Privacy Policy
We're committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data.
PRIVACY POLICY
Last updated: August 5, 2026
Applies to: the Rivet mobile app, getrivet.ca, and the Rivet service.
WHO WE ARE
Rivet Systems Inc. ("Rivet," "we," "us," or "our") is a Canadian company based in Belle River, Ontario. Rivet provides a practice-communication service to independent mental health practitioners — a dedicated practice phone number with calls, text messaging, voicemail transcription, and video sessions.
Rivet is designed to be consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable provincial health-privacy law, including Ontario's Personal Health Information Protection Act (PHIPA).
OUR TWO ROLES
For a practitioner's clients: when a practitioner uses Rivet, the practitioner is the health information custodian and Rivet acts as the practitioner's agent and service provider — we handle client information on the practitioner's behalf and under their direction. We do not use client information for our own purposes. This includes incidental callers (for example, wrong numbers); we treat all caller data with the same protections regardless of whether the caller becomes a client of the practice they reached.
For practitioners: we are responsible for the account, billing, and usage information of the practitioners who subscribe to Rivet.
The custodian-and-agent relationship described above is set out in full in the Rivet Data Processing Agreement, published at getrivet.ca/legal/dpa. Every practitioner accepts it when they create an account, at no additional cost. Where this policy and that agreement differ on how client information is handled, the agreement governs.
INFORMATION WE COLLECT
From a practitioner's clients (handled on the practitioner's behalf):
• Phone number (provided by the telephone network when a client calls or texts the practice).
• Voicemail recordings and their text transcriptions.
• The content of text messages exchanged with the practice number.
• Participation in, and metadata about, video sessions — for example, the time joined and the duration. We do not record video sessions.
• A name, scheduling preference, or other details a client volunteers.
• Responses to clinical assessments (PHQ-9, GAD-7, C-SSRS, and other instruments available in the service) completed by a client during a session with their practitioner — including item-by-item answers and derived scores.
• A derived risk level (none, elevated, or high) calculated from certain assessment item responses (C-SSRS intent and behaviour items; PHQ-9 item 9). This indicator is stored on the client record and is visible only to the practitioner.
The following categories are entered by the practitioner and maintained as part of the client's clinical record in the Rivet service:
• Progress note clinical content — DAP/SOAP format notes created by the practitioner, including signed and locked notes and any append-only correction addenda.
• Client record identity fields — date of birth, emergency contact name and number, referral source, and a consent log.
We do not ask clients for health or other sensitive information outside of clinical assessments completed as part of a session with their practitioner. Clinical assessment responses are processed as part of the clinical record that the practitioner maintains, and are handled under the practitioner's direction.
From subscribing practitioners:
• Business name, contact name, professional credentials, and service-configuration preferences.
• Email address — used as the sign-in identifier and for service communications.
• Phone numbers — the practitioner's personal cell where applicable, and the dedicated Rivet practice number we provision.
• Phone contacts you choose to import into Rivet — used only to display contact names alongside their communications, and to suppress auto-replies to contacts you tag as Personal. Never used for any other purpose.
• Mobile-device push-notification tokens — so we can deliver alerts about new calls, messages, and voicemails.
• Authentication tokens — stored encrypted in your device's secure storage. If you enable Face ID, Touch ID, or fingerprint unlock, your biometric data never leaves your device; only a yes/no signal from your operating system reaches Rivet.
• Payment and billing information — processed by Stripe. We do not store payment card numbers.
Automatically:
• Log and usage data (device type, IP address, timestamps) for security, troubleshooting, and service performance.
• Operating-system-level crash and diagnostic reports surfaced to us through Apple's and Google's standard developer-console channels. We do not run a third-party crash-analytics service.
COOKIES AND LOCAL STORAGE
The Rivet web app stores your authentication session in your browser's local storage so you stay signed in between visits. We do not use third-party cookies, advertising trackers, or analytics that profile individual visitors.
HOW WE USE INFORMATION
We use information to:
• Deliver calls, messaging, voicemail, and video sessions to the practitioner.
• Send a caller the practitioner's pre-written auto-reply.
• Transcribe voicemails into text and classify them by intent (such as "new client" or "reschedule") for inbox organization.
• Notify practitioners of new activity.
• Authenticate access to the app and protect the account.
• Operate, secure, support, and improve the service.
• Meet legal and regulatory obligations.
We do not sell or rent personal information. We do not use it for third-party marketing. No AI system ever generates a message sent to a client — every auto-reply is fixed text written by the practitioner.
ARTIFICIAL INTELLIGENCE PROCESSING
Voicemail transcription and intent classification run on Rivet's own infrastructure. Call audio and transcripts are not sent to any third-party AI service (such as OpenAI or Anthropic). The classifier produces only a category label for inbox organization. No AI system ever generates a message sent to a client.
VIDEO SESSIONS
Video and audio in a Rivet video session are encrypted end-to-end between the practitioner and client devices. When a direct peer connection is not possible (for example, behind certain corporate firewalls), encrypted media is relayed through Metered.ca's TURN servers; the relay cannot decrypt the contents.
Sessions are not recorded. Only the fact that a session occurred, its duration, and the participating phone numbers are stored.
MOBILE APP PERMISSIONS
The Rivet mobile app requests the following device permissions to deliver its features. Each permission is used only for the purpose described:
• Microphone — to place and receive voice calls, take part in video sessions, and record voicemail greetings.
• Camera — to take part in video sessions and to scan sign-in QR codes.
• Contacts — to allow you to choose specific contacts to import into Rivet. No contacts are read or transmitted without your explicit selection.
• Notifications — to deliver alerts for incoming calls, messages, and voicemails.
• Face ID, Touch ID, or fingerprint — optional. Used to unlock the app without re-authenticating each session. Your biometric data never leaves your device.
• Foreground service and background audio — to keep an active call or video session connected when you switch to another app.
• Bluetooth — to route audio to a connected Bluetooth headset during calls.
You may revoke any of these permissions at any time in your device settings. Some features will not work without their required permission.
HOW WE SHARE INFORMATION
We share limited information with service providers who help us operate Rivet. Each is contractually required to protect information and use it only to provide its service to us:
Twilio — Telephony, SMS delivery, and voicemail recording. Processing location: United States.
Supabase — Secure database storage. Processing location: Canada (ca-central-1, Montreal).
Cloudflare — Application hosting and content delivery, and object storage for voicemail greeting audio. Greeting audio is stored in a Canadian-jurisdiction bucket. Application hosting runs on Cloudflare's global edge network, which handles requests in transit and short-lived caches only — no client information is stored at rest there.
Metered.ca — WebRTC TURN relay for video sessions when a direct peer connection isn't possible. Cannot decrypt session media. Processing location: Canada.
Expo and EAS — Mobile-app build infrastructure and developer-tool services. Processing location: United States.
Stripe — Payment processing. Processing location: United States and Canada.
Resend — Transactional email delivery (sign-in links and service notifications). Message bodies contain no client information. Processing location: United States.
Apple — Mobile push-notification delivery on iOS. Processing location: United States.
Google — Mobile push-notification delivery on Android (Firebase Cloud Messaging). Processing location: United States.
We also disclose information to law enforcement or regulators when legally required, and to a successor if Rivet Systems Inc. is acquired or merged. Beyond this, no third party receives client information. SMS opt-in and consent data is never shared with any third party.
INTERNATIONAL TRANSFERS
Rivet operates in Canada. As of June 24, 2026, our primary database is hosted in Canada (Supabase ca-central-1, Montreal), and voicemail transcription and intent classification run on our own infrastructure in Belle River, Ontario. Every persistent record we hold about a practitioner or a client — voicemail transcripts, conversation history, call records, clinical records (progress notes, assessment responses, risk level, client record fields), audit logs, account settings — is stored on Canadian infrastructure.
Some service providers still process data outside Canada: Twilio (telephony and SMS delivery, United States); Stripe (payment processing, United States and Canada); Apple and Google (mobile push-notification delivery, United States); Expo and EAS (mobile-app build infrastructure, United States); Resend (transactional email delivery, United States). Voicemail audio held briefly at Twilio is automatically deleted at 30 days; SMS bodies and call records at Twilio are deleted at 90 days. While information is in another country it is subject to that country's laws. We require contractual safeguards for any cross-border transfer.
DATA RETENTION
• Voicemail audio recordings: 30 days, then automatically deleted.
• Voicemail transcripts and message history: retained while the related conversation is active. Caller personal information is purged 90 days after last activity. Purged data includes the caller's phone number, the caller's name, and message bodies. Anonymous metadata about the volume and timing of activity may be retained for service-performance analysis.
• Video sessions: not recorded. Session metadata (start, duration, participating numbers) retained 90 days.
• Call history: retained while your account is active. Subject to the same 90-day purge cycle for caller personal information.
• Imported contacts: retained while your account is active. Deleted on request or on account closure.
• Practitioner account data: retained while the account is active. Deleted within 30 days of cancellation.
• Clinical records (progress notes and note content, completed assessment responses and scores, derived risk level, and client record identity fields — date of birth, emergency contact, referral source, consent log): retained by Rivet for the duration of the practitioner's active account, so the practitioner can view and export them at any time. The practitioner is the custodian and is responsible, under their professional College requirements, for retaining clinical records for the period their obligations require — commonly at least 10 years from the date of the last clinical interaction with a client (or, for a client who was a minor at the time of service, 10 years after the client reaches the age of majority). That ongoing obligation is the practitioner's, to be met through their own system of record after export from Rivet. On cancellation, clinical records are made available for export and are deleted by Rivet at the end of a 90-day wind-down period (see Section 12). The 30-day and 90-day purge cycles that apply to voicemail recordings and messaging data do not apply to clinical records.
DELETING YOUR DATA
To request deletion of your Rivet account and all associated data, email hello@getrivet.ca with subject "Delete my data."
Within 7 business days we will delete:
• Your practitioner profile and business configuration.
• All voicemail recordings and transcripts.
• All call history, SMS conversation history, and video-session metadata.
• All imported contacts.
• Your authentication record.
For clinical records (progress notes, assessment responses, derived risk level, and client record identity fields), a 90-day wind-down period applies. These are not deleted within the standard 7-business-day window. On account closure, Rivet makes all clinical records available for export on or before the closure date; records are deleted on the practitioner's instruction or at the end of the 90-day wind-down period from the date of cancellation, whichever comes first. The ongoing obligation to retain clinical records in accordance with professional College requirements — commonly at least 10 years from the last clinical interaction with a client (or, for a minor, 10 years after they reach the age of majority) — is the practitioner's, as custodian, to be met through their own system of record after export from Rivet. Rivet does not retain clinical records for 10 years after account closure.
Retention exceptions (required by law or legitimate business interest):
• Billing and payment records — retained 7 years to meet Canada Revenue Agency requirements.
• Audit log — retained indefinitely as compliance evidence. Rivet keeps an append-only record of significant events on an account: sign-ins, access to a voicemail recording or a greeting, outbound messages, changes to practice settings, assessment submissions, session creation, share-link issuance, and acceptance of this policy's related agreements. Each entry records what happened, when, which account and practitioner it belongs to, and the IP address and browser or device the request came from. Entries never contain the content of a voicemail, message, note, or assessment answer — only identifiers, counts, and timestamps. The application cannot edit or delete an entry once written, even with full service credentials; that immutability is what makes the log usable as evidence.
If you have questions about deletion or want to delete specific data without closing your account, contact hello@getrivet.ca.
SECURITY
We use administrative, technical, and physical safeguards — Canadian data residency for every persistent record (Supabase ca-central-1 + on-premises AI processing on Rivet hardware in Belle River, Ontario), encryption at rest (AES-256) and in transit (TLS), access controls, biometric and password-protected device authentication, and retention limits — to protect information. No system is perfectly secure, but we work continuously to guard against unauthorized access, use, or disclosure, and we will notify affected custodians and individuals of a privacy breach as required by law.
SMS MESSAGING
Program: Rivet practice-communication service.
Consent: When a client contacts a practice that uses Rivet, the practitioner's auto-reply is a direct response to that client-initiated contact and falls within CASL's implied-consent provisions for response to an inquiry (s. 10(9)).
Frequency: Transactional only — one response per call within a de-duplication window. Frequency varies with call volume. No marketing messages are ever sent.
Message and data rates may apply. Reply STOP to opt out, HELP for help, or contact hello@getrivet.ca.
YOUR RIGHTS
Under PIPEDA, PHIPA, and applicable provincial law, you may:
• Request access to the personal information we hold about you.
• Request correction or deletion of that information.
• Withdraw consent for processing where applicable.
For client information, requests are fulfilled together with the practitioner, who is the custodian of that information. To exercise these rights, contact our Privacy Officer at hello@getrivet.ca.
CHILDREN'S PRIVACY
Rivet is a business tool intended for licensed practitioners. The service is not directed to children under 16. We do not knowingly collect information from minors.
PRIVACY OFFICER AND CONTACT
Rivet has designated a Privacy Officer accountable for compliance with this policy and applicable privacy law.
Privacy Officer
Rivet Systems Inc.
Belle River, Ontario
Email: adam@getrivet.ca (Privacy Officer direct) or hello@getrivet.ca (general inquiries)
CHANGES TO THIS POLICY
We may update this policy from time to time. Material changes will be posted here with a revised "Last updated" date at the top.