Skip to legal content
Reva
PrivacyTermsData deletion

Legal

Privacy policy

This policy explains which data Reva processes, why it is needed, which service providers are involved, and the choices available to customers and users.

Effective
17 July 2026
Contact
personaflowai@gmail.com

1. Scope

This policy applies to Reva websites, pilot workspaces, Customer Desk features, and support interactions. A customer organization controls which business sources and team members it authorizes. Reva processes that data only to provide, secure, support, and improve the agreed service.

A customer organization remains responsible for its own notices, permissions, and lawful use of employee, customer, vendor, and WhatsApp data.

2. Data we process

Account and workspace data

Names, business contact details, organization membership, role, authentication records, and workspace settings.

Authorized business data

Data a customer chooses to connect or upload, such as customer and vendor details, Gati or Excel records, orders, quotations, service matters, source receipts, approved notes, commitments, and next actions.

Customer Desk communication data

For connected WhatsApp Business assets, this may include business phone identifiers, customer phone identifiers, message content and media, direction, timestamps, delivery state, template and consent records, connection health, and the exact business number involved. Unsupported personal calls or WhatsApp groups are not represented as passively captured data.

Service and support data

Security and audit events, error and performance metadata, support correspondence, and information submitted through the public interest form. Product analytics, when enabled, exclude customer messages, source rows, model context, and ordinary business payloads.

3. Why we use data

  • Provide authenticated, organization-scoped product features.
  • Connect authorized sources and prepare source-backed business work.
  • Route, display, draft, review, and audit approved Customer Desk activity.
  • Protect accounts, investigate abuse, prevent duplicate or unauthorized actions, and maintain reliability.
  • Respond to support, deletion, security, and legal requests.
  • Measure product quality with bounded metadata rather than customer content.

Reva does not sell personal data or use customer operational content for third-party advertising. Customer content is not used to train general-purpose models by default.

4. Service providers and connected platforms

Reva uses providers only for the service functions they supply. Depending on the configured workspace, these may include:

  • Meta and WhatsApp for authorized WhatsApp Business onboarding, messaging, delivery events, and customer-owned assets.
  • Supabase for authentication, organization-scoped database services, and protected storage.
  • OpenAI for bounded model processing when an approved workflow is configured to use it.
  • Vercel for hosted application delivery and operational infrastructure.
  • Web3Forms for information submitted through the public interest form.

These providers may process data in the countries where they operate, subject to their contractual, security, and legal safeguards. A customer may request the current provider list for its configured service.

5. Retention and deletion

Retention follows the workspace setting, source type, and approved business purpose. Uploaded working data is ephemeral by default. Approved corrections, relationship facts, cases, commitments, actions, and audit receipts may be retained separately when the customer asks Reva to remember them.

Customer Desk keeps raw communication retention separate from approved operational records. Deleting a raw message or media object does not silently turn an approved note into a transcript, and access to a derived task does not grant access to restricted source content.

Requests are handled through the data deletion instructions. Limited records may remain where necessary for security, fraud prevention, legal obligations, dispute handling, or time-limited backups; those records remain restricted and are removed under the applicable schedule.

6. Security and access

Reva uses organization isolation, authenticated access, server-side credentials, least-privilege permissions, audit receipts, and deletion controls appropriate to the feature. No internet service can guarantee absolute security. Customers should report suspected unauthorized access promptly and should never send passwords, access tokens, or full exports through ordinary email.

7. Choices and rights

Subject to applicable law, a person may ask to access, correct, export, restrict, object to, or delete personal data. The organization that provided the data may need to handle the request first because it controls the business relationship and authorization. Reva will assist verified requests and explain any lawful limitation.

8. Updates and contact

Material changes will be posted here with a revised effective date. Questions about this policy or a privacy request can be sent using the contact address above. Please describe the organization and request without attaching customer exports, message histories, passwords, or platform tokens.

Reva · Built for controlled, source-backed business work.

Contact