Privacy notice
Effective 2026-09-01.
This notice describes what Rekvira does with personal data. Rekvira is an MCP service that retrieves official EU regulation text for AI assistants. It is written from what the system actually stores, not from intention.
Who we are
The operator of rekvira.com is the controller of the personal data described here. You can reach us at privacy@rekvira.com or hello@rekvira.com. When the registered legal entity is published, this notice will name it exactly as filed.
What Rekvira is, in data-protection terms
Rekvira searches and reads official EU regulation texts published on EUR-Lex. Those texts are public records; we do not treat them as your personal data.
What we hold about you is the small amount needed to run the service: trial-scoped assessments and private workflows that you deliberately save, trial metering, optional accounts, and API keys. We do not build advertising profiles, we do not sell data, and we do not search for or index people.
MCP queries and server logs
Procurement and security reviewers usually ask three things. This section answers them from what the system does today, not from intention.
Query text. Search queries and ordinary retrieval arguments are not written to a Rekvira database. Each retrieval call is handled in memory and discarded when the response is sent. Deliberate state tools are different: record_assessment stores the regulation, pinpoint, verdict, optional structured reason and timestamp; save_workflow stores the workflow ID, title, summary, body, published state and timestamps. Those records are keyed by the opaque trial_id returned by connect: a different trial_id cannot retrieve, update or delete them, and published does not share a workflow publicly. The other narrow exception is a message a user explicitly approves for submit_feedback; that deliberate feedback is described below and never gains the preceding query or call context.
Network addresses. Our hosting and CDN providers may record your network address in standard server access logs; see https://rekvira.com/subprocessors for who runs infrastructure and where. Rekvira does not currently build a user profile from those logs during the keyless trial.
After you create an account. When paid accounts and usage metering ship, we will record which tools were called and when so tier limits can apply, not the full text of every search query. Account data is kept while the account exists; see How long we keep it below. This notice will name the exact fields before checkout opens.
What we collect today (keyless trial)
During the keyless trial there is no account and no usage-metering database yet: search quota metering is not enforced (whoami returns searches_left_today: null). The service does keep the deliberate trial-scoped records described below. What follows is what applies today; planned account fields are marked separately.
Search and ordinary retrieval calls. Search queries and ordinary retrieval arguments are not written to a Rekvira database. Each retrieval call is handled in memory and discarded when the response is sent.
Assessments and private workflows you deliberately save. record_assessment stores the regulation, pinpoint, structured verdict/reason and timestamp you submit. save_workflow stores the workflow ID, title, summary, body, published state and timestamps you submit. Both use the opaque trial_id returned by connect, rather than an account, email or user profile. A different trial_id cannot retrieve, update or delete those records. The published state marks a workflow ready only inside that trial; it does not share it publicly. Do not put personal data in a private workflow.
Feedback you explicitly send. If you use submit_feedback after approving the exact message, Rekvira stores that message, its category, whether it was your own words or an agent draft you approved, and the time. There is no account or profile attached during the keyless trial. Rekvira does not attach a search query, tool arguments, or prior-call history to feedback. The latest real feedback is visible only to the operator's private traction view, not on a public page. Lawful basis: legitimate interest in knowing whether the product works, Art 6(1)(f).
Infrastructure logs. Our hosting and CDN providers may record your network address in standard server access logs. They are listed at https://rekvira.com/subprocessors with where they operate. Rekvira does not build a user profile from those logs during the keyless trial.
Founding Beta terms
Checkout and paid accounts are closed during founding beta. Pre-registered traction-read signal names for the founding-beta period are on https://rekvira.com/pricing#founding-beta-read. Lock terms are at https://rekvira.com/terms#the-founding-beta.
What we will collect when accounts open (not yet available)
Checkout and paid accounts are closed until the legal-entity gate clears. When they open, we expect to store the categories below. This notice will be updated before checkout enables: we name them now so procurement can review the plan.
Your account. An email address and optional organisation name, used to authenticate the account and apply tier limits. Lawful basis: performance of a contract, Art 6(1)(b).
API keys. Stored as a SHA-256 hash. We never hold the key itself. Lawful basis: Art 6(1)(b).
Sessions. A session identifier binding your AI assistant's connection to your account or trial bucket. Lawful basis: Art 6(1)(b) or Art 6(1)(f) for keyless use.
Usage records. Which tools were called and when: not the full text of every search query: so tier limits can be applied. Lawful basis: legitimate interest, Art 6(1)(f).
Keyless trial metering (when enforced). A one-way hash of your network address to count tool calls against a daily limit. The address itself is not stored as a profile. Lawful basis: legitimate interest in operating a free trial, Art 6(1)(f).
Feedback (if you send it). The current keyless feedback record remains a message, category, authorship and time only. If paid accounts later add an account link, this notice will name that change before it ships. Lawful basis: legitimate interest in knowing whether the product works, Art 6(1)(f).
Sub-processors
The providers that process personal data on our behalf are listed at https://rekvira.com/subprocessors with the date of the list. That page names hosting and edge infrastructure only: not the EUR-Lex corpus.
What we do not do
We do not sell personal data, we do not use it to train models, and we do not enrich it from third-party people-search sources. Rekvira is a regulation corpus tool for compliance professionals, and that boundary is deliberate.
How long we keep it
During the keyless trial, search queries are not kept as a profile and metering resets are not stored long-term. Trial assessments and private workflows remain in the private state ledger until they are replaced, deleted or removed following a privacy request; there is no automatic expiry for that state yet. delete_workflow removes a private workflow from the matching trial. Assessments do not yet have a self-service delete tool. A lost trial_id cannot be recovered by email because no email or account is associated with it. Explicitly submitted feedback is kept in the private feedback ledger until it is reviewed or you ask us to delete it; because keyless feedback has no account, include enough of the message for us to locate it. When accounts exist, account data lives as long as the account does. Usage records will be kept while the account exists because they are what tier limits are computed from.
Deleting your account
Write to privacy@rekvira.com. We will confirm by email before erasing an account, because an instruction typed into a chat window is not proof that the account holder wants it gone.
Your rights
You can ask for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent you can withdraw it at any time without affecting what came before.
Write to privacy@rekvira.com. We will answer within one month.
If you think we have handled your data wrongly you can complain to the supervisory authority where you live.
Changes
If this notice changes materially we will say so on the changelog at https://rekvira.com/changelog with the date, rather than quietly replacing the page.