Privacy Policy
Effective Date: May 12, 2026 · Last Updated: June 19, 2026
Revella, Inc. ("Revella," "we," "us," or "our") operates revella.ai, including the Companion chat service at revella.ai/companion (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
Revella is an AI-powered strategic partner for women navigating divorce with complex financial assets. Because our Service handles sensitive personal and financial information during a vulnerable time in your life, we take your privacy seriously and aim for full transparency in this document.
1. Information We Collect
We collect information in the following categories:
Account Information
- Email address (used for magic-link authentication; we do not collect or store passwords)
- Authentication tokens managed by Supabase Auth
Waitlist Information
- Name
- Email address
- State of residence
- Brief description of your situation (optional, if provided)
Conversation Data
- Messages you send to the Companion
- Responses generated by the Companion
- Conversation metadata (timestamps, session identifiers)
Structured Case File Data
As you interact with the Companion, we extract and store structured information to maintain continuity across your sessions:
- A case file snapshot (summary of your situation, assets, key facts)
- Asset inventory entries
- Deadlines and important dates
- Open questions you and the Companion are tracking
Uploaded Documents
When you upload a document to your case file (for example a PDF, spreadsheet, or image), we store the file itself along with structured information we extract from it:
- The file itself, stored in a private Supabase Storage bucket reserved for case documents
- File metadata (filename, MIME type, size, upload timestamp, internal storage path, and any note you attached)
- A categorization tag assigned by the Companion (for example, "Tax Return" or "Brokerage Statement")
- A text extraction and short summary the Companion uses to reason about the file in future sessions
Uploaded documents are encrypted at rest by Supabase and transmitted only over TLS. A row-level security policy at the storage layer ensures only you can read or list the files under your account — no other user, and no member of the internal AI agent team, has access. You can request deletion of any individual uploaded document, or of every document in your case file, at any time (see Section 6: Data Retention).
Artifact Data
- Generated artifacts (asset inventory templates, exports, mediation briefs, and other structured documents the Companion produces for you)
- Artifact metadata (type, creation date, unique URL slug)
Technical Data
- We use Vercel for hosting, which may collect standard server logs (IP addresses, browser type, referring pages). We do not operate our own analytics or tracking systems.
What We Do Not Collect
- Passwords (we use passwordless magic-link authentication)
- Payment or credit card information (the Service is currently in free beta)
- Social Security numbers or government-issued identification numbers
- Browser cookies for tracking or advertising purposes
- Data from third-party social media accounts
- Location data beyond what you voluntarily provide (e.g., your state of residence)
2. How We Use Your Information
We use your information for the following purposes:
To provide the Service
- Authenticating your identity via magic-link email
- Generating Companion responses tailored to your situation
- Maintaining your case file across sessions so the Companion remembers your context
- Producing artifacts (exports, templates, briefs) that you request
To maintain context and continuity
- After each conversation turn, a separate AI model (Claude Haiku by Anthropic) summarizes key facts from your conversation and writes them to your structured case file. This ensures the Companion retains important details across sessions without requiring you to repeat yourself.
To monitor service quality and costs
- We track aggregate API usage costs via an internal admin dashboard. This data is not tied to individual user identities in the dashboard view.
To communicate with you
- Sending magic-link authentication emails
- Service-related notifications if applicable in the future
We do not use your information for:
- Advertising or marketing to third parties
- Selling or renting your data to anyone
- Building user profiles for purposes unrelated to the Service
- Training AI models (see Section 3)
3. AI Processing and Your Data
Revella uses AI models provided by Anthropic to power the Companion. Specifically:
- Claude Sonnet 4.5 — powers the Companion's conversational responses and artifact generation (tool-use turns)
- Claude Haiku — powers the case-file summarizer that extracts structured facts after each conversation turn, and the conversation summarization safety net for long sessions
Your conversations are not used to train AI models.
Revella accesses Anthropic's models via the Anthropic API. Under Anthropic's API Terms of Service and Usage Policy, data submitted through the API is not used by Anthropic to train or improve their models. Your conversations remain your own.
Anthropic may process your messages temporarily in order to generate responses, but does not retain conversation content for training purposes. For full details, refer to Anthropic's Privacy Policy and API Terms at anthropic.com.
What the AI sees:
- When you send a message, the Companion receives your message along with relevant context from your case file and recent conversation history
- The case-file summarizer receives conversation content to extract structured facts
- Neither model retains memory between API calls beyond what we explicitly store in your case file in our database
Limitations of AI processing:
- AI-generated responses may contain errors or inaccuracies
- The Companion is not a lawyer, financial advisor, or therapist
- All Companion outputs should be verified with qualified professionals before relying on them for legal or financial decisions
4. Data Security
We implement the following security measures:
Infrastructure
- Account, conversation, and case-file data is stored in Supabase, a managed PostgreSQL platform with enterprise-grade security; uploaded documents are stored in a private Supabase Storage bucket separate from the database
- Row-Level Security (RLS) policies — applied to both the database and the document storage bucket — ensure each user can only access their own conversations, case file, artifacts, and uploaded documents; no other user, and no member of the internal AI agent team, can read or list your records
- All data is encrypted at rest and in transit (TLS/SSL)
Authentication
- We use passwordless magic-link authentication via Supabase Auth
- No passwords are stored or transmitted
- Magic-link tokens expire after use
Access Controls
- Only the founder has access to the internal admin dashboard (gated by ADMIN_EMAILS environment variable)
- No Revella team member or AI agent has access to individual user conversations or case files outside of the Companion's own processing
- The internal AI agent team (which handles marketing, content, and operations) does not have access to Supabase customer data
Hosting
- The Service is hosted on Vercel with automatic deployment from a private GitHub repository
- API endpoints run on Vercel's Edge Runtime
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
5. Third-Party Service Providers
We use the following third-party providers to operate the Service:
| Provider | Purpose | Data They Process |
|---|---|---|
| Anthropic | AI model provider (Claude Sonnet 4.5, Claude Haiku) | Conversation messages and context sent via API for response generation. Not retained for training per Anthropic API Terms. |
| Supabase | Database, authentication, and file storage | All user data (account info, conversations, case file, artifacts, and uploaded documents). Stored with row-level security and encryption. |
| Vercel | Hosting and edge compute | HTTP requests and standard server logs. May include IP addresses and browser metadata. |
Each provider processes data under their own terms of service and privacy policies. We select providers that maintain security standards appropriate for sensitive personal data.
We do not share your data with advertising networks, data brokers, or any other third parties not listed above.
6. Data Retention
We retain your data as follows:
- Account, conversation data, and uploaded documents: Retained for as long as your account is active. If you request account deletion, we will delete your account, conversation history, case file, uploaded documents, and artifacts within 30 days of your request.
- Waitlist data: Retained until you convert to an active account or request removal.
- Technical logs: Vercel server logs are retained per Vercel's standard data retention policy and are not under our direct control.
Your deletion rights:
You may request deletion of your account and all associated data at any time by contacting us at privacy@revella.ai. Upon receiving a verified deletion request, we will:
- Delete your user account
- Delete all conversation history
- Delete your structured case file and all entries
- Delete all uploaded documents from Supabase Storage
- Delete all generated artifacts
- Remove your information from the waitlist (if applicable)
Deletion is permanent and cannot be undone.
7. Your Rights Under California Law (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting the information, and the categories of third parties with whom we share it.
Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions.
Right to Correct
You have the right to request correction of inaccurate personal information.
Right to Opt-Out of Sale or Sharing
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
Categories of Personal Information Collected (CCPA categories):
| CCPA Category | Examples from Revella | Sold? | Shared for Advertising? |
|---|---|---|---|
| Identifiers | Email address, name | No | No |
| Internet or network activity | Conversation content, session data | No | No |
| Professional or employment information | Only if voluntarily shared in conversation | No | No |
| Inferences | Case file structured data extracted by AI | No | No |
To exercise any of these rights, contact us at privacy@revella.ai. We will verify your identity before processing your request.
8. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe a child under 18 has provided us with personal information, please contact us at privacy@revella.ai.
9. International Users
Revella is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify active users via the email address associated with their account
- Post the updated policy on our website
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
11. Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled, contact us at:
Email: privacy@revella.ai
Mailing address: Available upon request.