Retiola Privacy Policy
Canonical policy: https://retiola.com/privacy
Retiola collects the minimum data needed to provide its page-based discussion, annotation, note, notification, moderation, account, and optional subscription features. This can include username, login and notification email address, URLs and page context where the user actively opens or uses Retiola, submitted posts, replies, annotations, votes, reports, notes, bookmarks, badges, subscription status, and basic presence data. Retiola does not collect a user's complete browsing history, cross-site advertising identifiers, fingerprints, plaintext passwords, or payment-card details.
Data is used only to operate, secure, moderate, support, and improve the service. It is not sold or used for advertising. Primary application data is stored by Supabase in the European Union. Google OAuth is optional. Stripe processes payments when a user purchases an optional plan. Resend handles transactional email. Groq receives only the limited page, selection, or thread context needed when a user explicitly enables and invokes an AI summary. CDN providers receive ordinary connection metadata when their public assets are requested.
Data is transmitted over HTTPS and access is limited to what each processor needs. Users can export their data and delete their account in Settings. Private account data is deleted; public contributions may remain in anonymized form so conversations remain readable. Encrypted backups expire after at most 14 days.
Questions and GDPR requests: legal@retiola.com. Account support: support@retiola.com. Full policy and current processor, retention, legal-basis, international-transfer, and user-rights details are available at https://retiola.com/privacy. Last updated 2026-08-28.