Privacy Policy

Last updated: September 1, 2026

1. Who we are

retain.so is a churn prevention and customer analytics platform for SaaS businesses, operated by Gaviro Tecnologia LTDA (CNPJ 54.585.383/0001-36), a company incorporated in Brazil, trading as Retain ("Retain", "we", "us"). This policy explains what personal data we handle, why, and what rights you have over it.

Contact for any privacy matter: [email protected].

2. The two roles we play

Retain handles personal data in two distinct roles, and your rights differ depending on which data is involved:

3. Data we collect as a controller

4. End-User Data we process on your behalf

When you integrate Retain with your product, you may send us data about your users, including:

You are responsible for having a lawful basis to collect this data and share it with us, and for informing your users accordingly. Do not send us special categories of personal data (such as health, racial, or biometric data) or data about children.

5. How we use data

We do not sell personal data, and we do not use End-User Data for advertising or to build profiles for anyone other than the customer who sent it.

6. AI processing

Two features send data to OpenAI through its API. When you ask Retain to draft a re-engagement email, we send the account name, the risk factors we recorded, the health score, and your own name, email address, and role as the sender. We do not send the email address of the end user the message is about, and we do not send the message for you: the draft comes back to your dashboard and you send it yourself. When you open the retention cohort chart, we send aggregate retention percentages only, with no personal data at all.

Data sent to OpenAI through its API is not used by OpenAI to train its models, per OpenAI's API data usage policies. We do not train any model on your data or on End-User Data.

7. Subprocessors and connected services

These providers process data on our behalf to run Retain:

Separately, you may connect third-party services to your workspace. These are not our subprocessors: we act on them under your instructions, using credentials you provide. We read subscription data from Stripe and Polar and events from your PostHog, and we send the alerts you configure to Slack and Discord. Retain never collects payment through Polar; it exists only as a source we read your subscription data from.

8. When we disclose data

Beyond the subprocessors above, we only disclose personal data:

We never sell or rent personal data.

9. International transfers

We are established in Brazil and our infrastructure is hosted in the United States, so personal data crosses borders wherever you are located. Our Data Processing Agreement incorporates the EU Standard Contractual Clauses and the UK addendum, and applies automatically when you accept our Terms. For the equivalent clauses approved by the Brazilian ANPD, write to [email protected].

10. Retention

We keep account data for as long as your account is active, and we keep the event history you send us for the lifetime of that account. When your account is terminated, or when you ask us in writing, we delete your data and any End-User Data within 30 days, except where the law requires us to keep it. Deletion requests are handled by our team rather than by a button in the product.

11. Security

Data is encrypted in transit (TLS). Passwords are stored hashed, and access to production systems is restricted and authenticated. Every dashboard request is scoped to your organization, so one workspace cannot read another. Data ingestion is scoped by write keys that you can rotate at any time from your dashboard, and API keys issued to AI agents are stored only as a hash and shown to you once, at creation. We do not currently hold a SOC 2 or ISO 27001 certification.

12. Your rights

Under the GDPR you may request access, correction, deletion, portability, or restriction of your personal data, and object to certain processing. The LGPD gives Brazilian residents equivalent rights, with the ANPD as the supervisory authority. If you are a California resident, you have equivalent rights under the CCPA/CPRA, including the right to know, delete, and correct your personal information. We do not sell personal information. We do share it in the narrow sense the CCPA/CPRA gives that word: the Meta pixel on our marketing pages is cross-context behavioral advertising, and section 13 explains how to opt out. Write to [email protected] and we will respond within the legal deadlines. You may also lodge a complaint with your local supervisory authority.

If you are an end user of one of our customers, the controller of your data is that company. Please direct requests to them first; we assist our customers in fulfilling these requests.

13. Cookies and session recording

We use essential cookies for authentication and session management. They cannot be disabled without breaking sign-in.

On our marketing site, sign-up, and onboarding we use PostHog for analytics, served through our own subdomain so its cookies are first-party. This includes session recording, which captures navigation, clicks, and how long you spend on each step. Everything you type into a form is masked in those recordings, so we can see which field you stalled on but not what you entered. Analytics and recording are switched off when you enter the dashboard, which is deliberately outside analytics.

On our marketing pages, sign-up, and onboarding we also load the Meta pixel. It tells us which ads brought someone here, and it lets us show ads to people who visited without signing up.

It is not loaded inside the dashboard, with one exception: when you come back from Stripe after starting a subscription, we record that single conversion and then clear it from the address bar. Meta never sees the accounts, customers, or events you work with in Retain.

Under the CCPA/CPRA this counts as "sharing" personal information for cross-context behavioral advertising. We do not sell personal data, and we never share the data you send us as a customer. To opt out, write to [email protected]. Our marketing pages do not currently respond to browser "Do Not Track" or Global Privacy Control signals.

14. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced by email or in the dashboard before they take effect. The date at the top reflects the latest revision.

15. Contact

Questions about this policy or our data practices: [email protected].

Command palette

Search customers, alerts, events, pages and docs