Split identity and data planes
Rilev separates account access from assessment content so a normal readable identity-to-answer join is not part of the product model.
A plain-English explanation of the architecture Rilev has filed around privacy-preserving assessment access, data separation, recovery, and key rotation.
Rilev has filed a patent application for core parts of its anonymous lifecycle architecture. Patent pending means an application has been filed. It does not mean a patent has issued.
Rilev separates account access from assessment content so a normal readable identity-to-answer join is not part of the product model.
The system is designed around capability-style access and one-way proofs instead of trusting a browser-supplied account identifier alone.
Recovery flows are scoped to restore access without turning Rilev into a holder of the person behind the assessment.
Key rotation is designed so access can change over time while minimizing the creation of permanent cross-context links.
The goal is not only to protect stored records. It is to shape the product so private assessment answers do not become ordinary account-profile data in the first place.
That architecture supports Rilev's broader privacy model: anonymous assessment access, separated records, bounded recovery, and controlled handoff to product experiences that need payment or fulfillment.