Account Data
Email address, authentication identifiers, profile fields, settings, billing state, and organization membership data.
A compact view of what Revelar processes, why it is needed, how long it is kept, and how to exercise your rights.
Last updated: 2026-08-13Revelar is a trading name of Lucas Van Houtven, Bautersemstraat 3 bus 201, 2550 Kontich, Belgium, enterprise and VAT number BE 1024.931.197. Revelar is the controller for account and product data it controls. For patient data entered during clinical use under a customer data processing agreement (DPA), the customer organisation is the controller and Revelar acts as processor on its instructions. Conditions for processing health data under Article 9 GDPR are the customer-controller's and are exercised through the Article 28 DPA. For privacy inquiries, contact privacy@revelar.xyz. For support, contact support@revelar.xyz.
Email address, authentication identifiers, profile fields, settings, billing state, and organization membership data.
Report text can be processed during active AI and dictation workflows, but Revelar does not keep it as a server-side report archive.
Product, billing, credit, and safety metadata needed to run the service.
Session, device, diagnostic, and security metadata needed for authentication, abuse prevention, debugging, and reliability.
When you dictate, voice audio is sent to a configured third-party speech-to-text provider to produce the transcript that appears in your report.
Contact details you send from the public site, such as your email address, an optional name, the call times you picked, and the page the request came from. They are used to schedule and answer that request.
Processing needed to provide the reporting workspace, AI assistance, dictation, and organization features you have signed up for.
Processing needed for account access, authentication email, billing, settings, support, and statutory accounting duties.
Security monitoring, abuse prevention, and short-retention diagnostics. The interest is keeping the service reliable and safe to use, balanced against a bounded retention period.
Marketing communications are consent-based and can be withdrawn at any time.
To exercise these rights, email privacy@revelar.xyz or use the account data export page.
AI requests may process current report text when the user asks for assistance. Live dictation sends voice audio to a configured third-party speech-to-text provider to convert speech into editable text. Vendor retention and no-training evidence is tracked per AI route and per dictation route before stronger public claims are made. Short pieces of terminology you endorse can also be reused as recognition vocabulary for other users, but only when the model judges the term reusable and free of patient data; no report text, transcript, or patient context is shared with it, and you can have a shared term retired by emailing privacy@revelar.xyz.
Authentication, database, account data, organization data, and RLS-backed storage.
Hosting, serverless runtime, and deployment infrastructure.
OAuth sign-in where users choose Google authentication.
Authentication email through Supabase SMTP and support email from support@revelar.xyz. Email must not contain clinical report content.
Converts dictated voice audio into editable text during live dictation. The specific provider is configured per deployment, and voice audio is processed by this provider to produce the transcript.
Process current report text to produce the wording, formatting, and structure proposals you request. The specific providers are reached through the gateway and may process outside the EU.
Payment and subscription billing for paid plans. It receives billing and account identifiers, never report content.
Runtime error monitoring. It receives error metadata only, not report text, request bodies, or headers.
Revelar uses EU-first processing where documented, including configured realtime dictation routes and Resend domain sending from Ireland. Provider support, account data, email metadata, and logs may involve processing outside the EU, so this is not an EU-only residency claim. Customer DPA, subprocessor list, and transfer mechanisms still need to be published before stronger transfer claims are made.
For privacy inquiries, data subject requests, DPA questions, or complaints, contact our privacy mailbox.
privacy@revelar.xyzThis privacy notice may be updated as the product, processor list, DPA, and clinical deployment posture mature.