Summary. The only personal data this website itself collects is a waitlist entry: your email address, which form you used and when. It sets no cookies and runs no analytics. The Revl gateway is bring-your-own-key. Your provider API key is forwarded with each request and is never stored or logged. Request and response bodies are never logged. We train no models.
1. Who we are and scope
Revl AI ("we", "us") is an early-stage, founder-led project. We build an open-source, bring-your-own-key (BYOK) gateway that sits between an application and a model provider (Anthropic or OpenAI). Revl AI is independent. It is not affiliated with, endorsed by or sponsored by Anthropic or OpenAI.
Operator. Revl AI (Operated by Luat Nguyen), based in Da Nang, Vietnam.
This policy covers the website at proxyrevlvay.com, the hosted gateway at api.proxyrevlvay.com and email you send us. The hosted gateway is invite-only and is being rolled out to the waitlist.
It does not cover gateways run by other people. The gateway core is open source (source on GitHub) and anyone can host it on their own Cloudflare account. When someone self-hosts, Revl AI processes nothing. The operator of that deployment is responsible for its data.
2. What we collect
| When | What | Why | Where it goes |
|---|---|---|---|
| You visit the website | IP address and request metadata, such as URL, time and user agent | To deliver and protect the site | Processed by Cloudflare, our infrastructure provider, which keeps request logs for a short period |
| You join the waitlist or ask for API keys | Email address (stored in lower case), which form you used (waitlist or api-keys) and a timestamp |
To contact you about access to the hosted gateway | One row in a Cloudflare D1 database table. No IP address is stored in that table. |
| You submit a signup form | IP address, used briefly by a rate limiter | To allow at most 5 signup attempts per minute per IP address | Not written to the database by the site |
| You email us | Your email address and what you write | To answer you | The mailbox for founder@proxyrevlvay.com, read by the founder |
| You use the hosted gateway (invite-only) | A SHA-256 hash of your gateway key, one metadata log line per request, and cache entries only if you turn caching on | To authenticate your requests and run the gateway | See section 6 |
3. What we do not collect
- No cookies and no browser storage such as localStorage.
- No analytics, no advertising and no tracking pixels.
- No accounts, no passwords and no payments today. The paid plans shown on the site are planned pricing for the hosted gateway.
- No provider API keys. The gateway forwards your key for the one request it arrives with and never stores or logs it.
- No request or response bodies in logs.
We do not sell personal data.
4. Third-party resources loaded by the pages
Each page loads one thing from a third party: a font stylesheet from Google Fonts (fonts.googleapis.com) and the font files it points to (fonts.gstatic.com). The pages load no third-party scripts.
Your browser fetches these files directly. As part of serving a file, Google receives your IP address and user agent. Our referrer policy limits the referrer on those requests to the site's address, not the page you are on. Google handles that data under its own privacy policy. We do not get it from Google.
The site's Content Security Policy does not allow pages to load scripts, styles, fonts or images from any other third party.
5. How we use data
We use waitlist entries to contact you about access to the hosted gateway. We use email you send us to answer you. Request data handled by Cloudflare is used to deliver and protect the site and to limit signup attempts. Hosted gateway data is used to authenticate your requests, apply the options you set, forward requests to the provider you chose, enforce rate limits and troubleshoot.
We do not use any of it for advertising. Revl AI trains no models, so we do not use your content to train models.
6. Hosted gateway data
This section applies only if you have been invited to the hosted gateway, which runs the open-source core. The documentation describes each option.
6.1 Your provider API key (BYOK)
Revl AI does not resell, sublicense, pool or share model-provider API access. You supply your own provider API key with each request. The request is made under your own provider account, your own billing, and that provider's terms and usage policies. You are responsible for complying with them.
The gateway holds no model-provider credentials. Your key is forwarded to the provider you chose for that one request. It is never written to storage, never logged and never used for any other caller. Only provider API keys are accepted. OAuth tokens and consumer subscription tokens are rejected.
The provider handles what you send under its own terms and privacy policy. If your requests include other people's personal data, you are responsible for that data.
6.2 Your gateway access key
You authenticate to the gateway with a gateway access key in the X-Revl-Key header. We store only the SHA-256 hash of that key, with a tenant id, a label and a disabled flag. The key is not forwarded to the provider.
6.3 Caching
Caching is off by default. It applies only to a request where you send X-Revl-Cache: exact. An entry is stored only when the request is not streaming, the provider returned status 200 and the response is at most 1 MiB.
- An entry holds the provider's response: status, content type and body. With masking on, it is the response to the masked request, before your original values are put back.
- An entry is scoped to your tenant and to your provider key. It is never served to a different tenant or a different provider account.
- An entry expires after the TTL you set, between 60 seconds and 24 hours. If you set none, the TTL is one hour.
6.4 Masking
Masking is off by default. When you turn it on for a request, values that match the pii or secrets patterns are replaced with placeholders such as <EMAIL_1> before the request leaves the gateway. The mapping between placeholders and original values is held in memory for that request only.
Masking is pattern based. It will miss things, and it is not a compliance control by itself. It is not applied to tool definitions, tool call arguments, or image and document data.
6.5 Logging
Request and response bodies are never logged. The gateway writes one metadata log line per request, with these fields: request_id, tenant, route, model, status, cache, upstream_ms, masked, retries and stream. The line contains no bodies, no headers, no key material and no key hashes.
7. Who processes data for us
- Cloudflare is our infrastructure provider. It hosts the website, the waitlist database (Cloudflare D1) and the hosted gateway, and it keeps short-lived request logs. As with any website, it processes IP addresses and request metadata to deliver and protect the service. Cloudflare runs a global network, so data may be processed outside the country you live in.
- The model provider you choose (Anthropic or OpenAI) receives the requests you send through the hosted gateway. It does so under your own account and its own terms, not on our behalf.
- Our email service carries email you send to founder@proxyrevlvay.com.
We do not share personal data with anyone else, unless the law requires us to.
8. Retention
| Data | How long it is kept |
|---|---|
| Waitlist entries | Until you ask us to remove them, or until the waitlist closes |
| Request logs (website and hosted gateway) | Kept by our infrastructure provider for a short period |
| Cache entries | For the TTL you set, between 60 seconds and 24 hours |
| Masking mappings | In memory for the request only |
| Provider API keys | Not stored |
We list only the periods we know. If you want your data removed, email us.
9. Security
These measures are in place today:
- TLS. The website is served over HTTPS. Plain HTTP requests are redirected, and the site sends a Strict-Transport-Security header. The hosted gateway address is HTTPS, and the gateway calls providers over HTTPS.
- Security headers. Every response from the website carries a Content Security Policy, plus headers that block framing and content-type sniffing and limit the referrer.
- A narrow signup endpoint. It accepts same-origin JSON only, caps the request size and limits attempts per IP address. It gives the same answer whether or not an address is already on the list.
- Keys. Gateway keys are stored only as SHA-256 hashes. Provider keys are never stored or logged.
- No body logging. Request and response bodies are never logged.
We do not claim any security certification or independent audit. No system is perfectly secure, so keep your keys safe. If we learn of a breach that affects your personal data, we will tell you promptly.
10. Your choices and rights
You can ask us to confirm whether your email address is on the waitlist, to send you a copy of your entry, or to delete it. Email founder@proxyrevlvay.com from the address concerned. You do not need to give a reason.
We answer these requests from anyone, wherever you live, and we answer promptly. Depending on where you live, you may also have the right to complain to your local data-protection authority.
11. Children
The website and the gateway are tools for software developers. They are not directed at children, and we do not knowingly collect personal data from children. If you believe a child has given us an email address, tell us and we will delete it.
12. Changes to this policy
If we change this policy, we will post the new version here and change the "Last updated" date. If we introduce cookies, analytics, accounts or payments, we will update this policy first.
13. Contact
Revl AI (Operated by Luat Nguyen)
Da Nang, Vietnam
Email: founder@proxyrevlvay.com
This address is read by the founder. Use it for any privacy question or request.