Last updated September 5, 2026

Privacy policy

This policy explains what Feedoback collects, why, and what you can do about it. It is written to be read.

Who we are

Feedoback is operated by the Feedoback team (“we”). For privacy questions, write to [email protected].

Two kinds of people

Customers create an account and install the widget on their site. For their account data, we are the controller.

Visitors use a customer’s site and may send feedback through the widget. For what they send, the customer is the controller and we process it on their behalf and on their instructions. If you are a visitor with a question about your data, the site you sent it through is the right place to ask; we will help them answer.

What we collect from customers

  • Name, email address and a password hash when you create an account.
  • Workspace and project names, and the domains you allow the widget on.
  • Replies and status changes you make in the dashboard.
  • Technical logs of requests to the service (IP address, time, path) kept for security and kept for no longer than 30 days.

Legal basis: performing our contract with you, and our legitimate interest in keeping the service secure.

What we process for visitors

Only what the widget sends when a visitor presses send:

  • The message they wrote.
  • The page URL, title and referrer, viewport and screen size, browser user agent, language and time zone.
  • If they pointed at an element: a description of it and a picture of the visible page at that moment.
  • If they recorded: the screen recording and, if they chose, their microphone audio.
  • If they typed an email so the site can reply: that email.
  • Any identity or context the customer’s own code passes through the SDK.

The widget sets no cookies and stores nothing on the visitor’s device beyond session storage for the current tab. It does not track visitors across pages or sites.

How long we keep it

  • Account and workspace data: until you delete it. Deleting a project removes its threads and files. Deleting your account removes everything you own.
  • Deleted data leaves backups within 30 days.
  • Request logs: 30 days.

Who else sees it

We use a small number of providers to run the service, each bound by a data processing agreement:

ProviderPurposeLocation
[Hosting provider]Application hosting and database[Region]
[Storage provider]Screenshots and recordings[Region]

We do not sell personal data, and we do not use it for advertising.

Your rights

Under the GDPR and similar laws you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Most of this you can do yourself from account settings. For anything else, email [email protected]. You can also complain to your local data protection authority.

Cookies

The dashboard uses one strictly necessary cookie to keep you signed in. The public site and the widget set none. There is no consent banner because there is nothing to consent to.

Children

The service is for businesses and is not directed at children under 16.

Changes

When this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always says when it last changed. See also the terms of service.