Your evidence stays in your workspace.
RevStart stores business profiles, evidence, assessments, and sprint outcomes in a dedicated RevStart PostgreSQL database. Passwordless sign-in uses the existing Supabase identity service. Access is limited to enabled pilot accounts and each account can read only its own workspace.
What leaves the workspace
A website review requests the public URL you selected. Pages are inspected as HTML, without signing in or running the page’s scripts. When you choose live research and the pilot is enabled, your business brief, aggregate metrics and public page excerpts are sent to the explicitly selected provider, OpenAI or Anthropic, to evaluate the site and research channels. Customer notes, account details and credentials are not included. Research reports and usage counts are saved to your private workspace. Downloading an agent brief does not send it to an assistant; you choose where to use it.
Google Analytics, when you connect it
The optional Google connection requests read-only Analytics access. RevStart stores an encrypted refresh token scoped to your account and imports aggregate reports for the property and hostnames you select: traffic sources, landing paths, and selected event counts. These reports remain in your private RevStart database and are not sent to an AI provider by the growth dashboard. If you run or update site research, its prompt includes saved aggregate totals, selected event counts, reporting dates, and quality warnings. Property IDs, landing paths, source breakdowns, and Google credentials are excluded from that prompt. Up to eight snapshots per product are retained and can be exported separately. Disconnecting removes RevStart’s stored token and stops new imports; saved aggregate snapshots remain available. You can also revoke the grant through your Google account permissions. Google Analytics may undercount activity because of consent choices, browser blocking, and reporting thresholds.
Keep evidence proportionate
Administrator-supplied and personal API keys are encrypted in RevStart's PostgreSQL storage using a separate server encryption key. They are never returned to the browser or included in workspace exports. Connection checks send the selected key only to that provider's model lookup endpoint. Personal keys are scoped to the signed-in account. You can disconnect a personal key in My AI settings; RevStart will stop using it for new runs. Provider charges for personal-key research belong to your provider account. Disconnecting never switches research to another account automatically.
Use aggregate business metrics and short, anonymized customer notes. Avoid entering passwords, payment card details, or unnecessary personal information. Hosting providers may process operational request logs as part of delivering the service.
Examples and export
The example workspace contains fictional data and is stored only in this browser’s session storage. Resetting the example clears that example state. The private workspace offers a JSON export of your saved business records. Self-service account deletion and public signup are not part of this private pilot.