// privacy · v1.0 · effective 2026-05-29
Privacy Policy
We do not sell your data. We do not run third-party ad tracking. We log
scans for research transparency and model improvement only, with row-level
separation between public and authenticated requests.
TL;DR: Public scans (no login) are logged anonymously
for our retraining dataset. Authenticated scans are private to your
account. We never associate scans with you unless you log in. GDPR/UK-GDPR
compliant. Contact
ssolovev@revert.pro
for any data request.
1. Who we are
Data controller: Atlas Trading Agency LLC
(Trade Agency Atlas LLC), operating the REVERT brand, registered
in Bishkek, Kyrgyzstan.
2. What we collect
2.1 When you scan a contract anonymously (no login)
- Contract address you submit (public on-chain data)
- Contract bytecode fetched from public RPCs (Alchemy)
- Risk score, verdict, top features produced by our XGBoost model
- Latency metrics and our model version (for telemetry)
- Your IP address (for rate-limiting only, hashed within 24h)
We do not store your name, email, browser fingerprint,
cookies (other than session), or geographic location beyond IP-derived
rate-limit buckets.
2.2 When you create an account (Magic Link)
- Email address (to send Magic Link login)
- Authentication metadata via Supabase (UUID, JWT)
- All anonymous data above, linked to your user ID
- Scan history visible only to you (row-level security in DB)
2.3 When you request a paid tier (early access)
Free-tier keys are self-serve now; paid tiers are unlocked manually during
early access — generate a free key and email
ssolovev@revert.pro to lift the cap.
USDC checkout is live at revert.pro/pay. During early access paid tiers are unlocked
manually and no automated payment data is collected.
- If/when automated billing is enabled (a metered card or
crypto checkout), we will receive payment metadata
(subscription ID, plan, status) from our payment processor — we
never see your card number or crypto wallet
- If automated billing goes live, the payment processor (Merchant of Record)
would act as a separate data controller for billing data; their privacy policy
applies to that information
3. Why we collect
- Provide the service (you ask for a risk score, we return one)
- Improve the model via anonymous corpus growth (no user data attached)
- Prevent abuse (rate limiting, fraud detection)
- Bill you — only if/when automated paid billing is enabled (currently paid tiers are unlocked manually during early access)
- Security disclosure per our security policy
Legal basis (GDPR Art. 6): contract performance (you requested the scan),
legitimate interest (model improvement, abuse prevention), and consent
(cookies, marketing communications — opt-in only).
4. What we do NOT do
- We do not sell or rent personal data to any third party
- We do not run cross-site advertising trackers (no Google Analytics, no Meta Pixel, no Hotjar)
- We do not use scan data from authenticated accounts for our bounty hunting work — that is a strict data-lane separation rule
- We do not retain raw IP addresses beyond 24h
- We do not target ads at you
5. Where data lives
- Application database: Supabase (PostgreSQL),
Frankfurt region (EU)
- API service: DigitalOcean droplet, Frankfurt region (EU)
- Frontend hosting: Vercel (global CDN)
- Authentication: Supabase Auth (Frankfurt)
- Email: Supabase Auth provider for Magic Link delivery
All data at rest is encrypted (Supabase default). All data in transit is
encrypted via TLS 1.2+.
6. How long we keep it
- Scan log: indefinite (research artifact, no PII without account)
- Account email: until you delete your account, then 30 days
- Rate-limit IP buckets: 24h sliding window
- Server logs (uvicorn / nginx): 30 days
- Payment records (only generated when a paid tier is invoiced; during early access paid tiers are unlocked manually): 7 years (tax compliance requirement)
7. Your rights (GDPR / UK-GDPR)
You have the right to:
- Access all data we hold about you (export available on request)
- Rectify incorrect data
- Erase your data ("right to be forgotten") — we honor this within 30 days
- Restrict processing (pause our use without deleting)
- Data portability — receive your data in JSON
- Object to processing based on legitimate interest
- Withdraw consent at any time (where consent was the basis)
- Lodge a complaint with a supervisory authority
Email ssolovev@revert.pro with
subject [GDPR Request] — we respond within 30 days.
8. Cookies
We use only essential cookies — chiefly a session cookie for authenticated
users (Supabase Auth). We do not use tracking, analytics, or advertising cookies.
No consent banner is necessary because we do not place non-essential cookies.
9. Children's data
REVERT is a professional security tool. We do not knowingly collect
data from anyone under 18. If we learn we have, we will delete it
immediately.
10. International transfers
If you are outside the EU, your data may be processed in Frankfurt
(Germany). Vercel CDN may cache static assets globally (no PII in static
assets). Payment processor handles its own international transfers under
its DPA.
11. Changes to this policy
Material changes will be announced at least 30 days in advance via
email (for account holders) and via banner on our homepage. Minor edits
(typos, clarifications) take effect immediately. Version history is
available at /changelog.
12. Contact
Email: ssolovev@revert.pro
Postal: Atlas Trading Agency LLC (operating as REVERT) · Reg. №321952-3301-OOO · INN 00311202510097 · 55 Logvinenko St., Office 243, Bishkek, Kyrgyzstan
Founder: Sergei Solovev
For security disclosures: /.well-known/security.txt