Product

TeamsTestimonialsPricing

Legal

Privacy Policy

EFFECTIVE DATE: APRIL 17, 2026

Start with the quick summary for the short version, or scroll through the full legal policy below.

Quick Summary

  • No keystrokes, screenshots, or app content capture.
  • Users review and approve entries before team sharing.
  • Admins see approved entries and reports, not raw personal activity.
  • Rize does not permit third parties to train on customer data.
  • Automatic tracking requires the desktop app; manual entry remains available.

Privacy FAQ

No. Rize does not capture keystrokes, screenshots, screen recordings, or the content inside apps. It reads limited metadata from the active window, such as app name, URL when applicable, and window title, to help users review and approve time entries.

Managers and admins see approved time entries, reports, and other workspace data according to role-based permissions. The workspace reporting experience does not expose raw activity metadata, screen content, keystrokes, or other unapproved personal activity details.

Rize may use aggregated, de-identified, or anonymized information derived from User Data and Generated Content to improve its own algorithms and machine-learning models. Rize does not use identifiable customer workspace data to train shared third-party models and does not permit third parties to use such data for their own model training.

Yes. Users can edit, override, and exclude apps or websites from tracking before sharing approved time entries with a team workspace.

Automatic tracking requires the Rize desktop app on the device being used. If installation is not possible, users can add time manually through the web app. If AI or MCP-based manual entry is enabled for a workspace, that may also be used.

Yes. Historical time data remains accessible in your workspace, and you can export your data at any time.

We recognize that your privacy is very important. This privacy policy covers Rize's policies on the collection, use, and disclosure of your information when you access rize.io, Rize's desktop application, or any related services (collectively the "Platform") or anytime you interact with Rize.

Each time you use the Platform, you consent to the collection, use and storage of the collected information as described in this Privacy Policy. Please read it carefully and contact us at support@rize.io if you have any questions.

What Information Does Rize Collect on the Platform?

Account Holder and Authorized Users: In establishing an account, Subscribers must provide their first and last name, work-related email and create a password. In addition, Subscriber may designate Authorized Users to send and receive communications through the Services. Additional information is collected through the Rize product as permitted by the user which can include time spent on applications and websites. Emails are utilized for the purposes of confirming account and authorized user access and to provide Services-related communications. Your email may also be used to (i) communicate material changes to our Terms of Service and Privacy Policy; and/or (ii) help us maintain and improve Services offered. Payment information (name, address, credit card information) is collected upon the purchase of a Subscription by the Subscriber.

Cookies: Rize utilizes cookie technology to gather information on Internet use in order to serve you more effectively. Cookies are files with a small amount of data, which may include an anonymous unique identifier. Cookies are sent to your browser from a website and transferred to your device. Rize may utilize various tracking pixel services. Such third party services may use cookies, web beacons, and similar technologies to collect or receive information from your website and elsewhere on the internet and use that information to provide third party measurement services and targeted ads. You can set your browser to remove or reject cookies; however some Platform features or Services may not work properly without cookies.

How You Can Control Advertising Cookies: You can manage cookies used for online advertising via the consumer choice tools created under self-regulation programs, such as the US-based aboutads.info choices page or the EU-based Your Online Choices.

User Data Ownership, Generated Content, and AI Usage

User Data

"User Data" means the information you provide to the Platform or that is collected through your use of the Platform, including tracked activity, application usage, website usage, calendar data, metadata, and any other information captured or submitted through the Platform. You retain all rights, title, and interest in and to your User Data. Rize does not claim ownership over User Data.

Generated Content

"Generated Content" means any timesheets, summaries, insights, descriptions, or other content produced by the Platform based on your User Data. You retain all rights, title, and interest in and to your Generated Content.

Confidentiality

Rize treats User Data and Generated Content as confidential information. We do not access, use, or disclose this information except as necessary to provide, maintain, and improve the Platform, to comply with applicable law, or as otherwise authorized by you. Rize does not sell User Data or Generated Content to third parties.

AI and Model Training

Rize may use aggregated, de-identified, or anonymized information derived from User Data and Generated Content to develop and improve its own algorithms and machine-learning models. Rize does not use identifiable customer workspace data to train shared third-party models, does not sell User Data or Generated Content, and does not permit third parties to use such data for their own model training.

Workspace Admin Access

In team or organization workspaces, users with administrative roles may access approved time entries, reports, and other workspace data according to role-based permissions and solely to the extent necessary for time tracking, reporting, billing, and workspace management. Administrator access does not include raw activity metadata, screen content, keystrokes, or other unapproved personal activity details through the workspace reporting experience. All users retain the ability to view, edit, and override AI-generated categorizations.

Nothing in this Privacy Policy shall be interpreted as granting Rize any ownership rights in your User Data or Generated Content.

Is Information Collected by or Disclosed to Third Parties?

Rize does not sell the data collected through your use of the Platform with any third party. Information is collected to facilitate the Services offered or for internal analysis relating to product improvements. Information collected is shared with the following third parties to facilitate provision of the Services on the Platform as follows:

Email Processing. Rize utilizes Postmark for its email delivery services, including, inbound processing, notifications and metrics for email open, bounce and delivery events, etc. Information is collected and utilized in accordance with Postmark's Privacy Policy.

Website Performance Monitoring. Rize utilizes New Relic to measure and monitor the performance of its application and infrastructure. Information is collected and utilized in accordance with New Relic's Privacy Policy.

Error Tracking. Rize utilizes Rollbar for real-time error tracking and crash reports. Information is collected and utilized in accordance with Rollbar's Privacy Policy.

Subscriber Communications. Rize utilizes Mailchimp to assist in customizing its newsletters, customer communications and other marketing campaigns to its Subscribers. Subscribers should review Mailchimp's Privacy Policy for more information about their data collection and use practices.

Analytics. Amplitude collects non-personally identifiable information regarding the behavior and usage patterns of users of the Platform in accordance with Amplitude's Privacy Policy.

Credit or Debit Card Information. Rize does not itself store debit or credit card information on its servers. We work with a third party payment processor, Stripe, to manage and process payments in order to guarantee the security of your information. You should review Stripe's Privacy Policy before using the Platform and use available controls and settings on your device to reflect your preferences.

Other Potential Third-Party Disclosures. Information may also be disclosed to third parties (1) as required by law, such as to comply with a subpoena, or similar legal process; (2) when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request, or (3) if Rize is involved in a merger, acquisition, or sale of all or a portion of its assets.

We will use commercially reasonable efforts to notify users (i) about law enforcement or court ordered requests for data unless otherwise prohibited by law, or (ii) if your personal information is to be disclosed or transferred and/or becomes subject to a different privacy policy.

How Does Rize Comply with the Children's Online Privacy Protection Act?

Only persons age 18 or older are authorized to create a Rize account. We do not knowingly collect information from children under the age of 13 without parental consent. If a parent or guardian becomes aware that his or her child has provided us with information without their consent, he or she should contact us at support@rize.io. We will delete such information from our files within a reasonable time.

How Long Does Rize Retain Information Collected?

Rize will retain Subscriber data for a commercially reasonable time and as we deem necessary to provide our Services to our users. If you would like us to delete your registered account information, please contact us at support@rize.io and we will respond in a reasonable time.

What is Rize's Security Policy?

We have implemented reasonable administrative, technical and physical security measures to protect your personal information against unauthorized access, destruction or alteration in accordance with industry best practices. However, although we endeavor to provide reasonable security for information we process and maintain, no security system can ever be 100% secure.

Rize utilizes only PCI-DSS compliant third party payment processors to ensure the security of your personal information. Users should review Stripe's Security Policy for more information on their security practices.

How Does Rize Respond to "Do Not Track" Signals?

"Do Not Track" is a feature enabled on some browsers that sends a signal to request that a web application disable its tracking or cross-Platform user tracking. At present, Rize does not respond to or alter its practices when a Do Not Track signal is received.

Your Privacy Rights

Depending on your location, applicable privacy laws (including the EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the CPRA, and other U.S. state privacy statutes) may grant you the following rights with respect to your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that we correct inaccurate or incomplete personal information.
  • Deletion — request that we delete your personal information, subject to certain legal exceptions.
  • Portability — receive your personal information in a structured, commonly used, machine-readable format.
  • Restriction — request that we limit processing of your personal information under certain circumstances.
  • Objection — object to processing of your personal information where we rely on legitimate interests as the legal basis.
  • Withdraw Consent — where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.

Rize does not sell your personal information and does not use it for cross-context behavioral advertising. You will not receive discriminatory treatment for exercising any of these rights.

To exercise any of these rights, contact us at support@rize.io. We will respond within the timeframe required by applicable law (generally 30 days for GDPR requests and 45 days for CCPA requests). We may ask you to verify your identity before fulfilling a request.

If your data is processed on behalf of a workspace administrator, we may direct your request to that administrator. For details on how Rize processes data as a service provider, please review our Data Processing Agreement.

How Will I Be Notified of Changes to Your Privacy Policy?

If Rize makes material changes to its Privacy Policy, it will notify you either by: (i) changing the Effective Date at the top of the Privacy Policy, (ii) sending an email to its account holders, and/or (iii) adding a statement to the Platform.

You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

Contact Us

If you have any questions regarding our data collection and use practices, please contact us via email at support@rize.io.