Revela Privacy Notice

Last updated: 3 July 2026

Who we are

Revela ("we") helps you understand the terms of service and privacy practices of the digital services you use, and measures your privacy maturity. We are a data controller under the Kenya Data Protection Act, 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).

What we collect and why

What we don't do

Your rights

Under the Kenya DPA (ss. 26, 40) and GDPR (Arts. 15–21) you have the right to access, correct, export and delete your data, and to withdraw consent. You can exercise export and deletion instantly from Settings. Complaints can be lodged with the Office of the Data Protection Commissioner (Kenya) at odpc.go.ke or your local supervisory authority in the EU.

Retention

Your data is kept while your account is active. On deletion, all personal data is erased immediately; payment records are retained in anonymized form only, to meet financial record-keeping obligations.

Google user data and Gmail access

If you choose to use inbox auto-discovery, Revela requests the Google gmail.metadata permission only. We read message metadata (sender and date headers) and labels — never the subject lines, message bodies or attachments. This metadata is used solely to identify which online services you have accounts with, by matching sender domains, so we can present them for you to confirm. You can disconnect your inbox at any time, which revokes our access and erases the stored connection and discoveries.

Limited Use & AI

Revela's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you ask Revela to add an unrecognised service to your list, the sender's domain (for example steampowered.com) is sent to our AI processor, Anthropic, solely to generate a plain-language privacy summary of that service. Per Anthropic's Commercial Terms, data submitted through the Anthropic API is not used to train or improve Anthropic's models. Revela does not use, transfer, or sell Google user data — raw, aggregated, or derived — to train any artificial-intelligence or machine-learning model. Where Google-derived information (such as a sender's domain, or a service you confirmed from your inbox) is processed by an AI feature, it is sent only to Anthropic's commercial API and used solely to provide the user-facing feature you invoked.

Processors

Security

Sessions use signed, HTTP-only cookies. Data is stored in a access-controlled PostgreSQL database. Payment payloads to Lipad are AES-256 encrypted per their specification.

Contact

Data protection queries: privacy@eversetech.com