Legal
Privacy Policy
Last updated: June 17, 2026
Revoca exists to keep your company's knowledge safe and useful. That only works if you can trust how we handle data. This notice describes what personal data we collect, why we process it, your rights as a Data Principal under India's Digital Personal Data Protection Act, 2023 (DPDP Act), and how to contact us.
Data Protection Officer
Revoca Privacy Team serves as our Data Protection Officer and Grievance Officer.
- Email: revoca.ai@gmail.com
- Phone: +91-00000-00000
- Postal address: Revoca AI, India
Information we collect
We collect the following categories of personal data:
- Account information — name, email address, company name, and authentication identifiers when you sign up, log in, or book a demo.
- Connected workspace data — content from tools you connect (e.g. Slack, GitHub, Discord, documentation) to build your private context graph.
- Usage and analytics data — pages visited, features used, device/browser metadata, and interaction events (only when you consent to analytics cookies).
- Support and grievance data — information you submit through contact forms, grievance forms, or data-rights requests.
Purposes of processing
We process personal data to operate and improve Revoca, authenticate users, build and serve your company's private context graph, respond to inquiries and grievances, comply with law, and keep the platform secure.
We do not sell your personal information, and we do not use one customer's private workspace data to serve another customer.
Legal basis and consent
We process personal data based on your consent, contractual necessity, and legitimate uses permitted under the DPDP Act. Non-essential cookies and analytics tools are loaded only after you provide affirmative consent through our cookie banner. You may withdraw consent at any time using Manage consent in the site footer or by submitting a data rights request.
Your rights as a Data Principal
Under the DPDP Act, you have the following rights:
- Right of access — request a copy of personal data we hold about you. Submit via our data request form or email revoca.ai@gmail.com.
- Right to correction — request correction of inaccurate or incomplete data. Provide your registered email or account ID and the correction needed via the data request form.
- Right to erasure — request deletion of your personal data when it is no longer needed. Submit via the data request form; we will acknowledge within 7 business days and complete erasure within a reasonable period.
- Right to withdraw consent — withdraw consent for non-essential processing at any time with equal ease through Manage consent in the footer or a withdraw-consent request.
- Right to grievance redressal — raise a complaint through our Grievance Redressal mechanism. We acknowledge grievances within 48 hours and aim to resolve them within 90 days.
- Right to nominate — nominate another individual to exercise your data-protection rights in the event of your death or incapacity. Register a nominee via our data request form(select "Register a nominee").
- Right to complain to the Board — if your grievance is not resolved satisfactorily, you may file a complaint with the Data Protection Board of India. Complaints to the Data Protection Board of India are filed through the Board's official digital portal. Until a dedicated portal URL is published, refer to the Ministry of Electronics and Information Technology (MeitY) website for the latest filing instructions. Refer to MeitY for current filing instructions.
Grievance redressal
We maintain a dedicated grievance redressal mechanism at /grievance. You may also email revoca.ai@gmail.com. We acknowledge all grievances within 48 hours and resolve them within 90 days of receipt, unless a longer period is required and communicated to you.
Children's data
Revoca may be used by individuals of all ages, including those under 18. Where a user is under 18, we process personal data only with verifiable consent of a parent or legal guardian, as required under the DPDP Act.
We do not undertake behavioural monitoring, tracking, or targeted advertising directed at children. Non-essential analytics and session-recording tools load only after affirmative consent is given.
Parents or guardians may contact our Data Protection Officer to provide consent, review a child's data, or request its deletion.
Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy. Categories include:
- Strictly necessary — Required for the site to function — authentication sessions (Clerk), security (Cloudflare), and consent preferences. These cannot be disabled.
- Analytics & performance — Help us understand how visitors use the website so we can improve it. Data is aggregated where possible.
- Functional — Enable enhanced features such as session recordings and product diagnostics.
Third-party processors and trackers
We use the following third-party services that may process personal data on our behalf:
- Clerk — User authentication and account management. Data shared: Name, email address, session identifiers. Primary processing location: United States.
- PostHog — Product and website analytics. Data shared: Usage events, page views, device/browser metadata. Primary processing location: United States.
- Google Analytics — Website traffic analytics. Data shared: Page views, referral source, device/browser metadata. Primary processing location: United States.
- Microsoft Clarity — Session replay and heatmaps (when enabled). Data shared: Interaction patterns, page content snapshots. Primary processing location: United States.
- Vercel — Website hosting and content delivery. Data shared: IP address, request logs. Primary processing location: India / United States.
- Cloudflare — Security and bot protection (via Clerk). Data shared: IP address, request metadata. Primary processing location: India / United States.
Cross-border data transfers
Personal data is processed in India and United States. Primary operations and customer data may be stored in India; certain processors (such as authentication and analytics providers) operate in the United States.
We transfer data only to jurisdictions permitted under the DPDP Act and apply contractual and technical safeguards — including encryption in transit, access controls, and data-processing agreements — to protect your information.
Data retention and deletion
- Account and workspace data — retained while your account is active and for up to 90 days after account closure to honour deletion requests and resolve disputes.
- Usage and analytics data — retained for up to 26 months in aggregated form, or deleted sooner upon withdrawal of consent.
- Grievance and rights-request records — retained for up to 3 years to demonstrate compliance with the DPDP Act.
- Server and security logs — retained for up to 90 days for security and fraud prevention.
Security safeguards
Isolation is the core of Revoca's architecture. Each customer's knowledge base is segregated, and agents operate with strictly scoped access.
We apply encryption in transit (HTTPS/TLS), access controls, and industry-standard safeguards. We regularly review our security posture and limit internal access to what is necessary.
Personal data breach notification
In the event of a personal data breach likely to affect Data Principals, we will notify the Data Protection Board and affected individuals as required under the DPDP Rules. We aim to intimate the Board within 72 hours of becoming aware of the breach, and affected Data Principals without undue delay.
Notifications will describe the nature of the breach, data affected, likely consequences, and measures taken or proposed to address it.
Changes to this notice
We may update this notice as the product or law evolves. Material changes will be reflected on this page with an updated date. Where required, we will seek fresh consent for new processing purposes.
Questions about this policy? Contact our Data Protection Officer (Revoca Privacy Team) at revoca.ai@gmail.com.
To withdraw cookie consent or change your preferences, use Manage consent in the site footer.