Effective date: August 22, 2026
Revlr ("Revlr", "the Service") is operated by Andpixels LLC, doing business as &Pixels, a Texas limited liability company with its registered address at 5900 Balcones Drive, Ste. 165, Austin, TX 78731 ("we", "us", "our"). Andpixels LLC is the data controller responsible for your personal data under this Privacy Policy. For privacy-related questions, contact us at revlr.ai/contact or by mail at: Andpixels LLC 5900 Balcones Drive, Ste. 165 Austin, TX 78731 United States
2.1 Account data. Your email address, display name (if provided), and authentication credentials. Collected when you create an account. 2.2 Audit data. The URLs you submit for auditing, page content and metadata retrieved from those URLs, screenshots captured for display in audit reports, Lighthouse performance and accessibility metrics, inbound link metrics, audit findings and scores generated by the Service, and delta summaries produced on re-audits. Screenshots are captured and hosted by Firecrawl; Revlr stores the link to the image rather than the image file. 2.3 Usage data. Pages visited within Revlr, features used, timestamps of activity, browser type, device information, IP address, and referring URL. Collected via Google Analytics 4, Supabase, and server logs. 2.4 Payment data. If you purchase a paid plan, payment is processed by Stripe using Stripe Elements or Stripe Checkout. Your card details are entered directly into Stripe's payment interface and never touch Revlr's servers. We receive and store only a transaction identifier, plan type, billing status, and the last four digits of your card for display purposes. 2.5 Communication data. Messages you send through the contact form at revlr.ai/contact or via email, including your email address and any content you include. 2.6 Cookie and tracking data. Authentication cookies, analytics cookies, and theme or preference cookies. See Section 8 for details. 2.7 Marketing data. Your email address, subscription preferences, and engagement data (opens, clicks) when you subscribe to or receive marketing communications. See Section 9 for details. 2.8 Bot-verification data. Cloudflare Turnstile collects interaction signals (such as mouse movements and timing data) on the free-audit and newsletter forms to distinguish human users from automated bots. This data is processed by Cloudflare and is not stored by Revlr.
We use your data for the following purposes: 3.1 Delivering the Service. Generating, storing, and displaying your audit reports; fetching page content and capturing screenshots via Firecrawl; running Lighthouse analyses via Google PageSpeed Insights; retrieving inbound link data via the Moz Links API; processing URLs and page text through Anthropic's Claude API for AI-generated findings; calculating delta summaries on re-audits. (Legal basis under GDPR: performance of our contract with you.) 3.2 Authentication and security. Verifying your identity, managing sessions, enforcing Row Level Security on database queries, applying rate limiting via Upstash Redis, protecting forms against automated abuse via Cloudflare Turnstile, and preventing unauthorized access. (Legal basis: performance of contract; legitimate interest in platform security.) 3.3 Payment processing. Processing subscriptions and payments through Stripe. (Legal basis: performance of contract.) 3.4 Transactional communications. Sending login codes, account alerts, audit completion notices, and service-related messages via MailerSend. (Legal basis: performance of contract.) 3.5 Marketing communications. Sending newsletters, feature announcements, and product updates via MailerLite, subject to your consent where required. See Section 9. (Legal basis: consent for users in the EEA, UK, and Switzerland; legitimate interest with opt-out for users elsewhere.) 3.6 Analytics and improvement. Analyzing aggregated and anonymized usage patterns to improve the platform. (Legal basis: legitimate interest in improving our service.) 3.7 Legal compliance. Responding to lawful requests, enforcing our terms, and complying with applicable law. (Legal basis: legal obligation; legitimate interest.) We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit consent.
Revlr uses Anthropic's Claude API to generate audit findings. When you submit a URL for auditing, the following data is sent to Anthropic for processing: • The URL you submitted; • Page content and metadata retrieved from that URL. Screenshots are not sent to Anthropic. Screenshots are captured by Firecrawl for display in your audit reports and are not part of any AI request. Anthropic processes this data solely to generate the audit response and returns the results to Revlr. Under Anthropic's commercial API terms, data submitted through the API is not used by Anthropic to train its models. Revlr uses two Anthropic models in each audit: • Claude Haiku 4.5 generates findings for the Performance, Accessibility, SEO, Security, and Compliance & Privacy categories. • Claude Sonnet 4.6 generates findings for the Best Practices, AEO (Answer Engine Optimization), and GEO (Generative Engine Optimization) categories, as well as the Executive Summary, Overall Summary, Callout, Premium User Experience and Content sections, and delta summaries on re-audits. Audit results are stored in your Revlr account. The data sent to Anthropic is processed in the United States.
Revlr uses the following third-party services that may process your data: • Supabase: database, authentication, file storage, Row Level Security. Processes account data, audit data and findings, profile images, usage data. • Vercel: hosting, serverless functions, cron jobs. Processes all data in transit, and server logs. • Anthropic: AI audit generation (Claude API). Processes submitted URLs and page content. • Firecrawl: page fetching and screenshot capture. Processes the URLs you submit and the page content returned, and hosts the captured screenshots. • Google PageSpeed Insights: Lighthouse performance, accessibility, and best practices scoring. Processes the URLs you submit. • Moz Links API: inbound link metrics for SEO scoring. Processes the domain of submitted URLs. • Stripe: payment processing. Processes payment data; card details are entered directly into Stripe. • MailerSend: transactional email delivery. Processes your email address and message content. • MailerLite: marketing email delivery. Processes your email address and subscription and engagement data. • Google Analytics 4: usage analytics. Processes usage data and a truncated IP address. • Cloudflare Turnstile: bot protection on forms. Processes interaction signals such as mouse movements and timing. • Upstash Redis: rate limiting on audit creation and free scans. Processes your account identifier for signed-in requests, and your IP address for anonymous free scans. Each provider operates under its own privacy policy and applicable data processing agreements.
Revlr's infrastructure is hosted in the United States. Your data is stored on Supabase (US-hosted, AWS infrastructure) and Vercel (US-based hosting). Data sent to Anthropic for AI processing is processed in the United States. Firecrawl, Google PageSpeed Insights, and Moz process submitted URLs in the United States. Google Analytics may transfer data internationally through Google's global infrastructure. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data is transferred to the United States. We rely on the following mechanisms to safeguard these transfers: • The EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework, where the receiving provider is a participant; • Standard Contractual Clauses approved by the European Commission, incorporated into our data processing agreements with sub-processors that are not Data Privacy Framework participants.
7.1 Account and audit data. Retained for as long as your account is active. If you delete your account, your personal data and audit reports are permanently deleted within 30 days. 7.2 Payment records. Transaction records are retained for the period required by applicable tax and accounting law (typically seven years), even after account deletion. 7.3 Server logs. Retained for 90 days, then automatically purged. 7.4 Analytics data. Google Analytics data is retained in accordance with our GA4 data retention settings and Google's data retention policies. 7.5 Marketing data. Your email address and subscription preferences are retained until you unsubscribe. Engagement data is retained by MailerLite in accordance with its data retention policies. 7.6 Legal holds. Where retention is required by law, legal process, or active dispute, data subject to the hold is retained until the hold is lifted, notwithstanding the periods above.
Revlr uses the following cookies: • Session / authentication cookie: keeps you logged in and manages your session. Session, or up to 30 days. • Analytics consent cookie: records your analytics consent preference. 1 year. • Theme preference cookie: stores your display preference, such as dark mode. 1 year. • Google Analytics (_ga, _ga*): distinguishes unique users and sessions for usage analytics. Up to 2 years. Analytics consent. Analytics cookies (Google Analytics) are not loaded until you accept them through our cookie banner. This applies in every region, not only where the law requires consent, so analytics are never on by default. You may change your choice at any time using Cookie Settings in the site footer; choosing essential only after having accepted also deletes the Google Analytics cookies already on your device. We honor Global Privacy Control (GPC) signals: if your browser or an extension sends a GPC signal, analytics are off regardless of your location and the banner says so, and analytics will not load unless you affirmatively opt in despite the signal. GPC also overrides an acceptance given before the signal appeared. For additional detail, see our Cookie Policy at revlr.ai/cookies.
Revlr sends marketing emails, including newsletters, feature announcements, and product updates, via MailerLite. 9.1 Consent. For users in the EEA, UK, and Switzerland, we send marketing emails only with your prior opt-in consent. For users in other jurisdictions, we may send marketing emails based on our legitimate interest in communicating with our users, with an opt-out mechanism in every message. 9.2 Unsubscribe. Every marketing email includes an unsubscribe link. You may also manage your preferences through your account settings or by contacting us at revlr.ai/contact. Unsubscribe requests are processed promptly. Opting out of marketing does not affect transactional emails related to your account or service.
Depending on your location, you may have the following rights regarding your personal data: • Access the personal data we hold about you; • Correct inaccurate or incomplete data; • Delete your data (right to erasure); • Export your data in a portable, machine-readable format; • Object to or restrict certain processing activities; • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing; • Lodge a complaint with your local data protection supervisory authority (for EEA, UK, and Swiss users). To exercise any of these rights, contact us at revlr.ai/contact. We will respond within 30 days. If we need additional time, we will notify you of the extension and the reasons for it.
We implement industry-standard security measures, including: • Encrypted connections (TLS) for all data in transit; • Row Level Security enforced on all Supabase database queries; • Rate limiting on audit creation and free scans via Upstash Redis; • Bot protection on public forms via Cloudflare Turnstile; • Access controls on sensitive operations and administrative functions; • Payment card details processed exclusively through Stripe's PCI-compliant infrastructure and never stored on our servers. No method of transmission over the internet or electronic storage is completely secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.
Revlr is not intended for use by anyone under 13 years of age. We do not knowingly collect personal data from children under 13. In the European Economic Area, United Kingdom, and Switzerland, users must be at least 16 years of age. If we learn that we have collected data from a child below the applicable age threshold, we will delete that data promptly. If you believe a child has provided us with personal data, contact us at revlr.ai/contact.
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act provide you with additional rights regarding your personal information. 13.1 Categories of personal information collected. • Identifiers: email address, display name, IP address, account ID. • Commercial information: subscription plan, transaction history, billing status. • Internet or electronic network activity: pages visited, features used, timestamps, browser type, referring URL. • Inferences: audit scores and findings generated from submitted URLs. 13.2 Use and disclosure. We collect and use personal information for the business purposes described in Section 3. We disclose personal information to the service providers listed in Section 5 for the purposes described in this Privacy Policy. We do not sell or share (as defined by the CCPA/CPRA) your personal information, and we have not done so in the preceding 12 months. 13.3 Your California rights. You have the right to: • Know what personal information we collect, use, and disclose; • Delete your personal information, subject to legal exceptions; • Correct inaccurate personal information; • Opt out of the sale or sharing of personal information (we do not sell or share, but you may submit a request at any time); • Non-discrimination for exercising your privacy rights. To exercise these rights, contact us at revlr.ai/contact. We will verify your identity before processing your request.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice within the Service at least 30 days before the changes take effect. We may make non-material changes (such as formatting updates, clarifications that do not alter your rights, or changes required by law) without advance notice. Your continued use of Revlr after the effective date of a revised policy constitutes your acknowledgment of the changes. If you do not agree with a revised policy, you may delete your account at any time.
For privacy-related questions, to exercise your data rights, or to file a complaint: Online: revlr.ai/contact Mail: Andpixels LLC 5900 Balcones Drive, Ste. 165 Austin, TX 78731 United States