Privacy Policy
Last updated: August 10, 2026
1. Introduction
Revr AI, Inc. ("we," "us," or "our") operates the Revr platform at getrevr.com. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password. If you subscribe to a paid plan, we collect billing information through Stripe (we do not store credit card numbers directly).
Usage Data
We collect information about how you use the Platform, including features accessed, properties viewed, outreach sent, and AI interactions. This data is used to provide the service and improve the user experience.
Property & Contact Data
The Platform processes property information, owner data, and contact details obtained through third-party data providers on your behalf. This data is associated with your account and used to provide deal sourcing, scoring, and outreach services.
Outreach Data
If you use email or SMS outreach features, we process the content of messages sent and received through the Platform, including email addresses, phone numbers, message content, and engagement metrics (opens, clicks, replies).
Mailbox Content (only if you switch it on)
If you turn on mailbox reading for a connected Microsoft Outlook account, we process the messages in that mailbox, including senders and recipients, dates, subject lines and message bodies. It is off by default, it is never implied by connecting an account to send from, and it is not available for Gmail. Section 8 sets out exactly what is read, what is stored, for how long, and how to switch it off.
Mobile Number & Text Messaging Consent
If you opt in to receive text messages from us, we collect that mobile number, your opt-in consent and the time it was given, and the content of the messages you exchange with us. No mobile information is sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. See our SMS / Text Messaging Program section for the full terms.
Gmail API Usage & Compliance
Revr’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Send-only, never read. The Gmail API is used solely to send emails you personally compose or review and approve. Revr never reads, stores, or scans the contents of your inbox.
- Existing relationship or consent only. The Gmail API is used only to send messages to recipients with whom you have an existing business relationship or who have consented to be contacted. Cold or prospecting messages are never sent through the Gmail API — they are routed exclusively through other providers.
- No email warming. Revr does not provide email warming services for Gmail or any Google account. Any per-mailbox daily sending limits exist solely to protect your account’s health and deliverability, and are not a service to circumvent spam filtering or artificially inflate sender reputation.
- Recipient opt-out. Every commercial email sent through the Gmail API includes a working one-click unsubscribe link. Using it adds the recipient to a permanent suppression list that is enforced before any future send, so a recipient who opts out will not be emailed again through the Platform.
AI Conversations
Conversations with Reggie (our AI assistant) are stored to provide context continuity and improve the service. These conversations may include property data, investment criteria, and business preferences you share.
3. The Revr iPhone App
The Revr iOS app is a companion to your Revr account. It signs you in to the same workspace and shows the same records; there is no separate account and nothing is purchased inside the app. This section describes the device permissions the app asks for, what each one is used for, and what leaves your phone.
The app asks for a permission only at the moment the feature needs it, and never collects any of this in the background.Declining a permission disables that one feature and nothing else. You can change any of them later in iOS Settings → Revr.
Camera
Used only when you choose to photograph a building and attach the picture to that building's record. Photos you take are uploaded to your workspace's private storage and are visible to your team, exactly like a photo uploaded from the web. The app does not open the camera at any other time.
Photo Library
Used only when you choose to send an existing image to Reggie, such as a flyer, floor plan or listing sheet, so he can read it. The image is sent with that message and stored with the conversation. The app never browses or indexes your library.
Microphone
Used only while you are actively speaking to the app: dictating a message to Reggie, or taking your side of a practice call in Coach Reggie. Recording starts when you press the button and stops when you release it. The audio is sent to our speech-to-text provider to be transcribed, and it is the transcript, not the audio, that is saved to your workspace. The recording itself is written to the app's temporary cache on your phone, which iOS clears automatically, and Coach empties that cache when a practice session ends. The microphone is never opened without a press.
Location
Used only to centre the prospecting map on where you are standing, so you can scan the block in front of you. Your own position is used on the device to move the map; we do not store it, attach it to any record, or track your location in the background, and the app never reads it unless the map is open and you ask it to.
Separately, when you deliberately draw a search area or tap a specific parcel, the coordinates of that area or point are sent to our servers to run the search or look up the public record, because that is the request. Those are coordinates you chose on a map, not a reading of where your phone is.
Face ID
Optionally used to unlock the app instead of typing your password. Face ID is handled entirely by iOS: the app receives only a yes-or-no answer, and no biometric data of any kind is transmitted to us or stored by us.
Notifications
If you allow them, we send notifications about your own work, such as a reply arriving or a draft waiting for your approval. We do not send marketing notifications. You can turn them off in iOS Settings or in the app's own notification settings.
Data stored on the device
The app stores your sign-in token in the iOS Keychain, which is hardware-encrypted and erased when the app is deleted. It also keeps a small cache of records you have recently viewed so they remain readable without a connection. That cache is cleared when you sign out. Conversations, drafts and inbound messages are deliberately never cached.
Deleting your account from the app
You can delete your Revr account from within the app, under Settings → Sign in and security. Deleting removes your access immediately and permanently erases your workspace data after 30 days, the same as deleting from the web.
4. SMS / Text Messaging Program
This section describes how Revr AI, Inc. handles mobile numbers and text messaging consent. It applies to every text message program we operate.
No mobile information is sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with any third party or affiliate for marketing or promotional purposes. Mobile numbers are disclosed only to our messaging provider (Twilio) for the sole purpose of delivering the messages you asked for, and only under a contract that forbids any other use.
How we obtain your consent
You give consent directly to Revr, never through a partner, a lead vendor, or a purchased list. Consent is collected in one of two places:
- Demo requests. On our booking form at getrevr.com/book-demo you may tick an optional checkbox, unchecked by default, to receive text messages about scheduling and following up on your demo request. Submitting the form without ticking it means you will not be texted.
- Text Reggie. Inside your account you may verify your own mobile number to exchange messages with Reggie, our AI assistant, which then sends you replies to your questions, approval requests, and reminders.
Consent to receive text messages is never a condition of any purchase, and never a condition of booking a demo. We record the wording you agreed to and the time you agreed to it so we can evidence your consent on request.
What we collect and why
For these programs we collect your mobile number, your opt-in consent and its timestamp, and the content of the messages you exchange with us. We use this only to operate the messaging program you opted into.
Frequency, rates, and how to stop
Message frequency varies. Message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for help. You can also email privacy@getrevr.com. Opting out is honored immediately and permanently for that number, and it does not affect your account or your demo.
Messages our customers send
Separately from the programs above, Revr customers use the Platform to message their own contacts from their own connected accounts. In that case the customer is the sender and is responsible for obtaining consent from their recipients, and Revr acts only as the technology provider that transmits the message at their direction. See our Terms of Service for the obligations that apply to them.
5. How We Use Your Information
- To provide, maintain, and improve the Platform and its features.
- To process transactions and manage your subscription.
- To send emails and SMS messages on your behalf through your verified domain and provisioned phone number.
- To generate AI-powered property analyses, outreach copy, and recommendations.
- To track usage against your plan limits (tokens, daily pulls, skip traces).
- To send you service-related communications (billing confirmations, security alerts, feature updates).
- To detect and prevent fraud, abuse, or violations of our Terms of Service.
6. Third-Party Services
We use the following third-party services to operate the Platform. Each processes data according to their own privacy policies:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & authentication | Account data, property data, contacts |
| Google (Gmail API) | Send emails you author; never reads your inbox | OAuth tokens, sent-message metadata |
| Google (Calendar API) | Two-way sync of your own calendar events | OAuth tokens, your calendar event details |
| Microsoft (Outlook / Graph API) | Send emails you author; sync your calendar; read your mailbox if you switch that on (section 8) | OAuth tokens, sent-message metadata, calendar events, plus your Outlook message content when mailbox reading is on |
| Stripe | Payment processing | Name, email, payment method |
| Anthropic (Claude) | AI assistant & analysis | Conversation content, property data |
| Postmark | Transactional email delivery | Email addresses, message content |
| Twilio | SMS delivery & phone (your account) | Phone numbers, message content |
| BatchData | Property data & owner contact lookup | Property addresses |
| Coresignal | Business contact and company enrichment | Contact names, company info |
| Apollo.io | Business contact enrichment (optional, per account) | Contact names, company info |
| PeopleDataLabs | Contact enrichment | Contact names, company info |
| Apify | Listing data aggregation | Search parameters |
| Vercel | Hosting & deployment | Access logs, IP addresses |
7. Google API Services, Gmail & Calendar
Revr uses Google APIs to (a) send emails you author from your own Gmail account to your consented contacts, existing clients, leads who submitted your contact forms, active correspondents, and contacts you mark as your clients, and (b) display and manage events on your own Google Calendar. Recipient consent is recorded per contact and enforced server-side: Revr refuses Gmail sends to contacts without recorded consent. We do not read your Gmail inbox. Connecting Gmail and Google Calendar is optional and entirely controlled by you. (Mailbox reading, described in section 8, is a separate opt-in feature that applies to Microsoft Outlook accounts only and never to Gmail.)
What we access, Gmail
When you click "Connect Gmail", we request the following OAuth scopes from Google:
gmail.send, to send email from your account on your behalf, only for messages you compose or approve in Revr, and only to contacts with recorded consent (your clients, sphere, opted-in leads, and active correspondents).userinfo.email, to identify which Gmail account is connected and display it in Settings.
We deliberately do not request gmail.readonly, gmail.modify, or any other inbox-read scope. Replies to your outreach go directly to your own inbox, Revr never receives or reads them. If you want Reggie to help with a specific reply, you forward that one message to Reggie's inbound address, and only the message you choose to forward is processed. The rest of your inbox is never accessible to Revr.
What we access, Google Calendar
If you click "Connect Google Calendar", we additionally request:
calendar.events, to display your schedule inside Revr's Tasks calendar and to create or update events you choose to add. Sync is two-way and limited to your own calendar. We do not request the broadercalendarscope, which would also cover calendar settings and sharing.
We use your calendar data only to show your schedule and manage events inside Revr. We do not share it or use it for any other purpose, and the Limited Use commitments below apply equally to calendar data.
How we use this data
- Send messages you author within Revr to your consented contacts.
- Display the Google account you connected so you know which one is active.
- Show send status (sent / bounced) from delivery webhooks, not by reading your inbox. Replies stay in your own inbox unless you choose to forward one to Reggie.
- Show and manage your calendar events inside the Tasks calendar.
Limited Use disclosure
Revr's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not sell, transfer, or share Google user data (Gmail or Calendar) with third parties for advertising, marketing, or any unrelated purpose.
- We do not use Google user data to train or fine-tune any AI/ML model, including Reggie. AI processing of email content is limited to the in-product features the user explicitly invokes (e.g. drafting a message, or acting on a reply you forward to Reggie) and is never used for any generalized model training.
- We do not allow humans to read Google user data, except: (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations where the data has been aggregated and anonymized.
- We only access the Google user data necessary to deliver and improve the features you actively use.
Storage & encryption
OAuth access and refresh tokens are stored encrypted at rest in our database (Supabase) and transmitted over TLS. We retain only the minimum data needed to power your views: sent-message timestamps, the original outbound body you authored, the details of calendar events synced from your connected calendar, and the contents of any reply you explicitly forward to Reggie. The rest of your Gmail inbox is never transmitted to or stored by Revr.
Optional: the Gmail cold-outreach sender (app password)
Separately from the OAuth connection above, you may optionally connect a Google app password (a credential you generate yourself at myaccount.google.com/apppasswords) to send prospecting email from your own Gmail address. This sender does not use the Gmail API or the OAuth scopes above. Your app password is stored encrypted at rest (AES-256-GCM) and is used exclusively to submit outgoing messages you compose or approve via Gmail's SMTP service, never to read, list, or access any mail. You can remove it at any time in Settings → Integrations(which deletes the stored credential immediately) or revoke the app password itself from your Google Account, which cuts off Revr's access instantly.
Revoking access
You can disconnect Gmail at any time from two places:
- Inside Revr: Settings → Integrations → Gmail → Remove. This deletes your stored OAuth tokens immediately.
- From your Google Account: myaccount.google.com/connections → select Revr → Remove access.
Once revoked, Revr can no longer send email or access your calendar on your behalf. Existing outreach history saved in Revr remains visible until you delete your account or request data removal at privacy@getrevr.com.
8. Reading Your Connected Mailbox (optional)
Revr can optionally read the mailbox you connect, so that Reggie has the context of your real correspondence rather than only the messages Revr itself sent. This section describes exactly what that means. It is off unless you switch it on.
Connecting a mailbox so Revr can send on your behalf does not give Revr permission to read it. Mailbox reading is a separate choice, made separately, and it starts switched off. Turning it off again deletes the mail Revr stored.
Which accounts this applies to
Today this feature is available for Microsoft Outlook accounts only, using the Mail.Read permission you granted when you connected Outlook.
It is not available for Gmail. Revr does not request gmail.readonly, gmail.modify, or any other Gmail inbox-read permission, and cannot read a Gmail mailbox. Section 7 above describes the Gmail connection, which remains send-only. If that ever changes we will update this policy and Google’s own consent screen will ask you separately before anything is read.
What is read
When you switch it on, Revr reads the messages in your Outlook mailbox, including your Sent Items and any folders you have filed mail into, going back up to twelve months. New mail is then read as it arrives. Revr does not read your Drafts, Junk Email, or Deleted Items.
What is stored, and for how long
- For up to twelve months: the sender, the recipients, the date, whether the message was sent or received, the subject line, and the first line or two of the message.
- For ninety days: the full text of the message body. After ninety days the body is deleted automatically and only the details above remain. Messages already older than ninety days when they are first read never have their body stored at all.
- Never: attachments. Revr records whether a message had one, and does not download or store its contents through this feature.
What it is used for
One purpose: giving Reggie the context of your own correspondence inside your own workspace, so he can answer questions about a thread, tell you who is waiting on a reply, and write a follow-up that reflects what was actually said.
- We do not use your mailbox content to train or fine-tune any AI model, including Reggie.
- We do not sell, rent, transfer, or share it with third parties for advertising, marketing, or any unrelated purpose.
- We do not make it visible to your teammates. Mailbox content is private to your own account, even inside a shared workspace.
- We do not use it to build or enrich any dataset that spans customers.
- We do not allow our staff to read it, except (a) with your explicit consent, (b) to investigate abuse or a security incident, or (c) where the law requires it.
The other people in your mailbox
Reading a mailbox necessarily involves messages written by other people. Revr processes that content solely to provide this feature to you, the account holder, on the same terms set out above. It is stored under your account, deleted on the schedule above, and removed entirely when you switch the feature off.
Turning it off
You can switch mailbox reading off at any time in Settings → Integrations. Doing so stops all further reading and, by default, deletes every message Revr has stored from your mailbox. Disconnecting the Outlook account entirely, or revoking Revr’s access from your Microsoft account, has the same effect on future reading and cuts off access immediately.
9. Data Storage & Security
Your data is stored in Supabase (cloud-hosted PostgreSQL) with row-level security policies that isolate each user's data. We use encryption in transit (TLS) and at rest. Authentication tokens are managed securely and never exposed to client-side code.
Payment information is processed and stored by Stripe. We do not have access to your full credit card number.
While we implement industry-standard security measures, no system is completely secure. We cannot guarantee absolute security of your data.
10. Data Retention
We retain your account data and associated property/contact data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for reactivation, after which it is scheduled for deletion.
AI conversation history is retained for 12 months from the date of the conversation, after which it is automatically purged.
You may request data export or deletion at any time by contacting support@getrevr.com.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access , request a copy of the personal data we hold about you.
- Correction , request correction of inaccurate personal data.
- Deletion , request deletion of your personal data (subject to legal retention requirements).
- Portability , request your data in a machine-readable format.
- Opt-out , opt out of non-essential communications at any time.
To exercise any of these rights, contact us at privacy@getrevr.com.
12. Cookies & Tracking
Revr uses essential cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. We do not sell your data to advertisers or data brokers.
13. Outreach Recipients
When you use Revr to send outreach, the recipients of those messages are not our users, they are your contacts. We process their contact information (email, phone, name, address) solely to facilitate outreach on your behalf. We do not use recipient data for our own marketing purposes.
Recipients who unsubscribe from your emails or reply STOP to your SMS messages are added to a suppression list specific to your account. We honor all opt-out requests promptly.
14. Children's Privacy
Revr is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
16. Contact
For questions or concerns about this Privacy Policy or our data practices, contact us at:
Revr AI, Inc.
Email: privacy@getrevr.com
Web: getrevr.com