Privacy Policy
ReviewAhead is built to hold as little of your project as possible. Your archive and everything extracted from it are deleted the moment a scan ends, and what remains is the text of the findings themselves.
Last updated 5 September 2026
Who is responsible
The controller of the personal data described here is:
- Trader
- Not yet published. Ask by email and it will be given to you.
- Legal form
- a sole trader (eenmanszaak) registered in the Netherlands
- Registered address
- Not yet published. Ask by email and it will be given to you.
- Chamber of Commerce (KvK)
- Not yet published. Ask by email and it will be given to you.
- VAT identification number
- Not yet published. Ask by email and it will be given to you.
- Not yet published. This deployment has no contact address configured.
For any privacy question or request, email (no contact address published).
The short version
- Your uploaded archive is streamed to a temporary file and deleted when the scan finishes, whether it succeeded or failed.
- Extracted source lives in an isolated directory that is removed as the last step of the pipeline. You watch that step complete on screen.
- Your code is never executed, never used to train models, and never sold.
- What is kept is the report: findings, short evidence excerpts, the score and your answers.
- An account is optional. Scanning, reading and buying all work without one.
What is kept, and for how long
| Data | Kept for | Why |
|---|---|---|
| Uploaded archive | Until the scan ends | It is the input. Deleted in a `finally` block, so a crash deletes it too. |
| Extracted source | Until the scan ends | Read to produce findings, then the directory is removed. |
| Report and findings | 24 hours for a free report | So you can come back to it. Then it expires on its own. |
| App icon thumbnail | With the report | Re-encoded at most 128px square, so the report looks like it is about your app. |
| Session cookie | 30 days | Signed and httpOnly. It holds a random id and nothing else. |
| A report you paid for | 365 days | You bought it, so it outlives the free window. |
| Purchase record and billing email | Kept as required by law | It is a financial record and tax law requires it to be retained. |
Evidence excerpts are short, at most 200 characters, chosen by a rule, and masked where they matched credential-shaped text. Whole files are never stored.
What leaves the server
Nothing from your project, with two exceptions, both of which are visible to you.
AI-assisted review
Where AI review is enabled, a deliberately narrow payload is sent to the model provider: permission purpose strings, finding titles, severities, explanations and evidence notes, the target name, the bundle identifier and detected SDK names. The project tree, file contents and raw evidence excerpts are never sent. The report says whether AI review ran.
App Store Connect
If you link an app, ReviewAhead asks Apple what Apple already holds about it. The request carries the app's App Store Connect id and a signed token, and nothing from your project or your upload. If you connected your own API key, that key is held in your browser and used to sign a short-lived token; only the token reaches the server, and it is neither stored nor logged. Where you chose to store the key for other devices, what is stored is ciphertext encrypted under a passphrase you never send, so the server holds a blob it cannot open.
A review demo account's password is never requested and never stored. Only whether a name has been filled in is recorded.
Analytics
Product analytics are enabled. Where they run, they record how ReviewAhead is used and never what is in a scan: text on the scanner and the reports is masked. They do not run on the sign-in, sign-up or onboarding pages at all, which load no analytics code and are given no analytics cookie. You are asked before any non-essential analytics cookie is set, and you can decline.
Who processes data for ReviewAhead
These providers act as processors, under contract, and only for what they are named for:
- Stripe, payments. ReviewAhead never sees your card details.
- Supabase, storage of reports, accounts and purchase records.
- Clerk, sign-in, where you choose to create an account.
- Vercel and Fly.io, hosting and delivery.
- Anthropic, AI-assisted review, and only the narrow payload described above.
- PostHog, product analytics, where enabled.
- Resend, sending email such as a waiting-list confirmation.
Some of these operate outside the European Economic Area. Where they do, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
Legal bases
- Performance of a contract, for running the scan you asked for, delivering the report and handling your purchase.
- Legitimate interests, for keeping the service available and secure, including rate limiting. These interests are balanced against your rights and do not extend to profiling you.
- Consent, for non-essential analytics. You may withdraw it at any time.
- Legal obligation, for keeping financial records.
Your rights
Under the GDPR you may ask for access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. Email (no contact address published) and it will be handled within one month.
Some of this is faster to do yourself. Deleting a project removes it, every scan in its history and its metadata snapshot immediately. Reports also expire on their own, so deletion never depends on you coming back.
You may also complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
Children
ReviewAhead is a tool for people publishing software and is not directed at children. It is not knowingly used to collect data from anyone under 16.
Changes
This policy changes when the product does. The date at the top says when the current wording took effect. See also the Terms of Service and Refunds and Right of Withdrawal.