# Data and privacy Updated October 3, 2026. Applies to this Rivell IT Assessment package, not to all services offered by Rivell. The released package contains instructions, reference materials, templates, and an optional offline report helper. It contains no MCP server, analytics, network collector, business-account connection, CRM integration, or separate Rivell assessment database. The optional helper does not make network requests. Installation does not give Rivell access to your chat or business systems. Your ChatGPT, Codex, workspace, and any separately enabled tools handle conversation text, uploads and tool activity under their own applicable policies. This package cannot control their storage, training settings, access, retention, or deletion. Review your organization's approved use of those products. Do not interpret this package as a promise that uploaded evidence stays on your device. The assessment asks for minimal sanitized summaries, roles, broad business activities and evidence dates. Do not include passwords, tokens, recovery codes, account lists, customer or patient records, confidential contracts, or raw security logs. An optional checkpoint/report contains whatever sanitized information you supply. You control the saved files and decide whether to share or delete them. The helper performs a limited obvious-secret check, not guaranteed redaction. No report is sent to Rivell or another provider automatically. Provider evidence requests are drafts for you to review. If you independently contact Rivell, [Rivell's published privacy policy](https://rivell.com/privacy-policy/) and any applicable engagement terms govern that separate interaction. Public package downloads are hosted on Rivell.com and governed by [Rivell's published privacy policy](https://rivell.com/privacy-policy/). For non-sensitive package support, use [Rivell's contact page](https://rivell.com/contact/) and provide only a synthetic example. Never submit credentials or company evidence when reporting a product defect.