Retree

Legal

Privacy Policy

Effective date: 16 September 2026

1. Who is responsible for your data

The controller of the personal data processed through Retree, the team retrospective service available at https://retr.ee (the "Service"), is Dawid Zbiński, ul. gen. Władysława Sikorskiego 15/15, 34-400 Nowy Targ, Poland, NIP 7352921429, REGON 528114982 ("we", "us"). You can reach us about anything in this policy at dawid@zbinski.dev. We have not appointed a data protection officer, because the nature and scale of our processing do not require one.

We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and Polish data protection law.

2. What this policy covers

This policy covers the Service and everything under the domain retr.ee, including the retro pages you open from a shared link. It does not cover other websites that a retro's participants may link to in their cards or action items.

Retree has no user accounts. This policy therefore talks about your browser and the retros it joined rather than about an account.

We are the controller for everything described here. Where an organisation uses Retree for its team and is itself the controller of what its team enters, it can ask us for a data processing agreement at dawid@zbinski.dev; until one is concluded, this policy governs.

3. The data we process, why, and for how long

DataDetailsWhy we process it and on what basisHow long we keep it
Device identifier and sessionA random identifier (UUID) that your browser generates on first use and stores in its local storage; a signed session cookie that authenticates your browser; a participant record in our database (identifier, creation and last-update time).To recognise your browser across visits so that your retros, name, cards and votes stay yours without an account. Necessary to provide the Service you asked for (Article 6(1)(b) GDPR).The participant record is kept for as long as any retro it joined exists, or until you ask us to delete it. The cookie is valid for one year from the last time it was issued. The local-storage identifier stays until you clear your browser data.
Display nameThe name you enter (1–50 characters). Shown to the other participants of every retro you join, and on the join screen of a retro you are invited to (as an avatar with your initials).To show who is taking part, who wrote a card (when the retro is not anonymous), who is typing, who owns an action item. Necessary to provide the Service (Article 6(1)(b)).Same as the participant record. You can change it at any time in the Service.
Retro contentThe retro title; cards (text, column, time of creation and last edit, author); groups and their names; votes; action items (name, description, due date, assignee, creator, status); the current stage and timer; who joined and when; who hosts.To store the retro and show it to its participants in real time. Necessary to provide the Service (Article 6(1)(b)). Where the retro is run by an organisation, that organisation's interest in holding its retrospective (Article 6(1)(f)).For as long as the retro exists. Retros do not expire automatically today; any participant can request deletion (section 10). We may introduce automatic deletion of retros that have not been opened for a long time; we will update this policy and announce the period before it applies.
Presence and typingWhether your browser has an open connection to a retro, and which column you are currently typing in.To show who is online and who is writing. Necessary to provide the Service (Article 6(1)(b)).Not stored. Held in the server's memory only while your connection is open; a typing signal is discarded a few seconds after you stop typing.
Preferences in your browserYour theme choice, whether the action-items rail is open, and whether you switched product analytics off.Stored in your browser's local storage at your request. They are never sent to us, so we do not process them.Until you clear your browser data.
Technical data and server logsWhen you use the Service: your IP address, browser identification string (user agent), the requested address with the retro link removed, time, response status, referrer; on the application side, request identifiers, route templates, response status and duration (no IP address, no content).To deliver the Service to your browser, to keep it secure and stable, to limit abuse (creating sessions and retros is limited to 60 requests per minute per IP address), and to diagnose failures. Our legitimate interest in operating a secure and reliable service (Article 6(1)(f)).Rate-limit counters live in memory for one minute. Log files are kept for up to 30 days.
Product analyticsEvents describing how the Service is used, without any content — see section 5 for exactly what is and is not collected.To understand which features are used and how, so that we can improve the Service. Our legitimate interest in developing the Service (Article 6(1)(f)). You can object at any time (section 5).Raw analytics events are deleted after 12 months at the latest. Aggregated statistics that no longer relate to any person may be kept longer.
CorrespondenceE-mails you send us (your address, name if you give it, and the content), including complaints, deletion requests and notices about illegal content.To answer you, handle your request and, where needed, to establish, exercise or defend legal claims (Article 6(1)(b), (c) and (f)).For as long as needed to handle the matter and afterwards for the limitation period of possible claims, which is up to six years under Polish law.
BackupsDaily copies of our database, which contain the participant records and retro content described above.To restore the Service after a failure. Our legitimate interest in the continuity of the Service (Article 6(1)(f)).Each backup is kept for 30 days and then deleted. Data deleted from the Service disappears from backups within that period.

Providing the data marked as necessary to provide the Service (a device identifier, a name, and whatever you choose to write) is a condition of using the Service: without an identifier and a name a retro cannot tell participants apart. Nothing else is required.

Please do not enter special categories of personal data (such as data about health, ethnic origin, religious beliefs, sexual orientation or political opinions), payment details or passwords into a retro. The Service is built for feedback about how a team works, not for storing sensitive records.

4. Cookies and browser storage

The Service sets exactly one cookie and uses a few local-storage entries, all first-party. There are no advertising, tracking or third-party cookies, and the Service does not store anything for product analytics (section 5).

NameTypePurposeLifetime
retree_sessionCookie (HttpOnly, Secure, SameSite=Lax)Authenticates your browser as a participant; contains a signed participant identifier and nothing else.1 year from the last time it was issued
retree.deviceIdLocal storageThe random device identifier that links your browser to your participant record.Until you clear browser data
retree.themeLocal storageYour light / dark / system theme choice.Until you clear browser data
retree.actionItemsRailLocal storageWhether you left the action-items rail open.Until you clear browser data
retree.analyticsOptOutLocal storagePresent only if you switched product analytics off (section 5).Until you clear browser data

Storing these items does not require your consent: the cookie and the device identifier are strictly necessary to provide the service you asked for, and the remaining entries record preferences you set yourself. That is why the Service shows no cookie banner. You can delete all of them at any time through your browser's settings; afterwards the Service will treat your browser as new.

Reading this policy, the Terms of Service or the Legal notice does not create a session and stores nothing on your device.

5. Product analytics

We use PostHog, a product analytics service, to understand how the Service is used. PostHog is provided by PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, United States. We use PostHog's EU Cloud, so the analytics data is stored on servers in Frankfurt, Germany.

How it works. We run PostHog in its cookieless mode. It sets no cookies and stores nothing in your browser. Instead of a persistent identifier, each event carries a pseudonymous value computed on PostHog's servers as a one-way hash of your IP address, your browser identification string, the Service's host name and a random value that changes every day and is deleted afterwards. The hash cannot be reversed, and it changes every day, so you appear as a new visitor each day and cannot be tracked over time. PostHog derives your approximate location (country and region) from your IP address and then discards the address; the IP address itself is not stored. No person profile is ever created.

What we record. Page views with the retro link removed, and product events such as "retro created", "stage changed", "card added", "vote cast", "action item created" or "timer started", each with technical properties: browser, operating system, screen size, language, the domain you came from, and the approximate location described above. We also record which controls you click or otherwise interact with — buttons, links and form fields — identified only by their type and technical attributes, never by the text they display or the text you enter. We also record when you leave a page, and how quickly the page loaded and responded (the Core Web Vitals) — timing measurements only, never content. If the Service runs into an error, we record a technical error report: the error message, the technical trace of where it happened, your browser, and the page you were on with the retro link removed; such a report contains no content entered in a retro and no display name.

What we never record. The text of cards, group names, action items or retro titles; your display name; retro links or identifiers; what you voted for; the contents of your session (no session recordings, no heatmaps, no text of what you click, no form input).

Legal basis. Our legitimate interest in understanding and improving the Service (Article 6(1)(f) GDPR). We consider this interest proportionate because nothing is stored on your device, no content is collected, your IP address is not kept, and the identifier cannot follow you beyond a single day.

Your choices. You can switch product analytics off at the end of this page under "Your analytics choice"; the choice is stored in your browser only, and nothing about your usage is sent while it is off. The Service also honours the Do Not Track and Global Privacy Control signals of your browser: if either is enabled, product analytics is not loaded at all. You may also object to this processing at any time by e-mail (section 10).

6. Who can see what you write

Retree is a shared space, and the most important thing to know about your privacy in it is who else can see your data:

  • Anyone with the retro link can open the retro, see the title, the stage, the names and initials of the participants, and join. Share links only with the people who should take part.
  • Your cards are readable only by you during the preparation stage (other participants see a blurred placeholder of the same size). From the grouping stage onwards every card is visible to every participant of the retro.
  • Who wrote what. When "anonymous cards" is on (the default), no participant is shown the author of a card. When it is off, revealed cards show their author's name. In both cases, our database links every card to its author's participant record so that you can edit and delete your own cards; we do not disclose that link to participants or to anyone else.
  • Your votes are visible only to you while voting is open. Vote totals for each item are shown to everyone during the discussion and on the finish screen; who voted for what is never shown. During voting, participants can see that you have used all your votes.
  • Action items always show the name of the person who created them and of the person they are assigned to, in every retro, including anonymous ones.
  • The host sees exactly what other participants see. Hosting gives control over the stage and the timer, not extra visibility.
  • The summary on the finish screen can be copied by any participant and shared outside the Service. We have no control over what participants do with content they have legitimately seen.

7. Recipients and sub-processors

We do not sell or rent personal data. We share it only with the providers below, which process it on our behalf under data processing agreements, and with public authorities when the law requires it.

ProviderWhat they do for usWhere the data is
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, GermanyHosts the servers that run the Service, its database and its logs.Nuremberg, Germany
Backup storageStores the daily database backups described in section 3.European Union
PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, United StatesProduct analytics (section 5).Frankfurt, Germany (PostHog EU Cloud)
MXroute LLC, Hallsville, Texas, United StatesHosts the mailbox behind dawid@zbinski.dev, through which we receive and answer your e-mails.United States

8. International transfers

The Service, its database, its logs, its backups and the analytics data are stored in the European Union. Two of our providers are established in the United States:

  • PostHog, Inc. stores our analytics data in the EU. To the extent PostHog, Inc. accesses that data from the United States, the transfer is covered by PostHog's participation in the EU–U.S. Data Privacy Framework and by the Standard Contractual Clauses adopted by the European Commission, both of which form part of our data processing agreement with PostHog.
  • MXroute LLC hosts our e-mail. Correspondence you send to dawid@zbinski.dev is therefore stored in the United States. The transfer is based on the Standard Contractual Clauses adopted by the European Commission. If you would rather not have your correspondence stored outside the EU, tell us and we will agree another way of communicating.

We do not transfer personal data anywhere else outside the European Economic Area.

9. Security

  • The Service is available only over HTTPS, with HTTP Strict Transport Security enabled.
  • The session cookie is signed, HttpOnly and Secure; the retro link is a 256-bit random value that cannot be guessed or enumerated.
  • The database and the application server are not reachable from the internet; only the web server that serves the Service can talk to them.
  • Server logs never contain retro links, card content, cookies or request bodies.
  • Every response carries a strict content security policy, and the Service loads no third-party scripts other than, when analytics is on, PostHog's.
  • Access to the production systems is limited to the operator and protected by key-based authentication.
  • Backups are taken daily and stored separately from the running system.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the supervisory authority and, where required, the affected people, as the GDPR requires.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate data — you can change your display name and edit your own cards and action items directly in the Service;
  • erasure of your data (see below for how deletion works in a shared retro);
  • restriction of processing while a request of yours is being handled;
  • data portability for the data you provided to us — the finish screen of every retro lets you copy a full summary, and on request we provide your data in a machine-readable format;
  • object to processing based on our legitimate interests, including product analytics (which you can also switch off on this page) and server logs, on grounds relating to your particular situation;
  • lodge a complaint with a supervisory authority (section 14).

We do not rely on consent for any processing described in this policy, so there is no consent to withdraw; switching analytics off or objecting has the same effect.

To exercise a right, e-mail dawid@zbinski.dev. Because the Service has no accounts, we need to make sure the request comes from the right person: we will ask you to show that you hold the retro link concerned and, for requests about your own participant record, the device identifier stored in your browser (you can find it in your browser's local storage under retree.deviceId). We answer within one month; for complex or numerous requests we may extend this by two further months and will tell you if we do. Exercising your rights is free of charge.

Deletion in a shared retro. A retro's content belongs to everyone who took part. When you ask us to delete your data, we delete your participant record and everything that identifies you (your name and the link between you and your cards, votes and action items). We delete the cards and action items themselves when you wrote them, and the whole retro when you are its host or its only participant; otherwise the other participants' work stays, without any reference to you.

11. Children

The Service is not directed at children and may not be used by anyone under 16 years of age. We do not knowingly process the data of children under 16. If you believe a child has used the Service, contact us and we will delete their data.

12. Automated decision-making

We do not make any decision about you based solely on automated processing, and we do not profile you.

13. Changes to this policy

We may update this policy when the Service, our providers or the law change. We publish the new version at https://retr.ee/privacy with a new effective date and announce material changes in the Service before they take effect.

14. Contact and complaints

For anything about your personal data, write to dawid@zbinski.dev or to Dawid Zbiński, ul. gen. Władysława Sikorskiego 15/15, 34-400 Nowy Targ, Poland.

If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where the alleged infringement took place. The authority responsible for us is the President of the Personal Data Protection Office of Poland (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.

Your analytics choice

Retree uses privacy-preserving product analytics to see which features are used. Switch it off and nothing about your usage is sent.

Stored on this device only.