Privacy
Built for honest team conversations.
RetroRally collects only the information needed to run and retain a team retrospective.
What is stored
Host account details, securely hashed host passwords, team names, participant nicknames, room activity, mood scores, retrospective reflections and action ideas, votes, missions, retrospective summaries, optional post-retro ratings or comments, and contact-form names, email addresses, subjects, and messages.
Contribution privacy
Contribution anonymity is enabled by default. While creating the room, the host can instead choose named contributions; RetroRally then shows participant nicknames beside reflections and action ideas in the room and saved host summary. The selected mode is shown to participants and locks with the rest of the room settings as soon as the lobby is created. Mood responses, reactions, action votes, and post-retro feedback remain private regardless of this setting. The database retains internal player links for game integrity and recovery, so anonymous-mode contributions are hidden from the room rather than from the service operator. Room and host-history responses can contain opaque player identifiers for reconnect, participation, mission ownership, and recognition results. These identifiers do not contain an email address or account identity, and anonymous-mode reflections and action ideas are returned without their author link.
Retro feedback
The RetroRally platform administrator can see ratings and optional comments across customer teams, grouped with the retro and team. Customer hosts do not receive this platform-wide feedback view. Participant nicknames and player identifiers are not included in administrator feedback results. The database keeps an internal player link to enforce one response per participant, so this feedback is identity-hidden in the interface rather than anonymous to the service operator.
Website contact
The public contact form stores the name, email address, topic, subject, and message supplied by the visitor. These messages are visible only in the protected platform administrator inbox and are used to investigate and respond to the request. Do not include passwords, room passes, or other secrets.
Account email
Customer host email addresses are used for account verification and password recovery. Transactional messages are delivered through Resend, which processes the recipient address and message delivery data for that purpose. Verification and reset links are time-limited, stored as hashes, and can only be used once. These automated messages come from a no-reply address; help requests should use the contact form.
Optional tracker publishing
If the operator enables a GitHub or Azure DevOps connection and a host explicitly chooses to publish a mission, RetroRally sends the team and retro names, selected action and problem, mission owner and review date, and a link to the saved summary to that provider. Provider credentials stay on the server. No mission is published automatically.
Device storage
The browser stores room-scoped access passes so a host or participant can reconnect after refreshing. Clearing browser storage removes those local passes.
Operation and deletion
The operator controls the deployment database, provider backups, retention schedule, and deletion requests. Use the contact form for access or deletion requests. Before public launch, publish the applicable retention periods and the operator's legal identity.