Privacy Policy
Last updated: 29 August 2026. This describes what Revtect collects, why, and how you can delete it. It is written in plain language on purpose.
We are not a HIPAA-covered entity
Revtect is an informational AI assessment product. Unless and until we have a signed business associate agreement and operate as a covered entity or business associate under US HIPAA, we do not claim HIPAA compliance. Do not treat this service as a medical record system or as a confidential clinical relationship with a licensed provider.
What we collect
- Account when you sign up (email and password). Assessments require a Plus or Family plan (including during the 1-day free trial).
- Health timeline entries: date, a short title from your message, a truncated AI summary, whether a file was attached, and whether the reply looked urgent.
- Health memory: a rolling summary of prior chats, stored message history, flagged concerns, and lab/scan summaries, used to personalize later assessments.
- Report summaries: when you upload a scan or PDF, we store the AI’s extracted summary. We do not intend to keep the raw file after the request finishes.
- Rate-limit data: IP address and a count of messages in the current hour, to cap free-tier cost and abuse.
- Product analytics (first-party only): session started, messages sent per session (count, not full text), whether a message included an upload, and whether a device returned within 7 days. We do not send full chat transcripts or uploaded files to third-party analytics tools.
How it is used
To run the assessment, enforce rate limits, show your timeline, keep chat memory, and measure whether people come back. Model providers (currently OpenRouter / OpenAI GPT-4o, called from our server) receive the prompt and the files you attach for that request. Their processing is subject to their own terms.
Encryption and storage
This first version stores data in a local SQLite file on the server that runs Revtect. Disk encryption depends on the host: if you deploy to a managed Postgres provider later, those providers typically encrypt data at rest by default. The current SQLite file is not application-level encrypted; protect the server disk and the data/ directory. API keys live in server environment variables, never in the browser.
Delete my data
On the assessment page, use Delete my data to wipe this device’s user record, timeline, report summaries, and analytics events tied to that device ID.
If that fails, email privacy@revtect.com with the device ID shown in the error message (or from your browser’s localStorage key revtect_device_id) and ask us to delete it manually.
What we do not do
- We do not sell your health information.
- We do not log full raw chat content or uploaded files to analytics platforms.
- We do not use your assessments to train a public marketing dataset.
Medical disclaimer
Revtect provides AI-generated health information to support your own decisions. It is not a diagnosis, treatment, or substitute for professional medical care. If you think you have an emergency, contact local emergency services immediately.