Privacy Policy
Last updated: July 10, 2026
Overview
Revel ("we", "us") is operated by BlindspotLab. This policy explains what we collect when you use https://tryrevel.xyz, Mission Control, Partner API, MCP endpoints, OKX.AI marketplace integrations, and optional export connections (Linear, Notion, GitHub). We do not sell your personal data. We design exports so your reports are not written into a shared BlindspotLab workspace that other customers can browse.
What we collect
- Account data: email address, display name, optional username, profile image (e.g. from Google), and authentication identifiers when you sign in.
- Analysis data: website URLs you submit, generated reports (Reveal Index, blindspots, Blueprint, Action Queue), and analysis status — stored against your account so you can reopen history.
- Usage data: audit counts, API/MCP call metadata, partner platform identifiers, and activity events for rate limiting and admin analytics.
- Export connection metadata: if you connect Linear, Notion, or GitHub, we store encrypted OAuth tokens and non-secret labels (e.g. team name, workspace name, GitHub login) needed to run exports on your behalf. See Export integrations (OAuth) below.
- Partner applications: platform name, contact email, domain, and optional notes when you apply for Partner API access.
- Payment metadata: when you use OKX x402 billing, transaction references are processed by OKX — we do not store private keys or full wallet credentials.
- Technical data: IP address, browser type, and request logs for security and abuse prevention (via hosting provider).
How we use your data
We use collected data to run product audits, store your analysis history, enforce weekly usage limits, operate the Partner API, process marketplace payments, send transactional emails (account welcome, password reset, partner approval), run optional exports you request into your connected tools, and improve Revel. Public website content you submit for analysis is sent to our AI providers for processing and retained as part of your report.
Export integrations (OAuth)
Markdown, JSON, and GitHub-flavored Markdown downloads stay on your device. Cloud exports to Linear, Notion, or GitHub Gist use per-user OAuth connections: you authorize Revel to act in your account, and we create content there. Other Revel users cannot open those exports unless you share the link or grant them access in that product.
When you connect an integration, Revel requests only the access needed for export:
- Linear: read and write access sufficient to create issues (including
read,write, andissues:create). We create issues in a team on your Linear workspace from your Action Queue. - Notion: OAuth access to content you share with the Revel integration. We create a Blueprint page under a page or database you make available to the integration. We do not publish your Notion workspace publicly.
- GitHub:
gistscope only, to create a private Gist under your GitHub account. Only you can see it unless you change visibility or share the URL.
OAuth access tokens are stored encrypted at rest (AES-256-GCM) using a server-side encryption key. You can disconnect an integration at any time under Mission Control → Integrations, which deletes the stored tokens for that provider from our database. Revoking access in Linear, Notion, or GitHub also stops further exports until you reconnect.
We do not use your Linear, Notion, or GitHub connections to browse unrelated data for advertising, sell access tokens, or write exports into a shared BlindspotLab database visible to other customers.
Partner API & other integrations
Approved partners receive API keys stored as hashed values on our servers. Partners may only access analysis reports they initiated via the Partner API. Partner platforms (e.g. Arcapush) are responsible for how they display Revel insights to their users and for securing API keys on their servers.
Third-party services
- Google OAuth & NextAuth (authentication)
- Supabase / PostgreSQL (data storage)
- Groq, Google Gemini, and OpenRouter (AI analysis)
- Linear, Notion, and GitHub (optional export destinations you connect)
- OKX Onchain OS / x402 (agent marketplace payments)
- Resend (transactional email)
- Vercel (hosting)
- Plausible (optional, privacy-friendly analytics)
Each provider operates under its own privacy policy. When you export to Linear, Notion, or GitHub, content in those products is also governed by their terms and privacy policies.
Data retention & deletion
Analysis reports are retained while your account exists so you can access history and re-export. OAuth tokens are kept until you disconnect the integration or delete your account. Partner activity logs are retained for operational analytics. You may request account deletion by contacting us; we will remove personal identifiers and stored connection tokens where technically feasible. Content already created in your Linear, Notion, or GitHub accounts remains under your control there.
Your rights
Depending on your jurisdiction, you may request access, correction, or deletion of personal data we hold, and you may disconnect integrations at any time. Contact us using the details below.
Contact
Questions about privacy? Email hello@mail.tryrevel.xyz or visit our contact page.