RIVET

Build it. Rivet it.

Eight Clap Labs

Privacy Policy

Effective 24 July 2026 · Version 1.0

Rivet has no servers, no accounts, and no database. There is nowhere for your data to be collected to. This page explains what that means in practice, and what does happen when you use the app.

Where your data actually goes

Your iPhone
Google sign-in
Your own Firebase project
Rivet's servers

Not on this path — they don't exist

What Rivet collects

Nothing. Rivet is published by AddiO LLC, which operates under the name Eight Clap Labs. We run no server that receives your information. Rivet contains no analytics, no crash reporting, no advertising or tracking software, and no third-party software development kits of any kind.

We cannot see your Google account, your projects, the files you publish, or how often you use the app, because none of it is ever sent to us.

Signing in with Google

Rivet asks you to sign in with Google so it can work with the Firebase projects on your own Google account. That sign-in happens directly between your device and Google. Rivet never sees or handles your Google password.

Google returns a token that proves you granted permission. That token is stored in the iOS Keychain on your device and nowhere else. It is shared with Rivet's share extension so that publishing works from the share sheet, and it never leaves your device except when your device talks to Google.

The permissions Rivet asks for

You can review or revoke Rivet's access at any time at myaccount.google.com/permissions.

What is stored on your device

All of it lives on your device. Deleting the app removes it.

What you publish

When you publish, the file goes from your device straight to Firebase Hosting in your own Google account. Rivet does not host, copy, cache, or inspect it. Google hosts your site, bills you directly for it based on your own usage, and applies its own terms and privacy policy to that relationship.

Anything you publish becomes publicly reachable on the internet at your Firebase Hosting address. Please don't publish anything you wouldn't want found.

Photos

If you tap Save on a QR code for your site, Rivet asks for permission to add that image to your photo library. This is add-only permission: Rivet cannot see, read, or list your photos.

Children

Rivet is a developer tool and is not directed to children under 13. It requires a Google account, which Google's own terms already restrict by age.

Deleting your data

Signing out clears the stored Google token from your Keychain. Deleting the app removes everything else Rivet has kept on your device. To end Rivet's access to your Google account entirely, revoke it at myaccount.google.com/permissions.

Your Firebase projects and any sites you published belong to you and are unaffected by removing Rivet. Delete those from the Firebase console if you want them gone.

Changes to this policy

If this policy changes, the effective date above changes with it. If a future version of Rivet ever does send data to a server we operate, this page will say so plainly and in advance of that version shipping.

Contact

AddiO LLC

operating as Eight Clap Labs

support@eightclaplabs.com