Privacy Policy
Last updated July 19, 2026
This policy explains what Forest Hill Labs LLC (“Retenta,” “we,” “us”) collects when you use retenta.ai and the Retenta platform, how we use and protect it, and the choices you have. We aim to collect as little as the service needs and to describe the limits of our access honestly.
What we collect
- Account data. Your email address and authentication records. We use magic-link sign-in; we do not store passwords.
- Capsule content. The documents, notes, URLs, and writes you and your agents add to a capsule, and the chunks, embeddings, and versions derived from them.
- Usage & metering. Query, write, index, and export counts used to enforce quotas and bill, plus standard request logs (with keys, tokens, and obvious PII redacted).
- Payment metadata. Plan and subscription status. Card details go directly to our payment processor — we never see or store a card number.
How we use it
- To build, index, store, and retrieve your capsules and answer queries.
- To meter usage, enforce quotas, and bill your plan.
- To secure the platform, prevent abuse, and meet legal obligations.
We do not sell your data, and we do not use your capsule content to train shared or third-party models.
Encryption and our access to your data
All data is encrypted in transit (TLS 1.3) and at rest(AES-256 across our database, object storage, vector index, and cache). Access to production data is limited and least-privilege.
Retenta is not end-to-end encrypted. Retrieval and answering require reading your content, so we can technically access it to operate the service. That is the honest limit of any product that answers questions over your data. We minimize this access and never repurpose your content beyond providing and securing the service.
Trust-and-safety scanning and lawful requests
Because we can access content, we take responsibility for a narrow set of serious abuse. We run automated scanning to detect illegal material — specifically child sexual abuse material (CSAM) and credible threats of mass or catastrophic harm. This is a targeted safety check, not general monitoring of your memory.
When such material is confirmed, we preserve the associated records as evidence, remove or quarantine the content, and cooperate with valid legal process and report to the appropriate authorities (including, for CSAM, the National Center for Missing & Exploited Children) as required by law. Preserved evidence may be retained even after you delete the underlying content, where the law requires or permits it. We respond to lawful government and law-enforcement requests when they are valid and properly scoped.
Who processes data for us
We rely on a small set of subprocessors to run the service: our cloud infrastructure provider (compute, storage, database, and vector index) and our payment processor (billing). They process data on our behalf under their own security and privacy commitments.
Your data is yours
You can export a full capsule — corpus, manifest, eval set, and write log — at any time in an open, documented format. If you downgrade or cancel, we keep your data and move over-limit capsules to read-only rather than deleting them.
You may request access to, correction of, or deletion of your personal data. Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA/CPRA; we extend these choices to all users.
You can delete your account yourself, from your account page. Doing so erases every capsule you own — sources, extracted text, embeddings and uploaded files — along with your organisation, usage records and sign-in details. It is immediate and irreversible; export anything you want to keep first. Deleting an account is your decision, not a billing one: we never delete your knowledge because a payment lapsed.
Two records outlive a deleted account, on purpose. The first is a tamper-evident audit entry recording that the deletion happened, containing your account identifier and the time. That log is cryptographically chained across all customers, so removing one entry would destroy the integrity guarantee every other customer relies on. The second is any trust-and-safety finding already raised about prohibited content, which we retain as described above. We keep nothing else.
If you belong to a shared organisation and are its owner, transfer ownership before deleting your account — otherwise deleting yours would take capsules other members depend on. If you are a member rather than the owner, deleting your account removes you and your sign-in details; the organisation's capsules remain with the organisation.
Cookies
We use only essential cookies: a session cookie to keep you signed in and a preference cookie to remember your light/dark theme. We do not use advertising or cross-site tracking cookies.
Retention
We retain account and capsule data for as long as your account is active or as needed to provide the service, and usage and billing records as required for accounting and legal compliance. Evidence preserved under our trust-and-safety obligations is retained as the law requires.
Changes
We may update this policy as the product and our practices evolve. Material changes will be reflected in the “last updated” date above.
Contact
Questions or requests: privacy@retenta.ai.