Privacy

Privacy Policy

How RevLeak OS handles business, lead, payment, and workflow data during managed pilots and staged rollout.

Last updated: June 17, 2026

Data we expect to process

Business account details, business contact information, quote records, lead contact fields, service requested, quote value, notes, recovery statuses, payment event metadata, and audit/report activity.

Payment card data is not stored by RevLeak OS. Checkout and card entry stay hosted by the configured payment provider, such as PayPal, Stripe, Square, or another approved processor.

How data is used

To generate recovery drafts, organize human approval queues, classify replies, prepare proof reports, create onboarding records, and show operators what work is ready or blocked.

AI drafting is kept behind a feature flag. Live customer data should not be sent to an AI provider until provider terms, data handling, and customer consent are approved.

Security posture

RevLeak is operating in paid-pilot mode while the self-serve customer portal is hardened. Customer data access is limited to approved workspaces and human-reviewed recovery workflows.

Access to inboxes, calendars, or payment accounts must use OAuth or provider-hosted flows. RevLeak OS should not ask customers for email or card passwords.

Public route smoke checks and manual freshness checks support managed pilots. RevLeak OS does not claim a formal SLA, public status-page operation, always-on support, SOC 2 certification, HIPAA compliance, or production monitoring readiness until those gates are reviewed and proven.

Account lifecycle boundary

no-reply@revleakos.com is reserved for account/system email such as password reset, email verification, account invites, and system notices after provider verification.

Password reset is production-ready for managed users after provider-issued links, callback handling, and invalid-link safety proof. Email verification remains blocked until provider-issued verification proof passes.

Public signup and self-serve workspace creation remain blocked. Managed-pilot access is invite or owner/admin-created only.

Export, deletion, correction, and opt-out requests

Managed-pilot customers can request report corrections, export review, deletion review, privacy help, opt-out handling, and do-not-contact handling through the customer portal or support inbox.

These requests are manually reviewed before proof, data, or account records change. RevLeak OS does not provide public download links or automatic deletion from the customer portal.

Deletion review may require export review, workspace verification, legal/accounting retention checks, and completion notes before any manual record change is performed.

Paid-pilot note

RevLeak OS currently operates managed paid-pilot workflows. These pages describe product guardrails and should be reviewed by qualified counsel before broader self-serve launch.