Privacy Policy
Last updated September 2026
This Privacy Policy is issued by Revorex Technologies (Private) Limited ("Revorex", "we", "us", "our") and applies to the Revorex.ai platform.
What we collect
When you sign up, we collect your name, work email, business name, and website URL. Once your AI employee is live, we collect and store: conversation transcripts across every channel you connect (website chat, WhatsApp, Messenger, Instagram, TikTok), the public comments your AI employee replies to on your Facebook and Instagram posts and YouTube videos, leads and intents your AI employee detects, and the knowledge base content it is built from — your website's crawled pages, and anything you choose to upload. We do not collect more than a business needs to run its AI employee; the sections below describe exactly what each connected channel or feature involves.
How we use it
We use your data only to run your AI employee and your dashboard — never to train models, never to sell it, and never for our own marketing or analytics. Conversation, comment, and lead data power your AI employee's answers and your dashboard's views; if you opt into the AI Business Network, specific lead or business info is shared for referral matching only between tenants who have both explicitly opted in. We do not use one business's conversations to train models that answer for another business, and — full stop — we do not use any tenant's data to train, fine-tune, or improve any AI model at all. Disconnecting a channel stops new data collection from it immediately.
Meta Platform Data (WhatsApp, Messenger, Instagram, Facebook)
Revorex.ai uses Meta's WhatsApp Business Platform, Messenger Platform, and Instagram Platform APIs so your AI employee can talk to your customers on the channels they already use, and reply to public comments on your Facebook Page and Instagram posts through our Social Inbox feature. Specifically:
- WhatsApp: Revorex owns and operates the WhatsApp Business Account your number is registered on — you never create a Meta developer account or connect your own. We collect the phone number you register, the display name you choose, and every message sent and received on that number, plus, for a conversation that started from someone tapping a "Click to WhatsApp" ad, the ad's headline/body/link, so your AI employee has context instead of a cold start.
- Messenger and Instagram direct messages: when you connect your Facebook Page (and its linked Instagram professional account) via Facebook Login for Business, we receive and store the messages your customers send you and the Page-scoped/Instagram-scoped identifiers Meta uses to address them — never your customers' underlying Facebook or Instagram login credentials, which we never see.
- Facebook and Instagram post comments (Social Inbox): if you enable Social Inbox, we receive public comments posted on your own Page's and Instagram's own posts, and store what your AI employee (or you, reviewing before publishing) replies with. Only comments on your own business's posts are ever received — Revorex has no access to any other page, account, or private content on Facebook or Instagram.
- Meta Ads: if you connect a Meta Ads account, we read your campaign and ad-performance data (spend, reach, results) to show it in your dashboard, and match which of your ads a customer clicked before starting a conversation, so it opens with context instead of a cold greeting. We do not create, edit, or run ads on your behalf, and cannot access ad accounts you have not explicitly connected.
- What none of this is used for: Meta Platform Data described above is never sold, never shared with anyone outside the specific integration you connect it to, and never used for advertising, profiling, or any purpose other than running your AI employee and showing you your own dashboard. Disconnecting a channel in Settings stops new data collection from it immediately.
- Compliance: our use of Meta Platform Data complies with Meta's Platform Terms and Developer Policies. Some of these integrations are still going through Meta's own App Review process for full production access — during that period they may be limited to a small set of test accounts.
TikTok Platform Data
For businesses outside TikTok Shop markets, your AI employee can reply to TikTok direct messages once you connect your TikTok account. We collect the messages your customers send you and the TikTok-assigned identifier used to address them — never your TikTok login credentials. This is not available for TikTok Shop markets, which use TikTok's own separate Customer Service system that Revorex does not integrate with.
Google User Data
We've built a Gmail connector so your AI employee can identify which Gmail account a team member has connected. It is still in pre-launch testing and is not available to customers yet — we have not completed the Google review described below.
- Scopes requested: openid, email, and profile (to identify the connected Google account) and https://www.googleapis.com/auth/gmail.readonly. The readonly scope is reserved for a Gmail-reading feature we have not built yet; today it is requested but not used to read any message.
- Gmail messages: not read, parsed, or stored today. The only Gmail API call our code makes is a profile lookup for the connected email address — no message-list or message-content endpoint is ever called.
- Token security: OAuth tokens are encrypted at rest (AES-256-GCM) using the same method we use for every other integration credential, decrypted only server-side, and never exposed in the admin panel, API responses, or to Revorex.ai staff.
- Retention: disconnecting immediately revokes the token with Google and deletes the stored credential. The same happens automatically if you delete your account or organization.
- Sharing: never sold or shared with third parties. Used solely to show which Gmail account is connected; would only power the specific feature you connect it for once that exists.
- Disconnecting: the same one-click Disconnect button already used for every other integration on your dashboard's Integrations page, plus the account-deletion request described below.
- Compliance: gmail.readonly is a Google-restricted scope. We will not make this available to real customers until we've completed Google's OAuth verification, and any required security assessment, for that scope — until then, access is limited to internal testing accounts. This section will be updated before that changes.
- Outlook: a separate, Microsoft-run connector (not Google) was built alongside this one and is not covered by Google policy — it uses its own Microsoft Graph scopes and consent flow.
How your AI employee actually processes conversations
Every message, on every channel, is written to our database the moment it arrives and is retained there under the access controls described below — we keep it, we do not forget it (see 'Data retention and deletion'). Generating a reply is a separate step from that storage, and works one of two ways depending on your plan and settings:
- Your own AI provider key (BYOK): if you've connected your own OpenAI, Anthropic, or compatible provider key, our servers use it to call that provider directly on your behalf. The message content still passes through our servers to make that call — it does not go straight from your customer's device to your provider.
- Revorex-hosted AI: if you haven't connected your own key (or it's temporarily unavailable), we automatically fall back to AI models we operate ourselves, so your AI employee never just stops answering.
- Either way, the AI call itself is stateless: the model receives the conversation history we send it as context, answers, and retains nothing afterward — it has no memory of its own between calls. We supply that context from your own stored transcript; the model itself is never trained or fine-tuned on your data, for you or for any other tenant.
- Enterprise customers on our Zero-Access or Dedicated privacy tiers can require every reply to be generated only through their own connected provider key, or only on inference infrastructure reserved exclusively for them — see Enterprise Privacy Modes below.
Your knowledge base and what you upload
Two features feed your AI employee's knowledge base:
- Website crawling: when you connect your website, we fetch the page(s) you register, extract the visible text (not the raw HTML, images, or scripts), and store that text — split into small chunks — along with a vector representation used to find the right chunk to answer a question. Disconnecting a source deletes its stored chunks.
- WhatsApp chat-backup import: you can upload a .txt file exported from WhatsApp (Chat > Export chat) to seed your knowledge base. That file is processed once, in memory, to pull out general, reusable question-and-answer patterns — the raw file and your customers' original messages inside it are never written to disk, our database, or any storage, in any form. Only the extracted Q&A pairs are kept.
- None of this content — crawled text, uploaded-file extracts, or the vector representations built from them — is encrypted at rest today (see 'What's encrypted, and what isn't' below), though it is isolated per business the same way every other part of your account is.
Multi-tenant isolation
Every business's data is isolated at the database layer, and production data never leaves the production environment — staging and sandbox environments use synthetic or anonymized data only. There is no feature in our own admin tools that lets Revorex staff browse a tenant's conversations, messages, or knowledge base as a matter of normal operation — see Enterprise Privacy Modes below for exactly how any exception works, and who can request one.
Enterprise Privacy Modes
Every account has one of four privacy modes governing how — and whether — Revorex staff can ever request access to your content:
- Standard (default, every account): no standing staff access. Any access requires a different staff member to independently approve a specific, time-limited request (capped at 4 hours), and every request, approval, and access is logged in an audit trail.
- Private (free, opt-in): everything in Standard, plus your account owners and admins get a real-time email whenever a staff access request is approved, describing what was accessed, why, and for how long.
- Zero-Access (Enterprise): staff can never request or be granted access to your data, under any circumstance — the only way we can ever look at anything is if you yourself grant a specific, time-limited window through your own Settings page.
- Dedicated (Enterprise): the same guarantee as Zero-Access, plus AI inference reserved on infrastructure never shared with any other tenant's traffic.
- You can also grant our support team a one-time, time-boxed window to look at a specific issue you report — entirely your choice, and something only you can initiate.
- What this doesn't cover: this controls who inside Revorex can request access to your data through our own tools, and (for Zero-Access/Dedicated) which AI infrastructure processes it. It does not mean region-specific data storage (we don't offer that today) or encryption keys only you hold (we don't offer that today either) — see 'What's encrypted, and what isn't' below. Direct production-database access for operational and support purposes remains restricted to a small set of engineers, the same way it would at any software company that operates its own infrastructure.
What's encrypted, and what isn't
We encrypt at rest, using AES-256 encryption: every payment key, third-party integration token, courier or carrier account credential, and webhook secret you connect or that we generate on your behalf. These are never exposed in the admin panel or in any API response, including to Revorex.ai staff — support can see that a credential exists and is valid, never its value. Conversation transcripts, knowledge base content, and your customers' names, phone numbers, emails, and addresses captured through orders, returns, or chat are not encrypted at rest today — they're protected by the access controls described above (multi-tenant isolation, Enterprise Privacy Modes), not by encryption. We're telling you this plainly rather than implying otherwise.
Other connected platforms
Revorex integrates with e-commerce platforms (Shopify, WooCommerce), payment processors, courier and carrier accounts you connect for shipment tracking, and business tools like calendars and CRMs — always only the specific ones you choose to connect. Each integration only accesses what it needs to perform its function, and the credentials for every one of them are encrypted at rest as described above.
Data retention and deletion
We retain conversation, lead, and knowledge base data for as long as your account is active. There is currently no automatic deletion by age — data stays until you or we take action on it. Requesting deletion of your data at privacy@revorex.ai starts a manual process carried out by our team; it is not yet a fully automated, instant self-service action, and we're telling you that plainly rather than promising something we can't yet deliver on demand. Deleting your login account anonymizes your personal login details immediately; deleting the underlying business data (conversations, knowledge base, orders) is handled by our team on request. Regional erasure rights (GDPR/CCPA) are honored the same way, on request.
Regional compliance
We apply jurisdiction-aware handling based on your customers' detected region, including GDPR (EU/UK) and CCPA (California) awareness in how we process requests. We do not currently offer region-specific data residency (storing data only within a particular country or region) — if that's a hard requirement for your business, contact sales before onboarding so we can confirm current support.
Cookies
We use a small number of cookies for authentication (keeping you signed in) and basic product analytics. See our Cookie Policy for the full list.
Contact
Questions about this policy or a request regarding your data can be sent to privacy@revorex.ai.
وظّف أول موظف لك بالذكاء الاصطناعي هذا الأسبوع.
تجربة مجانية لمدة 14 يومًا. لا حاجة لبطاقة ائتمان للبدء، ويمكنك الإلغاء في أي وقت.