Privacy & Cookie Policy
Last revised September 16, 2026 · Effective September 21, 2026
Bubble Group, Inc. ("Reverse," "we," or "us") operates Reverse, a visual editor over your codebase available at reverse.dev. This Privacy & Cookie Policy ("Privacy Policy") describes how we collect, use, and share information in connection with the Reverse website, product, and related services (collectively, the "Service"). By using the Service, you consent to this Privacy Policy and our Terms.
1. DEFINITIONS
"User" means an individual with an Account who uses Reverse to connect and work with codebases, whether alone or together with others in a Workspace.
"Visitor" means an individual who visits reverse.dev, or a page shared through the Service (such as a public share link or another publicly accessible page generated by the Service), without registering.
"Workspace" means the shared environment in which one or more Users collaborate on connected repositories through the Service, and "Workspace Member" means any User who has access to a Workspace.
This Privacy Policy applies to both Users and Visitors except where specified. Capitalized terms not defined here have the meanings given in our Terms.
2. IMPORTANT INFORMATION
Data Controller: Bubble Group, Inc., 22 West 21st Street, 2nd Floor, New York, NY 10010.
Key sections: Please pay particular attention to the sections on International Data Transfer and Your Privacy Rights.
Policy updates: We may modify this Privacy Policy at any time. Material changes will be communicated by email or website notice before they take effect, and the effective date above will be updated.
3. LEGAL BASES FOR PROCESSING
We use your personal information only as permitted by law, including under these legal bases:
- • Legal compliance — to comply with our legal obligations.
- • Legitimate interests — where we have a legitimate interest that is not overridden by your rights, such as operating, securing, and improving the Service.
- • Contract — to perform our contract with you or take steps you request before entering into it.
- • Necessity — to protect your vital interests or those of another person.
- • Consent — where we rely on your consent, which you may withdraw at any time.
4. ARTICLE 27 REPRESENTATIVE
If you are in the European Economic Area or the United Kingdom, you may contact our Article 27 representative regarding the processing of your personal data.
EU Representative
Instant EU GDPR Representative Ltd.
Adam Brogden
contact@gdprlocal.com
Tel +35315549700
Office 2, 12A Lower Main Street, Lucan Co. Dublin
K78 X5P8
Ireland
UK Representative
GDPR Local Ltd.
Adam Brogden
contact@gdprlocal.com
Tel +44 1772 217800
1st Floor Front Suite
27-29 North Street, Brighton
England
5. DATA PRIVACY FRAMEWORK
Bubble Group, Inc. participates in, and has certified its compliance with, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, and adheres to the applicable Data Privacy Framework Principles with respect to personal data received in reliance on those frameworks. Bubble Group, Inc. remains liable for onward transfers to third parties that process such data in a manner inconsistent with the Principles, subject to the framework's limitations. The U.S. Federal Trade Commission has jurisdiction over compliance.
6. HOW WE COLLECT YOUR INFORMATION
Information you provide
When you create an Account (with GitHub or with an email address and password), we collect your email address and password and, from GitHub, your GitHub user ID, login, profile information, avatar, and organization memberships. Where an Account is created with an email address, we verify that address before the Account can direct changes to a connected repository other than a demonstration repository. You may provide optional profile information. If you make a payment, our payment processor collects your payment details. When you connect a repository, we store repository identifiers and metadata and process the contents of the repository you direct us to work with, including source code. When you use the Reverse AI Tools, we process your prompts and instructions, chat threads, agent task descriptions, and the before-and-after contents of proposed code changes, and any images you upload (which may be captioned by AI). When you submit a bug report or feedback, we collect the information in your message and limited diagnostic data (such as your browser user-agent, the page URL, viewport, and recent in-app errors). When you are invited to a Workspace, or create one, we collect the information needed to administer membership, including the email address used for the invitation and the role assigned to each Workspace Member. When you contact us, we collect the information in your message.
Information collected automatically
When you use the Service, our analytics providers automatically collect certain technical information, which may include your IP address, browser and device information, pages viewed, timestamps, and usage and event data, and may derive location from your IP address. We also send your email, name, and GitHub login to our analytics provider when you sign in. We do not store your IP address in our own database (we key rate-limiting to your account, not your IP); IP addresses are collected at the analytics layer described in the Cookies section. We use this information to operate, secure, analyze, and improve the Service.
7. WORKSPACES AND COLLABORATION
If you use the Service in a Workspace, other Workspace Members can see the name, email address, avatar, and GitHub login associated with your Account, and the documentation created in that Workspace. Agent runs and proposed code changes stay within the member's own thread until the change ships.
Each Workspace Member's role determines what that member can do. Only an Owner may remove a Workspace Member or change a Workspace Member's role. An Editor may create an invitation link through which another person may join the Workspace, and the Editor selects the role that person receives, which may be Editor or Viewer but never Owner and never a role above the Editor's own.
A conversation thread that you share with a teammate can be opened only by the Workspace Member you share it with, and only for as long as that person remains a member of the Workspace. Opening the thread places a copy of it in that person's own account, and that copy is not removed if they later leave the Workspace.
The Service verifies a Workspace Member's own GitHub permissions when that member attempts to open a pull request from an agent run. A member who is blocked at that point is shown a read-only list of the Owners and Editors who have linked a GitHub account. If we remove that verification, that list will no longer be shown.
Public share links. Where an Owner or an Editor enables a public share link for a project, the documentation generated for that project is available to anyone who has the link, without password, review, or expiration. That documentation routinely includes file paths, function and entity names, short excerpts of code, and the commit from which it was generated. A plain-text version of it is published at the same address with /llms.txt added to the end, and is accessible to automated crawlers. Revoking the link is the only way to withdraw access.
8. WHAT REVERSE WRITES INTO YOUR GITHUB REPOSITORY
When the coding agent acts on a User's instruction, the Service creates a working branch in the connected repository and commits changes to that branch. A User then opens the pull request. These actions are performed through the Reverse GitHub App and appear in GitHub under its identity rather than under the individual User's GitHub account.
Where documentation synchronization is enabled for a project, the Service also writes the documentation it generates into the connected repository, through a pull request that the Service opens in the background. That pull request appears under the Reverse GitHub App's identity as the documentation synchronization action and does not identify any Workspace Member.
A pull request opened from the Service at a Workspace Member's request identifies that Workspace Member. Anyone with access to the repository, and GitHub itself, can therefore see that identification, which is governed by GitHub's own privacy practices rather than this Privacy Policy.
9. ACTIVITY AND ACCESS RECORDS
The Service keeps records of activity in a Workspace. We record agent runs, including the run timeline and the before-and-after contents of proposed code changes; the opening and merging of pull requests; changes to Workspace membership and access; and Credit purchases, grants, and consumption. For project settings, we keep the current value rather than a history of changes.
Within the Service, a record of an agent run and of the pull request activity for that run is visible to the Workspace Member who started the run, and to other Workspace Members once the change ships, as are the non-sensitive fields of Credit activity. Records of changes to Workspace membership and access are kept internally for security purposes and are not viewable in the Service.
We keep records of agent runs and of pull request activity for as long as the Workspace exists. We keep records of changes to Workspace membership and access indefinitely, as a security record. We keep records of Credit purchases, grants, and consumption as business records.
Where a Workspace Member other than the last remaining Owner deletes their Account, the Workspace's records of agent runs and pull request activity remain and are attributed to a deleted user, while that member's own conversations are deleted. Where the last remaining Owner of a Workspace deletes their Account, the Workspace's projects, agent runs, proposed code changes, documentation, share links, and memberships are deleted thirty (30) days later.
10. SLACK AND CONNECTED APPLICATIONS
Where the Slack integration is available, an Owner may connect a Workspace's own Slack workspace to the Service, and an Owner or an Editor may map Slack channels to connected repositories. Once a channel is mapped, a Workspace Member of any role may ask questions in that channel. The answer is posted in the channel, so anyone with access to that channel can see content derived from the code in the mapped repository, whether or not they are a Workspace Member. Those questions and answers are also processed by Slack under its own privacy practices.
Where the Reverse MCP server is available to a Workspace, a User may connect an external AI client to the Service through it. A client connected in this way authenticates as the User who authorized it and can reach that User's projects with that User's level of access. A User may review the applications they have connected, and revoke a connection, in their account settings. We record authorization decisions for these applications, and we collect diagnostic and performance information about the calls they make. That diagnostic and performance information is collected through PostHog, our analytics provider.
11. COOKIES
We use cookies and similar technologies to operate and understand use of the Service, including on reverse.dev. We use:
- • Essential cookies — required for basic functionality, such as signing in.
- • Functionality cookies — to remember your preferences and settings.
- • Analytics and performance cookies — to understand how the Service is used, set through our analytics providers, PostHog and Google Analytics.
We do not use advertising or marketing pixels, and we do not use cookies to build advertising profiles or to serve targeted advertising. You can manage or disable cookies through your browser settings, though some features may not work without them.
12. HOW WE USE YOUR INFORMATION
We use your personal information to:
- • Create, secure, and manage your Account and any Workspace you own or belong to;
- • Provide, operate, maintain, and improve the Service, including the parsing, advisor, coding agent, documentation, and Workspace collaboration features;
- • Process payments and administer Credits, including Credits drawn from a shared Workspace Credit pool;
- • Respond to your requests and provide support for the products and services we offer;
- • Send administrative and, where permitted, marketing communications (you can opt out of marketing at any time);
- • Maintain records of activity and access, including for security and for administering Workspace membership and Credits;
- • Monitor usage and enforce our Terms; and
- • Comply with legal obligations and protect the rights and safety of Reverse, our users, and others.
Anonymized data. We may create and use de-identified and aggregated data for any purpose, including analytics and improving the Service.
Related products and services. We operate other products and services in addition to Reverse. Because these are offered by the same company, we may process your personal information across our teams and related products for internal purposes such as providing customer support and operating and improving our services. We share only the information reasonably needed for these purposes, and this processing remains subject to this Privacy Policy.
13. HOW WE MAY SHARE YOUR INFORMATION
We may share your information with:
Service providers and subprocessors that help us deliver the Service, including: GitHub (repository access and authentication); Anthropic and OpenAI (AI processing of code and prompts); Supabase (primary database hosting and image storage); Railway (application hosting); Daytona (sandbox execution for the coding agent); PostHog and Google Analytics (product and website analytics); Loops (email delivery); Slack (internal support notifications and, for a Workspace that connects the Reverse Slack integration, delivery of answers to the Slack channels that Workspace maps to its repositories); and Stripe (payment processing).
Payment processor. Payment information is provided directly to Stripe, whose use of your information is governed by its own privacy policy.
Legal and safety. We may share information to comply with law or legal process, enforce our Terms, protect against fraud or security issues, or protect the rights, property, or safety of Reverse, our users, or others.
Corporate transactions. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.
We do not sell your personal information or share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws.
14. AI TECHNOLOGIES
The Service uses AI technologies to provide its core features. To generate parses, advisor responses, proposed code changes, and documentation, we send relevant content — including the code from your connected repositories, your prompts, and related context — to Third Party AI Services, currently Anthropic (Claude) and OpenAI. When we process your data using our own accounts with these providers, they act as our service providers and do not use your data to train their models.
We do not use your code, prompts, or the outputs generated for you to train artificial-intelligence models. We may use usage and telemetry data (such as parse times and error and failure signals), any feedback you submit, and aggregated and de-identified data, to operate, evaluate, and improve the Service, including to improve parse quality and evaluate our AI features.
If you connect your own third-party AI account or API key (for example, under a bring-your-own-key option), your data is processed under your agreement with that provider, whose terms may permit the provider to use your data (including to train its models). Where you connect an AI client to the Service through the Reverse MCP server, content from your connected repositories may be made available to that client, and the provider's own terms govern that provider's use of the content, including any use of it to train models. It is your responsibility to review those terms.
15. THIRD-PARTY SITES
The Service may link to third-party websites and services that are not governed by this Privacy Policy. We are not responsible for their content or practices. Please review their privacy policies before providing information to them.
16. SECURITY
We use reasonable administrative, technical, and physical measures designed to protect personal information, including hashing of account passwords, encryption of stored credentials, secrets, and access tokens, access to uploaded files through short-lived signed URLs, isolation of each project's code-execution environment, and verification of email addresses used to create Accounts before those Accounts can direct changes to a connected repository other than a demonstration repository. However, no method of transmission or storage is completely secure. If you believe your interaction with us is no longer secure, please notify us at support@reverse.dev.
17. RETENTION
We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When you delete your Account, you are logged out and your Account is soft-deleted. If you sign back in within 30 days, your Account is reactivated; if you do not, we delete the personal information associated with your Account. Separately, if you make a standalone request to delete your personal information (a request to erase your data that is not part of the account-deletion and reactivation process above), we will act on that request within the time required by applicable law — generally one month under the EU/UK GDPR and 45 days under applicable U.S. state privacy laws — and will not hold it for the 30-day reactivation period. You may make such a request by emailing support@reverse.dev. We may retain limited information where required by law or for legitimate business purposes such as security, dispute resolution, and enforcing our agreements, and residual copies may persist in backups for a limited period before they are overwritten. Where feasible, we also direct our service providers to delete your personal information. As described under Activity and Access Records, we keep records of changes to Workspace membership and access, and records of Credit purchases, grants, and consumption, after an Account is deleted, as security and business records. Records of agent runs and of pull request activity in a Workspace are kept for as long as the Workspace exists and are not deleted when an individual Workspace Member deletes their Account.
18. INTERNATIONAL DATA TRANSFER
We are based in, and host the Service in, the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, whose data-protection laws may differ from those in your country. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on an appropriate transfer mechanism, such as the EU-U.S. Data Privacy Framework (and its UK and Swiss counterparts) or the Standard Contractual Clauses. By using the Service, you understand that your information will be transferred as described.
19. SENSITIVE PERSONAL DATA
Please do not submit sensitive personal information (such as government identification numbers, financial account credentials, health data, or special categories of data) through the Service except as strictly necessary. If you include such information in content you submit, you consent to our processing it as described in this Privacy Policy.
20. INFORMATION ABOUT CHILDREN
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us at support@reverse.dev and we will delete it.
21. YOUR PRIVACY RIGHTS
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- • Access — to request a copy of the information we hold about you.
- • Correction — to request that we correct inaccurate information.
- • Deletion — to request that we delete your information, subject to the exceptions described under Retention.
- • Portability — to request that we transfer your information.
- • Objection / restriction — to object to or restrict certain processing, and to withdraw consent where we rely on it.
- • Opt-out — of direct marketing and, where applicable, of profiling and of any "sale" or "sharing" (we do not sell or share personal information for cross-context behavioral advertising).
- • Non-discrimination and appeal — you will not be discriminated against for exercising your rights, and residents of certain U.S. states may appeal a declined request.
How to exercise your rights. To exercise any of these rights, email us at support@reverse.dev. We may need to verify your identity. We will respond within the timeframe required by applicable law (typically 45 days), and you may use an authorized agent where permitted.
22. COMPLAINTS
To file a complaint about our privacy practices, contact us at support@reverse.dev. If you are in the EEA, UK, or Switzerland and are not satisfied with our response, you may lodge a complaint with your local data-protection authority.
23. CHANGES TO THIS POLICY
We post changes to this Privacy Policy on this page with the effective date. Material changes will be communicated by email or website notice before they take effect.
24. CONTACT INFORMATION
If you have questions about this Privacy Policy, contact us at support@reverse.dev, or in writing at Bubble Group, Inc., 22 West 21st Street, 2nd Floor, New York, NY 10010, ATTN: Reverse Legal.