Back to Reva
Legal

Privacy Policy

Last updated: May 2026  ·  Effective immediately upon use

Read alongside our Terms of Service


01

Who we are

Reva is an AI-powered companion application, a product of Celesyn Labs ("we", "us", "our"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use Reva.

For privacy-related enquiries, contact us at: celesynlabs@gmail.com


02

What data we collect

We collect only what is necessary to operate the service:

  • Account data: email address, account creation date, premium subscription status
  • Usage data: message count, feature usage, session timestamps
  • Payment data: transaction status and order ID via Razorpay. We do not store card numbers or banking details — these are handled entirely by Razorpay.
  • Conversation content: messages you send to Reva are processed in real-time by our AI infrastructure. See §05 for details of how third-party providers handle this data.
  • Device/technical data: browser type, device type, IP address, and basic error/crash logs for service stability.
Please do not submit passwords, financial credentials, government identification numbers, or confidential third-party information through Reva conversations. We do not collect government ID, financial account details, precise location, biometric data, or sensitive health records — but sensitive information you share in conversation may be processed by our AI infrastructure providers.

03

How we use your data

We use your data to:

  • Operate and authenticate your account
  • Deliver AI responses via our language model infrastructure
  • Process payments and manage subscription status
  • Enforce usage limits (message count tracking)
  • Detect abuse and ensure service security
  • Improve and maintain the service

We do not use your data for advertising, profiling for third-party marketing, or sale to any third party.


04

Legal basis for processing (GDPR)

For users in the European Economic Area (EEA) and UK, we process your data under the following legal bases:

  • Contract performance: account data, message delivery, payment processing — necessary to provide the service
  • Legitimate interests: security, abuse prevention, error logging — balanced against your privacy rights
  • Consent: where we ask you specifically before processing (e.g. optional analytics)
  • Legal obligation: where required by applicable law

05

Third-party processors

We use the following third-party services to operate Reva. Each acts as a data processor under our instructions:

  • Supabase — database and authentication (account data, message counts). Servers may be located in the US or EU depending on configuration.
  • Vercel — hosting and serverless infrastructure. Request logs may be temporarily retained by Vercel for operational and security purposes per their own data retention policy.
  • Groq — processes your conversation messages in real-time to generate Reva's responses. Your messages are transmitted to Groq's API and may be temporarily retained by them for security, abuse prevention, or operational purposes in accordance with Groq's privacy policy at groq.com/privacy-policy.
  • Razorpay — payment processing for Android and web users. Razorpay's own privacy policy governs payment data.
  • Apple In-App Purchase (StoreKit) — payment processing for iOS users. Apple's own privacy policy governs payment data collected through this service.

We do not sell your data to any of these parties or to anyone else.


06

Conversation data and storage

We do not intentionally permanently store full conversation histories on our own servers beyond what is technically necessary to provide the service. Temporary processing or retention may occur through our infrastructure providers for security, abuse prevention, debugging, or operational purposes in accordance with their respective policies.

Message count data (a number, not message content) is stored in Supabase to enforce usage limits. This is not a record of your conversations.


07

International data transfers

Reva is operated from India. By using Reva, you acknowledge that your data may be transferred to and processed in countries outside your own, including India, the United States, and the EU, where our infrastructure providers are hosted.

For EEA/UK users: where data is transferred outside these regions, we rely on Standard Contractual Clauses (SCCs) or equivalent mechanisms as required by GDPR.


08

Data retention

We retain your data for as long as your account is active or as needed to provide the service.

  • Account data: retained until account deletion
  • Message count and usage data: retained for the duration of your account
  • Payment records: retained for up to 7 years as required by applicable financial laws
  • Conversation content: not intentionally stored beyond session processing on our own servers
  • Logs/technical data: retained for up to 90 days

After account deletion, residual data may persist in backups for up to 30 days before permanent removal.


09

Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of your personal data
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your account and associated data
  • Portability: request your data in a machine-readable format (EEA/UK users)
  • Objection / restriction: object to or restrict certain processing (EEA/UK users)
  • Opt-out of sale: we do not sell data, so this right is satisfied by default (California users)
  • Withdraw consent: where processing is consent-based, you may withdraw at any time

To exercise any of these rights, contact us at celesynlabs@gmail.com. We will respond within the timeframe required by applicable law (typically 30 days, with extensions permitted where allowed by law). We may ask you to verify your identity before processing the request.

EEA/UK users also have the right to lodge a complaint with your local data protection authority.


10

Account deletion

You may request deletion of your Reva account via the app settings or by contacting us at celesynlabs@gmail.com. Upon verified request, we will delete your account and associated data within 30 days, subject to retention obligations under applicable law (such as payment records required by financial regulations).

After deletion, residual copies may remain in encrypted backups for up to 30 days before permanent removal.


11

Children's privacy

Reva is intended for users aged 17 and above. We do not knowingly collect personal data from anyone under 17. If we become aware that a user under 17 has provided personal data, we will delete that data and terminate the account promptly.


12

Cookies and tracking

Reva uses minimal cookies and local storage strictly necessary to operate the service — for authentication session management and preference storage. We do not use third-party advertising cookies or cross-site tracking technologies.

Push notifications: if you grant permission, Reva may send push notifications to your device. We collect and store a device token solely for the purpose of delivering these notifications. You can revoke notification permission at any time via your device settings. Device tokens are not shared with third parties for advertising or tracking purposes.

If we introduce optional analytics in the future, we will update this policy and seek consent where required by law.


13

Automated processing

Reva uses automated AI systems to generate all responses. No human reviews your conversations in real-time. Outputs are generated algorithmically and may be inaccurate, incomplete, or contextually inappropriate. You should not rely on Reva's responses as authoritative without independent verification.

We do not use your data for automated decision-making that produces legal or similarly significant effects on you.


14

Security

We implement reasonable technical and organisational security measures to protect your data, including encrypted connections (HTTPS/TLS), server-side API key storage, and access controls via Supabase authentication. No system is completely secure and we cannot guarantee absolute security of your data.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.


15

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice within the app prior to taking effect. The "last updated" date at the top of this page reflects the most recent version. Your continued use of Reva after changes constitutes acceptance of the updated policy.

Privacy questions or data requests: celesynlabs@gmail.com
Terms of Service Reva · Celesyn Labs