Privacy Policy

Last updated: 16 August 2026

Retrouse is a private journaling and reflection app. This policy explains what we collect, why, and the choices you have. We built Retrouse local-first: your journal lives encrypted on your device, and syncing to the cloud is optional.

Who we are

Retrouse ("we", "us") provides the Retrouse apps (Windows, macOS, Android, and web) and the optional Retrouse cloud sync service. If you have questions, contact us at **privacy@retrouse.com**.

What we collect

  • Account data — your email address and, if you set one, a display name. Passwords are never stored in plain text; social sign-ins (Google, Microsoft, Apple) return only a verified email and name.
  • Your content — the journal entries, plans, stamps, reflections, moods, and file attachments you create. On your device this is stored in an encrypted SQLite database (SQLCipher, AES‑256).
  • Sync data — if you enable cloud sync, your entries and attachments are transmitted over TLS and stored on our servers so your devices stay in step. Attachment binaries are stored in Azure Blob Storage.
  • Usage counters — aggregate counts we keep to run subscriptions (e.g. number of entries, attachment sizes by type, AI usage for the current billing period). These are numbers, not the contents of your entries.
  • Device & diagnostic data — basic technical logs (app version, error traces, timestamps) used to keep the app working. We do not run third‑party advertising trackers.
  • Integration tokens — if you connect Google or Microsoft (Calendar, To‑Do, OneNote, Drive), we store the OAuth refresh token needed to sync, scoped to the permissions you granted.

How we use your data

  • To provide the app and, when enabled, sync your journal across your devices.
  • To authenticate you and keep your account secure.
  • To operate subscriptions and enforce plan limits (via the usage counters above).
  • To provide optional AI features you invoke.
  • To diagnose and fix problems.

We do not sell your data, and we do not use the contents of your journal to train AI models.

Cookies and local storage

The Retrouse website and web app use cookies and browser local storage for essential, functional purposes only: keeping you signed in, remembering preferences you set (such as language, theme, or a remembered e‑mail on the sign‑in page), and monitoring that the site works. You can clear or block them in your browser; parts of the web app (staying signed in, your local journal database) will stop working without them. We do not use advertising cookies, and we do not store your name, contact, or demographic information in cookies for use by third parties.

Encryption and local-first storage

Your journal database is encrypted at rest on your device with a per‑user key held in your operating system's secure store. Cloud sync is opt‑in — until you turn it on, your entries never leave your device (except for features you explicitly trigger, such as an export).

AI features

Retrouse offers optional AI assistance (summaries, prompts, reflections). Depending on your settings this runs either on‑device (a local model) or via our backend to a hosted model. Only the text you choose to send for a given AI action is processed; it is used to produce your result and is not retained to train models.

Third‑party integrations

When you connect an integration, data flows only as you direct it: calendar events, tasks, or notes you import, or backups you export to your own Google Drive. Those providers process that data under their privacy policies. You can disconnect an integration at any time in Account → Integrations.

Your responsibility for your data and devices

You are fully responsible for the data you choose to enter into Retrouse and for what happens to it on your side of the Service. We encrypt your journal at rest and in transit, but no measure of ours can protect data on a device or account you no longer control. To the fullest extent permitted by law, Retrouse ("we", "us") is not responsible for the security of your data, or for its loss, disclosure, unintentional use, or misuse, where this results from circumstances on your side — for example a lost or stolen device, a device left unlocked, unauthorised access to your device or sign‑in method, shared credentials, or copies and exports you keep outside the Service. Protect your devices with a lock, keep your sign‑in method to yourself, and use the in‑app export and sign‑out tools when you hand a device over. See also Terms of Service → Your responsibility for your content and your devices.

Sharing and disclosure

We share data only with the processors that run the service (e.g. cloud hosting, email delivery) under contract, or when required by law. We never sell personal data or share your journal content for advertising.

Data retention and deletion

Your content is kept while your account is active. You can export your data or delete your account from the app at any time; deleting your account removes your synced content and attachments from our systems, subject to short‑lived backups that age out on a rolling schedule.

Your rights

Depending on where you live (e.g. the EU/EEA under GDPR), you may request access to, correction of, export of, or deletion of your personal data. Use the in‑app export/delete tools, or email **privacy@retrouse.com**.

Children

Retrouse is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect their data.

Changes to this policy

We may update this policy; we will post the new version here and update the "last updated" date. Material changes will be surfaced in the app.

Contact

Questions or requests: **privacy@retrouse.com**.