IconRevestor

Legal

Privacy Policy

Last Updated: August 19, 2026

1. Introduction

AtInfinite LLC ("we," "us," or "our") operates Revestor. This Privacy Policy explains how we collect, use, and share information about you when you use our website, mobile application, and cloud services (collectively, the "Services").

2. Information We Collect

Account Information: We collect information you provide when you create an account, such as your name and email address.

Financial and Property Data: We collect information you upload or sync to the Services, including property details, expense data, income records, mileage logs, and receipt images.

AI-Processed Data (in-app): When you use Revestor’s own AI features (receipt scanning, smart imports, in-app assistant), your uploaded content is processed by Google Gemini under Revestor’s API contract. We use that processing only to provide the requested feature. We do not grant Gemini a right to train its foundation models on your Revestor records.

AI connector data: If you connect Claude, ChatGPT, or a similar assistant to your Revestor account, we send that assistant the read-only record data its tools request. For paid plans that can include bounded line items such as property addresses, time-log hours and descriptions, transaction amounts/categories/notes, mileage purpose, and stored depreciation values for tax years your plan allows. Free accounts share counts and bare property IDs only. That transfer happens only after you approve the connection. We do not send receipt images, vault PDFs, bank account numbers, tax identification numbers, or CPA export files through this connection. Connector reads do not use Gemini and do not spend Revestor AI credits.

Payment Information: Subscription and in-app purchase transactions are processed by RevenueCat and Apple/Google payment systems. We do not store your credit card details directly.

Usage Data: We collect information about how you interact with our Services, including your IP address, browser type, device information, and feature usage patterns.

3. How We Use Information

We use the information we collect to provide, maintain, and improve our Services, to communicate with you, to process AI-powered features, to generate export packages, and to protect our users and Services.

4. Information Sharing

We do not sell your personal information. We may share information with the following third-party service providers who perform services on our behalf:

  • • Google Cloud / Firebase: Infrastructure, authentication, and data storage
  • • Google Gemini AI: In-app receipt scanning and Revestor-hosted AI features (our API contract)
  • • RevenueCat: Subscription and payment management

AI assistants you connect (not our subprocessors): Anthropic (Claude), OpenAI (ChatGPT), and other MCP or plugin hosts are third-party services you choose — not Revestor subprocessors for that connection. We send them data because you asked their product to read Revestor. After the data leaves Revestor, their privacy policy, retention, logging, and model-training rules apply — including consumer settings that may use chats to improve models unless you opt out with them. We cannot audit or control those products. Review their policies before connecting:

  • • Anthropic Privacy Policy: anthropic.com/legal/privacy
  • • OpenAI Privacy Policy: openai.com/policies/privacy-policy

This disclosure follows the same pattern those products use for third-party connectors: the connected service (Revestor) describes what it sends; the assistant describes how it uses Inputs. OpenAI’s Apps guidelines require a published privacy policy covering categories of data, purposes, recipients, retention, and user controls. Anthropic treats content you grant Claude via connected services as Inputs.

We may also disclose information to comply with legal obligations or to protect our rights.

4a. AI connectors — purposes, retention, and controls

Purposes: to answer questions you ask in the connected assistant using your Revestor books; to let that assistant propose new time, mileage, or expense rows that stay pending until you Accept them in Revestor; to enforce your Revestor plan or account tier (Free / Pro / Investor); to rate-limit abuse; and to keep a grant and audit trail (tool name, argument digest, time — not full ledgers).

Retention at Revestor: Revoking a connection marks the grant inactive so new access stops immediately. Grant records and hashed token index documents may remain until they expire or until we purge them; they are removed with your account under Section 7 (within 30 days of deletion). Audit events (tool name, argument digest, time — not full ledgers) are kept for security and support and are also removed with account deletion. Ledger data stays in your account under Section 7.

Retention at the assistant: governed by that product. Revoking Revestor does not delete past chats on Claude or ChatGPT.

Your controls: approve or deny each new client on the Revestor consent screen (shows the registered client name, redirect host, and requested scope); Accept or dismiss proposed connector entries in AI Review; revoke connected apps under Profile → AI connectors (beta); export or delete your Revestor account; manage training/opt-out and chat deletion in the assistant’s own settings.

5. Data Security

We use AES-256 encryption, bank-level security protocols, and Google Cloud infrastructure to protect your information. All data is transmitted over TLS-encrypted connections. We take reasonable measures to protect your information from unauthorized access, use, or disclosure.

6. Cookies and Tracking

We use essential cookies required for authentication and session management. We do not use third-party advertising cookies or sell data to advertisers.

7. Data Retention

Your data remains accessible for as long as you maintain an account. If you cancel a paid subscription, your data remains available on the free plan. You can export all your data at any time. If you request account deletion, we will remove your data within 30 days, including AI connector grants, hashed token index documents, and connector audit events.

8. Contact Us

If you have any questions about this Privacy Policy, please contact us at contact@revestor.app.