Privacy
Privacy policy
Last updated 12 August 2026
Overview
Revrse is a platform run by WithNature Institute & Foundation, a Section 8 non-profit company registered in India. It is infrastructure for the lifecycle of a sustainability project — from a raw idea to verified impact to funding. This policy explains what we collect to make that work, why we collect it, and what happens to it.
The short version: we collect what's needed to run your project, prove your results, and — if you choose to give — process your donation. We don't sell your data, we don't run advertising trackers, and we tell you plainly when something can't be deleted because it's part of a tamper-evident evidence record.
Information we collect
Depending on how you use Revrse, we collect:
- Account information — your email address and authentication details, handled by our identity provider (Supabase Auth).
- Profile— a display name (which defaults to the part of your email before the "@"), whether you make your profile public, and your email-notification preference.
- Project content — anything you write into a project: your raw description, structured plan, claims, and any corrections you make to what the AI reads back to you.
- Evidence you attach — photos, documents, sensor readings, or links you add to a claim, together with the location, accuracy, and capture time you enter for them, and basic file details such as a content hash.
- Organization data — if you join or create a funder organization, we store its membership and the funding programs it lists.
- Donation information — if you donate, we store your email, the amount, and the payment reference from our gateway. Once 80G receipts are available, we also collect the name and PAN you give for the receipt. We never receive or store your full card or bank details.
- Communications — if you email us or use the contact form (which opens your own email app), we keep that correspondence to answer you.
- Usage & operational data — basic logs (timestamps, error rates, request metadata) needed to run and secure the service. Records of AI calls store only a hash of the input and character counts, not the text itself.
We do not run advertising trackers or third-party analytics on Revrse.
How we use your information
We use what you give us to run the platform: to structure your project, generate coaching questions and a verification plan, route your evidence to the right reviewer, compute your impact record, and match you with funders when you choose to be visible to them. If you donate, we use your information to process the payment and, where available, issue a receipt. We also use it to send you email you have opted into or that a transaction requires, to keep the service secure, to debug problems, and to meet legal obligations.
AI processing
Comprehension, coaching, verification planning, report drafting, and knowledge-base answers are generated by a third-party AI model provider (currently Fireworks AI), acting as our processor. Relevant project text is sent to that provider to generate a response, and where a check needs it — for example matching a photo to what was claimed — the evidence image is sent too. An image may contain a location or a person, so treat what you upload accordingly. This data is not used by Revrse to train our own models; we do not control how the provider itself retains inference data, so see their policy for specifics.
AI output is always shown to you before it becomes part of your record — nothing an AI proposes is written as fact until you confirm it, or a qualified human reviewer verifies it.
Location & satellite imagery
The location and capture time attached to a piece of evidence are the ones you enter when you upload it, not data we silently extract from your files. When a project's verification plan includes a remote-sensing check, we send a small geographic bounding box around that location — not your identity — to the Copernicus Data Space (Sentinel Hub) to retrieve public satellite-imagery statistics. Only aggregate figures come back; no imagery or personal data is exchanged. This check is off unless a project's plan calls for it.
Payments & donations
Online donations are processed by Razorpay, acting as our payment processor. Card and bank details are entered on Razorpay's secure checkout and never touch Revrse. We receive and store the donation email, amount, and payment references so we can record the gift and reconcile it; once 80G receipting is live, we also store the donor name and PAN needed for the receipt. Donation records are visible only to WithNature administrators — never to project creators or the public.
When we send you email — a donation receipt, or a notification you have turned on, such as a claim being verified — delivery is handled by a third-party email provider (currently Resend). Your email address and the message content are shared with it to deliver the message. You can turn off notification emails from your account.
Programmes for schools & colleges
Separately from the platform, we run education programmes and competitions for schools, colleges and their students. Those involve personal data that does not arrive through an account, so it is worth setting out plainly.
What a school or college gives us. To enrol students and issue certificates we need a roster: the student's name, class or year, and the institution. We ask for nothing more. We do not ask for a student's phone number, email address, home address or date of birth, and we would rather you did not send them.
Consent is obtained by the institution. Where participants are under 18, the school or college is responsible for obtaining verifiable consent from a parent or guardian before sending us anything about them, and for telling them what it is for. We supply a letter you can use. If consent is withdrawn, tell us and we will remove the student's data.
Work students submit. Some programmes ask students to record a measurement or submit evidence of something they built. Where photographs are involved, we ask for pictures of the work — the meter, the bin, the plant, the prototype — not of the student. Submissions are assessed, and are published only where the institution and guardian have agreed to it.
What we never do. We do not profile students, track their behaviour, use their data to target advertising, or share it with anyone outside the people assessing the programme. There is no advertising on any part of this service.
How long we keep it. Rosters and submissions are kept for the programme year and the period needed to settle results and appeals, then deleted. Aggregate and anonymised results — how a cohort performed, with no individual identifiable — may be kept longer, and certificates issued in a student's name remain valid.
Evidence, verification & the impact record
Once you send something to be checked, what the checkers did and what they concluded are written into a permanent, tamper-evident record. Entries there cannot be edited or removed afterwards — not by you, and not by us. That is deliberate rather than an oversight: a result nobody can quietly change afterwards is the only kind worth calling "confirmed".
To keep that record honest without keeping your words in it, free-text entries are committed to the chain as a one-way cryptographic digest, not as the text itself — the digest proves what was there without being reversible. One consequence remains: once evidence or a verification step is part of this record, the underlying proof (such as a file's content hash and the location attached to it) generally cannot be edited or deleted, even if you later close your account. See "Your rights and choices" for what we can and cannot remove.
Sharing with funders
Your project stays private by default. Nothing is shared with a funder organization unless a match is proposed and a human administrator approves sharing it — and even then, only your verified results (never raw drafts) are visible in the shared readout.
Who we share data with
We don't sell your data. We share it only with the service providers that make the platform work, each acting on our behalf:
- Supabase — authentication, database, and private file storage.
- Fireworks AI — the AI processing described above.
- Razorpay — payment processing for donations.
- Resend — delivery of transactional and opted-in email.
- Copernicus Data Space — public satellite imagery for remote-sensing checks (a bounding box only, no personal data).
- Vercel & GitHub — hosting, and a daily append of non-personal record hashes used to anchor the tamper-evident chain.
We may also disclose information where the law requires it, or to protect the safety and integrity of the platform and its users.
Where your data is processed
WithNature operates from India. Some of the providers above process data on servers outside India. By using Revrse you understand that your information may be processed in other countries under those providers' own safeguards and terms.
Cookies & sessions
We use a small number of strictly necessary cookies to keep you signed in, and occasional short-lived cookies for one-time actions such as revealing a newly created API key. We don't use cookies for advertising or cross-site tracking. Sign-in cookies are set with SameSite protection, and sensitive actions are additionally guarded by server-side origin checks rather than a separate tracking token.
Data retention
We keep account and project data for as long as your account is active. If you close your account or ask us to erase your data, we remove what we can (see below); entries that are part of the tamper-evident record persist in digested or de-identified form to preserve the integrity of other projects' records.
Your rights & choices
You can view and correct your project and profile information from within the app at any time, and control whether your profile is public and whether you receive notification emails.
From the account page you can also request erasure of your personal data. When we act on that request, we de-identify you across the platform — your display name is removed wherever names appear, and your login is retired — and we redact the free-text you contributed so only the non-reversible digest remains in the record. What we cannot remove is the underlying proof that makes verified results trustworthy: file hashes, the location attached to evidence, and record entries that already exist stay in place, but without anything that identifies you. For any privacy question, or to exercise a right, contact us below.
Security
Access to your data is controlled by row-level security enforced at the database layer, scoped to your account, your organization, and your platform role. Evidence files are stored privately and served only via short-lived signed links.
Children & minors
Revrse accounts are for people aged 18 or older. It is not directed at children, and we don't knowingly let a minor create their own account. A young person can still take part — through the account of a parent, guardian, teacher, or institution who accepts these terms and supervises the work. If you believe a minor has created an account, contact us and we'll remove it.
Students taking part in our school and college programmes never hold an account of their own. Their institution enrols them and supervises their participation, and the consent, minimum-data and retention rules set out under "Programmes for schools & colleges" above apply to everything we hold about them.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and post meaningful changes here before they take effect.
Contact
Questions about this policy or your data can be sent to info@revrse.org or via our contact page.