Privacy

Privacy defaults for workflow reliability data.

A concise privacy overview for the Norevin beta and MVP. This page will evolve as the product and customer base grow.

Data Norevin stores

Norevin stores account profile, organization membership, client, workflow, checkpoint, validation, incident, alert, report, billing, and aggregate usage metadata needed to operate the product.

Workflow payloads

Raw automation payload storage is off by default. Norevin is designed to prove missing checkpoints and validation outcomes with bounded operational data, not broad customer data collection.

How data is used

Data is used to authenticate users, isolate workspaces, monitor workflow reliability, validate AI outputs, generate reports, deliver alerts, provide support, prevent abuse, and operate billing.

Acquisition and referral data

When a visitor arrives with referral or UTM parameters, Norevin may store limited first-party attribution data such as landing page, referrer, campaign parameters, and signup source to understand which organic channels are working. This does not include raw workflow payloads or payment data.

Service providers

Norevin uses providers such as Supabase, Vercel, Stripe, Resend, and GitHub to host, authenticate, bill, send operational emails, and maintain the service.

Report sharing

Shared reports are token-gated and can be revoked from the console when access should end.

Retention and deletion

Operational data follows the plan-based retention model. Workspace owners can request export, deletion, or access removal from the owner email.

Security reports

Security concerns, suspected abuse, or data exposure reports should be sent to founders@norevin.com. Do not include secrets or raw API keys in email.

Requests

Use the workspace owner email for privacy and deletion requests.

Contact founders@norevin.com for access, correction, export, deletion, or privacy questions. Enterprise customers can request a signed DPA before broader rollout.

View retention policy