Privacy Policy

Your privacy matters. Learn how we protect your data.

Last Updated: 2026-08-17

1. Introduction

Welcome to Retrospective.fun ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our retrospective collaboration platform.

2. Our Role: Data Controller and Data Processor

Depending on the data involved, we act either as a data controller or as a data processor under applicable data protection law, including the General Data Protection Regulation (GDPR):

  • As a data controller: For personal data relating to your own account — such as your name, email address, authentication credentials, and billing information — we determine the purposes and means of processing, and we act as the controller.
  • As a data processor: For personal data that you or your organization submit to the service while running retrospectives — such as notes, comments, votes, and other collaboration content ("Customer Content") — the customer organization is the controller and we process that data on its behalf and in accordance with its instructions.

Where we act as a processor, the customer organization is responsible for ensuring it has a lawful basis to collect and share that data with us. Business customers may enter into a Data Processing Agreement (DPA) with us that governs this processing (see our Terms of Service).

3. Information We Collect

2.1 Information You Provide

  • Account Information: When you create an account, we collect your name, email address, and authentication credentials.
  • Team and Session Data: Information about teams you create or join, retrospective sessions, notes, and collaboration data.
  • Billing Information: Payment details processed securely through our payment provider (Stripe) when you subscribe to paid plans.

2.2 Automatically Collected Information

  • Usage Data: Information about how you interact with our service, including session duration, features used, and performance metrics.
  • Device Information: Browser type, operating system, IP address, and device identifiers.
  • Cookies and Local Storage: We use cookies and browser storage (localStorage, sessionStorage) to maintain authentication sessions, remember your preferences (such as theme settings), and improve user experience. We do not use third-party tracking cookies.
  • Error Data: Technical details about errors in the app, so we can find and fix them (via Sentry). We do not collect performance or page-timing data through Sentry.

4. How We Use Your Information

We use the collected information for the following purposes:

  • Provide, maintain, and improve our retrospective collaboration services
  • Process transactions and send related information
  • Send administrative notifications, updates, security alerts, and retrospective reminders
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze usage patterns and trends
  • Generate AI-powered insights and suggestions to improve your retrospectives (Pro Plus features)
  • Detect, prevent, and address technical issues and security vulnerabilities
  • Comply with legal obligations

5. Legal Basis for Processing (EEA and UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data only where we have a lawful basis to do so under Article 6 of the GDPR. The basis depends on the purpose of processing:

  • Performance of a contract: To create and manage your account, provide and maintain the service, process transactions, and deliver the features you have subscribed to. This includes the AI processing that comes with a paid plan: session content is sent to Azure OpenAI so that embeddings can be generated, and AI-powered features are provided on the plan that includes them. Section 13 describes that processing in full.
  • Legitimate interests: To secure our platform, prevent and detect fraud and abuse, analyze usage, and improve our products and services — provided these interests are not overridden by your rights and freedoms.
  • Consent: For marketing communications, which we send only if you have asked for them. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Legal obligation: Where processing is necessary for us to comply with applicable law, such as tax, accounting, or other regulatory requirements.

Guests take part in a single session without registering an account. The notes a guest writes are processed so that we can provide the session they chose to join, under the plan held by the team that invited them. That includes the AI processing described in Section 13, on the same terms as content written by the team's own members.

6. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Team Members: Information you share within team retrospectives is visible to other team members.
  • Service Providers: We work with third-party providers for hosting, databases, authentication, payments, email and error monitoring. Section 12 names all of them.
  • Legal Requirements: We may disclose information if required by law or in response to valid legal requests.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:

  • Encryption of data in transit and at rest
  • Secure authentication using Firebase
  • Regular security assessments and updates
  • Access controls and monitoring

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Retention periods vary based on:

  • Active account status and subscription level
  • Legal and regulatory requirements
  • Dispute resolution and enforcement needs

You may request deletion of your account and associated data at any time through your account settings or by contacting us directly.

9. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and data
  • Export: Export your retrospective data
  • Opt-out: Unsubscribe from promotional communications

To exercise these rights, please contact us using the information provided below.

10. Children's Privacy

Our service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where some of our service providers operate. These countries may have data protection laws different from those in your country.

Where we transfer personal data of individuals in the EEA or the United Kingdom to a country that has not received an adequacy decision from the European Commission (or, for the UK, from the UK Government), we rely on appropriate safeguards to protect that data — in particular, the Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum where applicable. You may request more information about these safeguards by contacting us using the details below.

12. Third-Party Services

Our service integrates with third-party services:

  • Firebase (Google): Authentication and real-time database services
  • Azure (Microsoft): Cloud hosting, infrastructure, and AI services (Azure OpenAI)
  • Neon: PostgreSQL database hosting
  • Stripe: Payment processing
  • Mailjet: Transactional email delivery (session invites, reminders, notifications)
  • Sentry: Error monitoring

These third parties have their own privacy policies. We encourage you to review their policies to understand how they handle your information.

13. AI-Powered Features

Our service uses artificial intelligence to enhance your retrospective experience. AI-powered features are available on the Pro Plus plan. The following applies:

  • Data Processing: Content from your retrospective sessions (such as notes and discussion topics) may be processed by Azure OpenAI to generate insights, suggestions, and summaries.
  • No Training: Your data is not used to train AI models. Azure OpenAI processes data only to provide the requested service and does not retain it for model improvement. Microsoft's abuse monitoring for Azure OpenAI may store the content sent to it, and the responses returned, for up to 30 days, where authorised Microsoft personnel can review it if misuse is suspected. We have not been granted an exemption from that monitoring.
  • Embeddings: We may create numerical representations (embeddings) of your content to enable features like pattern detection and cross-session insights. These embeddings are stored in our database.
  • Determined by your plan: AI processing follows your team's subscription plan, and there is no separate setting to enable or disable it. On a paid plan, the text you create in a session is sent to Azure OpenAI automatically as it is created, so that embeddings can be generated — this happens without any further action by you or your team. Because the processing follows the plan, the way to decline it is not to subscribe to a plan that includes it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending a notification through our service or via email

Your continued use of our service after changes are posted constitutes your acceptance of the updated policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Data Controller: Yngve Bakken-Nilsen (sole proprietor, operating retrospective.fun)

Email: privacy@retrospective.fun

Website:www.retrospective.fun

16. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including:

  • The right to access your personal data
  • The right to rectification of inaccurate data
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object to processing
  • Rights related to automated decision-making and profiling

To exercise these rights, please contact us using the information above. You also have the right to lodge a complaint with your local data protection authority.

17. CCPA Compliance (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including:

  • The right to know what personal information is collected
  • The right to know if personal information is sold or disclosed
  • The right to opt-out of the sale of personal information
  • The right to deletion of personal information
  • The right to non-discrimination for exercising CCPA rights

We do not sell personal information. To exercise your CCPA rights, please contact us using the information above.

Loading...