Privacy Policy

Last updated 28 August 2026

Rileno is client and project management software for agencies and freelancers. This policy explains what we collect, why, and who else is involved in processing it.

What we collect

Account information. Your name, email address and password hash when you create an account, plus your job title and avatar if you provide them. If you sign in with Google, we receive your name, email address and profile picture from Google, and no password is stored.

Content you create. Everything you put into your workspace: leads, clients, contacts, projects, milestones, tasks, meetings, notes, documents, quotes, invoices and payment records. This is your data. We process it to provide the service and for no other purpose.

Your clients’ information. If you invite clients to the client portal, we store their names, email addresses and sign-in credentials. You are the controller of that data; we are a processor acting on your instructions.

Third-party services

We use the following processors. Each receives only what it needs to do its job.

  • Google — for sign-in, and for calendar access if you connect Google Calendar. Calendar access is read-only and used solely to show your availability and detect meetings. We never modify or delete your calendar events.
  • Our meeting recording provider — records and transcribes meetings you explicitly choose to record.
  • Cloudflare R2 — stores documents you upload.
  • Brevo — sends transactional email such as invitations, password resets and booking confirmations.
  • AI providers, via Vercel AI Gateway — generates summaries, decisions and action items from meetings you have recorded. Meeting content is sent for processing and is not used to train models.
  • Vercel — hosts the application.

Google user data

Rileno’s use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

We request the narrowest scopes that work. Signing in requests only your basic profile and email address. Connecting a calendar additionally requests read-only access to calendar events. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except where you have explicitly asked us to, where it is necessary for security, or where the law requires it.

How we use your data

  • To provide the service and keep your workspace working
  • To authenticate you and keep your account secure
  • To send transactional email you have asked for, such as invitations and booking confirmations
  • To meet legal and accounting obligations

We do not sell your data. We do not use your workspace content to train AI models.

Retention

We keep your data for as long as your account is active. If you delete your workspace, we delete its content within 30 days, except where we are legally required to retain records such as invoices for tax purposes.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. To exercise any of these, contact us at the address below and we will respond within 30 days.

You can disconnect Google Calendar at any time from your integrations settings, or revoke access from your Google account permissions.

Security

Data is encrypted in transit. Passwords are hashed with bcrypt and never stored in plain text. Access to production data is limited to those who need it to operate the service.

Changes

If we make material changes to this policy we will notify account holders by email before the changes take effect.

Contact

Questions about this policy, or about your data, can be sent to privacy@rileno.com.