Revive Privacy Policy
How Revive collects, uses, shares, retains, and lets you delete your data, including Google user data accessed via the Revive add-on.
Effective date: July 30, 2026
This Privacy Policy explains how Fortify Media, Inc. (“Fortify Media”, “we”, “our”, or “us”) collects, uses, shares, retains, and protects information in connection with Revive—our AI-assisted media restoration service, offered as a Google Workspace add-on for Google Drive and as a web application at revive.fortifymedia.io (together, the “Service”). It applies to the Revive Service specifically; the broader Fortify Media platform is covered by the Fortify Media Privacy Policy.
1. Information we collect
- Account data: your name, email address, and a hashed password (or, if you sign in with Google, your Google account identifier and email).
- Billing data: a Stripe customer reference and the brand and last four digits of any card you save. We never receive or store full card numbers—card data is handled exclusively by Stripe.
- Usage data: which files you submit for processing, processing timestamps, job status, and the number of tokens consumed.
- Telemetry: server logs, error reports (via Sentry), and request metadata used for security, debugging, and reliability monitoring.
2. Google user data we access
When you use the Revive add-on in Google Drive, Revive requests only the following, narrowly-scoped access:
- Per-file access to files you select (
drive.filescope): Revive can read a file only after you explicitly select it for processing, and it writes the restored result back to your Drive. Revive cannot see or browse the rest of your Drive. - Add-on metadata (
drive.addons.metadata.readonlyscope): the minimal context Google provides to run the add-on interface. - Secure external processing (
script.external_requestscope): lets the add-on transmit the file you selected to Revive’s processing API (hosted on AWS) over an encrypted connection and return the restored result. This transmission is transient and used only to fulfil your request.
We use the content of a selected file solely to perform the restoration you requested and to return the result to you. We do not use Google user data for advertising, and we do not sell it.
Limited Use disclosure. Revive’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or use Google user data to train generalized AI/ML models; file content is used only to produce your requested output. Our personnel do not access the content of your files except when necessary to provide support or resolve an error, with your consent, or where required by law.
3. How we use information
- To provide, operate, and maintain the Service and process the files you submit.
- To process payments and manage your token balance and account.
- To monitor security, prevent fraud and abuse, and debug and improve reliability.
- To communicate with you about your account, transactions, and material changes to the Service.
- To comply with legal obligations.
4. How we share information
We do not sell your personal data. We share it only with service providers that help us run the Service, and only as needed:
- Stripe — payment processing.
- Amazon Web Services (AWS) — hosting and processing infrastructure.
- Google Cloud / Google Workspace — the add-on runtime and delivery of results to your Drive.
- Sentry — error and performance monitoring.
- Law enforcement or authorities — only when legally compelled, or to protect rights, property, or safety.
- A successor entity — in connection with a merger, acquisition, or asset sale, subject to this policy.
5. Data retention
- File content: files you submit are processed transiently. Source and output file content is deleted from our processing systems within 30 days of job completion; restored outputs remain in your Google Drive under your control.
- Account data: retained while your account is active and deleted within 30 days after you close your account or request deletion, except where we must retain it longer by law.
- Billing records: retained for up to 7 years to meet tax, accounting, and audit obligations. Stored billing/webhook payloads are stripped of personal identifiers before persistence.
- Logs and telemetry: retained for up to 90 days for security and reliability, then deleted or aggregated.
6. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example, under the GDPR or the CCPA/CPRA). To exercise any of these rights, email legal@fortifymedia.io. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising these rights.
You can revoke Revive’s access to your Google account at any time, and request deletion of your data, using the steps in our Data Deletion & Access Revocation page.
7. Security
We use industry-standard administrative, technical, and physical safeguards, including encryption in transit and at rest, scoped access controls, and least-privilege OAuth scopes. Card data is handled exclusively by Stripe under its PCI DSS Level 1 attestation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children and age
The Service is not directed to children under 13, and we do not knowingly collect their personal data. Because tokens are a paid product, account creation and purchases are limited to adults aged 18 or older (or the age of majority in your jurisdiction), consistent with our Terms of Service.
9. Cookies and similar technologies
Revive uses only essential cookies and similar technologies needed to operate and secure the Service (for example, to keep you signed in). We do not use cookies for cross-site tracking or advertising. Our error and performance monitoring (Sentry) may set limited technical identifiers used solely for reliability.
10. California privacy notice (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you specific rights. The categories of personal information we collect are: identifiers (name, email, account ID); commercial information (tokens purchased and consumed); internet or network activity (usage and log data); and financial information limited to a Stripe reference and card brand and last four digits. We disclose these categories to the service providers listed in section 4 (Stripe, AWS, Google, Sentry) for the business purposes described above. We do not “sell” or “share” personal information as those terms are defined by the CCPA/CPRA. To exercise your rights, contact legal@fortifymedia.io.
11. International data transfers
If you access the Service from outside the United States, including the EEA, the United Kingdom, or Switzerland, your personal data may be transferred to and processed in the United States by us and our providers (such as AWS). Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism, to protect your data.
12. Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will post the updated version here and revise the “Effective date” above; material changes will be communicated where required.
13. Contact
Fortify Media, Inc. — the data controller for the Service.
Privacy inquiries: legal@fortifymedia.io
Mailing address: 8605 Santa Monica Blvd #556394, West Hollywood, CA 90069, USA.
Revive