revvy

Revvy Review Composer - Privacy Policy

Last updated: 1 June 2026

Revvy Review Composer is a browser extension that helps business owners draft responses to customer reviews on third-party platforms. This policy explains what data the extension accesses, how it is used, and how it is stored.

1. Data collection

(a) Personal information provided by the user

  • Email address
  • Business name
  • API authentication token
  • Authentication cookie - the extension reads a session cookie from api.revvy-app.com to verify your login status. This cookie is set by Revvy's own servers and is not read from any third-party site.
  • Password - during login, your email and password are transmitted over HTTPS to api.revvy-app.com for authentication. Your password is never stored in the extension or in local storage; it is used only to obtain an authentication token.

(b) User preferences

  • Default response tone
  • Default response length
  • Brand context text

(c) Review data extracted from web pages

When you click the "Draft Reply" button on a supported review platform, the extension reads the following from the page:

  • Review text
  • Reviewer's public display name
  • The star rating, where the platform provides one. On Facebook this is a "recommends / doesn't recommend" recommendation rather than a 1 to 5 star rating
  • Platform name

This data is only read when you explicitly click the "Draft Reply" button. The extension never reads review data automatically, and it does not monitor your browsing activity. The extension uses a standard browser API (MutationObserver) to detect when new reviews load dynamically on supported platforms, solely to inject the "Draft Reply" button into the page. This observer does not read, record, or transmit any page content.

(d) Data we do not collect

  • Browsing history
  • Data from non-review pages
  • Analytics or tracking data
  • Cookies from third-party sites (the extension only reads its own authentication cookie from api.revvy-app.com, which is a Revvy-operated domain)
  • Anything from Google properties (including Google Search, Google Maps, and Google Business Profile)

2. Data handling

The table below maps each data type to its purpose:

Data typePurpose
Email address / Business nameDisplay in extension settings
API authentication tokenAuthenticate requests to our API
Preferences (tone, length, brand context)Personalise draft responses
Review text, reviewer name, rating, platformGenerate a draft reply via AI

We do not use your data for advertising, profiling, or AI model training.

Automated processing

Our AI generates draft responses based on the review data and your preferences. You always review the draft before it is used. No automated decisions are made that produce legal effects or similarly significant consequences.

Ephemeral processing

Review data (review text, reviewer name, rating, and platform) is held in the extension's working memory only for the duration of a single draft request. Once the API returns a response, this data is deleted from memory. It is never written to local storage or cached between sessions.

3. Data storage

Local storage

The extension stores data in your browser via chrome.storage.sync:

  • API authentication token
  • Business ID
  • Email address
  • Business name
  • Preferences (tone, length, brand context)

This data syncs across your Chrome browsers via your Google account. It is not sent to third parties.

Server-side storage

Review text is not logged or permanently stored on our servers. It is used only in real time to generate a draft response. Account data is governed by the main Revvy Privacy Policy.

Retention and deletion

Local data persists until you sign out of the extension, uninstall it, or clear extension data in Chrome settings. To request deletion of your account and associated data, email support@revvy-app.com.

4. Data sharing

We do not sell, rent, or trade your personal data. The only external data transmission is to our own API at api.revvy-app.com. Each draft request sends the following data over HTTPS: review text, reviewer display name, star rating, platform name, brand context, preferred tone, preferred length, and your authentication token. No data is transmitted to any other external service.

Service providers

Our infrastructure is hosted by Railway under a data processing agreement. Railway does not have independent access to your data and only processes it on our behalf.

Legal disclosure

We may disclose personal information if required to do so by law or in response to valid requests by public authorities.

5. Data security

  • All communication with our API uses HTTPS/TLS encryption.
  • Chrome synced storage is encrypted via your Google account credentials.
  • API requests use Bearer token authentication.
  • No data is stored in plain text outside Chrome's built-in storage mechanisms.

6. Browser permissions

The extension requests the following browser permissions:

  • activeTab - to read review content from the current tab when you click "Draft Reply"
  • storage - to save your preferences and authentication token locally in your browser
  • cookies - to read the Revvy authentication cookie from api.revvy-app.com only, so the extension can verify your login status without requiring a separate login. The extension does not read, write, or access cookies on any other domain, including the review platforms where it operates.
  • host permissions - for TripAdvisor (11 country domains), Trustpilot, Facebook, Yelp (.com and .co.uk), and api.revvy-app.com - to operate on review pages and communicate with our API

7. Children's privacy

The Revvy Review Composer extension is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us at support@revvy-app.com.

8. Your rights

8.1 UK and EU GDPR

If you are in the United Kingdom or the European Union, you have the following rights under the UK GDPR and EU GDPR:

  • Right to access your personal data
  • Right to correct inaccurate data
  • Right to delete your data
  • Right to restrict processing
  • Right to object to processing
  • Right to data portability

Our legal basis for processing is legitimate interest. The extension is operated by Huw Williams (trading as revvy), registered with the UK Information Commissioner's Office under registration number ZC115483.

8.2 California CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of the sale of personal information

We do not sell personal information.

9. Changes to this policy

We may update this privacy policy from time to time. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the extension after any changes constitutes acceptance of the revised policy.

10. Contact

If you have any questions about this privacy policy, please contact us at support@revvy-app.com.