Last updated: May 2025
Privacy Policy
This policy explains what data Revu collects, why, how it is protected, and what rights you have as a user or client.
1. Data controller
Revu is published by Naja Studio, France.
Contact: hello@getrevu.co
2. Data we collect
We only collect the data necessary for the service to function:
- Editor account — email address, studio name, password (hashed by Supabase).
- Projects — title, status, delivered video, client brief, timestamped comments, attached files.
- Clients — name and email address of the end client (provided by the editor).
- Messages — text exchanges within the project portal.
- Payment — processed by Stripe. Revu never stores your card details.
- Audit logs — key actions (login, approval, plan change) along with IP address and User-Agent.
- Waitlist — email address voluntarily provided.
3. Legal basis (GDPR)
- Performance of the contract — processing of data necessary to provide the service (projects, comments, notifications).
- Legitimate interest — security logs, fraud detection, billing integrity.
- Consent — waitlist (you may unsubscribe at any time).
4. Subprocessors and transfers
| Subprocessor | Role | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Vercel | Application hosting | EU edge |
| Stripe | Payment | EU + US (SCC) |
| Resend | Transactional email delivery | EU |
| Upstash | Rate limiting (Redis) | EU |
All transfers outside the EU (Stripe) are governed by the European Commission's Standard Contractual Clauses (SCC).
5. Data retention
- Account data — retained until the account is deleted.
- Projects and files — retained until the account is deleted or manually archived.
- Audit logs — rolling 12 months.
- Billing data (Stripe) — 10 years (French legal requirement).
- Waitlist — until you unsubscribe.
6. Cookies
Revu only uses cookies that are strictly necessary for the service to function. No advertising or third-party tracking cookies are set.
| Cookie | Purpose | Duration |
|---|---|---|
| revu_auth | Editor authentication session (HMAC-signed) | 30 days |
| revu_trial_ok | Caches subscription status (avoids a DB query on every page) | 5 minutes |
| revu_landing_pw | Remembers that the private landing page has been unlocked | 30 days |
| revu_admin | Admin panel session | 8 hours |
As these cookies are strictly necessary, they do not require prior consent under the ePrivacy Directive.
7. Your rights (GDPR)
You have the following rights over your personal data:
- Access — obtain a copy of your data.
- Rectification — correct inaccurate data.
- Erasure — delete your account and all associated data (see below).
- Portability — receive your data in a machine-readable format.
- Objection — object to certain processing based on legitimate interest.
- Complaint — file a complaint with the CNIL.
To exercise your rights or ask a question: hello@getrevu.co. We respond within 30 days.
8. Deleting your account
You can delete your account at any time from Dashboard → Settings → Danger zone → Delete workspace.
Deletion permanently and immediately erases: your organization, all your projects, clients, comments, files, and your authentication account. Stripe billing data is retained for 10 years in accordance with French law.
9. Security
Data is encrypted in transit (TLS 1.3) and at rest. Authentication uses JWTs signed by Supabase. Sessions are protected by httpOnly, secure, and sameSite=lax cookies, signed with HMAC-SHA256.
10. Changes
In the event of a material change, we will notify editors by email at least 30 days before the changes take effect.
Revu — getrevu.co · hello@getrevu.co