Security and privacy
What Revial does with your data in practical terms, and where to find the authoritative documents.
This section covers what Revial does with your data day to day: what gets recorded, who can see it, and what you control.
For the questions enterprise security teams ask most often during evaluation, see the Security and privacy FAQ.
For further information, these carry the full detail:
- Trust Center — certifications, written policies and controls
- Data Processing Agreement — sub-processors, GDPR roles and international transfers
- Intended Use, Limitations & AI Transparency — how the AI features are designed and assessed
What Revial records, and when
Revial records a meeting only when it is in the meeting — as a bot participant in a remote meeting, or through your device microphone in a face-to-face one. Recording does not start on its own, and you can stop it at any time.
The customer's consent is required before recording, every meeting. See asking the customer for consent.
You can remove Revial from an individual meeting from the meeting card, and an administrator can restrict it to external meetings only.
Who can see a transcript
Meetings are visible to the people on the calendar invite. Roles determine the rest:
| Role | Sees |
|---|---|
| Member | their own meetings only |
| Admin | their own, plus the organisation's other users' data |
| Owner | everything, plus all organisation settings |
| Viewer | the organisation's data, without working access |
See managing members for how roles are assigned.
Access control you configure
- Single sign-on via SAML 2.0 and OIDC, integrated with your identity provider — see SSO setup
- Multi-factor authentication, required for accounts that do not use SSO, and enforceable organisation-wide by an admin
- Role-based access control on the roles above, with custom roles on Enterprise plans
- SCIM 2.0 provisioning and de-provisioning, on Enterprise plans
- Session timeout, configurable, 12 hours by default
AI and your data
Customer data is never used to train, fine-tune or improve any AI model.
Summaries and analyses are generated, not extracted — review anything customer-facing before you send it. Background research about a company is drawn from public external sources and can be inaccurate; verify figures and dates before repeating them to a customer.
Revial's AI features are decision-support tools. They do not process biometric data, do not infer emotions, and take no autonomous actions. The full assessment is in the AI Transparency documentation.
Getting your data out, and deleting it
You can export your data at any time from the application, or request a structured export.
What happens at the end of a contract — return, deletion timelines and written confirmation — is governed by the DPA and summarised in the FAQ.
Reporting a security issue
Email support@revial.ai with [Security] at the
start of the subject line. We acknowledge within two business days.