Legal

Privacy Policy

We believe privacy is a right, not a checkbox. This policy explains exactly what we collect, why we collect it, and how you stay in control.

Last updated: May 12, 2026

1. Overview

ReviewBod, Inc. ("ReviewBod", "we", "us", or "our") operates the ReviewBod platform, available at reviewbod.com and related subdomains. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our services. By accessing or using ReviewBod you agree to the terms of this Privacy Policy. If you are using ReviewBod on behalf of an organization, you represent that you have authority to bind that organization to this policy.

2. Information We Collect

2.1 Information you provide directly

When you create an account or use our services you may provide: name, email address, job title, company name, billing information (processed by our payment provider, Stripe — we do not store card numbers), profile photos, and any content you submit through the platform such as performance review text, goals, and feedback.

2.2 Information from third-party integrations

When you connect external services (GitHub, Linear, Jira, Slack, Notion, Figma, Google Drive, etc.) we collect data necessary to provide the platform's features. This may include repository metadata, pull request information, issue and project data, calendar events, and file metadata. We access only the scopes you explicitly authorize during the OAuth flow.

2.3 Automatically collected information

We collect standard log data including IP addresses, browser type and version, operating system, referring URLs, pages visited, and timestamps. We also collect usage analytics (feature clicks, session duration, error reports) to improve the product. This data is collected via server logs and first-party analytics tools.

2.4 Cookies and similar technologies

We use strictly necessary cookies to maintain your authenticated session and preference cookies to remember your settings. We do not use third-party advertising cookies. You can control cookie preferences through your browser settings, although disabling session cookies will prevent you from logging in.

3. How We Use Your Information

We use collected information to: • Provide, maintain, and improve the ReviewBod platform and its features • Process transactions and send related billing and account notices • Generate AI-powered performance grades, insights, and recommendations within your organization's workspace • Send transactional notifications such as review cycle reminders and deadline alerts • Respond to support requests and communicate about your account • Monitor platform health, detect security incidents, and prevent fraud • Comply with legal obligations and enforce our Terms of Service We do not use your private organizational data — including source code, internal documents, or review content — to train any publicly available machine learning models.

4. How We Share Your Information

We do not sell your personal information. We share data only in the following circumstances: Service providers. We engage vetted sub-processors (cloud infrastructure, payment processing, transactional email, error monitoring) under data processing agreements that restrict them from using your data for their own purposes. A current list of sub-processors is available on request. Within your organization. Data you or your colleagues submit is visible to other authorized members of your ReviewBod organization according to the role-based permissions you configure. Legal requirements. We may disclose information where required by law, subpoena, or government request, or to protect the rights, property, or safety of ReviewBod, our users, or others. Business transfers. If ReviewBod is acquired or merges with another entity, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy.

5. Data Retention

We retain your account data for as long as your organization maintains an active subscription, plus 90 days after cancellation to allow for account recovery. After that window, personal data is deleted from production systems within 30 days and from backup systems within 90 days. You may request earlier deletion by contacting privacy@reviewbod.com. Deletion requests are processed within 30 days, subject to our obligations to retain certain data for legal or financial compliance purposes.

6. Security

ReviewBod maintains a SOC 2 Type II certification. Our security program includes: • Encryption in transit (TLS 1.2+) and at rest (AES-256) • Role-based access controls and least-privilege principles for internal staff • Quarterly third-party penetration testing • Continuous vulnerability scanning and dependency monitoring • Incident response procedures with defined SLAs for breach notification No method of electronic transmission or storage is 100% secure. If you discover a potential security vulnerability, please report it to security@reviewbod.com rather than disclosing it publicly.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data: Access & portability. Request a copy of the personal data we hold about you in a machine-readable format. Correction. Ask us to correct inaccurate or incomplete data. Erasure. Request deletion of your personal data, subject to legal retention requirements. Restriction. Ask us to restrict processing of your data in certain circumstances. Objection. Object to processing based on legitimate interests. To exercise any of these rights, email privacy@reviewbod.com. We will respond within 30 days. Where you are an employee whose data is managed by your employer's ReviewBod organization, please direct requests to your employer as the data controller; we will cooperate as data processor.

8. International Data Transfers

ReviewBod is headquartered in the United States. If you access the platform from outside the US, your data is transferred to and processed in the US. For transfers from the European Economic Area, UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission.

9. Children's Privacy

ReviewBod is designed for use by organizations and professionals. We do not knowingly collect personal information from individuals under the age of 16. If we become aware that a minor has provided personal data, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice within the platform at least 14 days before the change takes effect. Continued use of ReviewBod after the effective date constitutes acceptance of the updated policy.

11. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact: ReviewBod, Inc. Attn: Privacy Team privacy@reviewbod.com