Legal

Privacy Policy

A compact view of what Revelar processes, why it is needed, how long it is kept, and how to exercise your rights.

Last updated: 2026-08-13

1. Data Controller

Revelar is a trading name of Lucas Van Houtven, Bautersemstraat 3 bus 201, 2550 Kontich, Belgium, enterprise and VAT number BE 1024.931.197. Revelar is the controller for account and product data it controls. For patient data entered during clinical use under a customer data processing agreement (DPA), the customer organisation is the controller and Revelar acts as processor on its instructions. Conditions for processing health data under Article 9 GDPR are the customer-controller's and are exercised through the Article 28 DPA. For privacy inquiries, contact privacy@revelar.xyz. For support, contact support@revelar.xyz.

2. Data We Process

Account Data

Email address, authentication identifiers, profile fields, settings, billing state, and organization membership data.

Workspace Report Text

Report text can be processed during active AI and dictation workflows, but Revelar does not keep it as a server-side report archive.

Usage Metadata

Product, billing, credit, and safety metadata needed to run the service.

Technical Data

Session, device, diagnostic, and security metadata needed for authentication, abuse prevention, debugging, and reliability.

Dictation Voice Audio

When you dictate, voice audio is sent to a configured third-party speech-to-text provider to produce the transcript that appears in your report.

Booking and Contact Data

Contact details you send from the public site, such as your email address, an optional name, the call times you picked, and the page the request came from. They are used to schedule and answer that request.

3. Legal Basis

Contract, Article 6(1)(b)

Processing needed to provide the reporting workspace, AI assistance, dictation, and organization features you have signed up for.

Contract and legal obligation, Articles 6(1)(b) and 6(1)(c)

Processing needed for account access, authentication email, billing, settings, support, and statutory accounting duties.

Legitimate interests, Article 6(1)(f)

Security monitoring, abuse prevention, and short-retention diagnostics. The interest is keeping the service reliable and safe to use, balanced against a bounded retention period.

Consent, Article 6(1)(a)

Marketing communications are consent-based and can be withdrawn at any time.

4. Retention

Workspace report text
Active local session, not kept as server archive
AI edit review state
Active local session
Account data
Until deletion request or account lifecycle need
Security and diagnostic metadata
As needed for security, reliability, and legal obligations
Safety-audit report snippets
180 days, then deleted by a scheduled job. Each snippet is capped at 600 characters.
Developer diagnostics
30 days, then deleted by a scheduled job. May contain short transcript or report fragments.
Learned wording preferences
Until you remove them or delete your account.

5. Your Rights

To exercise these rights, email privacy@revelar.xyz or use the account data export page.

  • Access your personal data through the data export feature or privacy request.
  • Request correction of inaccurate personal data.
  • Request deletion of your account and personal data, subject to legal retention duties.
  • Receive exportable account data in JSON format.
  • Object to processing where applicable.
  • Withdraw consent for marketing communications at any time.
  • Request restriction of processing where Article 18 applies.
  • Lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorite de protection des donnees), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be.

6. AI Processing

AI requests may process current report text when the user asks for assistance. Live dictation sends voice audio to a configured third-party speech-to-text provider to convert speech into editable text. Vendor retention and no-training evidence is tracked per AI route and per dictation route before stronger public claims are made. Short pieces of terminology you endorse can also be reused as recognition vocabulary for other users, but only when the model judges the term reusable and free of patient data; no report text, transcript, or patient context is shared with it, and you can have a shared term retired by emailing privacy@revelar.xyz.

7. Processors

Supabase

Authentication, database, account data, organization data, and RLS-backed storage.

Vercel

Hosting, serverless runtime, and deployment infrastructure.

Google

OAuth sign-in where users choose Google authentication.

Resend

Authentication email through Supabase SMTP and support email from support@revelar.xyz. Email must not contain clinical report content.

Realtime dictation provider

Converts dictated voice audio into editable text during live dictation. The specific provider is configured per deployment, and voice audio is processed by this provider to produce the transcript.

AI model providers via the Vercel AI Gateway

Process current report text to produce the wording, formatting, and structure proposals you request. The specific providers are reached through the gateway and may process outside the EU.

Stripe

Payment and subscription billing for paid plans. It receives billing and account identifiers, never report content.

Sentry

Runtime error monitoring. It receives error metadata only, not report text, request bodies, or headers.

8. Cookies and local storage

Revelar uses necessary authentication cookies and local browser storage for requested product functions such as sessions, workspace state, language, organization selection, and first-use warnings. Revelar uses no analytics, advertising, or third-party tracking cookies.

9. International Transfers

Revelar uses EU-first processing where documented, including configured realtime dictation routes and Resend domain sending from Ireland. Provider support, account data, email metadata, and logs may involve processing outside the EU, so this is not an EU-only residency claim. Customer DPA, subprocessor list, and transfer mechanisms still need to be published before stronger transfer claims are made.

10. Security Measures

  • TLS in transit and managed provider encryption for hosted infrastructure.
  • Row-Level Security and membership checks for account and organization-backed data.
  • Workspace inactivity controls clear local workspace state.
  • Workspace report text is not kept as a server-side report archive.

11. Contact

For privacy inquiries, data subject requests, DPA questions, or complaints, contact our privacy mailbox.

privacy@revelar.xyz

12. Updates

This privacy notice may be updated as the product, processor list, DPA, and clinical deployment posture mature.