Legal

Privacy Policy

How ByteGuard S.L. collects, uses, stores, and protects data in RIZR.

Technical update: July 11, 2026

Translated version

This localized version is provided for clarity. The binding legal version is the Spanish text; contact support for any discrepancy.

ByteGuard S.L., based in Spain, is the controller for personal data processed through RIZR and rizr.me. This policy summarizes the data flows, purposes, recipients, retention, and rights under the GDPR and Spanish data-protection law.

01

Controller and data collected

Contact: [email protected]. Account use can involve name, email, preferences, subscription and credit data, activity, manual chat text, uploaded screenshots, and generated replies. OAuth provider passwords are never stored.

02

Public demo and account uploads

The anonymous demo processes readable text or images in memory for the request and creates no file or history; an idempotent result may remain for up to 15 minutes and HMAC quota identifiers for a rolling 24-hour window. Account uploads and generation history remain linked to the account until deletion; there is no fixed automatic expiry.

03

Purposes and legal bases

Data is used to provide requested AI generations, maintain accounts and history, manage subscriptions and credits, secure the service, prevent fraud, and send service communications. Contract performance, consent, and legitimate interests are used as applicable. Marketing analytics and advertising storage require consent.

04

AI providers, analytics, and transfers

Requested content can pass through ByteGuard infrastructure, Vercel AI Gateway, and the active model provider such as Google, xAI, or OpenAI. Other processors can include RevenueCat, Apple, Google, Cloudflare Turnstile, PostHog, Google Analytics, Microsoft Clarity, and Linear. International transfers depend on each active contract and safeguard. RIZR does not train its own models on raw chat content.

05

Security, retention, and your rights

Transport uses HTTPS/TLS. Account data, uploads, history, credits, and sessions are deleted through the account-deletion flow, with file deletion attempted separately; an audit record can remain for up to 12 months. You may request access, correction, deletion, portability, restriction, or objection at [email protected] and withdraw optional analytics consent at any time.