Who operates the service
Reverser Space is currently independently operated by Duckie. Privacy questions and requests can be sent to [email protected].
Information collected
Account and authentication
Username, email address, password hash, authentication sessions, connected OAuth clients, and information returned by a social sign-in provider when you choose that method.
Workspace content
Uploaded binaries and symbols; Ghidra projects; analysis state; comments, notes, findings, chat, activity, debugging traces, and files or metadata produced by the workspace.
Usage and operations
Workspace visits, feature operations, capacity and quota use, errors, security events, and ordinary infrastructure logs. The public marketing-site counter stores daily aggregate page totals without cookies, IP addresses, user agents, or individual visitor records.
Billing and communications
Plan and subscription status, provider identifiers, support messages, and verification emails. Payment-card details are handled by the payment provider rather than stored by Reverser Space.
How information is used
- Provide, secure, maintain, and troubleshoot the service.
- Authenticate users and enforce session permissions.
- Run requested analysis, debugging, collaboration, MCP, and publishing features.
- Operate quotas, billing, abuse prevention, and service communications.
- Understand aggregate product use and improve reliability.
Reverser Space does not sell personal information and does not use private customer binaries or workspace content to train shared AI models.
Service providers and transfers
Information is processed only as needed by infrastructure and features you use. Current categories include Cloudflare for web delivery and durable object storage, Google Cloud for configured analysis or isolated debugging compute, Stripe for configured billing, email delivery infrastructure, Google or GitHub when selected for sign-in, and the model provider selected when you connect or run an agent.
These providers may process information in countries different from yours under their own data-protection terms. A current customer-specific subprocessor description can be requested before a managed pilot.
Retention and deletion
- Private workspace content remains until the owner deletes it or the account is deleted.
- Deleted private workspaces are recoverable for seven days and are then scheduled for permanent deletion from durable workspace storage.
- Published writeups remain public until their author removes them.
- Account, billing, security, and operational records are kept only as long as necessary for the service, legal obligations, dispute resolution, fraud prevention, and security.
Some information may remain briefly in provider backups or logs before normal expiry. A managed pilot may define shorter retention and written deletion requirements.
Your choices
You can keep sessions private, revoke share links and agent connections, delete workspaces, remove published writeups, replace model credentials, or request account deletion. You may also request access to or correction of personal information, subject to applicable law.
Send a request from the email associated with the account. Identity verification may be required before information is disclosed or deleted.
Changes to this notice
Material changes will be reflected by updating the effective date and, when appropriate, notifying account holders through the service or email.
Privacy contact
Ask a question or make a data request.
Email a privacy request →