Reverse

Privacy & Cookie Policy

Last revised July 22, 2026 · Effective July 22, 2026

Bubble Group, Inc. ("Reverse," "we," or "us") operates Reverse, a visual editor over your codebase available at reverse.dev. This Privacy & Cookie Policy ("Privacy Policy") describes how we collect, use, and share information in connection with the Reverse website, product, and related services (collectively, the "Service"). By using the Service, you consent to this Privacy Policy and our Terms.

1. DEFINITIONS

"User" means an individual with an Account who uses Reverse to connect and work with codebases.

"Visitor" means an individual who visits reverse.dev, or a page shared through the Service (such as a public share link or explainer), without registering.

This Privacy Policy applies to both Users and Visitors except where specified. Capitalized terms not defined here have the meanings given in our Terms.

2. IMPORTANT INFORMATION

Data Controller: Bubble Group, Inc., 22 West 21st Street, 2nd Floor, New York, NY 10010.

Key sections: Please pay particular attention to the sections on International Data Transfer and Your Privacy Rights.

Policy updates: We may modify this Privacy Policy at any time. Material changes will be communicated by email or website notice before they take effect, and the effective date above will be updated.

3. LEGAL BASES FOR PROCESSING

We use your personal information only as permitted by law, including under these legal bases:

  • Legal compliance — to comply with our legal obligations.
  • Legitimate interests — where we have a legitimate interest that is not overridden by your rights, such as operating, securing, and improving the Service.
  • Contract — to perform our contract with you or take steps you request before entering into it.
  • Necessity — to protect your vital interests or those of another person.
  • Consent — where we rely on your consent, which you may withdraw at any time.

4. ARTICLE 27 REPRESENTATIVE

If you are in the European Economic Area or the United Kingdom, you may contact our Article 27 representative regarding the processing of your personal data.

EU Representative

Instant EU GDPR Representative Ltd.

Adam Brogden

contact@gdprlocal.com

Tel +35315549700

Office 2, 12A Lower Main Street, Lucan Co. Dublin

K78 X5P8

Ireland

UK Representative

GDPR Local Ltd.

Adam Brogden

contact@gdprlocal.com

Tel +44 1772 217800

1st Floor Front Suite

27-29 North Street, Brighton

England

5. DATA PRIVACY FRAMEWORK

Bubble Group, Inc. participates in, and has certified its compliance with, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, and adheres to the applicable Data Privacy Framework Principles with respect to personal data received in reliance on those frameworks. Bubble Group, Inc. remains liable for onward transfers to third parties that process such data in a manner inconsistent with the Principles, subject to the framework's limitations. The U.S. Federal Trade Commission has jurisdiction over compliance.

6. HOW WE COLLECT YOUR INFORMATION

Information you provide

When you create an Account (with GitHub or with an email address and password), we collect your email address and password and, from GitHub, your GitHub user ID, login, profile information, avatar, and organization memberships. You may provide optional profile information. If you make a payment, our payment processor collects your payment details. When you connect a repository, we store repository identifiers and metadata and process the contents of the repository you direct us to work with, including source code. When you use the Reverse AI Tools, we process your prompts and instructions, chat threads, agent task descriptions, and the before-and-after contents of proposed code changes, and any images you upload (which may be captioned by AI). When you submit a bug report or feedback, we collect the information in your message and limited diagnostic data (such as your browser user-agent, the page URL, viewport, and recent in-app errors). When you contact us, we collect the information in your message.

Information collected automatically

When you use the Service, our analytics providers automatically collect certain technical information, which may include your IP address, browser and device information, pages viewed, timestamps, and usage and event data, and may derive location from your IP address. We also send your email, name, and GitHub login to our analytics provider when you sign in. We do not store your IP address in our own database (we key rate-limiting to your account, not your IP); IP addresses are collected at the analytics layer described in the Cookies section. We use this information to operate, secure, analyze, and improve the Service.

7. COOKIES

We use cookies and similar technologies to operate and understand use of the Service, including on reverse.dev. We use:

  • Essential cookies — required for basic functionality, such as signing in.
  • Functionality cookies — to remember your preferences and settings.
  • Analytics and performance cookies — to understand how the Service is used, set through our analytics providers, PostHog and Google Analytics.

We do not use advertising or marketing pixels, and we do not use cookies to build advertising profiles or to serve targeted advertising. You can manage or disable cookies through your browser settings, though some features may not work without them.

8. HOW WE USE YOUR INFORMATION

We use your personal information to:

  • • Create, secure, and manage your Account;
  • • Provide, operate, maintain, and improve the Service, including the parsing, advisor, coding agent, and documentation features;
  • • Process payments and administer Credits;
  • • Respond to your requests and provide support for the products and services we offer;
  • • Send administrative and, where permitted, marketing communications (you can opt out of marketing at any time);
  • • Monitor usage and enforce our Terms; and
  • • Comply with legal obligations and protect the rights and safety of Reverse, our users, and others.

Anonymized data. We may create and use de-identified and aggregated data for any purpose, including analytics and improving the Service.

Related products and services. We operate other products and services in addition to Reverse. Because these are offered by the same company, we may process your personal information across our teams and related products for internal purposes such as providing customer support and operating and improving our services. We share only the information reasonably needed for these purposes, and this processing remains subject to this Privacy Policy.

9. HOW WE MAY SHARE YOUR INFORMATION

We may share your information with:

Service providers and subprocessors that help us deliver the Service, including: GitHub (repository access and authentication); Anthropic and OpenAI (AI processing of code and prompts); Supabase (primary database hosting and image storage); Railway (application hosting); Daytona (sandbox execution for the coding agent); PostHog and Google Analytics (product and website analytics); Loops (email delivery); Slack (internal support notifications); and Stripe (payment processing).

Payment processor. Payment information is provided directly to Stripe, whose use of your information is governed by its own privacy policy.

Legal and safety. We may share information to comply with law or legal process, enforce our Terms, protect against fraud or security issues, or protect the rights, property, or safety of Reverse, our users, or others.

Corporate transactions. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.

We do not sell your personal information or share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws.

10. AI TECHNOLOGIES

The Service uses AI technologies to provide its core features. To generate parses, advisor responses, proposed code changes, and documentation, we send relevant content — including the code from your Connected Repositories, your prompts, and related context — to Third Party AI Services, currently Anthropic (Claude) and OpenAI. When we process your data using our own accounts with these providers, they act as our service providers and do not use your data to train their models.

We do not use your code, prompts, or the outputs generated for you to train artificial-intelligence models. We may use usage and telemetry data (such as parse times and error and failure signals), any feedback you submit, and aggregated and de-identified data, to operate, evaluate, and improve the Service, including to improve parse quality and evaluate our AI features.

If you connect your own third-party AI account or API key (for example, under a bring-your-own-key option), your data is processed under your agreement with that provider, whose terms may permit the provider to use your data (including to train its models). It is your responsibility to review those terms.

11. THIRD-PARTY SITES

The Service may link to third-party websites and services that are not governed by this Privacy Policy. We are not responsible for their content or practices. Please review their privacy policies before providing information to them.

12. SECURITY

We use reasonable administrative, technical, and physical measures designed to protect personal information, including hashing of account passwords, encryption of stored credentials, secrets, and access tokens, access to uploaded files through short-lived signed URLs, and isolation of each project's code-execution environment. However, no method of transmission or storage is completely secure. If you believe your interaction with us is no longer secure, please notify us at support@reverse.dev.

13. RETENTION

We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When you delete your account, you are logged out and your account is soft-deleted. If you sign back in within 30 days, your account is reactivated; if you do not, we delete the personal information associated with your account. Separately, if you make a standalone request to delete your personal information (a request to erase your data that is not part of the account-deletion and reactivation process above), we will act on that request within the time required by applicable law — generally one month under the EU/UK GDPR and 45 days under applicable U.S. state privacy laws — and will not hold it for the 30-day reactivation period. You may make such a request by emailing support@reverse.dev. We may retain limited information where required by law or for legitimate business purposes such as security, dispute resolution, and enforcing our agreements, and residual copies may persist in backups for a limited period before they are overwritten. Where feasible, we also direct our service providers to delete your personal information.

14. INTERNATIONAL DATA TRANSFER

We are based in, and host the Service in, the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, whose data-protection laws may differ from those in your country. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on an appropriate transfer mechanism, such as the EU-U.S. Data Privacy Framework (and its UK and Swiss counterparts) or the Standard Contractual Clauses. By using the Service, you understand that your information will be transferred as described.

15. SENSITIVE PERSONAL DATA

Please do not submit sensitive personal information (such as government identification numbers, financial account credentials, health data, or special categories of data) through the Service except as strictly necessary. If you include such information in content you submit, you consent to our processing it as described in this Privacy Policy.

16. INFORMATION ABOUT CHILDREN

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us at support@reverse.dev and we will delete it.

17. YOUR PRIVACY RIGHTS

Depending on where you live, you may have some or all of the following rights regarding your personal information:

  • Access — to request a copy of the information we hold about you.
  • Correction — to request that we correct inaccurate information.
  • Deletion — to request that we delete your information.
  • Portability — to request that we transfer your information.
  • Objection / restriction — to object to or restrict certain processing, and to withdraw consent where we rely on it.
  • Opt-out — of direct marketing and, where applicable, of profiling and of any "sale" or "sharing" (we do not sell or share personal information for cross-context behavioral advertising).
  • Non-discrimination and appeal — you will not be discriminated against for exercising your rights, and residents of certain U.S. states may appeal a declined request.

How to exercise your rights. To exercise any of these rights, email us at support@reverse.dev. We may need to verify your identity. We will respond within the timeframe required by applicable law (typically 45 days), and you may use an authorized agent where permitted.

18. COMPLAINTS

To file a complaint about our privacy practices, contact us at support@reverse.dev. If you are in the EEA, UK, or Switzerland and are not satisfied with our response, you may lodge a complaint with your local data-protection authority.

19. CHANGES TO THIS POLICY

We post changes to this Privacy Policy on this page with the effective date. Material changes will be communicated by email or website notice.

20. CONTACT INFORMATION

If you have questions about this Privacy Policy, contact us at support@reverse.dev, or in writing at Bubble Group, Inc., 22 West 21st Street, 2nd Floor, New York, NY 10010, ATTN: Reverse Legal.