Retain7 stores project memory for the AI agents you connect. This policy explains what personal data we handle, why, who sees it, how long we keep it, and what you can do about it.
Who is responsible
We run Retain7 and are the controller of the personal data described here, such as your account and usage data. For the content your team saves in Retain7 (memories, handoffs and project data), your team is the controller and we process it on your behalf and on your instructions. If you need a data processing agreement, email [email protected].
What we collect
- Account details: your name, email address, password hash and, if you use one, the Google account id. We never see your Google password or anything else in your Google account.
- Team details: team names, members, roles and invitations, including the email addresses people are invited with.
- Your content: the titles, bodies, types, tags and file paths of memories and handoffs that you and your agents save, their edit history, and which tool saved them. Our check blocks text that looks like a secret, but please do not save personal data you do not need to.
- Usage records: which tool an agent called, when, from which client, how long it took and how many results it returned. They contain no memory text.
- Technical data: IP address, browser and device details, and request logs, used for sign-in, rate limiting and abuse prevention.
- Claude Code hooks, if you install them: the repository's git remote at session start, and the last assistant message of a session, held briefly to write the handoff.
- Billing: Dodo Payments handles payment. We store your Dodo customer and subscription ids, the plan, seats and status, never your card number.
- Messages: emails you send us, and the account and billing emails we send you.
Why we use it
- To provide the service: sign you in, store and search memories, show them to your team, enforce plan limits and review inboxes.
- To take payment and keep accounts in good standing: subscriptions, seats, invoices and tax through Dodo Payments.
- To keep it safe: prevent abuse, fraud and bulk sign-ups, secure accounts, and investigate incidents.
- To contact you about the service: verification and password emails, trial and billing notices, and team changes such as someone joining. We send no marketing email.
- To improve and fix the service, using usage records and error logs, not memory text.
- To meet legal duties and handle legal claims.
We do not sell your data, share it for advertising, or use your content to train AI models.
Legal bases
Where the GDPR or similar laws apply, we rely on: performing our contract with you (account, content, billing, service emails); our legitimate interests in running, securing and improving the service and preventing abuse, which we weigh against your rights; your consent, where we ask for it, which you can withdraw at any time; and legal obligations such as tax and accounting rules.
Search and AI processing
Memories are turned into search vectors by an embedding model that runs on our own infrastructure. Memory text is not sent to third-party AI providers by Retain7. The AI tools you connect, such as Claude, ChatGPT, Cursor or Codex, receive the memories they ask for and handle them under their own terms and privacy policies. No decision with legal or similarly significant effect on you is made by automated means.
Who receives it
Within your team, members and the agents they connect see the team's memories, subject to roles. Our staff access data only to run the service, give support you ask for, investigate abuse, or where the law requires. We use these providers (processors) and no others for the purposes shown:
- Dodo Payments: checkout, invoices, tax and payment fraud checks, as merchant of record. It also acts as an independent controller of your payment details.
- Our hosting and infrastructure provider: stores and serves the service and its data.
- Our email delivery provider: sends account, billing and team emails.
- Google: only if you choose to sign in with Google.
We may also disclose data when the law requires it, to protect rights and safety, or in a merger or sale of the business, with the same protections.
International transfers
Our providers may process data in countries other than yours, including countries without the same data protection rules. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. Ask us at [email protected] for details.
How long we keep it
- Account and team data: while your account exists, then deleted as below. Accounts that never verify their email may be deleted after 3 days.
- Memories: until you delete them. A deleted memory can be restored for 30 days, then it is removed for good.
- Edit history of memories: up to 12 months, or until the project is deleted.
- Deleting a project, team or account removes its memories and history for good within a day. Copies in backups expire on the normal backup schedule.
- Usage records: 30 days.
- Session text from the Claude Code hooks: up to a day.
- Invoices and payment records: as long as tax and accounting law requires, held by Dodo Payments and us.
- Security and request logs: for a short period needed to run and protect the service.
Security
We protect data with encryption in transit, access controls between teams, hashed passwords, limited staff access, rate limiting, and a scanner that blocks text that looks like a secret. No system is perfectly secure. If a breach affects your personal data, we will tell the affected account owners without undue delay and notify authorities where the law requires it.
Your rights
Depending on where you live, you can ask to access, correct, delete, restrict or export your personal data, object to our use of it, and withdraw consent. Most of this you can do yourself in the dashboard: edit your profile, export a project as JSON or Markdown, and delete memories, projects, teams or your account. For anything else, email [email protected] and we will answer within one month. You may also complain to your data protection authority. If your data sits in a team you do not control, we may refer you to the team owner.
Children
Retain7 is for professional use and is not directed to children. We do not knowingly collect data from anyone under 16. If you think a child has signed up, email us and we will delete the account.
Cookies
We use only the cookies and local storage needed to keep you signed in, protect forms against forgery, and remember your display preference. No tracking, analytics or advertising cookies. We do not respond to Do Not Track signals because we do not track you across sites.
California and similar laws
We do not sell or share personal information as those terms are defined in California privacy law, and we do not use sensitive personal information to infer characteristics. California residents and residents of other US states with privacy laws can use the rights above, and we will not treat you differently for doing so.
Changes
We will post changes here and update the date above. For changes that matter, we will email account owners before they take effect.
Contact
Questions or requests about your data: [email protected].