The Retention LabThe Retention Lab

Privacy Policy

Last updated: 27 July 2026

This policy explains what The Retention Lab does with your personal data. The service is operated by Brightrock Ltd, a company registered in Bulgaria under UIC 206254783, which is the data controller.

We are established in the EU, so the GDPR applies to everything here, and we apply the same standard to members everywhere rather than offering weaker protection outside Europe.

What we collect

  • Account data — your email address and a securely hashed password. We never store passwords in a readable form and cannot recover them, only reset them.
  • Profile data — display name, full name, biography and avatar, if you add them. All optional except a display name.
  • Payment data — handled entirely by Stripe. We store a Stripe customer reference, your plan and its status. We never see or store your card number.
  • YouTube channel data — only if you connect a channel. See the section below, which is deliberately specific.
  • Discord account data — only if you link one. Your Discord user id, username and avatar.
  • Your own work — notes, reviews, bookmarks, comparisons and anything else you write in the lab.
  • Usage measurement — which pages you open, described below.

YouTube data

The Retention Lab uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.

We request two read-only permissions and no others: youtube.readonly and yt-analytics.readonly. With those we access, store and use:

  • Your channel's name, handle and picture.
  • Your videos and their details — title, publish date, duration, thumbnail, view count, and whether each is a Short, a livestream or a long-form video.
  • Audience retention curves — how much of each video viewers watched.
  • Headline watch statistics for each video — its view count, average view duration and average percentage viewed.

We use this only to show you your own analysis. We do notrequest permission to modify your channel, and we do not request revenue data. We never sell it, never use it for advertising, and never show one member's channel data to another — except in Community Review, which you have to opt into video by video and which is described below.

You can revoke our access at any time. Disconnect in Settings → Connections, or independently of us through the Google security settings page. Disconnecting deletes the channel data we hold — see Retention.

Opening a video inside the lab loads YouTube's player in your browser, which contacts Google directly. We use the youtube-nocookie.com host so that fewer cookies are set, but that request is between you and Google and is covered by their policy.

What other members can see

Most of what you do here is private to you. These are the exceptions, and they are the only ways another member ever sees anything of yours.

  • Your display name and avatar appear on the leaderboard, alongside your points total and which plan tier you are on. Your email address is never shown.
  • Community Review nominations. If you submit one of your videos, and an admin selects it, then that video, your channel name, its retention curve, view count and average view percentage become visible to every member. You are told exactly this before you submit and have to confirm it. Nothing is published automatically.
  • Notes you write on a Community Review video are public to members, with your display name attached.

Your own private analysis — your library, your reviews, your notes on your own videos — is never visible to another member, and administrators only access it where genuinely necessary to support you or operate the service.

Usage measurement

When you are signed in and open a page inside the lab, we record your account id, the address of that page, and the time. We do this ourselves, on our own servers.

We do not record your IP address, browser, device or referring site; we record nothing when you are signed out; we set no additional cookie for it; and none of it goes to an analytics company or is used for advertising. The lawful basis is our legitimate interest in understanding which parts of the product are used.

Why we are allowed to use it

  • To provide the service you asked for (Art. 6(1)(b)) — your account, your analysis, your subscription.
  • Your consent (Art. 6(1)(a)) — connecting YouTube, linking Discord, nominating a video for Community Review, and marketing email. Each can be withdrawn.
  • Our legitimate interests (Art. 6(1)(f)) — keeping the platform secure, preventing abuse, and understanding usage.
  • Legal obligation (Art. 6(1)(c)) — keeping invoicing and tax records.

Who we share it with

We do not sell personal data, and we never have. We use these processors to run the service:

  • Supabase — database, authentication and account email. Hosted in Ireland.
  • Vercel — application hosting. Our servers run in Ireland.
  • Stripe — payments and billing.
  • Google / YouTube — the channel data you authorise, and the embedded player.
  • Discord — community features, if you link an account.
  • Cloudflare — hosting and delivery of our own lesson videos.

If you link Discord, we store your Discord user id, username and avatar, and ask permission to add you to our own server. We use it for one thing: keeping your role there matched to your membership, so upgrading, downgrading or cancelling takes effect in the community too. We cannot see which other servers you are in, cannot read your messages, and cannot act as you anywhere on Discord. Unlinking removes the roles we granted and deletes the stored authorisation; it does not remove you from the server, and anything you posted there remains subject to Discord's policy.

Cookies

We use essential cookies to keep you signed in, and embedded third-party content sets some of its own. See our Cookie Policy.

How long we keep it

  • Account and profile — while your account exists. Deleting your account starts a 14-day grace period, after which everything is permanently removed.
  • YouTube channel data — while the channel is connected. Disconnecting YouTube deletes it: your video list, retention curves and sync history all go. Your own notes and written reviews are yours and are kept.
  • Discord link — until you unlink or delete your account.
  • Community Review— a published video and its community notes stay in the archive. You can ask us to remove the performance data at any time and we will, 30 days after the request. The notes other members wrote remain, because they are those members' work.
  • Billing records — kept as long as tax and accounting law requires, which is longer than your account may last.

Your rights

You can access, correct, delete, export, restrict or object to the processing of your personal data, and withdraw consent at any time. Two of these are self-service, right now, on your Data & Privacy page: a full export of everything we hold, and account deletion.

For anything else, email business@brightrock.com. If you think we have handled your data badly, you can complain to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live.

International transfers

Our database and servers are in Ireland. Some processors — Stripe, Google, Discord, Cloudflare — may process data outside the EEA, under Standard Contractual Clauses or an adequacy decision.

Children

The Retention Lab is not for children. You must be at least 16 to use it, and 18 to buy a subscription. We do not knowingly collect data from children, and will delete any we discover.

Changes

We will post any new version here and update the date above. If a change materially affects your rights, we will tell you directly rather than relying on you noticing.

Contact

Brightrock Ltd (UIC 206254783), Bulgaria — business@brightrock.com.