Retily

Privacy Policy

Last updated: July 31, 2026

1. What this policy covers

This policy explains how Retily handles personal data on this website (retily.com) and in the Retily application (app.retily.com). Retily is customer-support software: workspaces use it to handle their customers' emails, live chats, tickets, files, and knowledge bases, with AI assistance.

Two roles matter throughout. For the account data of the people who sign up and use Retily, Retily decides how and why data is processed (acting as a controller). For the support data a workspace processes about its own customers, the workspace is the controller and Retily processes that data on its behalf and under its instructions (acting as a processor).

2. Data we collect

Account and workspace data: name, email address, password (stored as a secure hash), workspace name and settings, roles and permissions, and billing details (handled by Stripe; we do not store full card numbers).

Customer support content, processed on behalf of your workspace: email conversations, chat transcripts, tickets, contact records of your customers, uploaded files and attachments, knowledge base articles, internal notes, tasks and team messages, and satisfaction ratings.

Technical data needed to run the service securely: server logs (IP address, timestamps, requests), device and browser information, and delivery or error events. This marketing site itself sets no analytics or tracking cookies.

3. How we use data

We use data to provide the service (routing conversations, storing content, delivering email and push notifications, serving file downloads through signed expiring links); to secure it (authentication, permissions, abuse prevention, logging); to bill subscriptions through Stripe; to communicate with you about your account; and to comply with legal obligations. We do not sell personal data and we do not run third-party advertising trackers.

4. AI processing

Retily's AI features generate answers for your customers from your workspace's knowledge base and assist your team with drafting replies. To do this, the relevant conversation content and knowledge base passages are sent to third-party AI model providers for processing. Our agreements with these providers restrict them from using your data for anything other than providing the service, including a restriction on using it to train their models.

AI output is marked in the product where it matters (for example, answers attributed to the AI agent), and conversations can always be taken over by a human on your team.

5. Building an agent from a website

The agent builder at retily.com/try reads the public pages of a website address you enter, so that the demo agent can answer questions about that business. It runs because you asked it to, about an address you typed; it is not a background crawler. What our crawler is, what it reads, and how to block it are documented at retily.com/bot.

We read those pages with our own crawler first. Where a site's bot protection refuses our crawler, we may fetch the page through a third-party web scraping provider instead. What passes through that provider is the content of the public web pages you asked us to read — not your account details, and not your customers' support data. Our crawler checks the site's robots.txt before any request, including any request made through that provider: we do not use a third party to fetch something we would not fetch ourselves.

That provider holds SOC 2 Type II and ISO 27001 certifications, processes data under a data processing agreement, and relies on Standard Contractual Clauses for transfers to the United States.

If you would prefer that nothing leaves our systems, you can build an agent by adding your content directly instead. No third party is involved in that route.

6. Legal bases

Where laws such as the GDPR apply, we process account data to perform our contract with you, on our legitimate interests in securing and improving the service, and to comply with legal obligations. Support content belonging to your workspace is processed on your documented instructions as controller.

7. Who we share data with

We share data only with service providers that help us run Retily: infrastructure and hosting providers (where the application and its database run), Stripe for payment processing, email delivery providers for sending and receiving support email, push notification services for the mobile app experience, AI model providers as described above, and a web scraping provider used only in the narrow case described in section 5. Each provider processes data under a contract that limits it to providing their service to us.

We may disclose data where the law requires it, to protect the rights and safety of users, or as part of a merger or acquisition, in which case this policy continues to apply to data collected before the change.

8. Cookies

The application uses cookies that are strictly necessary to keep you signed in and to protect your session. The application also sets one display-only cookie readable by this marketing site (rt_auth_hint) that indicates whether you are signed in, so the site can show the right buttons. It contains the value 1 and nothing else: no session data and no identifiers. It is cleared when you log out.

This marketing site sets no cookies of its own and uses no analytics.

9. Your customers' data

When your customers contact your business through Retily (by email, the chat widget, or the contact form), their data belongs to your workspace. You decide how long to keep it, who on your team can access it (through roles and permissions), and when to delete it. We process it only to provide the service to you. Requests from your customers about their data should be directed to the business they contacted; we assist workspaces in fulfilling them.

10. Retention

Account data is kept for as long as your account exists. Support content is kept for as long as your workspace keeps it. When a workspace is deleted, its content is removed from production systems within a reasonable period, and from backups on the backup rotation schedule. Logs are kept for a limited period for security and troubleshooting.

11. Security

Data is encrypted in transit. Access inside a workspace is governed by roles and permissions, and workspaces are isolated from one another. File downloads use signed links that expire. Access to production systems is restricted and logged. No system is perfectly secure; if a breach affects your personal data, we will notify you as the law requires.

12. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or delete your personal data, and to complain to a supervisory authority. You can exercise these rights by contacting us through the details published on this site. Where the data belongs to a workspace as controller, we will refer the request to them and assist.

13. International transfers

Our providers may process data in countries other than yours. Where data protected by European or similar law is transferred internationally, we rely on recognized safeguards such as standard contractual clauses with the providers involved.

14. Children

The service is for businesses and is not directed at children. We do not knowingly collect personal data from children for our own purposes.

15. Changes to this policy

We may update this policy as the service and the law evolve. Material changes will be announced on this site or by email before they take effect, with the date above updated accordingly.

16. Contact

Privacy questions and requests can be sent to us through the contact details published on this site.