Privacy Notice
Last updated: 2026-09-10
This notice explains how retru·vai uses the personal information you give us across two products:
- Stuart, our event companion app, which helps you meet the right people at an event you are attending.
- the prep tool, which helps you prepare for your own one-on-one meetings.
The sections under "At a retru·vai event: the Stuart app" cover the event app specifically. Some events also let you register in advance on this website; the section "Signing up for an event on our website" covers that. The other sections apply to both products unless they say otherwise. If your information was entered by someone else rather than by you, the notice that applies to you is here: notice to non-users.
We have tried to keep this short and plain. If anything is unclear, email hello@bemorestuart.com.
RETRUVAI Ltd (trading as retru·vai) is the company that runs this service. We are incorporated in England & Wales (company number 17076193, incorporated 7 March 2025) and based in the United Kingdom. We are the data controller for the personal information described below, which means we decide how and why it is used.
You can reach us at:
- Email: hello@bemorestuart.com
- Post: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
When you use the prep tool, we hold the following information about you:
- Account information: your email address, and a unique identifier created when you sign in.
- Your background: anything you choose to save in the "your background" section so it can be re-used across meetings.
- Meeting context: information you give us about each meeting you prepare for, including who you are meeting, why, and anything you paste in.
- Prep cards we generate for you: the output the tool produces for each meeting.
- Feedback you give us: thumbs up or down, free-text comments, any edits you make.
- Technical information: timestamps, model usage and cost, latency, the IP address you signed in from. We use this to keep the service running, prevent abuse, and improve quality.
We refuse inputs containing the most sensitive categories of special-category data (for example, named clinical conditions, treatment records, observant religious practice, sexuality with self-attribution, trade union or political-party membership, criminal records). Our system detects and rejects these before any AI model sees them. We do not generate inferences about anyone's health, religion, sexuality, ethnicity, trade union membership, or political views.
| What we do | Why | Legal basis (UK GDPR) |
|---|---|---|
| Sign you in and let you use the service | To deliver what you asked for | Article 6(1)(b), contract |
| Save your background and meeting history | Same | Article 6(1)(b), contract |
| Generate prep cards | Same | Article 6(1)(b), contract |
| Prevent abuse, rate-limit, log errors | To keep the service safe and reliable | Article 6(1)(f), legitimate interests |
| Use your feedback to improve the tool | To make the service better for you and others | Article 6(1)(f), legitimate interests |
| Send you product updates, if you opt in | Marketing | Article 6(1)(a), consent |
To improve the service, we may use your data, including your profile summary, your psychographic answers, your match outcomes, and your post-meeting feedback, to train and refine our own matching and machine-learning models, using pseudonymised or aggregated data where we can. You can object at any time by emailing hello@bemorestuart.com, with no effect on your use of the core service. Our third-party AI provider does not train its models on your inputs. We do not sell your data.
We use a small number of trusted vendors to run the service. They process information on our behalf, not their own. Our current list is at sub-processors. It includes:
- Supabase: database and authentication.
- Anthropic: the AI model that generates prep cards and event summaries.
- Vercel: hosting.
- Resend: the email that delivers your sign-in code (Stuart event app).
- Sentry: error reporting that helps us find and fix crashes.
- Expo, Apple, and Google: delivery of push notifications (Stuart event app).
We will update the list before adding any new vendor. We do not share your data for advertising. We do not share it with other users beyond what you make visible to a match.
We may share information if required by law or to defend our legal rights.
Event-app retention is in its own table under "At a retru·vai event: the Stuart app".
| What | How long |
|---|---|
| Account information | Until you delete your account |
| Your background | Until you delete your account or update it |
| Prep cards we generated for you (default) | 90 days, then automatically deleted |
| Prep cards you pin | Kept while you keep them pinned and continue to use them. If you don't open, edit, or regenerate a pinned card for 24 months, we auto-purge it. Unpin a card and it deletes on the same 90-day clock as everything else. |
| Post-meeting notes you add to a card | Kept with the card (same lifetime as the card) |
| Feedback | 12 months in identifiable form, then aggregated |
| Technical logs (our own application telemetry) | 30 days. Note: this is our own application's logs. Each sub-processor (Supabase, Anthropic, Vercel) keeps its own platform logs under its own retention policy; those are described in our Transfer Risk Assessment summary. |
You can delete anything sooner from inside the app, or by emailing hello@bemorestuart.com.
If someone asks us to remove their information from your cards. If the person you met asks us to delete their information, we will delete the entire card by default (including any cards you have pinned) within 72 hours of receiving their request. If they prefer, they may instead ask us to remove only their identifying content and leave your own notes about the meeting in scrubbed form. Most people who contact us will get the full delete; the scrubbed-notes alternative is offered only at their request. You will see the absence of the deleted card at next access.
Stuart is our event companion app. You join an event, tell Stuart a little about yourself, and it helps you find the people worth meeting in the room.
Who is the controller. RETRUVAI Ltd is the controller for the information you create inside the app (your profile, your matches, your reflections). For the original invite list an organiser gives us, the organiser is the controller and we act as their processor. For the matching activity itself, we and the organiser are joint controllers. You can exercise your rights against either of us, and we will route your request to the right place. Email hello@bemorestuart.com.
When you create your account
When you create an account we ask for your name, email address, a password, your mobile number and your date of birth.
- Your mobile number is for your sign-in code and for account recovery, and later for invites you choose to send, for finding people you already know, and for filling in your details when you share them. It is never shown to anyone.
- Your date of birth is how you tell us you are over 18, and it lets Stuart respect age preferences later. Nobody ever sees your date of birth or your age: they are only ever compared, never shown.
- We also ask how you'd like Stuart to write about you (gender, with self-describe and prefer-not-to-say as full choices). It is used for your matching preference, for organiser headcounts (always as anonymous totals), and so Stuart uses the right words. It never appears on any card.
Your recordings and answers
When you tell Stuart about yourself, out loud or in writing, we keep what you gave us so Stuart can re-read it and get your card right. It is deleted when you delete your account, along with every future use of it. Stuart may also learn from what you gave us to get better at writing and matching; you can switch this off any time in Settings ("Help improve Stuart"). One honest limit: what an already-trained model has learned cannot be unlearned, though nothing new is ever learned from you after you opt out or leave.
Until 11 August 2026, voice recordings were deleted as soon as your summary was confirmed; anything already deleted stays deleted.
What Stuart collects at an event
- Your profile: your first name, the short "what you're building", "what you can give", and "what you want to learn" answers you write during onboarding, and an optional profile photo.
- Event membership: the event you joined (using a short join code), and your check-in at the door (you scan a code at the door to mark you have arrived. We change this every few seconds to ensure that only people who are present are checked into the event).
- Proximity: short-range Bluetooth sightings of other attendees while you have Stuart open at the event (see below).
- Matches: the people Stuart suggests you meet, the inputs to the score, and the short explanation shown to you.
- Reflections and ratings: after a meeting, whether you met, a rating, and any one-line note you choose to add.
- Push token: a device token so we can send you match and event notifications.
- Contact details you choose to share: if you tap share on someone's page, the email or number you type and hand to that specific person.
- Messages: short messages you send to a connection through Stuart. They are encrypted at rest; we relay them, we do not read them.
- Optional social-link context you paste in to enrich your matches.
- Your interests: the interests you pick appear on your card AND help Stuart choose who to suggest and when a nudge is worth it.
- What you ask for help with: if you ask Stuart for help ("Need help? Ask"), the one line you type about what you need. Stuart matches it against the people you have met and shows only you the result; it is encrypted at rest and deleted within 48 hours.
Why we use it, and the legal basis
| What we do | Legal basis (UK GDPR) |
|---|---|
| Run your account and event membership, check you in at the door | Article 6(1)(b), contract |
| Detect nearby attendees over Bluetooth | Article 6(1)(a), explicit consent |
| Keep sensing over Bluetooth while your screen is off at an event, if that switch is on | Article 6(1)(a), consent, withdrawable at any time in Settings |
| Suggest matches and show you as a possible match to others | Article 6(1)(f), legitimate interests, with your in-app setting defining the scope |
| Show the people you have met your current "what you're building" and "what you can give" lines | Article 6(1)(f), legitimate interests, with an Article 21 right to object; blocking stops it immediately |
| Prompt you for reflections, share pasted social links to a match | Article 6(1)(a), consent |
| Show your name, participation, engagement, and connections to the event organiser, unless you switch organiser visibility off | Article 6(1)(f), legitimate interests, with an Article 21 right to object (for some events the organiser runs as controller, such as a company offsite, a different basis applies and we tell you) |
| Improve matching for future attendees using meeting outcomes | Article 6(1)(f), legitimate interests, with an Article 21 right to object, on pseudonymised or aggregated data |
| Create your account: your name, email, password, mobile number and date of birth | Article 6(1)(b), contract |
| Learn from the recordings and answers you gave us, to write and match better | Article 6(1)(f), legitimate interests, switchable off any time in Settings ("Help improve Stuart") |
| Include what you do in Stuart in published research, only if you tick the box | Article 6(1)(a), consent, never pre-ticked |
| Take a single location reading, kept as a rough area only, when you tap "I'm free", and once more if you accept an introduction | Article 6(1)(a), consent |
| Search the people you have met, when you ask Stuart for help with something | Article 6(1)(a), consent, given each time you send an ask |
| Keep the event safe, prevent abuse, support safeguarding | Article 6(1)(f), legitimate interests |
Separately, and only if you tick the box, what you do in Stuart may appear in published research, always as measurements and patterns, never your name or words. This is entirely optional and never pre-ticked.
We do not rely on contract for the matching or event features beyond your core account. We do not use special-category data to match you. We do not sell your data. Our third-party AI provider does not train its models on your inputs; separately, we may use your own data to train and refine our own matching models, and you can object at any time (see "Your rights").
Bluetooth proximity
While you are at an event, your phone broadcasts and scans a short-range Bluetooth signal so nearby attendees can be suggested to you.
- If "Keep sensing when my screen is off" is on, sensing carries on from the moment you join until the event ends or you leave, including with the screen off. Off, it runs only while Stuart is open on your screen. Either way Stuart does not process any Bluetooth signal from outside the app.
- What we store is a room-scale "sighting": a rotating, hashed beacon identifier, a signal strength, and a timestamp. It is not a position on a map and we cannot reconstruct where you walked.
- Raw sightings are deleted within 7 days, and immediately if you switch proximity off.
- From 11 August 2026, sensing with the screen off is on by default for new accounts, because Stuart is built to work from your pocket. Leaving the event stops it. You can turn proximity off at any time in Privacy. If you already had an account, nothing changes until we ask you once; your existing answer stands until you answer, and a no always stands.
- While you are sensing at an event, with the screen on or off, Stuart also helps nearby attendees' phones find each other.
- You can turn proximity off at any time in the app, and you can object under Article 21.
After an event, Stuart may turn sensed co-presence into a private morning-after question for each person: add them to your people, or not. When Stuart is confident two people talked, each sees the other's first name. Declines and silence are never shown to the other person. These encounter records expire 48 hours after the conversation; any private note you add is deleted the moment it can no longer lead to a connection.
Location
Stuart does not track your location. The one exception, from 11 August 2026, with the I'm-free feature: when you tap "I'm free", the app takes a single location reading, and once more if you accept an introduction, so introductions only happen when you're near each other. Your phone lets you choose whether that reading is precise or approximate; either way, what Stuart keeps is only the rough area (a neighbourhood, never an address). A precise reading, if you allow one, is used to place you in that rough area and is discarded immediately. The rough area is deleted when your free window ends, nothing is ever read in the background, and no location history exists.
While you both choose to, Stuart shows each of you where the other is on the way to a meeting, on that page only, and keeps nothing after.
From 6 October 2026, while your free window is open, only the people you have met and then chosen in the Free tab of Your people can see that you are free and until when, and nothing about where. Nobody is chosen until you choose them. You can switch it all off under Privacy, and then nobody sees it either way. (From 4 to 6 October 2026 this was everyone you had both said you met.)
If Stuart suggests a place for two people to meet, it picks a public venue between your two rough areas and shows each of you an estimated walk time. The estimate is worked out from the rough areas, not from your exact positions, so it tells the other person roughly how far away you are and nothing more. The plan itself (the venue and the walk times) is stored encrypted with the introduction it belongs to, not with your location: it stays as long as that introduction or its message thread does, and it is deleted with your account or on request.
Asking for help, wider
From 5 October 2026, when you ask Stuart for help and nobody you know fits, you can ask once a week whether anyone your people know might. Stuart then looks, on your behalf, at the people of your friends who allow it, and answers only with the friend's name ("Lena knows someone who does design"), never the other person's. The only way to reach that person is for your friend to introduce you, which they may decline. What Stuart matches on is limited to the short words your friend kept about the person in Stuart's own vocabulary, never your friend's notes. You can switch this off under Privacy, and then your people are never used to answer a friend's ask, and a friend's ask is never answered with you.
Finding people you know
Coming later: an optional "find people you already know" feature. If you use it, your contact book is matched by scrambled codes that are deleted the moment matching finishes; contacts who aren't members are never stored and never profiled, and any invites are sent by you, never by us.
Introducing two people you know
Stuart may suggest that two people you have met would be worth introducing, and you can also decide that yourself. Either way Stuart writes each of them a note and shows it to you first. Nothing is sent until you have read it and pressed send. A no is never shown to either of them: each hears anything only when both say yes.
How matching works
Stuart suggests people you might have a good five minutes with, based mainly on your compatibility-quiz answers and on who is physically near you at the event. The other things you tell Stuart, such as your onboarding answers and any context you add, help it explain why a match could work.
A suggestion is a suggestion, not a decision. Stuart never messages anyone or books anything on your behalf, and never introduces you to a stranger without you choosing it. You choose whether to act on a match, dismiss it, or block. Because nothing happens until you act, Stuart is not making an automated decision about you. Each match card shows a "why this could land" panel explaining the main reasons, and you can give feedback or ask a person to review a suggestion by emailing hello@bemorestuart.com.
What the organiser can see
How much the organiser sees is set per event, and you control your own part of it.
- For every event: the organiser sees aggregate counts, for example how many people onboarded, arrived, and engaged, and how meetings and matches went across the event as a whole. These are group totals, not individual records.
- Unless you switch it off: the organiser also sees that you took part, your name, your engagement (such as that you arrived and how many meetings you had), and, at events set up for it, who you connected with. Your "organiser visibility" setting is on by default, and you can switch it off at any time in the app. You have an absolute right to object (see "Your rights"). How much an organiser can see is set per event, from counts only up to the connection graph (who met whom). The default is counts only, and you can switch your own visibility off. The organiser never sees your reflections or your rating of any specific person unless you have been notified and given permission.
- An organiser may also see anonymised, aggregated rating summaries for the event, only once enough people have rated, and never who you rated or what you wrote.
Ratings and reflections
After a meeting we may ask "how did it go?". The free text you write in a reflection, and the name or label you give the other person, are encrypted at rest in our database. This protects them on our servers. It is not end-to-end encryption: our event functions can decrypt them to operate the service and to action your requests.
We use the outcomes (your rating, whether you met) to improve matching for future attendees, on the basis of our legitimate interest, and you can object at any time (see "Your rights"). We minimise this to pseudonymised or aggregated data where we can, stripping out names and direct identifiers.
What the people you have met can see
The two short lines you write about what you're building and what you can give are shown to people you have actually met and kept, on your card in their app. Stuart writes them to describe your work, and never puts your name or your employer in them. You can also write them yourself, and then what you write is what people read. The app says who sees them before you type.
They are live: if you change them, the people who kept you see the new version rather than the one they met. Your summary and interests already work this way. The same controls apply as everywhere else: block someone and they stop seeing you, and deleting your account removes the lines along with the rest.
Profile photo
A profile photo is part of taking part: it is how someone knows they have found the right person. Before you both say yes to meeting, a suggestion shows your first name and photo, nothing else. We do not display your photo to the room, to the organiser, or in any notification.
Push notifications
We send proximity and match suggestions, a reflection prompt after a meeting, and occasional organiser or service messages. Lock-screen notifications never name another person; names appear only once you open Stuart. They never include your location, your surname, or any reflection content.
Deleting your account
You can delete your Stuart account at any time from inside the app. We hard-delete your profile, your photo and uploads, your proximity sightings, your co-presence and match records, your meetings and reflections, your social links, and your attendance, and we purge the associated files from storage. One exception, because a business card given is given: contact details you deliberately shared with a specific person on or after 21 July 2026 stay with that person, together with the name on your profile, much like a paper business card. Blocking someone before you delete prevents this for that person, and you can ask us at hello@bemorestuart.com to remove your details from anyone's records at any time, before or after you delete. We acknowledge in writing within 7 days. Copies in our backups roll off within about a further 7 days. We keep a minimal delivery and audit log, and any safeguarding record, only where the law requires it, as described below.
If someone names a person who is not at the event
An attendee may mention a person who is not attending in a reflection or an answer. If that person is you, the notice that applies is our notice to non-users. You can ask us to remove that information at any time.
How long we keep your event information
We do not keep your event information longer than the periods below, and you can ask us to delete anything sooner from inside the app or by email.
| What | How long |
|---|---|
| Account and profile (name, onboarding answers, photo) | Until you delete your account |
| Account details (mobile number, date of birth, how Stuart writes about you) | Until you delete your account |
| Recordings and uploads you gave Stuart about yourself | Until you delete your account |
| What you type when you ask Stuart for help | Deleted within 48 hours. Stuart reads it once to search the people you have met, shows you the result, and keeps no copy of the result |
| Rough-area reading taken when you tap "I'm free" | Deleted when your free window ends |
| Meeting plan (suggested venue and walk times) | Kept, encrypted, as long as the introduction or message thread it belongs to; deleted with your account, or on request |
| Introductions offered or made (including the short cards in them) | Kept encrypted; deleted with your account, or on request |
| Bluetooth proximity sightings | 7 days, or immediately if you switch proximity off |
| Co-presence pairs, match candidates, social links | The event's retention window: 30 days by default, set by the organiser, measured from the event end |
| Suggestions Stuart considered but did not make | One month. When Stuart weighs up whether to suggest someone, it keeps a note of the pair, the day and the reason, including people it nearly suggested and did not. This is how we tell a Stuart that is being usefully selective from one that is too quiet |
| Detected encounters (the morning-after question about who you met) | 48 hours to answer; unanswered or declined records are deleted once that window passes, and any private note is deleted the moment it can no longer lead to a connection. Records for pairs who both said yes follow the co-presence row above |
| Morning-after summary push log | 90 days |
| People you met (your reflections, ratings, and their card in "Your people") | 30 days from the event end by default. If your reflection says you want to see them again, 12 months from your latest reflection about them. If you tap Keep in rolodex on their page, until you release them. Stuart tells you in the app, seven days ahead, before anyone you have reflected on is removed from your list. |
| Contact details someone deliberately shared with you | Yours to keep, like a business card, for as long as you keep the person (the row above) |
| Door check-in / attendance record | The event window plus 7 days |
| Reflections you pin and keep using | While you keep using them; auto-purged after 24 months of no activity |
| Push delivery log | 90 days |
| Safeguarding signals | 12 months, tightened to 30 days for any sensitive free-text leakage; longer only while an investigation is open |
| Event audit log (consent changes, deletions, organiser actions) | 24 months |
| Backups | Up to 7 days beyond live deletion |
The organiser can shorten or lengthen the default window within the range our systems enforce (7 days to 12 months); changes apply going forward only. They cannot extend proximity, check-in, or safeguarding retention beyond the limits above.
Staying safe at an event
Stuart is for adults: you must be 18 or over to use it. Inside the app you can quietly add someone to an avoid-list so neither of you is suggested to the other, block someone, or report a concern to a named safeguarding lead through a secure in-app channel.
Some of our events open a page on this website where you can register in advance (for example, the Enterprise Lab event at bemorestuart.com/elab). This is separate from the Stuart app: it is a short form you fill in on the website. RETRUVAI Ltd is the controller for what you submit.
What we collect
- Your details: first and last name, mobile number, and your Imperial email address. The mobile number is the key we use to tie your registration to your Stuart account, so we can pre-fill it if you ask.
- Your programme or role at Imperial.
- A few short answers: three quick multiple-choice questions and four short open-text boxes about what you are working on, what you can help with, what you are looking for, and a little about you. With your consent, we use these to suggest who you might click with and to pre-fill your Stuart profile. They are not published on your profile.
- Dietary requirements or access needs, only if you choose to tell us (see below).
- Anyone you tell us is also coming, if you choose to name them (see below).
- A registration number and timestamp we create, and whether you have agreed to hear from us.
Why, and the legal basis
- Register you and manage your place at the event: Article 6(1)(f), legitimate interests (running an event you asked to attend).
- Use your answers to suggest who to meet and pre-fill your Stuart profile: Article 6(1)(a), consent, which you give by ticking the box and can withdraw at any time.
- Email you about your place, and about Stuart if you agree: Article 6(1)(f) for the event details you need, and Article 6(1)(a), consent, for anything further.
Dietary requirements and access needs
If you tell us about a dietary requirement or an access need, that can reveal something about your health or beliefs, so it is special-category data. This event form is the one place we ask for it, and we collect it only because you choose to give it, on the basis of your explicit consent (Article 9(2)(a)). We use it for one purpose only: to run this event safely and well, meaning catering, the layout of the room, and emergency procedures. We do not use it for matching and we do not profile you with it, and only the small team running the event can see it. Email hello@bemorestuart.com if you would like us to delete it after the event.
If you name someone else who is coming
If you name someone else who is attending, you are giving us information about another person. We use it only to help make good introductions at the event. The notice that applies to the person you named is our notice to non-users, and they can ask us to remove it at any time.
How long we keep event-registration information
We keep your event-registration information for as long as we need it to run the event and for a reasonable period afterwards, for example to follow up, to understand how the event went, and to tell you about future events if you have agreed to hear from us. We do not keep it for longer than we need. You can ask us to delete it at any time by emailing hello@bemorestuart.com, and we will delete your dietary and access information after the event if you ask. If you also create a Stuart account, the information inside the app follows the app's own retention described above.
Under UK data protection law, you can:
- Ask for a copy of what we hold about you (subject access).
- Ask us to correct anything that is wrong.
- Ask us to delete your data.
- Ask us to restrict how we use it.
- Object to use based on legitimate interests.
- Withdraw consent at any time if we relied on it.
- Complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy.
Most of these you can do from the app. For anything else, email hello@bemorestuart.com and we will respond within one month.
Some of our vendors are based outside the UK (mostly in the USA, including our AI provider Anthropic, our hosting provider Vercel, our email provider Resend, and our error-reporting provider Sentry). When your data moves outside the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We have completed a Transfer Risk Assessment using the ICO's TRA tool, looking at US surveillance law (FISA 702) and the supplementary measures our vendors have in place. The short version: data is encrypted in transit and at rest, retention is short, our AI vendor does not train on your inputs, and your reflection content is encrypted in our database. A summary of the assessment is available on request.
We use essential cookies to keep you signed in. We do not use advertising or tracking cookies. If we ever add non-essential cookies, we will ask first.
If we change anything substantive, we will tell you in the app and by email. You can see the version history at the privacy history page (on request).
- For privacy questions: hello@bemorestuart.com
- For everything else: hello@bemorestuart.com
- The Information Commissioner's Office: ico.org.uk or 0303 123 1113