Privacy Policy
What reaches us, what we keep, and what never leaves your machine.
The short version
RevampKey runs on your machine and works against code on your machine. We hold the account, not the work.
- Your files, conversations, plans and design artifacts stay local. We do not store them.
- We do not train AI models on your code or prompts, and we contract with our model providers on the same basis.
- To answer a request, the prompt and the code context it needs are sent to an AI model provider through our proxy. That is unavoidable — it is how the model sees the question — and it is described in full below.
- What we record about a request is metering, not content: how many tokens, which model, what it cost, when.
- We never see your full card number. Payment happens on our payment provider’s page.
- We do not sell your personal data, and we do not use it for advertising.
The rest of this page is the detail behind those statements.
Who we are
Rev AI Private Limited, a private limited company incorporated in India (CIN U62011HR2025PTC139209), registered at 93, PF Office, Sector 45, Gurgaon, Haryana 122003, India, is the data fiduciary — the controller — responsible for the personal data described here.
This policy covers the RevampKey desktop application, this website and the hosted services behind them. It should be read with our Terms of Service.
What stays on your machine
This is the part most people want answered first, so it comes before the list of what we do collect. The following never reach our servers as stored data:
- Your repositories and files. RevampKey reads and edits them locally.
- Your conversations, plans, specs, task trackers, flow diagrams and design canvases. These are project files on your disk with their own local revision history.
- Your application preferences and settings.
- Credentials for servers and tools you connect. These are held in your operating system’s own secure keychain — the same encrypted store it uses for your passwords — not in a configuration file and not on our servers.
- The values of secrets and environment variables. When a task has to read or change one, that step is performed locally so the value is not placed into a model request, a log, or a report.
A practical consequence: if you close your account, none of the above is affected, and if you lose your machine we cannot restore any of it. Keep your own backups.
What we collect
Account information
Held so you have an account and we can bill it: your email address, first and last name, whether the email is verified, an account type, an optional profile image and phone number, your billing country, your timezone, and the identifier your account carries in our identity provider. We record when you last signed in.
We do not store a password. Authentication is handled by our identity provider, and if you sign in through Google or GitHub, that provider handles it.
Billing information
Your plan, subscription status, billing period, invoices, payment receipts, credit balances and the country your billing is based in. Where you provide a tax registration number, we store it to put on your invoice.
We do not receive or store your card number, CVV or UPI credentials. Those go directly to our payment provider, who returns us a reference and the last four digits.
Usage and metering
For each AI request: which model answered it, how many prompt and completion tokens it used, what it cost, the credits it consumed, a request identifier, and the time. This is what makes your allowance and your invoice add up, and it is what a billing dispute is settled from.
This record contains no prompt or completion content. It counts tokens; it does not keep them.
Technical and diagnostic data
IP address, application version, operating system and device type, and server logs of requests to our API — including timestamps, endpoints and status codes. We use these to run the service, investigate faults, and detect abuse. Where a crash or error report includes more than this, we say so at the point we ask you to send it, and sending it is your choice.
What you send us directly
If you contact sales, ask for support, or file an issue, we keep what you sent and our correspondence with you, so we can answer and keep track of it.
What happens to an AI request
This is the one place where your code leaves your machine, so it is worth being precise about.
When you ask RevampKey to do something that needs an AI model, the application assembles a request: your instruction, plus the parts of your codebase needed to answer it. That request is sent over an encrypted connection to our proxy, which authenticates it, checks your allowance, and forwards it to the AI model provider that serves the model being used. The provider’s answer comes back the same way.
Along that path:
- In transit, the content is encrypted (TLS) between your machine, our proxy and the provider.
- At our proxy, the content is processed in memory to route and meter the request. We do not write prompt or completion content to our database.
- At the provider, the content is handled under that provider’s terms. We contract with providers on terms that do not permit training on our customers’ content, and providers may hold content briefly for abuse monitoring under their own policies.
- After the request, what remains with us is the metering record described above.
You control what goes into a request by choosing what to ask and which project to ask it about. If a codebase is sensitive enough that its contents must not reach a third-party model provider at all, that is a decision to make before pointing an AI request at it.
If you connect your own servers or tools, those receive whatever the task requires them to receive, under their own terms and outside our control.
We do not train on your code
We do not use your source code, prompts, conversations or generated output to train, fine-tune or evaluate AI models — ours or anyone else’s. We do not sell them, and we do not share them for anyone else’s training.
This is not conditional on a setting you have to find and switch off. It is how the service is built, and it is reflected in the contracts we hold with our model providers.
We do use aggregate, non-content metering — request volumes, model mix, error rates — to run capacity and improve reliability. That data describes traffic, not code.
Why we process it, and our legal basis
We process personal data on the following bases. Under India’s Digital Personal Data Protection Act, 2023 this is generally your consent or a legitimate use; under the GDPR, where it applies to you, the corresponding bases are named below.
- To provide the Service — accounts, authentication, routing and answering your requests. Performance of a contract.
- To bill you and keep the books — plans, invoices, metering, tax records. Contract, and legal obligation.
- To keep the Service secure and working — logs, abuse detection, rate limits, fault investigation. Legitimate interests.
- To support you — answering what you write to us. Contract, and legitimate interests.
- To send service messages — security notices, billing notices, material changes to these terms. Contract, and legal obligation. You cannot opt out of these while you hold an account, because they are how we tell you things you need to know.
- To send product or marketing email — only if you asked for it. Consent, withdrawable at any time from a link in every such message.
- To comply with the law — tax, accounting, and responding to lawful requests. Legal obligation.
Who we share it with
We share personal data only with processors that help us run the Service, each bound to use it only on our instructions:
- AI model providers — receive the prompt and code context needed to answer a request (see above).
- Payment providers — handle checkout, subscriptions and invoices, and hold the payment details we never see.
- Identity provider — runs sign-in and account credentials.
- Cloud hosting and database providers — run our servers and store the account and billing data described above.
- Email delivery provider — sends account, billing and support email on our behalf.
- Error and performance monitoring — helps us find and fix faults.
We may also disclose data where we are legally required to, to establish or defend a legal claim, or to protect the rights and safety of our users or the public. If we are ever part of a merger, acquisition or sale of assets, data may transfer as part of it, and we will tell you before it becomes subject to a different policy.
We do not sell personal data, and we do not share it for advertising.
How long we keep it
- Account data — while your account is open, and for up to 90 days after you close it, so it can be restored if you closed it by mistake.
- Billing records, invoices and tax records — for eight years after the financial year they relate to, as Indian tax and company law requires. These survive account deletion because we are not permitted to delete them.
- Metering records — for 24 months, so a billing question can be answered.
- Server and security logs — for up to 90 days, unless one is retained longer as part of investigating a specific incident.
- Support and sales correspondence — for up to 24 months after the conversation ends.
After these periods, data is deleted or irreversibly anonymised.
Security
We encrypt data in transit with TLS, and account and billing data is encrypted at rest by our infrastructure providers. Access to production systems is restricted to staff who need it, and authenticated individually. Secrets are held in managed secret storage rather than in code or configuration files.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will notify you and the Data Protection Board of India as the law requires.
If you believe you have found a security issue, please write to hello@revampkey.com rather than filing it publicly. We will acknowledge it and keep you updated.
Your rights
You can ask us to:
- Tell you what we hold about you, and who we have shared it with
- Correct anything inaccurate, incomplete or out of date
- Delete your personal data, subject to records we are required by law to keep
- Give you a copy in a structured, machine-readable format
- Withdraw consent where we relied on it, without affecting what was done beforehand
- Object to or restrict processing based on our legitimate interests
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated, as the Digital Personal Data Protection Act, 2023 provides
Write to hello@revampkey.com from the address on your account. We respond within 30 days. There is no charge unless a request is manifestly excessive or repetitive, and we will tell you before charging anything.
If we get it wrong, you can complain to our grievance officer below, and then to the Data Protection Board of India. If the GDPR applies to you, you can complain to your local supervisory authority.
International transfers
We are based in India, and our providers — hosting, AI models, payments, email — may process data outside India, including in the United States and the European Union.
Where data is transferred out of a jurisdiction whose law restricts it, we rely on appropriate safeguards: standard contractual clauses, adequacy decisions, or the transfer rules that apply under the Digital Personal Data Protection Act, 2023. You can ask us which safeguard applies to a particular transfer.
Cookies and analytics
This website and the account area use cookies that are necessary to make them work: keeping you signed in, holding your session, and remembering your theme preference. These cannot be switched off without breaking sign-in.
Our contact form uses Google reCAPTCHA to keep out automated submissions. Google’s privacy policy and terms apply to it.
We do not use advertising cookies, and we do not track you across other websites. Your browser can block or delete cookies; blocking the necessary ones will stop sign-in from working.
Children
The Service is not for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to hello@revampkey.com and we will delete it.
Changes to this policy
We may update this policy. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will tell you by email or in the product before it takes effect, and where the law requires your consent, we will ask for it.
Grievance officer
As required by the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, complaints about how we handle your personal data can be sent to our grievance officer at hello@revampkey.com, or by post to Rev AI Private Limited, 93, PF Office, Sector 45, Gurgaon, Haryana 122003, India.
We acknowledge complaints within 48 hours and aim to resolve them within 15 days.
Contact us
Rev AI Private Limited
CIN: U62011HR2025PTC139209
Registered office: 93, PF Office, Sector 45, Gurgaon, Haryana 122003, India
Privacy: hello@revampkey.com
Everything else: hello@revampkey.com