Privacy Policy
Effective date: September 16, 2026 · Last updated: September 16, 2026
Retrn is a personal CRM that helps you remember and keep in touch with the people you meet. Because Retrn holds information about you and the people in your network, we want to be clear about exactly what we collect, why, who we share it with, and the control you have over it.
The short version: we collect what you put into Retrn so we can store it, sync it, and help you use it. We don’t sell your data, we don’t show ads, we don’t track you across other apps or websites, and you can export or delete your data at any time.
1. Who we are & what this policy covers
Retrn (“Retrn,” “we,” “us,” “our”) is operated by Neil Shah, an individual based in the United States, who is the controller of the personal information described in this policy. You can reach us at privacy@retrncrm.com.
This Privacy Policy applies to the Retrn website at retrncrm.com, the Retrn web app, the Retrn iOS app, the Retrn browser extension, and any related services that link to this policy (together, the “Service”). It should be read together with our Terms of Service.
2. Information we collect
2.1 Information you give us
- Account information. Your email address and a password (stored only as a salted hash by our authentication provider). If you sign in with Google or Apple, we receive the name, email address, and profile photo URL that provider shares with us; if you use Apple’s “Hide My Email,” we receive only the relay address.
- Profile information. Optional details you add to your own shareable profile: name, headline, company, school, graduation year, major, LinkedIn URL, X/Twitter handle, website, email, and phone number, and the college you select in the app.
- Contacts and network data. Information you enter about people you know, such as their name, photo, company, job title, industry, email, phone, social links, school, graduation year, major, how and where you met, who introduced you, talking points, notes, tags, follow-up goals, last-contact date, and activity history.
- Other content you create. Calendar meetings (title, description, location, time, attendees from your contacts), recruiting-pipeline opportunities (company, role, stage, deadlines, links, notes), outreach templates, and tags.
- Follow-ups and key dates. Reminders you set to get back to someone (a due date and what to do) and yearly dates such as a contact’s birthday or work anniversary.
- Photos. Images you take with your camera, choose from your photo library, or link by URL to use as a contact’s photo, and photos of business cards you choose to scan. We only access your camera or photo library when you choose to add or scan a photo, and only the image you select is used. A business card photo is used to read the card and is not stored (Section 4.1).
- Contacts you import. If you import from your iPhone’s Contacts or a contacts file, the people you choose and their name, company, job title, email, phone, links, and birthday (Section 4.3).
- Voice and typed input. Sentences you speak or type to add a contact or talk to the assistant (see Section 4 for how speech is handled).
- School email verification. If you verify a school email (for example, an @babson.edu address), we store that address, its domain, and the date it was verified.
- Communications. Messages you send us, such as support requests, feedback, and privacy requests.
2.2 Information collected automatically
- Log and device data. When your device talks to our servers, our hosting and database providers automatically record technical information such as IP address, browser or device type, operating system, the pages or endpoints requested, timestamps, and error information. We use this to run, secure, and debug the Service.
- On-device storage. The app stores your sign-in session, theme preference, and a few interface preferences (like dismissed banners and cached results) in your browser’s local storage or, in the iOS app, in the app’s private on-device storage. The website also uses a service worker to cache the app shell so it loads quickly and works offline. None of this is used for advertising or cross-site tracking.
We do not use third-party analytics, advertising, or tracking SDKs, and we do not use cookies for advertising. We do not collect your precise location, we do not access your device’s calendar or health data, and we only read your device’s address book when you choose to import from it.
2.3 Information from other sources
- Sign in with Google or Apple, as described above.
- Other Retrn users. If another Retrn user adds you as a contact (for example, by scanning your shareable QR profile or typing in your details), that information is stored in their account, not yours. See Section 6.
- The browser extension, when you use it on Gmail, Outlook, or LinkedIn (see Section 5).
3. How we use information
We use the information described above to:
- Provide the Service: create and secure your account, store your network, sync it across your devices, and run features like search, reminders, the calendar and its subscription feed, the recruiting pipeline, templates, and import/export.
- Power optional AI features such as smart capture, the daily briefing, the assistant, outreach drafts, coffee-chat prep, and tag suggestions (see Section 4).
- Verify eligibility for student or school-based access.
- Communicate with you: sign-in links and codes, verification codes, security and account notices, responses to your requests, and (only with your consent) product updates.
- Keep the Service safe: prevent abuse, fraud, and unauthorized access; rate-limit and authenticate requests; and debug problems.
- Improve the Service based on aggregate technical information and feedback you send us.
- Comply with the law and enforce our Terms of Service.
We do not sell your personal information, share it for cross-context behavioral advertising, use it to build advertising profiles, or use it for tracking as defined by Apple’s App Tracking Transparency framework.
Legal bases (EEA/UK users). Where the GDPR or UK GDPR applies, we process personal information to perform our contract with you (providing the Service), for our legitimate interests (securing and improving the Service, in ways that don’t override your rights), with your consent (for example, optional marketing emails, which you can withdraw at any time), and to comply with legal obligations.
4. AI features and voice input
4.1 AI features
Retrn’s AI features are designed to help you act on your own network. When you use one, or when a screen that includes one loads (for example, the daily briefing on your dashboard or smart capture after you dictate a contact), Retrn sends the text needed for that task through our server to a third-party large language model provider. That text can include:
- What you typed or dictated, and your questions to the assistant
- Relevant details from your contacts (for example names, companies, roles, tags, notes, how you met, and last-contact dates)
- Relevant upcoming meetings, pipeline opportunities, templates, open follow-ups, and birthdays
- A photo of a business card, when you choose to scan one
- Today's date, so relative dates like "next Tuesday" can be resolved
Our AI requests are currently processed by Anthropic’s Claude models, reached through a model gateway hosted on Microsoft Azure in the United States. Requests are sent only on behalf of a signed-in Retrn user, and the results are returned to your device. Under the commercial terms that govern this access, the model provider does not use these inputs or outputs to train its models. We do not use your content to train AI models either.
AI output can be wrong. Nothing an AI feature proposes is saved to your account until you review and confirm it, and AI features never send a message, email, or invitation on your behalf.
Business card scanning. When you scan a card, the photo is resized on your device and sent once to our AI provider to read the name, company, title, and contact details printed on it. The fields it finds are filled into the contact form for you to review. Retrn does not store the photo, and it is not saved as the contact’s picture.
4.2 Voice input
Retrn never records, uploads, or stores audio. When you use the microphone to add a contact, speech-to-text is handled by your device’s or browser’s built-in speech recognition, and Retrn receives only the resulting text:
- iOS app: Apple’s speech recognition framework, which may process audio on your device or send it to Apple’s servers, under Apple’s Privacy Policy. We ask for microphone and speech-recognition permission before first use, and you can revoke it anytime in iOS Settings.
- Web app: your browser’s Web Speech API. In Chrome and Edge, audio is sent to Google’s or Microsoft’s speech service, respectively, under their privacy policies.
The transcribed text is treated like anything else you type: it is saved only if you save the contact, and it may be sent to our AI provider for smart capture as described above.
4.3 Importing contacts
In the iOS app you can import people from your iPhone’s Contacts, and on the web from a contacts (.vcf) file. Retrn asks for Contacts permission only when you start an import. Your address book is read on your device and shown as a list; only the people you select are uploaded to your Retrn account, along with the name, company, job title, email, phone, links, and birthday stored for them. Nothing else from your address book leaves your device, and Retrn does not re-read your contacts in the background. You can revoke Contacts access at any time in iOS Settings.
4.4 Reminders and notifications
If you allow notifications in the iOS app, Retrn schedules reminders for your follow-ups and key dates on your device, using iOS local notifications. There is no push notification server: the reminder is created by the app from data already on your phone, and no device token is sent to us or to anyone else. A notification shows the contact’s name and your follow-up note, so it may be visible on your lock screen depending on your iOS settings. Signing out removes all scheduled reminders from the device.
5. The Retrn browser extension
The Retrn extension for Chrome lets you log an email or LinkedIn conversation to a contact, or add a contact from a LinkedIn profile. It works only when you click the Retrn toolbar button.
- What it reads: when you click the button on Gmail, Outlook, or LinkedIn, it reads the page you are viewing to pick out the email subject, participants’ names and email addresses, the date, the page link, and the text of the latest message in the open thread (without quoted replies), or a LinkedIn profile’s name, headline, company, and URL. It reads only the page you have open, never your inbox in the background, and never attachments.
- What it saves: only what you confirm: an activity entry (type, date, your summary, and optionally a link back to the email or conversation) on the contact you choose, and, if needed, a new or updated contact. Message text is saved only if you choose to add it to the summary; otherwise it is discarded when the popup closes.
- Sign-in: to connect, the extension reuses your Retrn session from an open Retrn tab (or a password you enter) and keeps it in the extension’s local storage.
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information only to provide the extension’s logging features; we don’t sell it, use it for advertising, or let people read it except as described in this policy.
6. Information about other people in your network
Most of what Retrn stores is information you enter about other people. We process that information on your behalf, and only to provide the Service to you. We don’t use it to contact those people, combine it across accounts, or build profiles of them, and one user’s contacts are never visible to another user.
You are responsible for having the right to record information about the people you add, and for using it lawfully and respectfully (see our Terms of Service). Please avoid storing sensitive information about others, such as health, financial-account, government ID, or similar details, that you don’t need.
If you think a Retrn user has stored your information, we can’t see or change the contents of other users’ private accounts on request, but you can ask that person to delete it. If you believe Retrn is being used to misuse your information, email privacy@retrncrm.com and we will look into it.
7. How we share information
We share personal information only in the following ways, and never sell it.
7.1 Service providers
We use the following companies to run the Service. They process data on our behalf, under contracts that require them to protect it and use it only to provide their services to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and sign-in / verification emails | Account, profile, and all content you store in Retrn; log data |
| Vercel | Website hosting and server functions (AI relay, calendar feed, school verification) | Requests passing through our servers; log data such as IP address |
| Anthropic | AI model processing for AI features | Text sent for an AI request (Section 4) |
| Microsoft Azure | Hosting for our AI model gateway | Text sent for an AI request, in transit to the model provider |
| Google Fonts | Typeface delivery for the website and app | IP address and browser information |
| Google, Apple | Optional sign-in with Google / Sign in with Apple | Identity information described in Section 2 |
If we introduce paid plans, payments will be handled by Apple (for purchases made in the iOS app) or by a payment processor for purchases made on the web. Your full card number will never be stored by Retrn. We will update this policy to name any new provider before it receives your data.
7.2 When you choose to share
- Your shareable profile / QR code. The profile details you choose to include are encoded into the link, so anyone you share it with (or who scans your code) can see them and add you to their own Retrn network.
- Calendar subscription feed. If you turn on the calendar feed, anyone with its private link can view your Retrn meetings, including their titles, times, locations, and descriptions. Share it only with calendar apps you use; you can revoke the link at any time from the calendar’s subscribe dialog.
- Emails you compose. Outreach templates open in your own email app; Retrn does not send them.
7.3 Legal and safety reasons
We may disclose information if we believe in good faith that it is required by law, subpoena, or other legal process; necessary to protect the rights, property, or safety of Retrn, our users, or others; or needed to investigate fraud or security issues. Where legally allowed, we will tell you about requests for your data.
7.4 Business transfers
If Retrn is involved in a merger, acquisition, incorporation, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
8. Security
- Account isolation: every record in our database is tied to your account and protected by row-level security, so other users can’t read or change it.
- Encryption: all traffic uses HTTPS/TLS, and our providers encrypt stored data at rest.
- Least privilege: administrative credentials are kept server-side only, and our AI and verification endpoints authenticate every request.
No system is perfectly secure. Please use a strong, unique password and tell us right away at privacy@retrncrm.com if you suspect unauthorized access to your account. If a breach affects your personal information, we will notify you and any required authorities as required by law.
9. Data retention & deletion
- While your account is open, we keep your data so the Service works. You can delete any contact, meeting, opportunity, template, or tag at any time, and deletions take effect immediately.
- Clear all data: Settings → Clear all data permanently deletes every contact (with their follow-ups and key dates), activity, tag, opportunity, and template in your account while keeping your login.
- Deleting your account: Settings → Delete account permanently deletes your account and everything in it, immediately and from inside the app — no request and no waiting period. When an account is deleted, all of its contacts, follow-ups, key dates, meetings, opportunities, templates, tags, calendar feed links, and verification records are deleted with it. If you would rather we did it for you, email privacy@retrncrm.com from the address on your account and we will delete it within 30 days.
- Backups and logs: deleted data may remain in encrypted backups and server logs for a limited time, generally no more than 30 days, before being overwritten.
- Legal holds: we may keep limited information longer if required by law (for example, billing or tax records) or to resolve disputes and enforce our agreements.
Uninstalling the iOS app or the extension removes data stored on that device but does not delete your Retrn account.
10. Your choices & rights
Wherever you live, you can:
- Access and export your data as JSON or CSV from Settings → Export, or ask us for a copy.
- Correct information by editing it in the app.
- Delete individual items, all of your data, or your whole account from Settings → Delete account (Section 9).
- Withdraw permissions for the camera, photo library, contacts, microphone, speech recognition, and notifications in your device settings. The rest of Retrn keeps working.
- Opt out of marketing emails using the unsubscribe link. Account and security emails will still be sent.
- Object to or restrict certain processing, and withdraw consent where we rely on it.
To make a request, email privacy@retrncrm.com. We may need to verify your identity (usually by confirming control of your account email) and will respond within 30 days, or within the time required by your local law. You may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights.
U.S. state privacy rights. Residents of California and other states with consumer privacy laws have rights to know, access, correct, delete, and port their personal information, and to opt out of its sale, sharing for targeted advertising, or profiling. Retrn does not sell or share personal information for targeted advertising and does not engage in profiling that produces legal or similarly significant effects. In the last 12 months, the categories of personal information we have collected are those in Section 2 (identifiers, customer records, internet activity, audio-derived text, and professional or education information you enter), for the purposes in Section 3, disclosed only to the service providers in Section 7. If we deny your request, you may appeal by replying to our decision, and if you disagree with the outcome you may contact your state attorney general.
EEA, UK, and Swiss users. You also have the right to data portability and to lodge a complaint with your local data protection authority.
11. International data transfers
Retrn is based in the United States, and our service providers store and process data primarily in the United States. If you use Retrn from outside the U.S., your information will be transferred to, stored, and processed there, where data protection laws may differ from those in your country. Where required, we rely on appropriate safeguards, such as the Standard Contractual Clauses offered by our providers.
12. Children
Retrn is not directed to children, and you must be at least 16 years old to use it. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has given us personal information, contact privacy@retrncrm.com and we will delete it.
13. Emails we send
We send transactional emails you need to use Retrn, such as sign-in links, verification codes, and security or account notices. We will only send newsletters or promotional emails if you opt in. Every marketing email includes an unsubscribe link, and we honor opt-outs promptly, in line with the CAN-SPAM Act and similar laws.
14. Changes to this policy
We may update this Privacy Policy as Retrn changes. We will post the updated version here and change the dates at the top. If the changes are material, for example a new category of data or a new way of sharing it, we will notify you by email or in the app before they take effect, and we will ask for your consent where the law requires it.
15. Contact us
Questions, requests, or concerns about privacy? Email privacy@retrncrm.com. For anything else, reach us at hello@retrncrm.com.