Legal

Privacy Policy

Last updated 30 August 2026 · Vrevoil Tech

In plain language

VREVOIL stores what you deliberately put into it: sources you capture and the claims, assumptions and decisions committed from them. Everything is scoped to your workspace and enforced by the database, not just the interface. We do not sell your data, we do not run advertising or third-party tracking, and in this prototype your content is not sent to an external AI model. Because VREVOIL is a knowledge-state system, it supersedes and archives rather than silently deletes — and this document explains what that means for you.

1. Who this covers

This policy describes how Vrevoil Tech (“we”) handles personal data in VREVOIL, a knowledge-state application. It applies to the VREVOIL web application and nothing else. It is written against how the product actually works today; when the product changes in a way that affects this document, we update the document.

2. What we collect, and why

Account data. To create an account you provide an email address and a password, or you sign in with Google. Passwords are handled by our managed authentication service and are never stored in readable form or visible to us. If you sign in with Google, we receive your email address, and your name and profile image where Google supplies them. We use this only to identify your account and scope your workspace.

Content you put in. VREVOIL stores what you create and capture: workspace and cabinet names, knowledge subjects, and sources — ideas, pasted text, links, meeting notes, imported conversations and uploaded files. It also stores the governed state derived from those sources: claims, assumptions, decisions, evidence links and knowledge commits. This content may contain personal data about you or third parties, because you decide what goes in. Section 8 sets out your responsibility for that.

Uploaded files. Files you upload are stored in a private storage bucket, under a folder keyed to your workspace. They are not public, are not indexed by search engines, and are readable only by members of that workspace.

Activity and governance records. VREVOIL is built around an auditable history, so it records state events (what changed in a subject, and when), governance records for commits (proposed, accepted, modified or rejected, and by whom), and technical records of AI operations: which operation ran, which provider and model version, latency, status and a correlation identifier. AI operation records deliberately do not contain your source text.

Technical data. Our hosting and backend providers process the ordinary technical data required to serve the application — IP address, timestamps, request paths and error diagnostics — for security, abuse prevention and debugging. We do not build advertising or behavioural profiles from it.

3. What we do not do

  • We do not sell, rent or trade your personal data or your content.
  • We do not run advertising, ad networks, or third-party analytics or tracking pixels.
  • We do not use tracking cookies. Browser storage is used to keep you signed in and to remember interface preferences — every item is listed in our Cookie Policy.
  • We do not use your captured content to train models.
  • We do not read your workspace content out of curiosity. Access by our staff happens only where you ask us for support, or where we must investigate a specific security or integrity problem.

4. Legal bases for processing

Where data-protection law requires a legal basis, we rely on: performance of a contract (operating the account and the service you asked for); our legitimate interests (keeping the service secure, preventing abuse, maintaining the audit history that makes VREVOIL function); your consent, where you optionally choose Google sign-in; and compliance with legal obligations where they apply to us.

5. Who can see your data

Every table in VREVOIL is protected by workspace-scoped access rules enforced in the database itself, not merely hidden in the interface. A signed-in user can only read or write rows belonging to a workspace they are a member of. Uploaded files are constrained the same way by workspace path. Members of your workspace can see the content of that workspace; nobody outside it can.

6. Artificial intelligence

VREVOIL proposes; you decide. Extraction of candidate claims, comparison against existing state, answers in Ask VREVOIL, and the resume brief are all generated inside the application by a deterministic component in this prototype. Your captured content is not transmitted to an external model provider today.

If we later introduce an external model provider, we will update this policy and identify the provider before that processing begins. Nothing an AI component produces becomes authoritative state in VREVOIL until a person reviews and accepts it.

7. Service providers we rely on

We use a small number of processors to run VREVOIL: our application hosting provider, and the managed backend that provides the database, authentication and file storage. Google is involved only if you choose Google sign-in. These providers process data on our instructions in order to deliver the service, and for no independent purpose of their own. We do not add advertising, marketing or analytics vendors.

8. Content about other people

You control what you capture. If you upload documents, notes or conversations containing other people’s personal data or a third party’s confidential information, you are responsible for having the right to do so. Do not put content into VREVOIL that you are not permitted to store or process.

9. Retention: why VREVOIL supersedes instead of deleting

VREVOIL exists to keep knowledge state reconstructable, so its core rule is that history is not rewritten. When state changes, the previous version is marked superseded and preserved alongside the new one; rejected proposals are recorded as rejected rather than erased; and state events and audit records are append-only. This is a deliberate product property, and you should assume that anything you commit remains visible in your workspace history until the workspace itself is deleted.

Deletion. You can archive subjects and content within the app. To delete an account or an entire workspace and its stored sources, files and history, email us at legal@vrevoiltech.com from the account address. We action such requests within 30 days. Backups and system logs may retain copies for a short additional period before they age out, and we may retain the minimum necessary to meet a legal obligation or resolve a dispute.

Content in a shared workspace cannot be unilaterally removed from other members’ history if it is part of the committed record; leaving a workspace removes your access, not the workspace’s history.

10. Your rights

Subject to your local law, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to certain processing, or provide it in a portable form. Much of this you can do yourself inside the app; for the rest, write to legal@vrevoiltech.com. We will not treat you worse for exercising these rights. If you are unhappy with our response, you may complain to your local data-protection authority.

11. Security

Data is transmitted over encrypted connections, authentication and session handling are delegated to a managed provider, database access is constrained by row-level policies tied to workspace membership, uploaded files sit in a private bucket, and privileged operations run only on the server — never in your browser. Internal helper functions used by access policies are not callable through the public API.

No system is immune to compromise, and we make no guarantee of absolute security. If we become aware of a breach affecting your personal data, we will notify you and any required authority without undue delay, describing what happened and what we are doing about it.

12. Location of processing

VREVOIL is delivered through globally distributed infrastructure, so your data may be processed in countries other than your own, including outside the EEA and the UK. Where such a transfer requires a safeguard, we rely on our providers’ standard contractual protections.

13. Children

VREVOIL is a professional tool and is not directed at children. Do not use it if you are under 16, or under the minimum age of consent in your country if that is higher. If we learn we have collected a child’s data, we will delete it.

14. Changes to this policy

If we change this policy we update the date at the top, and for material changes — particularly any change to how AI processing works or which providers are involved — we notify account holders before the change takes effect.

15. Contact

Write to Vrevoil Tech at legal@vrevoiltech.com. See also our Terms of Service.

Questions about this document? Contact Vrevoil Tech at legal@vrevoiltech.com.