Revial
Security and privacy

Security and privacy

What Revial does with your data in practical terms, and where to find the authoritative documents.

This section covers what Revial does with your data day to day: what gets recorded, who can see it, and what you control.

For the questions enterprise security teams ask most often during evaluation, see the Security and privacy FAQ.

For further information, these carry the full detail:

What Revial records, and when

Revial records a meeting only when it is in the meeting — as a bot participant in a remote meeting, or through your device microphone in a face-to-face one. Recording does not start on its own, and you can stop it at any time.

The customer's consent is required before recording, every meeting. See asking the customer for consent.

You can remove Revial from an individual meeting from the meeting card, and an administrator can restrict it to external meetings only.

Who can see a transcript

Meetings are visible to the people on the calendar invite. Roles determine the rest:

RoleSees
Membertheir own meetings only
Admintheir own, plus the organisation's other users' data
Ownereverything, plus all organisation settings
Viewerthe organisation's data, without working access

See managing members for how roles are assigned.

Access control you configure

  • Single sign-on via SAML 2.0 and OIDC, integrated with your identity provider — see SSO setup
  • Multi-factor authentication, required for accounts that do not use SSO, and enforceable organisation-wide by an admin
  • Role-based access control on the roles above, with custom roles on Enterprise plans
  • SCIM 2.0 provisioning and de-provisioning, on Enterprise plans
  • Session timeout, configurable, 12 hours by default

AI and your data

Customer data is never used to train, fine-tune or improve any AI model.

Summaries and analyses are generated, not extracted — review anything customer-facing before you send it. Background research about a company is drawn from public external sources and can be inaccurate; verify figures and dates before repeating them to a customer.

Revial's AI features are decision-support tools. They do not process biometric data, do not infer emotions, and take no autonomous actions. The full assessment is in the AI Transparency documentation.

Getting your data out, and deleting it

You can export your data at any time from the application, or request a structured export.

What happens at the end of a contract — return, deletion timelines and written confirmation — is governed by the DPA and summarised in the FAQ.

Reporting a security issue

Email support@revial.ai with [Security] at the start of the subject line. We acknowledge within two business days.

On this page