Security and privacy
Your health data, and what we do with it
What happens to what you describe
When you tell Reva what you are recovering from and how you feel, that text is sent to a model provider to produce your session, and stored in our database against your account so you can open the session again later. That is the whole journey.
Your description is transmitted over TLS 1.2 or better and stored encrypted at rest by our database provider. It is never posted anywhere public, never shared with another user, and never sent to any third party other than the model provider that builds your session.
Model providers and training
Reva routes across model providers. In this deployment the live provider is OpenAI, and the routing table on the How the AI works page shows which model handles which step. Building your session and adjusting it run on the balanced model. The red-flag screen uses the fast model. More involved descriptions escalate to the frontier model.
We use these providers under their business API terms, which prohibit training on API traffic. We do not fine-tune any model on what users describe. We do not use your sessions to improve prompts without asking. We do not sell or license user text to anyone for any purpose.
Who at Reva can see your sessions
Access to the production database is limited to the two engineers who operate it, used to fix problems, not to browse. We do not read user descriptions for product research.
If you open a support ticket about a specific session and share the session link, we may open that one session to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.
How long we keep it
- Sessions and the descriptions stored with them: until you delete them, or until 30 days after you delete your account, whichever is sooner.
- Account records: for as long as the account is open, then 30 days.
- Form submissions from the contact, help and careers forms: 24 months.
- Server logs, which record request paths and timings but not what you described: 30 days.
- Backups: rolling 7 days, after which deleted data is gone from backups too.
Your control
Delete any session from your dashboard, which removes the description and the session built from it. Delete your whole account from Settings, which removes every session, every stored description, and the account record.
Both are immediate and neither needs a support ticket. Your data is also available for export from the Your data page. If you want written confirmation of deletion for your own records, email us and we will send it.
Accounts and access
- Passwords are hashed with a secure one-way algorithm and a per-user salt. We never store or log a password, and nobody at Reva can see one.
- Sessions are httpOnly, sameSite cookies signed with a server-side secret, and they expire after 30 days.
- Google sign-in is supported so you do not have to keep another password at all.
- Every request for a session checks that the session belongs to the account asking for it, in the database query itself rather than in the page.
Our own posture
- Two-factor authentication is required on every service Reva uses, with no exceptions and no shared logins.
- Production access is limited to the two founding engineers and is reviewed quarterly.
- Dependencies are updated on a weekly cadence and security advisories are acted on within 72 hours for anything reachable from production.
- We do not yet hold a SOC 2 report. Reva is a Pre-Seed company and we would rather say so plainly than imply otherwise. If you need a completed security questionnaire for review, email us and we will fill it in honestly.
Reporting something
Email security@reva.fit. We acknowledge within two business days, we will not act against you for reporting in good faith, and we will tell you when the issue is fixed. If you would like to be credited, say so and we will.
This page describes what Reva does today. The privacy policy is the legal version of the same thing, and the terms cover the rest. Last reviewed July 2026.