RetroRally

Security and trust

Clear boundaries, without vague promises.

A practical overview of RetroRally account security, room access, contribution privacy, infrastructure, and responsible disclosure.

A practical RetroRally guide · Updated August 2026

Important privacy distinction: contribution anonymity is enabled by default. In anonymous mode, reflection and action-idea authors are hidden from the host and participants; if the host selects named contributions while creating the room, participant nicknames appear beside them. Mood responses, reactions, votes, and post-retro feedback remain private in either mode. Records can remain internally linked to enforce one response, recovery, and abuse controls, so anonymous mode is pseudonymous rather than absolute database anonymity.

Host accounts and sessions

Customer hosts use email verification and a password of at least 12 characters. Verification and reset links are time-limited, hashed at rest, and single-use. A password reset invalidates active customer sessions and outstanding account-action links.

Room access

Hosts control rooms through an authenticated account and a room-specific host pass. Participants enter with a short room code and receive a reconnect credential for that room. Administrative routes are separate from customer-host access.

Team separation

Customer dashboard and history queries require membership of the relevant team. The platform administrator can see operational statistics, contact messages, and post-retro feedback across customer teams, with participant names and player IDs omitted from the admin interface.

Transport and hosting

The production site uses HTTPS. The application runs in an isolated container behind a reverse proxy with a loopback-only application port, a non-root process, resource limits, and health checks. Infrastructure backups are maintained at server level.

Data minimisation

Participants do not need accounts. Public room snapshots use allowlists and do not expose host account IDs, reconnect hashes, normalised account data, or anonymous author IDs. Automated cleanup removes stale demo data, abandoned unverified accounts, expired account-action tokens, and old rate-limit records. The operator controls deletion requests and the retention schedule for customer rooms, contact messages, feedback, and provider backups.

What RetroRally cannot promise

No internet service can promise perfect security or absolute anonymity from its operator. Do not submit secrets, regulated personal data, or information that should not be processed by the service. Use neutral descriptions of team problems rather than names.

Report a concern

Use the contact form and select the security topic. Include the affected URL, impact, and reproduction steps, but do not send credentials or exploit data belonging to other people.

Ready to rally?

Run the format with your team.

RetroRally guides the room from a private mood check to a concrete action with an owner.