Privacy Policy

Last Updated: [EFFECTIVE_DATE] · Effective Date: [EFFECTIVE_DATE]

Summary of Key Points

  • We collect professional profile data to power AI-driven matching between founders and builders.
  • Your profile text is processed by OpenAI to generate AI embeddings (numerical representations).
  • Your data is stored on Supabase servers in the EU (London, UK).
  • You can delete your account and all data at any time from Settings.
  • We do not sell your personal data to third parties.
  • We do not use analytics or tracking cookies.

This Privacy Policy explains how RiseNet ("RiseNet," "we," "us," or "our") collects, uses, processes, shares, and protects your personal data when you use the Service at risenet.io. The term "RiseNet," "we," "us," or "our" refers to RiseNet.

1. Data Controller

The data controller responsible for your personal data is:

RiseNet

[COMPANY_ADDRESS]

Email: [DPO_EMAIL]

If you are in the EU/EEA, you may contact your local data protection authority. In Spain: AEPD (aepd.es). In the UK: ICO (ico.org.uk).

2. Data We Collect

2.1 Account Data

DataDescriptionLegal Basis
Email addressUsed for login, verification, and communicationsContract performance
Password (hashed)Stored by Supabase Auth — we never see your plaintext passwordContract performance
Google OAuth profileEmail and Google user ID if you use Google sign-inContract performance
IP address (registration)Collected by Supabase Auth for fraud preventionLegitimate interest

2.2 Profile & Professional Data

DataDescriptionLegal Basis
First name, last nameDisplayed on your public profileContract performance
UsernameUnique identifier for your public profile URLContract performance
CountryUsed for profile display and regional contextContract performance
User type"founder" or "builder" — determines matching contextContract performance
RoleYour current or target professional roleContract performance
SectorIndustry or domain (e.g., FinTech, HealthTech)Contract performance
SkillsUp to 20 professional skillsContract performance
Startup stageCurrent stage of your project (Idea → Profitable)Contract performance
AvailabilityHours per week available for collaborationContract performance
"About" narrative80–1,000 character description of yourselfContract performance
"Looking for" narrative80–1,000 character description of your ideal collaboratorContract performance
Profile photo (avatar)Optional image stored in our storageConsent (optional)

2.3 AI-Derived Data — Important

When you complete or update your profile, your professional information is transmitted to OpenAI's API to generate the data described below. OpenAI does not use API-submitted data to train its models by default. OpenAI Privacy Policy →

AI-Derived DataDescriptionRetention
Profile embeddingA 1,536-dimensional numerical vector representing your professional profileDeleted on account deletion
Looking-for embeddingA 1,536-dimensional numerical vector representing what you seek in collaboratorsDeleted on account deletion
Match reasonA 2-sentence AI-generated explanation of compatibility between two matched profiles (uses both users' data)Deleted on account deletion
Community name & descriptionAI-generated community identity based on member profile dataDeleted with community dissolution

What is sent to OpenAI:Your first name, role, sector, "About" text, skills list, startup stage, availability hours, and "Looking for" text. We do not send your email address, password, or direct messages to OpenAI.

2.4 User-Generated Content

Content TypeVisibilityRetention
Posts (project/question/thought)All platform usersUntil deleted by you or removed by moderation
Post commentsAll platform usersUntil deleted by you or removed by moderation
Direct messagesOnly sender and recipientUntil account deletion
Group messagesCommunity members onlyUntil account deletion or community dissolution

2.5 Activity and Usage Data

DataDescriptionLegal Basis
last_active_atTimestamp of your last activity (used for archiving inactive accounts)Legitimate interest
Connection requestsWho sent/received requests, with status (pending/accepted/rejected)Contract performance
Match historyWhich profiles you were matched with and compatibility scoresContract performance
Post likesWhich posts you have likedContract performance
Community membershipCommunities you belong to, with membership status and similarity scoreContract performance
Notification read statusWhich notifications you have readContract performance

3. How We Use Your Data

PurposeLegal Basis
Creating and managing your accountContract performance
Displaying your public professional profile to other usersContract performance
Generating AI profile embeddings for matchingContract performance / Legitimate interest
Computing compatibility scores between usersContract performance
Generating AI-written match explanations via GPT-4o-miniLegitimate interest
Forming AI-curated communities through nightly clusteringLegitimate interest
Sending notifications about connections, matches, and activityContract performance
Archiving profiles inactive for more than 30 daysLegitimate interest
Enforcing our Terms of Service and Acceptable Use PolicyLegitimate interest
Responding to legal requests and preventing harmLegal obligation
Improving the Service using aggregated, de-identified insightsLegitimate interest

4. AI Processing and Automated Decision-Making

4.1 Automated Matching

RiseNet's core feature involves automated processing of your profile data to generate numerical embeddings, compute compatibility scores, select and rank potential matches, generate AI-written explanations of compatibility, and suggest communities based on profile clustering.

This constitutes automated decision-making under GDPR Article 22. The decisions include: which profiles appear as your potential matches, your compatibility score with other users, and which AI-curated communities you are suggested to join.

4.2 Your Rights Regarding Automated Processing

  • Request human review of any automated decision by emailing hi@risenet.io.
  • Object to processing — we will evaluate and respond within 30 days.
  • Request explanation of how a specific match score was generated.
  • Opt out of AI matching by not using the matches feature; decline community suggestions individually in the app.

5. Data Sharing and Sub-processors

We do not sell, rent, or trade your personal data. We share data only as described below.

5.1 Other Users

Your public profile (name, username, user type, role, sector, skills, stage, availability, about text, avatar, country) is visible to all registered users. Direct messages are private between sender and recipient. Group messages are visible to community members only.

5.2 Sub-processors

Sub-processorCountryData ProcessedPurpose
Supabase Inc.USA (servers: EU — London, UK)All user data, content, filesDatabase, Authentication, Storage
OpenAI, LLCUSAProfile text fields (name, role, sector, about, skills, looking_for, stage, availability)Embedding generation, match reasons, community naming
Google LLCUSAEmail address, Google profile IDOAuth authentication only

All sub-processors are bound by data processing agreements.

5.3 Legal Requirements

We may disclose your data to law enforcement or courts when legally required, or when necessary to prevent imminent harm.

5.4 Admin Access

RiseNet administrators can access user profiles and public content for moderation. All admin actions are logged in our audit system. Admins do not access the content of private direct messages unless required by law.

6. International Data Transfers

Your data is stored on servers in the EU (London, UK — AWS eu-west-2). Some sub-processors are located in the US. OpenAI transfers are governed by OpenAI's Data Processing Agreement and Standard Contractual Clauses (SCCs). Google authentication is governed by Google's applicable terms and SCCs.

7. Data Retention

Data CategoryRetention Period
Account data (email, auth)Until account deletion
Profile data and AI embeddingsUntil account deletion
Match history (scores and reasons)Until account deletion
Posts and commentsUntil you delete them or your account is deleted
Direct messagesUntil both sender and recipient accounts are deleted
NotificationsUntil deleted by you or 12 months after creation
Avatar filesDeleted from storage within 30 days of account deletion
Waitlist data90 days after you create a full account, or upon request
Admin audit logs2 years
Server access logs90 days

Archiving:Accounts inactive for more than 30 days are marked as archived and hidden from discovery. You can reactivate by logging in. Accounts archived for more than 12 months may be scheduled for deletion with 30 days' email notice.

8. Your Rights Under GDPR (EU/EEA Users)

Right of Access (Art. 15)

Obtain a copy of your personal data. Access profile data in Settings. For a full data export (posts, messages, activity), contact hi@risenet.io.

Right to Rectification (Art. 16)

Correct inaccurate data directly in the Settings page. For account data corrections, contact hi@risenet.io.

Right to Erasure (Art. 17)

Delete your account and all associated data via Settings > Account > Delete Account. If you cannot log in, contact hi@risenet.io.

Right to Restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances. Contact hi@risenet.io.

Right to Data Portability (Art. 20)

Receive your personal data in a structured, machine-readable format (JSON). Contact hi@risenet.io.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including automated matching and AI profiling. Contact hi@risenet.io.

Rights re Automated Decisions (Art. 22)

Request human review of automated decisions. See Section 4.2 for details.

To exercise any right, email hi@risenet.io with your registered email and a description of the right you wish to exercise. We respond within 30 days. Rights requests are free of charge.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the sale of personal information. We do not sell personal information.

Categories of personal information collected: identifiers (email, username, IP), personal information (name, photo), professional information (role, sector, skills), electronic network activity (sessions, login), and inferences (AI embeddings, match scores).

To exercise CCPA rights, contact hi@risenet.io or hi@risenet.io.

10. Security Measures

MeasureDescription
Encryption in transitAll data transmitted over HTTPS/TLS
Encryption at restManaged by Supabase (AES-256)
Row Level Security (RLS)Database-level access controls — users can only access their own data
JWT authenticationValidated on every backend API request
Rate limitingMatching: 2/hour; connection requests: 20/hour per user
AI input sanitizationHTML tags and null bytes stripped before OpenAI submission
Admin audit loggingAll admin actions logged with actor, target, and timestamp

In the event of a breach, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and notify affected users without undue delay. Report security vulnerabilities to [SECURITY_EMAIL].

11. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a user is under 18, we will terminate their account and delete their data. To report a concern, contact hi@risenet.io.

12. Cookies

We use minimal cookies. See our full Cookie Policy for details. We do not use analytics or advertising cookies.

13. Changes to This Policy

We may update this Privacy Policy. When we make material changes, we will update the "Last Updated" date, send an email notification, and display a notice in the Service. Continued use of the Service constitutes acceptance of the updated policy.

14. Contact and Data Protection

RiseNet

[COMPANY_ADDRESS]

Data protection: [DPO_EMAIL]

Legal: hi@risenet.io

Security: [SECURITY_EMAIL]

Support: hi@risenet.io