Cookie Policy
Retrievy — Unified Security Posture Management Platform
Effective Date: May 23, 2026 Last Updated: May 23, 2026 Version: 1.1
This Cookie Policy explains how Retrievy ("Company," "we," "us," or "our") uses cookies and similar tracking technologies on our websites (retrievy.com and your_tenant.retrievy.com) and within our platform (collectively, the "Service"). This Cookie Policy is incorporated by reference into our Privacy Policy and Terms of Service.
You have the right to control how we use cookies. You can manage your preferences at any time through our Cookie Consent banner or through your browser settings.
Table of Contents
- What Are Cookies?
- Why We Use Cookies
- Types of Cookies We Use
- Specific Cookies on the Retrievy Platform
- Third-Party Cookies and Tracking
- Your Cookie Choices
- Managing Cookies in Your Browser
- Do Not Track Signals
- Cookies and Sensitive Security Data
- Changes to This Cookie Policy
- Contact Us
1. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile phone) by websites you visit. They are widely used to make websites work correctly, more efficiently, and to provide information to the operators of the site.
Beyond cookies, we may also use related technologies such as:
- Web Beacons (Pixels): Tiny invisible image files embedded in web pages or emails that signal when content has been loaded or an action has been taken;
- Local Storage: A browser-side storage mechanism used to persist user preferences (e.g., dashboard theme, sidebar state) across sessions;
- Session Storage: Similar to Local Storage, but data is cleared when the browser tab is closed;
- Device Fingerprinting: In certain security contexts (e.g., detecting suspicious login attempts), we may collect a combination of browser and device attributes to identify patterns. This data is used exclusively for fraud prevention and security, and is never used for advertising.
Throughout this Cookie Policy, we refer to all of these technologies collectively as "cookies."
2. Why We Use Cookies
We use cookies for the following primary reasons:
- To make the Service work: Certain cookies are strictly necessary for authentication, session management, and core platform functionality. Without them, the Service cannot operate correctly.
- To remember your preferences: We use cookies to remember your settings (e.g., language, theme, notification preferences) so you don't have to re-configure them on every visit.
- To understand how you use the Service: Analytics cookies help us understand which features are used most, where users encounter difficulties, and how we can improve the platform.
- To protect your account: Security cookies help us detect and prevent fraudulent logins, session hijacking, and other security threats.
- To communicate with you: Where you have given consent, we may use cookies to determine whether you have read our announcements or completed onboarding steps.
3. Types of Cookies We Use
We classify cookies by their duration and their purpose:
3.1 By Duration
| Type | Description |
|---|---|
| Session Cookies | Temporary cookies that expire when you close your browser or log out. Used primarily for authentication and security. |
| Persistent Cookies | Cookies that remain on your device for a set period (from minutes to years). Used for preferences and analytics. |
3.2 By Purpose
We use the IAB Europe Transparency and Consent Framework categories to classify our cookies:
🔒 Category 1 — Strictly Necessary Cookies
These cookies are essential for the Service to function and cannot be disabled. They do not require your consent under applicable law (ePrivacy Directive, GDPR). Without these cookies, core features such as login, authentication, and navigation will not work.
Basis for use: Legitimate interest / Essential for service delivery.
⚙️ Category 2 — Functional / Preference Cookies
These cookies remember your choices and personalize your experience on the platform. Examples include your preferred dashboard view, sidebar collapse state, selected cloud provider filters, and notification settings.
Basis for use: Consent (or legitimate interest where strictly functional).
📊 Category 3 — Analytics and Performance Cookies
Retrievy uses Plausible Analytics, a privacy-first, open-source analytics platform that we self-host on our own infrastructure. Plausible does not use cookies, does not track individual users across sessions or devices, does not collect personal data, and is fully compliant with GDPR, CCPA, and PECR without requiring consent banners for analytics purposes.
All analytics data is aggregated and anonymized by design. We cannot identify you from the data Plausible collects, and your data never leaves our own servers.
Basis for use: Legitimate interest (no cookies set; no personal data collected).
🎯 Category 4 — Marketing / Targeting Cookies
If applicable, these cookies may be used on our public marketing website (retrievy.com) to understand the effectiveness of our campaigns and attribute conversions. We do not use behavioral advertising cookies within the authenticated platform (your_tenant.retrievy.com).
Basis for use: Consent.
4. Specific Cookies on the Retrievy Platform
The following table lists the primary cookies we set, organized by category:
4.1 Strictly Necessary Cookies
| Cookie Name | Provider | Duration | Purpose |
|---|---|---|---|
retrievy-session |
Retrievy | Session (2 hours) | Core session identifier. Maintains your authenticated session. Contains an encrypted session token. |
XSRF-TOKEN |
Retrievy | Session | Cross-Site Request Forgery (CSRF) token. Required to authenticate form submissions and protect against CSRF attacks. |
remember_web_* |
Retrievy | 5 years | "Remember me" persistent login token. Stored as a cryptographically hashed value. Only set if you check "Remember me" at login. |
Consent record (
cookie_consent): Your cookie consent decision is stored in your browser's localStorage (not a cookie). It persists across sessions without being transmitted with every HTTP request. It is cleared automatically when you clear your browser's site data, or you can re-open the consent banner at any time via the "Cookie Preferences" button in the footer.
Tenant routing: The multi-tenant architecture identifies your Tenant context from the subdomain (e.g.,
your_tenant.retrievy.com), not a cookie. Notenancycookie is set.
4.2 Functional / Preference Cookies
Retrievy does not currently set custom functional cookies. UI preferences (such as sidebar state, dashboard filters, and theme) are stored client-side in your browser's localStorage and are never transmitted to our servers. They can be cleared at any time via your browser's "Clear site data" controls without affecting your account.
If we introduce functional cookies in the future, this section will be updated and your consent will be requested where required by law.
4.3 Analytics and Performance
Retrievy uses Plausible Analytics (self-hosted), which is cookieless by design. Plausible does not set any cookies on your device and does not collect personally identifiable information. For this reason, no cookies are listed in this category.
Plausible collects only: page URL (without query strings containing personal data), HTTP referrer, browser family, device type, and country (derived from a partial IP hash that is discarded after processing — the IP address itself is never stored).
| Tool | Provider | Cookies Set | Data Location | Purpose |
|---|---|---|---|---|
| Plausible Analytics | Retrievy (self-hosted) | None | Retrievy infrastructure only | Aggregate page-view and session analytics — no personal data |
retrievy_perf |
Retrievy | Session (1st party) | Retrievy servers | Internal performance monitoring. Tracks page load times and API response latencies. No personal data stored externally. |
Privacy Guarantee: Because Plausible is self-hosted by Retrievy, your usage data never reaches any third-party analytics server. There is no Google, no Meta, and no advertising network involved in our analytics pipeline.
Note on timing: Because Plausible does not require consent under ePrivacy or GDPR (no cookies, no personal data, anonymous and aggregated), it begins collecting aggregate pageview data the moment a page loads, regardless of whether the cookie consent banner has been interacted with. This is the standard approach for cookie-less, privacy-first analytics and is consistent with guidance from the French CNIL, the German Datenschutzkonferenz, and the Brazilian ANPD. To opt out entirely, enable "Do Not Track" in your browser; our Plausible instance honors this signal natively.
4.4 Third-Party Functional Cookies (Conditional)
| Cookie Name | Provider | Duration | Purpose |
|---|---|---|---|
__stripe_mid |
Stripe | 1 year | Fraud prevention for payment transactions. Only set on billing-related pages. |
__stripe_sid |
Stripe | 30 minutes | Session-level fraud prevention for Stripe payment flows. |
5. Third-Party Cookies and Tracking
Retrievy is designed to minimize third-party exposure. Our analytics are self-hosted and our font delivery uses a privacy-respecting CDN (Bunny Fonts, which does not build advertising profiles). The only significant third-party cookies introduced are those strictly required for payment processing.
| Provider | Cookies Set | Purpose | Privacy Policy |
|---|---|---|---|
| Stripe | Yes (see §4.4) | Payment processing and fraud prevention on billing pages | stripe.com/privacy |
| Bunny Fonts | No | Privacy-first web font delivery (fonts.bunny.net). No tracking, no fingerprinting. | bunny.net/privacy |
| Plausible Analytics | No | Self-hosted by Retrievy. No data leaves our infrastructure. | This Cookie Policy |
No Google. No Meta. No advertising networks. Retrievy does not integrate with Google Analytics, Google Tag Manager, Google Ads, Facebook Pixel, or any behavioral advertising platform. Your browsing behavior on retrievy.com is never shared with third-party advertising ecosystems.
Within the authenticated platform (tenant.retrievy.com): No third-party analytics or tracking scripts are loaded. All monitoring is performed by Retrievy's own self-hosted tooling.
6. Your Cookie Choices
6.1 Cookie Consent Banner
When you first visit retrievy.com, you will be presented with a Cookie Consent banner that allows you to:
- Accept All — Acknowledge all cookie categories, including marketing cookies where applicable;
- Essential Only — Limit cookies to those strictly necessary for the Service to function.
Your decision is saved in your browser's localStorage as cookie_consent and respected on all subsequent visits.
You can change your cookie preferences at any time by clicking the "Cookie Preferences" link in the footer of our website.
6.2 Withdrawing Consent
To withdraw your previously given consent to non-essential cookies:
- Click the "Cookie Preferences" link in the footer of retrievy.com to re-open the consent banner;
- Update your choice and save;
- Or, clear the
cookie_consententry from your browser's localStorage (via browser developer tools or "Clear site data") to be shown the consent banner again on your next visit.
Note: Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
6.3 Impact of Disabling Cookies
| Cookie Category | Impact of Disabling |
|---|---|
| Strictly Necessary | Not possible. The Service will not function without these cookies. |
| Functional | Some preferences (theme, sidebar state, filters) will not be saved between sessions. |
| Analytics | We lose the ability to measure and improve platform performance. No impact on your use of the Service. |
| Marketing | You will not be tracked for advertising attribution on the public website. |
7. Managing Cookies in Your Browser
All modern browsers allow you to view, manage, block, and delete cookies. Note that blocking all cookies will impair the functionality of many websites and platforms, including Retrievy.
Here are links to cookie management guides for major browsers:
| Browser | Instructions |
|---|---|
| Google Chrome | support.google.com/chrome/answer/95647 |
| Mozilla Firefox | support.mozilla.org/kb/cookies-information-websites-store |
| Apple Safari (macOS) | support.apple.com/guide/safari/manage-cookies |
| Apple Safari (iOS) | support.apple.com/HT201265 |
| Microsoft Edge | support.microsoft.com — Microsoft Edge cookies |
| Opera | help.opera.com/en/latest/web-preferences/#cookies |
Browser-level blocking of the
retrievy-sessionandXSRF-TOKENcookies will prevent you from logging in. If you experience authentication issues, please ensure that cookies fromyour_tenant.retrievy.comare not being blocked by your browser or any security extension.
8. Do Not Track Signals
Some browsers and browser extensions support a "Do Not Track" (DNT) signal. Retrievy's analytics infrastructure uses Plausible Analytics (self-hosted), which natively respects DNT signals by excluding users who have DNT enabled from all statistical tracking.
For other aspects of the Service (session cookies, functional cookies), there is currently no universally accepted industry standard for responding to DNT signals beyond what Plausible already handles. We will reassess this position as industry standards evolve and will update this Cookie Policy accordingly.
9. Cookies and Sensitive Security Data
The Retrievy platform handles highly sensitive security data, including vulnerability findings, infrastructure configurations, compliance scores, and hardening workflows. No security scan data, infrastructure findings, or Customer Data is ever stored in cookies.
Cookies on the Retrievy platform are used exclusively for session management, preference storage, and platform analytics. All sensitive data is stored server-side in your isolated Tenant database, encrypted at rest with AES-256.
The retrievy_session cookie contains only an encrypted session token — a cryptographically random identifier that references your server-side session. It does not contain your user credentials, scan data, or any personally identifiable information in human-readable form.
10. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies we use, third-party integrations, or applicable legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this document;
- Post the updated Policy at retrievy.com/cookie-policy;
- Reset your cookie consent prompt on the website so you can review the changes.
We will provide at least 14 days' notice before material changes take effect by displaying a notice on our website.
11. Contact Us
If you have any questions or concerns about our use of cookies or this Cookie Policy, please contact us:
| Contact | Details |
|---|---|
| Email (Support) | [email protected] |
| Website | retrievy.com |
| Cookie Preferences | Footer of retrievy.com → "Cookie Preferences" |
You also have the right to lodge a complaint with your local data protection authority (e.g., the CNIL in France, the ICO in the United Kingdom, the ANPD in Brazil, or the relevant DPA in your EU member state) if you believe your rights have been violated.
This Cookie Policy was prepared in accordance with the requirements of the EU ePrivacy Directive, the General Data Protection Regulation (GDPR), the UK GDPR, and the Brazilian General Data Protection Law (LGPD).
Last reviewed: May 23, 2026
© 2026 Retrievy. All rights reserved.