Privacy Notice
Last updated: 2026-06-22
This notice explains how retru·vai uses the personal information you give us across two products:
- Stuart, our event companion app, which helps you meet the right people at an event you are attending.
- the prep tool, which helps you prepare for your own one-on-one meetings.
The sections under "At a retru·vai event: the Stuart app" cover the event app specifically. The other sections apply to both products unless they say otherwise. If your information was entered by someone else rather than by you, the notice that applies to you is here: notice to non-users.
We have tried to keep this short and plain. If anything is unclear, email hello@bemorestuart.com.
RETRUVAI Ltd (trading as retru·vai) is the company that runs this service. We are incorporated in England & Wales (company number 17076193, incorporated 7 March 2025) and based in the United Kingdom. We are the data controller for the personal information described below, which means we decide how and why it is used.
You can reach us at:
- Email: hello@bemorestuart.com
- Post: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
When you use the prep tool, we hold the following information about you:
- Account information: your email address, and a unique identifier created when you sign in.
- Your background: anything you choose to save in the "your background" section so it can be re-used across meetings.
- Meeting context: information you give us about each meeting you prepare for, including who you are meeting, why, and anything you paste in.
- Prep cards we generate for you: the output the tool produces for each meeting.
- Feedback you give us: thumbs up or down, free-text comments, any edits you make.
- Technical information: timestamps, model usage and cost, latency, the IP address you signed in from. We use this to keep the service running, prevent abuse, and improve quality.
We refuse inputs containing the most sensitive categories of special-category data (for example, named clinical conditions, treatment records, observant religious practice, sexuality with self-attribution, trade union or political-party membership, criminal records). Our system detects and rejects these before any AI model sees them. We do not generate inferences about anyone's health, religion, sexuality, ethnicity, trade union membership, or political views.
| What we do | Why | Legal basis (UK GDPR) |
|---|---|---|
| Sign you in and let you use the service | To deliver what you asked for | Article 6(1)(b), contract |
| Save your background and meeting history | Same | Article 6(1)(b), contract |
| Generate prep cards | Same | Article 6(1)(b), contract |
| Prevent abuse, rate-limit, log errors | To keep the service safe and reliable | Article 6(1)(f), legitimate interests |
| Use your feedback to improve the tool | To make the service better for you and others | Article 6(1)(f), legitimate interests |
| Send you product updates, if you opt in | Marketing | Article 6(1)(a), consent |
To improve the service, we may use your data, including your profile summary, your psychographic answers, your match outcomes, and your post-meeting feedback, to train and refine our own matching and machine-learning models, using pseudonymised or aggregated data where we can. You can object at any time by emailing hello@bemorestuart.com, with no effect on your use of the core service. Our third-party AI provider does not train its models on your inputs. We do not sell your data.
We use a small number of trusted vendors to run the service. They process information on our behalf, not their own. Our current list is at sub-processors. It includes:
- Supabase: database and authentication.
- Anthropic: the AI model that generates prep cards and event summaries.
- Vercel: hosting.
- Resend: the email that delivers your sign-in code (Stuart event app).
- Sentry: error reporting that helps us find and fix crashes.
- Expo, Apple, and Google: delivery of push notifications (Stuart event app).
We will update the list before adding any new vendor. We do not share your data for advertising. We do not share it with other users beyond what you make visible to a match.
We may share information if required by law or to defend our legal rights.
Event-app retention is in its own table under "At a retru·vai event: the Stuart app".
| What | How long |
|---|---|
| Account information | Until you delete your account |
| Your background | Until you delete your account or update it |
| Prep cards we generated for you (default) | 90 days, then automatically deleted |
| Prep cards you pin | Kept while you keep them pinned and continue to use them. If you don't open, edit, or regenerate a pinned card for 24 months, we auto-purge it. Unpin a card and it deletes on the same 90-day clock as everything else. |
| Post-meeting notes you add to a card | Kept with the card (same lifetime as the card) |
| Feedback | 12 months in identifiable form, then aggregated |
| Technical logs (our own application telemetry) | 30 days. Note: this is our own application's logs. Each sub-processor (Supabase, Anthropic, Vercel) keeps its own platform logs under its own retention policy; those are described in our Transfer Risk Assessment summary. |
You can delete anything sooner from inside the app, or by emailing hello@bemorestuart.com.
If someone asks us to remove their information from your cards. If the person you met asks us to delete their information, we will delete the entire card by default (including any cards you have pinned) within 72 hours of receiving their request. If they prefer, they may instead ask us to remove only their identifying content and leave your own notes about the meeting in scrubbed form. Most people who contact us will get the full delete; the scrubbed-notes alternative is offered only at their request. You will see the absence of the deleted card at next access.
Stuart is our event companion app. You join an event, tell Stuart a little about yourself, and it helps you find the people worth meeting in the room.
Who is the controller. RETRUVAI Ltd is the controller for the information you create inside the app (your profile, your matches, your reflections). For the original invite list an organiser gives us, the organiser is the controller and we act as their processor. For the matching activity itself, we and the organiser are joint controllers. You can exercise your rights against either of us, and we will route your request to the right place. Email hello@bemorestuart.com.
What Stuart collects at an event
- Your profile: your first name, the short "what you're building", "what you can give", and "what you want to learn" answers you write during onboarding, and an optional profile photo.
- Event membership: the event you joined (using a short join code), and your check-in at the door (you scan a code at the door to mark you have arrived. We change this every few seconds to ensure that only people who are present are checked into the event).
- Proximity: short-range Bluetooth sightings of other attendees while you have Stuart open at the event (see below).
- Matches: the people Stuart suggests you meet, the inputs to the score, and the short explanation shown to you.
- Reflections and ratings: after a meeting, whether you met, a rating, and any one-line note you choose to add.
- Push token: a device token so we can send you match and event notifications.
- Contact details you choose to share: if you tap share on someone's page, the email or number you type and hand to that specific person.
- Messages: short messages you send to a connection through Stuart. They are encrypted at rest; we relay them, we do not read them.
- Optional social-link context you paste in to enrich your matches.
Why we use it, and the legal basis
| What we do | Legal basis (UK GDPR) |
|---|---|
| Run your account and event membership, check you in at the door | Article 6(1)(b), contract |
| Detect nearby attendees over Bluetooth | Article 6(1)(a), explicit consent |
| Keep sensing over Bluetooth while your screen is off at an event, if you switched that on and started sensing there | Article 6(1)(a), consent, withdrawable at any time in Settings |
| Suggest matches and show you as a possible match to others | Article 6(1)(f), legitimate interests, with your in-app setting defining the scope |
| Prompt you for reflections, share pasted social links to a match | Article 6(1)(a), consent |
| Show your name, participation, engagement, and connections to the event organiser, unless you switch organiser visibility off | Article 6(1)(f), legitimate interests, with an Article 21 right to object (for some events the organiser runs as controller, such as a company offsite, a different basis applies and we tell you) |
| Improve matching for future attendees using meeting outcomes | Article 6(1)(f), legitimate interests, with an Article 21 right to object, on pseudonymised or aggregated data |
| Keep the event safe, prevent abuse, support safeguarding | Article 6(1)(f), legitimate interests |
We do not rely on contract for the matching or event features beyond your core account. We do not use special-category data to match you. We do not sell your data. Our third-party AI provider does not train its models on your inputs; separately, we may use your own data to train and refine our own matching models, and you can object at any time (see "Your rights").
Bluetooth proximity
While you have Stuart open at the event, your phone broadcasts and scans a short-range Bluetooth signal so we can tell which other attendees are in the same room as you, and surface people who are co-present.
- By default this happens only while Stuart is open on your screen. If you have turned on "keep sensing when my screen is off" and you start sensing at an event, Stuart can keep sensing with the screen off or the phone in your pocket, but only from just before the event starts until just after it ends, and you can stop it at any moment (on Android, a permanent notification shows sensing is on and carries a stop button). Either way Stuart does not use GPS or your device location, does not process any Bluetooth signal from outside the app, and does not build a location history or a movement trail.
- What we store is a room-scale "sighting": a rotating, hashed beacon identifier, a signal strength, and a timestamp. It is not a position on a map and we cannot reconstruct where you walked.
- Raw sightings are deleted within 7 days, and immediately if you switch proximity off.
- Sensing with the screen off is off unless you switch it on, and the switch is never pre-ticked. You choose it when you create your account (or the first time you open the app after this feature arrives), and you can change it any time in Settings.
- You can turn proximity off at any time in the app, and you can object under Article 21.
After an event, Stuart may turn sensed co-presence into a private morning-after question for each person: keep in touch, or not. When Stuart is confident two people talked, each sees the other's first name. Declines and silence are never shown to the other person. These encounter records expire 48 hours after the conversation; any private note you add is deleted the moment it can no longer lead to a connection.
How matching works
Stuart suggests people you might have a good five minutes with, based mainly on your compatibility-quiz answers and on who is physically near you at the event. The other things you tell Stuart, such as your onboarding answers and any context you add, help it explain why a match could work.
A suggestion is a suggestion, not a decision. Stuart never introduces you, messages anyone, or books anything on your behalf. You choose whether to act on a match, dismiss it, or block. Because nothing happens until you act, Stuart is not making an automated decision about you. Each match card shows a "why this could land" panel explaining the main reasons, and you can give feedback or ask a person to review a suggestion by emailing hello@bemorestuart.com.
What the organiser can see
How much the organiser sees is set per event, and you control your own part of it.
- For every event: the organiser sees aggregate counts, for example how many people onboarded, arrived, and engaged, and how meetings and matches went across the event as a whole. These are group totals, not individual records.
- Unless you switch it off: the organiser also sees that you took part, your name, your engagement (such as that you arrived and how many meetings you had), and, at events set up for it, who you connected with. Your "organiser visibility" setting is on by default, and you can switch it off at any time in the app. You have an absolute right to object (see "Your rights"). How much an organiser can see is set per event, from counts only up to the connection graph (who met whom). The default is counts only, and you can switch your own visibility off. The organiser never sees your reflections or your rating of any specific person unless you have been notified and given permission.
- An organiser may also see anonymised, aggregated rating summaries for the event, only once enough people have rated, and never who you rated or what you wrote.
Ratings and reflections
After a meeting we may ask "how did it go?". The free text you write in a reflection, and the name or label you give the other person, are encrypted at rest in our database. This protects them on our servers. It is not end-to-end encryption: our event functions can decrypt them to operate the service and to action your requests.
We use the outcomes (your rating, whether you met) to improve matching for future attendees, on the basis of our legitimate interest, and you can object at any time (see "Your rights"). We minimise this to pseudonymised or aggregated data where we can, stripping out names and direct identifiers.
Profile photo
Your profile photo is shown only to someone you have mutually matched with, and only briefly so you can recognise each other in the room. We do not display your photo to the room, to the organiser, or in any notification.
Push notifications
We send proximity and match suggestions, a reflection prompt after a meeting, and occasional organiser or service messages. Notifications carry only first names and a short framing line. They never include your location, your surname, or any reflection content.
Deleting your account
You can delete your Stuart account at any time from inside the app. We hard-delete your profile, your photo and uploads, your proximity sightings, your co-presence and match records, your meetings and reflections, your social links, and your attendance, and we purge the associated files from storage. One exception, because a business card given is given: contact details you deliberately shared with a specific person on or after 21 July 2026 stay with that person, together with the name on your profile, much like a paper business card. Blocking someone before you delete prevents this for that person, and you can ask us at hello@bemorestuart.com to remove your details from anyone's records at any time, before or after you delete. We acknowledge in writing within 7 days. Copies in our backups roll off within about a further 7 days. We keep a minimal delivery and audit log, and any safeguarding record, only where the law requires it, as described below.
If someone names a person who is not at the event
An attendee may mention a person who is not attending in a reflection or an answer. If that person is you, the notice that applies is our notice to non-users. You can ask us to remove that information at any time.
How long we keep your event information
We do not keep your event information longer than the periods below, and you can ask us to delete anything sooner from inside the app or by email.
| What | How long |
|---|---|
| Account and profile (name, onboarding answers, photo) | Until you delete your account |
| Bluetooth proximity sightings | 7 days, or immediately if you switch proximity off |
| Co-presence pairs, match candidates, social links | The event's retention window: 30 days by default, set by the organiser, measured from the event end |
| Detected encounters (the morning-after keep-in-touch question) | 48 hours to answer; unanswered or declined records are deleted once that window passes, and any private note is deleted the moment it can no longer lead to a connection. Records for pairs who both said yes follow the co-presence row above |
| Morning-after summary push log | 90 days |
| People you met (your reflections, ratings, and their card in "Your people") | 30 days from the event end by default. If you mark someone "keep in touch", 12 months from your latest reflection about them. If you tap Keep on their page, until you release them. Stuart tells you in the app, seven days ahead, before anyone you have reflected on is removed from your list. |
| Contact details someone deliberately shared with you | Yours to keep, like a business card, for as long as you keep the person (the row above) |
| Door check-in / attendance record | The event window plus 7 days |
| Reflections you pin and keep using | While you keep using them; auto-purged after 24 months of no activity |
| Push delivery log | 90 days |
| Safeguarding signals | 12 months, tightened to 30 days for any sensitive free-text leakage; longer only while an investigation is open |
| Event audit log (consent changes, deletions, organiser actions) | 24 months |
| Backups | Up to 7 days beyond live deletion |
The organiser can shorten or lengthen the default window within the range our systems enforce (7 days to 12 months); changes apply going forward only. They cannot extend proximity, check-in, or safeguarding retention beyond the limits above.
Staying safe at an event
Stuart is for adults: you must be 18 or over to use it. Inside the app you can quietly add someone to an avoid-list so neither of you is suggested to the other, block someone, or report a concern to a named safeguarding lead through a secure in-app channel.
Under UK data protection law, you can:
- Ask for a copy of what we hold about you (subject access).
- Ask us to correct anything that is wrong.
- Ask us to delete your data.
- Ask us to restrict how we use it.
- Object to use based on legitimate interests.
- Withdraw consent at any time if we relied on it.
- Complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy.
Most of these you can do from the app. For anything else, email hello@bemorestuart.com and we will respond within one month.
Some of our vendors are based outside the UK (mostly in the USA, including our AI provider Anthropic, our hosting provider Vercel, our email provider Resend, and our error-reporting provider Sentry). When your data moves outside the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We have completed a Transfer Risk Assessment using the ICO's TRA tool, looking at US surveillance law (FISA 702) and the supplementary measures our vendors have in place. The short version: data is encrypted in transit and at rest, retention is short, our AI vendor does not train on your inputs, and your reflection content is encrypted in our database. A summary of the assessment is available on request.
We use essential cookies to keep you signed in. We do not use advertising or tracking cookies. If we ever add non-essential cookies, we will ask first.
If we change anything substantive, we will tell you in the app and by email. You can see the version history at the privacy history page (on request).
- For privacy questions: hello@bemorestuart.com
- For everything else: hello@bemorestuart.com
- The Information Commissioner's Office: ico.org.uk or 0303 123 1113