Effective: 18 August 2026 Last updated: 18 August 2026
This policy explains what personal data FileRevive (filerevive.tech) processes when you use the service, why, who it is shared with, how long it is kept, and how you can exercise your rights.
It is written to meet the EU General Data Protection Regulation (GDPR) and Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
If there is any discrepancy between this English text and the Turkish version, the Turkish version prevails.
| Controller | TO FILL: full name | |
| Status | Natural person (no registered company at this time) | |
| Address | TO FILL: full postal address | |
| TO FILL: published contact address | ||
| Country | Türkiye | |
| EU representative (GDPR Art. 27) | TO FILL: not yet appointed |
FileRevive is an independent one-person project. The only person with access to your data is the controller.
| Data | Source | |
|---|---|---|
| Email address | You | |
| Password | You — stored only as a hash by Supabase Auth. We never receive or see your password in plain text. | |
| Google account identifier (only if you choose "Continue with Google") | ||
| Account creation date, last sign-in | Automatic |
By the nature of the service, the content of your file is processed. The file is stored on our server disk under a randomly generated name; the filename you provide never reaches the file system and is kept only to display back to you.
The repaired output file is stored the same way.
Important: Your file may contain personal data — a photograph, a contract, a medical report. We do not inspect or classify file contents; we cannot know what you uploaded. Responsibility for the content therefore rests with you. We recommend that you do not upload files containing special category data (health, biometric, religious, sexual orientation, criminal conviction data).
For each repair job we keep a technical record: filename, extension, size, MIME type, status and phase, diagnostic findings, the human-readable report, integrity scores before and after, error codes, and timestamps.
The server records incoming requests. These records contain your IP address, the request path and a timestamp. The purpose is debugging and security.
To limit how many jobs come from one connection, your IP address is irreversibly hashed (HMAC, truncated; IPv6 addresses are rounded to the /64 block). The raw IP is not written to disk for this purpose. Counters live in memory (Redis) and expire automatically after 48 hours.
When you delete your account, the number of files you processed that month is stored against an irreversible hash of your email address. The email address itself is not stored; the record cannot be read back to identify you.
The reason: deleting an account also deletes the job records, and re-registering creates a new account identifier. Without this record, deleting your account and signing up again with the same email would reset your monthly allowance, making the free plan effectively unlimited.
The record is deleted automatically after 60 days.
The sign-in and sign-up screens show an hCaptcha checkbox. Its provider, Intuition Machines, Inc., processes certain data in its own right at that moment, including your IP address and browser/device signals. That data is not passed to us; we receive only a pass/fail result.
We sort cookies and browser storage into three groups. The bar that appears at the bottom on your first visit asks which groups you accept.
1. Strictly necessary — no consent required
Under Article 5(3) of the ePrivacy Directive, storage that is strictly necessary to provide the service does not require consent. These cannot be turned off:
| Item | Purpose | Duration | |
|---|---|---|---|
sb-…-auth-token | Keeping you signed in | Until you sign out | |
fr_reload_… | Preventing an infinite reload loop | Until the tab closes | |
fr_riza | Remembering your choice on this page | 1 year | |
| hCaptcha's own storage | Bot protection | Set by hCaptcha |
2. Preferences — with your consent
| Item | Purpose | Duration | |
|---|---|---|---|
fr_onb, fr_dragdemo | Showing the intro once | Persistent |
When off, these are never written; the intro reappears on every visit.
3. Statistics — with your consent
We use Google Analytics 4 to measure which pages are used.
| Cookie | Purpose | Duration | |
|---|---|---|---|
_ga | Distinguishing visitors | 2 years | |
_ga_<measurement-id> | Keeping session state | 2 years |
When this group is off, the Google Analytics code is never loaded. No request reaches Google and the cookies above are not written. Choosing "Only essential" on the consent bar, or turning this group off in Settings, is enough — you do not need to do anything else.
If you turn it off later: measurement stops immediately and any _ga cookies already written are deleted.
Provider: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Data may be transferred to the United States; the legal basis is the EU–US Data Privacy Framework (European Commission adequacy decision of 10 July 2023; Google LLC is certified under that framework).
Features we disable: advertising identifiers and personalisation (allow_google_signals and allow_ad_personalization_signals are off), IP anonymisation on. Measurement data is not used for advertising.
Changing your choice. You can switch each group on or off at any time under Settings → Interface. Withdrawing consent is as easy as giving it (GDPR Art. 7(3)). If a new cookie group is added, your earlier consent does not cover it and the bar asks again.
We use no advertising or profiling cookies. Fonts and JavaScript libraries are served from our own server; no third-party host is contacted for those files.
| Purpose | GDPR basis | KVKK basis | |
|---|---|---|---|
| Creating your account and authenticating you | Art. 6(1)(b) contract | Art. 5/2-c | |
| Receiving, repairing and returning your file | Art. 6(1)(b) | Art. 5/2-c | |
| Showing your past files in your account | Art. 6(1)(b) | Art. 5/2-c | |
| Counting your monthly allowance | Art. 6(1)(b) | Art. 5/2-c | |
| Sending transactional email (verification, password reset) | Art. 6(1)(b) | Art. 5/2-c | |
| Preventing abuse, rate limiting, bot protection | Art. 6(1)(f) legitimate interests | Art. 5/2-f | |
| Keeping usage history of deleted accounts (hashed email) | Art. 6(1)(f) legitimate interests | Art. 5/2-f | |
| Security and debugging logs | Art. 6(1)(f) | Art. 5/2-f | |
| Complying with legal obligations | Art. 6(1)(c) | Art. 5/2-ç |
We do not process data for marketing and we do not profile. There is no automated decision-making; the outcome of a repair has no legal effect on you.
We do not sell your data and we share it with no one for marketing. The following service providers (sub-processors) are used to run the service:
| Recipient | What it receives | Where | Transfer basis | |
|---|---|---|---|---|
| Supabase, Inc. | Email address, password hash, job records | Mumbai, India | Standard Contractual Clauses (Supabase DPA). India is not covered by an EU adequacy decision. | |
| Anthropic PBC | Parts of your file for diagnosis — structural headers and analysis-tool output | USA | Standard Contractual Clauses (Anthropic commercial terms and DPA). Under Anthropic's commercial terms this data is not used to train models. | |
| Hostinger International Ltd. | File content, repaired output, server logs (hosting) | TO FILL: data centre country | TO FILL: no transfer if the data centre is in the EU; otherwise Standard Contractual Clauses | |
| Intuition Machines, Inc. (hCaptcha) | IP address, browser/device signals | USA | Standard Contractual Clauses | |
| Google Ireland Limited (Google Analytics) | Page views, browser/device info, anonymised IP — only if you consent | Ireland / USA | EU–US Data Privacy Framework | |
| Google LLC | Only if you choose "Continue with Google": account identifier and email | USA | Standard Contractual Clauses | |
| Google LLC (Gmail SMTP) | Delivery of transactional email | USA | Standard Contractual Clauses. This is a temporary arrangement; a business email provider will replace it. | |
| Polar Software, Inc. | Only if you pay: name, email, billing address, payment details | USA | Standard Contractual Clauses. Polar is the *merchant of record*: it is legally the seller of the transaction and handles VAT reporting and refunds. Your card details never reach us. |
Beyond these, data may be disclosed where legally required (court order, lawful request from a competent authority).
We set this out separately because it is the most important point about the service.
Your file is repaired inside an isolated container with no internet access. The AI agent that decides how to repair it (Anthropic's Claude model) runs commands inside that container — for example a tool that reads the file's header bytes. The output of those commands is sent to the model. So not the whole file, but the parts needed for diagnosis, do reach Anthropic.
You should decide with this in mind: if a file contains something you would not want leaving your machine, do not upload it.
| Data | Period | |
|---|---|---|
| Your uploaded file and the repaired output | Automatically deleted 24 hours after upload. Deleting them sooner takes one click. | |
| Orphaned files (uploads with no matching record) | Deleted automatically after 6 hours | |
| Job record (filename, report, scores) | Kept even after you delete the file (file keys are cleared and a deletion date is set). The record is kept because your monthly allowance is counted from it. Retained until your account is deleted. | |
| Account data (email) | Until your account is deleted | |
| Server logs (including IP address) | 14 days, then deleted automatically | |
| Access log (raw IP, browser identifier, email, action — see 2.9) | 12 months. Retained even if you delete your account (GDPR Art. 17(3)(e)). | |
| Hashed IP counters | 48 hours | |
| Usage history of a deleted account (hashed email + count) | 60 days | |
| Backups (database and configuration) | 14 days. When you delete your account you are removed from the live system immediately; you may remain in backups for up to 14 more days, after which they are overwritten. Backups are kept solely for disaster recovery and used for nothing else. |
Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to:
Write to the email address above. We answer within 30 days at the latest (KVKK Art. 13; one month under GDPR Art. 12).
You can already delete your files and job records yourself from the panel in one click. Full account deletion is also done from the panel: Settings → Delete account. You are asked to type your email address to confirm; after that your account, files and job records are permanently deleted. You may also send the request by email if you prefer.
Note: deleting your account does not restore that month's allowance. If you sign up again with the same email, your usage from before the deletion still counts (see 2.6). This prevents the free plan from becoming unlimited.
authority of your country.
(kvkk.gov.tr).
access.
No system is completely secure. In the event of a data breach we will notify the relevant authority within the statutory period (72 hours under GDPR; without undue delay under KVKK) and inform affected users.
The service is not designed for or directed at anyone under 16. If we learn that an account belongs to someone under 16, we delete it.
When this policy changes, the effective date is updated. For material changes we send a notice to the email address on your account.
For any privacy question: TO FILL: contact address