Sentinelby Reviewal

Privacy Policy

Last updated: 27 July 2026

This Privacy Policy explains how Reviewal ("we," "us," or "our") collects, uses, shares, and protects personal data when you use Sentinel by Reviewal (the "Service" or "Sentinel"). It also describes your rights regarding your personal data and how to exercise them.

Sentinel is a business-to-business (B2B) social media compliance monitoring platform. As of the effective date of this Policy, Sentinel supports Instagram accounts; support for additional platforms may be added over time. This Policy applies globally to all users of the Service.

By using Sentinel, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

1. Who we are and how to contact us

The data controller for the personal data processed by Sentinel is Chafai Solutions LLC, operating as Reviewal. For all privacy-related inquiries, please contact us at sentinel@reviewal.team.

We aim to respond to all privacy-related inquiries within thirty (30) days, and to urgent requests (such as data deletion or security matters) as quickly as reasonably possible.

EU / UK Representatives: Reviewal has not yet appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR / UK GDPR. Data subjects in the EU or UK may contact us directly via the email address above for any inquiries concerning the processing of their personal data. We intend to appoint local representatives as our EU/UK customer base grows.

2. What personal data we collect

2.1 Account and identity data

When you create a Sentinel account, we collect your email address and, if you set one, a password (which is never stored in readable form; password hashing is managed by our authentication provider, Supabase). If you sign in with Google, we receive the basic profile information Google returns (name, email, profile image). We also store your language preference and other interface settings.

2.2 Connected social media account data

When you connect an Instagram account for monitoring, we collect the account's public profile information: username/handle, display name, avatar URL, verified status, follower count, and bio. We only collect data for the account you connect, being the account you own or are authorized to monitor. We do not collect data about other users' accounts.

2.3 Content and metrics from connected accounts

For each connected account, we retrieve the account's own public posts, captions, media thumbnails, permalinks, timestamps, media types, and public engagement counts (likes, comments). Where available, we also retrieve reach, impressions, saves, shares, and profile-visit counts. We store daily snapshots of follower count and account-level metrics to power growth and trend charts.

What we deliberately do not collect: commenter identities, other users' personal information, direct messages, or any private (non-public) content.

2.4 Scan inputs and results

When you use the Post Scan or Caption Analyzer feature, we process the text and/or media you upload (captions, images, videos) to produce a compliance assessment. We store the input (or a hash of it), the resulting score, verdict, findings, and AI-generated explanation. Manual pre-publish scans are kept in your private scan history and never displayed publicly.

2.5 Preferences and settings

We store your notification preferences, email digest cadence, timezone, language preference, and similar interface settings so Sentinel functions as you expect.

2.6 Activity logs

We maintain a per-user audit trail of significant account actions (connecting or disconnecting accounts, subscription changes, deletion requests) including the action, an optional detail, severity, timestamp, and the IP address the action originated from.

2.7 Operational and technical data

We collect standard technical data required to operate Sentinel: IP address, browser type, device information, referring URLs, and pages accessed.

2.8 Billing data

For paid subscriptions, we store your subscription status, plan, billing cycle, and the opaque customer/subscription identifiers issued by our payment processor, Stripe. We do not store or process credit card numbers, bank account details, or other payment card data. All payment card data is handled directly by Stripe, which is PCI-DSS compliant.

3. How we use personal data

4. Legal bases for processing (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar privacy laws, we rely on the following legal bases to process your personal data:

5. AI-assisted processing and automated decisions

Sentinel uses AI models to assess whether social media content complies with the policies of the target platform (currently Instagram / Meta). Specifically:

Sentinel's compliance assessments are informational estimates, not legally significant decisions about you. No automated decision produces legal effects or similarly significant effects for you. You retain full control over what to do with the recommendations Sentinel produces.

We have selected AI providers with strong data protection commitments. Our AI sub-processors (Anthropic and Groq) do not use API inputs to train their models under their standard API terms. See our AI Transparency Notice for further detail.

6. Third parties we share data with

We share personal data only with the third-party sub-processors necessary to operate Sentinel. All sub-processors are bound by contractual data protection obligations consistent with GDPR requirements.

Sub-processorPurposeLocationSafeguards
SupabaseAuthentication and primary database hostingEuropean UnionEU-hosted; DPA in place
RailwayApplication hosting, backend workers, and user-uploaded content storageEuropean UnionEU-hosted; DPA in place
AnthropicPrimary AI engine for compliance analysis of captions, bio text, and uploaded mediaUnited StatesSCCs; no training on API inputs
GroqFallback AI engine and Whisper audio transcription for video scansUnited StatesSCCs; no training on API inputs
ApifyScraping public Instagram profile and post dataEuropean Union / United StatesSCCs
ResendTransactional email delivery (notifications, alerts, receipts)United StatesSCCs
StripePayment processing and subscription managementUnited States / European UnionSCCs; PCI-DSS Level 1

Our website also loads a fallback avatar image service (ui-avatars.com) when a connected account has no avatar available. When your browser loads that image, the provider receives your IP address as part of the standard web request.

We also disclose data (a) when required by law, subpoena, or lawful government request; (b) to protect the rights, safety, and property of Reviewal, our users, or the public; and (c) in connection with a corporate transaction (for example a merger, acquisition, or asset sale), in which case we will notify affected users.

We do not sell your personal data. We do not use your personal data for advertising or ad targeting.

7. International data transfers

Primary customer data (identity, account records, connected account content, and user-uploaded content) is stored in the European Union via Supabase and Railway. Some processing takes place outside the European Union, in particular:

For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States or other third countries, we rely on appropriate safeguards under GDPR Chapter V, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, sub-processor participation in the EU-U.S. Data Privacy Framework. We only send the minimum data necessary for each processing purpose.

8. How long we retain personal data

We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law:

When you request full account deletion, we will delete or anonymize your personal data across our production systems within thirty (30) days, and it will be fully purged from all backups within a further backup rotation cycle (typically 7 to 14 days).

9. Your rights

Depending on your jurisdiction, you have certain rights regarding your personal data. We honor these rights globally, to the extent operationally practical, regardless of where you are located.

9.1 Rights under GDPR (EEA) and UK GDPR

9.2 Rights under CCPA / CPRA (California)

9.3 Rights under UAE PDPL

9.4 How to exercise your rights

To exercise any of these rights, please contact us at sentinel@reviewal.team. We may need to verify your identity before processing your request. We will respond to verified requests within thirty (30) days (or such shorter timeframe as required by applicable law). We will not charge you a fee for exercising your rights, unless your request is manifestly unfounded or excessive.

10. Security measures

We take the security of your personal data seriously. Our security measures include:

No security system is impenetrable. While we implement industry-standard safeguards, we cannot guarantee absolute security. You are responsible for protecting your account credentials and for the confidentiality of your session.

11. Internal team access

For customer support, quality assurance, and security purposes, authorized members of our internal team may access your account data, including your compliance results, in order to reproduce and resolve issues and to check the accuracy of our automated assessments. That access is read-only: our systems refuse any attempt by staff to modify an account they do not own. Every such access is recorded in an append-only audit log, and is used only for legitimate support, safety, or legal-compliance purposes. We rely on our legitimate interest in providing and improving an effective service as the legal basis for this processing.

12. Children's privacy

Sentinel is not directed to children under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected personal data from a person under 18, we will delete it promptly. If you believe we have collected data from a minor, please contact us at sentinel@reviewal.team.

13. Cookies and similar technologies

We use only strictly necessary cookies and browser storage required for authentication and functional preferences (such as your language and interface settings). We do not use advertising cookies, tracking cookies, or cross-site tracking. For full detail on our cookies and browser storage, please see our separate Cookie Policy.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the "Last updated" date at the top of this Policy and, where legally required or otherwise appropriate, notify you by email or via an in-app notice. Continued use of the Service after an updated Privacy Policy becomes effective constitutes your acceptance of the update.

15. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact Reviewal at sentinel@reviewal.team.

Reviewal is the trading name of Chafai Solutions LLC, a limited liability company organized under the laws of the State of Delaware, United States, with registered office at 16192 Coastal Highway, Lewes, Delaware 19958, United States. Chafai Solutions LLC is the data controller for the purposes of the GDPR and equivalent data protection laws.