purchase. After verification, Rivet keeps a cryptographic hash of the purchase token for matching and an AES-256-GCM encrypted copy for subscription reconciliation.
  • Optional support or data-deletion request details.
  • Construction project information and plan files you choose to sync.

Service metadata

Cloud features use a random installation identifier, device name, platform, licence identifier, encrypted-workspace size, revision number, checksums, and last-seen time. When you first arrive through a campaign link, Rivet may retain a limited first-party snapshot of the campaign labels, landing path, and referring website origin so we can understand which outreach led to account creation. This snapshot does not include project content, advertising identifiers, or cross-site behavioural tracking. Rivet does not request location, contacts, camera, microphone, or access to unrelated files.

How information is used

Information is used only to provide estimating, licensing, encrypted sync, customer support, security, fraud prevention, account messages, payment and subscription administration. Rivet's transactional email provider processes the recipient address and message content only to deliver requested account emails. Stripe processes website Checkout, billing methods, receipts, and subscription management under its own privacy terms. Google processes Play purchases under its own privacy terms; Rivet verifies purchases through the Google Play Developer API before granting access. Rivet does not sell personal information and does not include third-party advertising or behavioural analytics.

Security and retention

Network traffic uses HTTPS. Cloud project content uses AES-256-GCM authenticated encryption on the device and remains encrypted in persistent Cloud storage. Workspace keys are stored server-side only in KMS-wrapped form and are unwrapped transiently for the limited Cloud processing described above. This means Rivet Cloud is not a zero-knowledge service. Pairing codes expire after ten minutes and device tokens are stored on the server only as cryptographic hashes. Rivet Cloud keeps the latest five committed encrypted revisions. Temporary upload sessions expire after two hours. Purchase and deletion records may be retained when reasonably necessary for support, security, accounting, or legal obligations.

Optional setup progress

On the web, you can choose to share basic setup milestones from the Projects screen. This is off by default. If enabled, Rivet records account-linked milestones after verified local saving, such as saving a plan, verifying scale, completing a takeoff, pricing an estimate, or recording a downloaded customer proposal. These reports contain fixed milestone names and a sample-versus-own-plan indicator, not project names, drawings, measurements, quantities, prices, or customer details. They help us understand where the first-project experience needs improvement. They are client-reported progress signals, not proof of measurement accuracy or customer adoption. Turn sharing off on the Projects screen to stop future reporting; contact support to request removal of previously recorded progress.

Deletion

The owner device can permanently delete an encrypted cloud workspace from Settings → Rivet Cloud. You can also submit a request from the public data-deletion page. Local-only profiles are offline accounts and can be removed by resetting local app data or uninstalling the app after exporting anything you wish to keep.

Children

Rivet is a professional construction productivity tool and is not directed to children under 13.

Contact

Questions about privacy can be sent to support@rivetestimator.ca.

Rivet Estimator · British Columbia, Canadasupport@rivetestimator.ca