Privacy policy
Last updated: September 30, 2026
Retreev ("Retreev", "we", "us" or "our") provides a recruiting workspace for staffing and recruiting teams. This privacy policy explains what personal information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to the Retreev web application (the "Service") and to this website, retreev.ai (together, the "Services").
1. Our role: customer data and our own data
Our customers are recruiting and staffing businesses. They use Retreev to store and work with information about candidates, their own clients, and jobs. For that information ("Customer Data"), the customer decides what is collected and why, and Retreev processes it only on the customer's behalf and under the customer's instructions. In privacy-law terms, the customer is the "controller" or "business" and Retreev is the "processor" or "service provider".
If you are a candidate or a client contact whose information is in Retreev, the recruiter or agency that added it is responsible for it. Please contact them first about your information; we will help them respond (see Your choices and rights).
For information about our own customers' users, visitors to this website, and people who contact us, Retreev decides how it is used, and this policy describes our practices.
2. Information we collect
Account and workspace information
- Name, email address, role, and the workspace a user belongs to.
- Sign-in information, such as a password (stored only in scrambled, hashed form) and, where used, two-step verification settings.
- Workspace settings, such as company name, logo, team members and their access, and reminder preferences.
- Plan and billing records, if a paid plan applies.
Customer Data: candidates, resumes and job postings
Customers add recruiting records to Retreev, which can include:
- Resumes received from candidates or from the customer's own clients, and the details in them: name, contact details, location, work history, skills, certifications, education and security clearance information.
- Candidate details recorded by the recruiter, such as current and expected compensation, availability, work preferences, clearance status and verification, and tags.
- Job postings and job descriptions received from the customer's clients, and the requirements, budgets and deadlines in them.
- Client information, such as company names, contact names and email addresses, and fee terms.
- Notes of conversations with candidates and clients, including notes or transcripts the recruiter pastes in.
- Submissions and outcomes, such as which candidates were submitted for which jobs, confirmations of the candidate's permission to be represented, interview stages, reasons a client passed, and placement fees.
- Appointments and follow-ups, such as interviews, calls and reminders.
Some of this information, such as compensation and security clearance details, is sensitive. Customers should add only what they need for recruiting and have a lawful basis to hold.
Calendar information (only if a user connects a calendar)
Connecting a Google Calendar or Microsoft 365 / Outlook calendar is optional. If a user connects one, Retreev receives:
- the email address of the connected calendar account;
- the list of the user's calendars (name, color, time zone, and whether the user can add events to it);
- for the calendars the user chooses to show in Retreev, events from 14 days ago to 90 days ahead: title, start and end time, location, online meeting link, organizer, attendees and their replies, and a link to the event;
- access tokens that let Retreev act on the calendar with the permissions the user approved.
Communications
If you email us or ask for support, we keep your message and our reply.
Technical and usage information
When you use the Services, our hosting providers automatically record standard technical information, such as IP address, browser and device type, pages requested, and the date and time. Retreev also keeps an activity history within each workspace (for example, who changed a record and when) and records of AI usage for cost and abuse monitoring. We do not use third-party analytics or advertising tracking.
3. Where information comes from
- From you, when you sign up, are invited, use the Service or contact us.
- From our customers, who add Customer Data such as resumes, job postings and notes. Customers receive this information from candidates, from their own clients, and from other sources they use in their recruiting work.
- From Google or Microsoft, when a user connects a calendar.
- Automatically, when you use the Services (see Technical and usage information above).
4. How we use information
- To provide the Service: store and display each workspace's records; read resumes and job postings to fill in details; match candidates to jobs and explain the match; check for duplicate candidates and duplicate submissions; send reminders; and send the invitations and calendar events users ask for.
- To provide calendar sync: show a user's calendar events beside their Retreev appointments; create, update or cancel the events they schedule in Retreev (sending invitations only after they confirm the recipients); and show attendees' replies.
- To communicate with you: service emails such as workspace invitations, sign-in links and important notices, and replies to support requests. We do not send marketing email without permission.
- To keep the Services secure and reliable: prevent fraud and abuse, monitor usage and costs, fix problems, and make backups.
- To comply with law and enforce our agreements.
We do not sell personal information, and we do not use it for advertising.
5. How we use AI
Retreev uses an AI service to read resumes, conversation notes and job descriptions, pull out details (such as skills, years of experience and clearance level), and write short explanations of why a candidate matches a job.
- Only the text needed for the task is sent to the AI service.
- Details the AI finds are shown to the recruiter to review and correct before they are saved. The AI is instructed to leave a field empty rather than guess.
- The AI service processes this information only to provide its service to Retreev and does not use it to train its models.
- Retreev does not use Customer Data to train AI models.
- Calendar data is never sent to the AI service.
- Matching results help recruiters decide whom to contact; Retreev does not make hiring decisions, and recruiters make every decision about candidates.
6. Google user data
If a user connects a Google account, Retreev asks Google for these permissions:
| Permission | Why Retreev needs it |
|---|---|
See your email address (openid, email) | To show which Google account is connected and to recognize it when you reconnect. |
See your list of calendars (calendar.calendarlist.readonly) | So you can choose which calendars appear in Retreev and which one receives the appointments you make. |
View and edit events on your calendars (calendar.events) | To show your events beside your Retreev appointments, and to create, update or cancel the interviews and calls you schedule in Retreev, including sending their invitations after you confirm the recipients. |
Retreev's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the calendar features users can see in Retreev.
- We do not transfer Google user data to others, except as needed to provide those features (to the hosting providers described in How we share information), to comply with law, or as part of a merger, acquisition or sale of assets with notice to users.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve or train generalized or non-personalized AI or machine-learning models, and we do not send it to AI services.
- No person at Retreev reads Google user data, unless the user asks us to for support, it is needed for security or to comply with law, or it has been made anonymous and aggregated.
A user's calendar events are visible only to that user in Retreev. When they link an event to an appointment they share with their team, the team sees that appointment, not the rest of their calendar.
7. Microsoft user data
If a user connects a Microsoft 365 or Outlook.com account, Retreev asks Microsoft for permission to read the user's basic profile and email address, and to read and write their calendars, and to keep that access until the user disconnects. We use and protect this data in the same way as Google user data: only to provide the calendar features described above, never for advertising, never sold, never sent to AI services, and never used to train AI models.
8. How we share information
We do not sell or rent personal information. We share it only as follows:
- Within a workspace. Workspace members see the workspace's records according to the access the workspace owner gives them. Calendar events are the exception: they are visible only to the user who connected the calendar.
- With service providers that run parts of the Service for us, under terms that limit their use of the information to providing their service to us:
- cloud hosting, database and file storage providers, which store Retreev's data and resume files;
- sign-in and email delivery providers, which let users sign in and send service emails such as invitations;
- an AI service provider, as described in How we use AI;
- payment processors, if a paid plan applies.
- With Google or Microsoft, only when a user connects their calendar: Retreev sends them the calendar changes the user makes in Retreev.
- At your direction, for example when you send an invitation or calendar event to someone.
- For legal reasons, when we believe in good faith that the law requires it, or to protect the rights, property or safety of our users, the public or Retreev.
- In a business transfer, such as a merger, acquisition or sale of assets, in which case the information stays subject to this policy's protections and we will notify affected customers.
Retreev staff who administer the Service use a separate administration area that does not give access to workspaces' candidates, resumes or notes. We access Customer Data only when a customer asks us to for support, or when needed for security or to comply with law.
9. Cookies and similar technologies
Retreev does not use advertising cookies, cross-site tracking or third-party analytics. The app uses your browser's storage to keep you signed in and to remember settings such as your last view. Our hosting provider may set strictly necessary cookies to protect the Services against attacks. You can clear this storage in your browser settings at any time; you will then need to sign in again.
Because we do not sell or share personal information for advertising, there is nothing to opt out of through "Do Not Track" or Global Privacy Control signals, and we treat such signals as a request not to do so.
10. How we protect information
- All connections to the Services are encrypted (HTTPS), and our providers encrypt stored data.
- Each workspace's records are separated from every other workspace's, and this separation is checked by the database on every request and by automated tests.
- Resume files are stored privately and served only to members of the workspace they belong to.
- Calendar access tokens are encrypted before they are stored and cannot be read by signed-in users.
- Retreev administrators must use two-step verification, and administrative actions are recorded in an audit history.
- Backups are encrypted.
No system is perfectly secure. If we learn of a security incident affecting your personal information, we will notify affected customers and users as required by law.
11. How long we keep information
- Customer Data is kept while the customer's workspace is active. Customers can archive and delete records, and can ask us to delete their workspace. After deletion, copies remain in encrypted backups until those backups expire (see below).
- Calendar data: only the window described above is kept, and it is refreshed regularly. When a user disconnects a calendar, Retreev deletes its access tokens and its copy of that calendar's events straight away, and asks Google to revoke Retreev's access. Appointments made in Retreev, and meetings already in the user's calendar, stay where they are.
- Backups are made nightly and kept for up to 14 days, with weekly backups kept for up to 8 weeks.
- Account information is kept while the account is active and deleted when the account is removed, except where we must keep records for legal, tax or security reasons.
- Technical logs are kept for a limited time by our hosting providers for security and troubleshooting.
12. Where information is stored
Retreev is operated from the United States, and information is stored and processed in the United States. Our hosting provider delivers the website through servers around the world. If you use Retreev from outside the United States, your information will be transferred to the United States, where privacy laws may differ from those where you live. Where the law requires it, we use appropriate safeguards for these transfers, such as standard contractual clauses.
13. Your choices and rights
- Your account: you can view and update your account details in Retreev, and ask us to delete your account.
- Calendar connections: you can disconnect a calendar at any time in Retreev under Settings, Calendar. You can also remove Retreev's access at myaccount.google.com/permissions (Google) or account.microsoft.com (Microsoft).
- Access, correction and deletion: depending on where you live, you may have the right to ask for a copy of your personal information, to correct it, to delete it, to receive it in a portable format, or to object to or restrict some uses. Email privacy@retreev.ai. We will respond within the time the law requires, and may need to verify your identity first.
- Candidates and client contacts: if your information was added by a Retreev customer, please contact that recruiter or agency. If you contact us instead, we will pass your request to the customer and help them respond.
We will not treat you differently for exercising your privacy rights.
14. Additional information for U.S. state residents
Privacy laws in some U.S. states, including California, Colorado, Connecticut, Virginia and others, give residents additional rights. This section applies to personal information Retreev handles for its own purposes; for Customer Data, we act as a service provider to our customers.
- Categories we collect: identifiers (such as name, email address and IP address); professional or employment-related information (such as work history, skills and compensation in resumes and notes); education information; internet activity (such as technical logs); and, within Customer Data, security clearance information. See Information we collect for details and Where information comes from for sources.
- Purposes: as described in How we use information.
- Disclosures: we disclose these categories only to the service providers and parties described in How we share information, for business purposes.
- No sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.
- Sensitive information: we use sensitive personal information only to provide the Services, and not to infer characteristics about anyone.
- Your rights: you may ask to know, access, correct or delete your personal information, and appeal our decision on a request by replying to it. You may use an authorized agent, who must show us your written permission. To make a request, email privacy@retreev.ai.
15. Additional information for people in the EEA, UK and Switzerland
Where European or UK data protection law applies to information Retreev handles for its own purposes, we rely on these legal bases: to perform our contract with you or your organization (providing the Services); our legitimate interests in running, securing and improving the Services; your consent, where we ask for it (for example, connecting a calendar), which you may withdraw at any time; and compliance with legal obligations. You have the rights described in Your choices and rights, and the right to complain to your local data protection authority.
16. Children
Retreev is a business tool and is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
17. Links to other websites
The Services may link to other websites, such as a candidate's online profile or a meeting link. Their own privacy policies apply, not this one.
18. Changes to this policy
We may update this policy from time to time. We will change the date at the top, and for significant changes we will notify customers by email or in the Service before the change takes effect.
19. Contact us
For questions, requests or complaints about privacy, email privacy@retreev.ai.
