Privacy Policy
Last updated: June 2026
Contents
1Introduction
RetroScale ("we", "our", "us") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform. We comply with the General Data Protection Regulation (GDPR) and applicable data protection laws.
2Data We Collect
We collect the following categories of personal data: (a) Account information — name, email address, and profile photo obtained via OAuth providers (Google, GitHub). (b) Usage data — retrospective sessions, board items, votes, mood check-ins, and icebreaker responses you create. (c) Technical data — IP addresses, browser type, and access logs for security and debugging purposes. (d) Communication data — any messages or feedback you send us.
3Legal Basis for Processing
We process your data on the following legal bases: (a) Contractual necessity — to provide the RetroScale service you signed up for. (b) Legitimate interests — for security monitoring, fraud prevention, and service improvement. (c) Consent — for optional analytics cookies and marketing communications. You may withdraw consent at any time.
4How We Use Your Data
We use your data to: provide and maintain the RetroScale service; authenticate your identity and manage your account; generate AI-powered retrospective analysis; send transactional notifications (invites, session updates); improve platform features and user experience; detect and prevent fraud, abuse, and security incidents.
5Data Sharing
We do not sell your personal data. We may share data with: (a) OAuth providers (Google, GitHub) solely for authentication. (b) Infrastructure providers (Vercel, Neon/PostgreSQL) for hosting and storage, under data processing agreements. (c) AI providers (Google Gemini) for sprint analysis features — only anonymized retrospective text is sent. (d) Law enforcement, if required by applicable law.
6Data Retention
We retain your personal data for as long as your account is active. Audit logs are retained for 12 months. When you delete your account, we permanently erase your personal data within 30 days, except where retention is required by law.
7Your Rights (GDPR)
Under GDPR you have the right to: (a) Access — request a copy of your personal data. (b) Rectification — request correction of inaccurate data. (c) Erasure — request deletion of your account and data. (d) Restriction — request that we limit processing of your data. (e) Portability — receive your data in a machine-readable format. (f) Object — object to processing based on legitimate interests. To exercise these rights, use the Privacy controls in your Workspace Settings or contact us at [email protected].
9Security
We implement industry-standard security measures including TLS encryption in transit, bcrypt-hashed credentials, PostgreSQL Row-Level Security (RLS), rate limiting, and audit logging to protect your personal data.
10Contact & DPO
For privacy-related inquiries, to exercise your rights, or to reach our Data Protection Officer, contact us at: [email protected]
Questions about this policy? Contact our Data Protection Officer at [email protected]