Legal
Privacy Policy
Effective 2026-07-07
Revent AI Lab is operated by Revent ("we", "us", "our"). This policy explains what data we handle, how we protect it, and the choices you have. In plain terms: for the business data you bring into your workspace — such as your emails, files, or contracts — you are the data controller and we act as your processor, handling it only on your instructions; for your own account and billing data, we are the controller. We handle personal data in line with applicable data-protection law, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
1. What we collect
Account data: name, email, password hash (never stored in plaintext), OAuth account identifiers when you sign in with Google.
Workspace data: workspace name, industry, website, country, and any data you explicitly connect an agent to on your behalf — for example Google Search Console and Analytics metrics, and, only where you choose to connect them, Gmail messages, Google Calendar events, Google Drive files, and contracts you upload. An agent only accesses a source after you grant it access, and only with the narrowest permission its feature needs — for Google Drive, access is limited to the specific files you pick.
Billing data: Stripe customer id and subscription state. We never see or store your card number — Stripe handles that and is PCI-DSS compliant.
Operational data: session metadata (IP address, user agent, last active timestamp) for security and abuse prevention. Audit log of significant actions (agent install, coupon apply, workspace settings change).
2. How we use it
- Provide the Service and keep it running.
- Bill you for the agents you install.
- Send transactional email (signup verification, password reset, install confirmation) via Resend.
- Detect and prevent abuse (brute-force, credential stuffing, scraping).
- Improve the Service via aggregate, anonymized usage signals.
3. How we protect it
Workspace data is encrypted at rest with per-workspace data encryption keys (DEKs); each DEK is encrypted with a master key encryption key (KEK) held only in our production environment. Sessions are signed and rotated. OAuth tokens for third-party services (Google, etc.) are encrypted with the same envelope scheme before being persisted.
4. Sub-processors
To run the Service we rely on a small set of vetted sub-processors, each bound by a data-processing agreement. We never sell your data or share it for advertising.
- Anthropic (Claude) — the AI that powers your agents' reasoning. Anthropic is contractually prohibited from using your data to train its models, and deletes the data it processes within 30 days by default.
- Voyage AI — turns your content into the numerical embeddings that let agents search it. Configured so your content is not used to train any models and is not retained after it is processed.
- Groq — high-speed AI inference for features such as transcription. Contractually barred from using your data for training, and does not retain it after processing.
- Google — only when you connect a Google-based feature (Gmail, Calendar, Drive, Search Console, or Analytics). Access is limited to the account you connect and to the narrowest permission each feature needs — for Drive, only the specific files you pick. We only read your data (except where you explicitly enable an agent to send email from your account) and never modify or delete it. Your access tokens are stored encrypted.
- Stripe — billing, payment method storage, invoice delivery.
- Resend — transactional email delivery.
- Neon — managed Postgres database hosting (London / AWS eu-west-2).
- DigitalOcean & Cloudflare — application hosting and network protection (including DDoS mitigation and a web application firewall). They handle technical connection data such as IP addresses, not your business content.
None of our AI providers use your content to train their models — this is a contractual commitment, not merely a setting. Your content is processed only to generate your results and is then discarded under each provider's retention terms.
Google user data — Limited Use. Revent AI Lab's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google Workspace APIs (Gmail, Google Calendar, Google Drive) is used only to provide and improve the user-facing features you enable; it is never used for advertising, never sold or transferred to data brokers, and is never used — by us or by our AI providers — to develop, improve, or train generalized artificial-intelligence or machine-learning models.
We do not sell your data, share it for advertising, or expose it to third parties outside this list without your explicit consent or a legal obligation.
5. Your rights
Depending on where you live (GDPR, CCPA, etc.) you may have rights to access, correct, export, or delete your personal data. You can:
- Edit your profile at /app/account.
- Edit your workspace at /app/settings.
- Cancel any agent at any time from /app/marketplace; cancel your subscription on /app/billing.
- Email admin@revent.store for export or deletion requests not yet self-service.
6. Retention
Active workspace data is retained for as long as your account is active. On account deletion, encrypted data is permanently destroyed via cryptographic erasure of the workspace DEK; backups are purged within thirty (30) days. Audit log entries are retained for two (2) years for security forensics.
7. Cookies
We use cookies only for authenticated sessions (Better Auth's session cookie) and CSRF defense. We do not run third-party advertising trackers. We may add first-party analytics (e.g. self-hosted Plausible) with appropriate consent before opening to general availability.
8. International transfers
Your workspace data is hosted in the United Kingdom (London / AWS eu-west-2). To deliver the Service, some data is transferred to sub-processors in the United States — our AI providers (Anthropic, Groq, Voyage), Stripe, and Resend. Where data moves outside your country, we rely on appropriate contractual safeguards — data-processing agreements and standard contractual clauses that bind each recipient to protect your data — and, where required, on your consent. Your rights over your data remain effective wherever it is processed. If you are in the UAE, this section provides the cross-border-transfer transparency expected under Federal Decree-Law No. 45 of 2021.
9. Children
The Service is not directed to children under sixteen (16). We do not knowingly collect data from children.
10. Changes to this policy
Material changes will be communicated via the email on file at least fourteen (14) days before they take effect. The latest version is always at /privacy.
11. Contact
Privacy questions: admin@revent.store.