Legal

Privacy Policy

Last updated: July 7, 2026

FeedbackGraph is built privacy-first: reports are redacted for personal information twice before any AI touches them, enrichment runs locally by default, tenants are isolated at the database, and you stay in control of what is captured and how long it is kept.

This Policy explains, in plain terms, what we collect, why, who we share it with, how we protect it, and the rights you have — wherever in the world you are.

1. Overview

This Privacy Policy explains how FeedbackGraph ("FeedbackGraph", "we", "us", or "our") collects, uses, discloses, and safeguards personal data when you visit our website, create an account, or use the FeedbackGraph products, widget, APIs, and related services (together, the "Service"). It also describes the choices and rights you have.

FeedbackGraph is a bug- and feedback-intelligence platform. An embeddable widget captures reports from an end user's browser, our pipeline enriches them with AI that runs privacy-first by default, and the results are routed to your team's tools. Because of this, we handle two very different kinds of data — data about you and your team, and data your end users submit — and we play a different legal role for each. Section 2 explains the distinction; please read it first.

This document is provided for transparency and general information. It is not legal advice and does not create any right or obligation beyond those in your agreement with us. Where this Policy and a signed data processing agreement conflict, the signed agreement controls for the data it covers.

2. Who we are and the roles we play

The applicable data-protection law (for example, the EU/UK GDPR) distinguishes the "controller" — who decides why and how personal data is processed — from the "processor," who processes it on the controller’s behalf. We act in both capacities depending on the data:

We are the controller
For personal data about our customers, account holders, website visitors, prospects, and billing contacts — for example, when you create an account, contact us, or browse our site. This Policy is our controller-facing notice for that data.
We are the processor (or service provider)
For the reports, media, and technical context that end users submit through a customer’s widget or that a customer imports ("Customer Data"). Here, our customer is the controller and decides what is collected and why; we process Customer Data only on the customer’s documented instructions to provide the Service. If you are an end user, please direct privacy requests to the organization that deployed the widget; we will support that organization in responding.

The processing of Customer Data is governed by our Terms of Service and, where applicable, a Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses and the UK Addendum. To request our DPA, contact privacy@feedbackgraph.com.

3. Key terms

Personal data
Any information relating to an identified or identifiable person. "Personal information" under US laws is treated equivalently here.
Processing
Any operation performed on personal data — collection, storage, use, disclosure, or deletion.
Customer
The organization or individual that subscribes to or uses the Service under an account.
End user
A person who submits a report through a customer’s widget or reporter page.
Customer Data
Reports, media, technical context, and other content submitted to or through the Service by a customer or its end users.
Sub-processor
A third party we engage to process personal data on our behalf to run the Service (see Section 9).
Sensitive data
Special-category or sensitive personal data (e.g., health, precise geolocation, government IDs, payment card numbers, credentials). The Service is not intended to collect sensitive data; see Sections 4 and 6.

4. Personal data we collect

A. Account, profile, and organization data

  • Your name and email address.
  • Authentication data: we use passwordless email one-time codes and optional Google or Apple single sign-on; if you enable it, a time-based one-time-password (TOTP) multi-factor secret.
  • Your organization, team membership, and role/permissions.
  • Preferences and settings you configure.

B. Authentication and security logs

To secure accounts and detect abuse, we keep an audit trail of sign-in and sensitive actions that includes IP address, browser/device (user-agent), timestamps, and success/failure reasons.

C. Billing data

Payments are handled by Polar acting as our Merchant of Record. Polar collects your billing name, email, billing country, IP address (for tax and fraud purposes), and the transaction, tax, and invoice records; card and other payment-instrument details are handled by Polar and its PCI-DSS-compliant payment processors, not stored by us. We receive confirmation of your plan, status, and non-sensitive transaction metadata.

D. Customer Data captured by the widget (processed as processor)

When an end user files a report, the widget can capture — subject to the customer’s configuration, consent settings, and the redaction described in Section 6:

  • The description text the reporter writes.
  • A screenshot, a screen recording (video only — no microphone or audio is ever captured), and/or a session replay of the reporter’s own session.
  • Diagnostic context: recent console logs, failed network requests, JavaScript errors, and interaction breadcrumbs (including rage-click signals).
  • Environment and device signals: browser, operating system, device type, language, time zone, viewport and color depth, user-agent, platform, approximate device memory and CPU hints, connection type, and orientation.
  • Page context: the URL, path, referrer, and page title of the page the report was filed from.
  • Cookies present on the host page (with credentials, tokens, and other secrets redacted — see Section 6).
  • Optional sentiment and satisfaction (CSAT) scores, and the consent state recorded at capture.

The widget does not, by itself, capture the reporter’s identity. A customer may choose to associate a reporter’s name or email with reports. Uploaded media is stored in object storage and served only through short-lived, signed URLs.

E. Website and product usage data

When you use our website and dashboard we may process pages viewed, features used, referring pages, and approximate location derived from IP address. Where we use analytics, we use a privacy-first, cookieless tool by default (see Section 7).

F. Communications

If you contact support, request a demo, or submit a lead or contact form, we process the information you provide (such as name, email, company, and message) to respond and follow up.

G. Data from third parties

We receive limited data from single sign-on providers (Google, Apple) when you use them, from payment/billing (Polar), and — at your direction — from integrations you connect (such as Jira, Linear, GitHub, Slack, Intercom, or Zendesk) and from files you import.

5. How and why we use personal data

We use personal data for the purposes below. Where the GDPR or similar laws apply and we are the controller, the corresponding legal basis is shown. Where we are a processor, we act only on the customer’s documented instructions and the customer is responsible for establishing a legal basis toward end users.

PurposeLegal basis (where GDPR applies)
Provide, operate, maintain, and support the Service; authenticate you; deliver reports and notifications.Performance of a contract
Process payments, billing, invoicing, and prevent payment fraud.Contract; legal obligation; legitimate interests
Secure the Service, keep audit logs, prevent, detect, and investigate abuse or security incidents.Legitimate interests; legal obligation
Enrich reports with AI (classification, summarization, deduplication, embeddings) on the customer’s behalf.Performance of a contract (as processor, on customer instructions)
Improve and develop the Service and understand usage through privacy-first analytics.Legitimate interests (or consent where required)
Send service, security, and transactional messages.Performance of a contract; legitimate interests
Send marketing communications (which you can opt out of at any time).Consent and/or legitimate interests
Comply with law and respond to lawful requests; establish, exercise, or defend legal claims.Legal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing as described in Section 13. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

6. AI processing, redaction, and automated decisions

Privacy is built into the enrichment pipeline, not bolted on. Before any AI processing, report descriptions, OCR text, transcripts, and captured context pass through two independent layers of PII redaction — once in the end user’s browser before data leaves the page, and again on our ingestion service. Screenshots additionally mask sensitive form fields (such as passwords, emails, and card numbers) before they are rasterized, and customers can force-redact any element they choose.

By default, enrichment runs on a local, self-contained AI path with no external AI calls: classification uses heuristics and a local embedding model. A hosted large-language-model (LLM) provider is called only on paid plans that have "Full AI" enabled, and only on already-redacted content. You choose and configure that provider; the current sub-processors are listed in Section 9.

We do not use personal data to train third-party or public foundation models, and we do not sell personal data. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement; AI outputs (such as suggested type or severity) are advisory and reviewable by your team, and always shown alongside the evidence they were derived from.

7. Cookies, analytics, and tracking technologies

We use strictly necessary cookies and similar technologies to keep you signed in, secure sessions, remember settings, and operate the Service. These are essential and cannot be switched off through our systems.

For product and marketing analytics we use a privacy-first, cookieless tool by default (Plausible), which does not set cookies, does not track you across sites, and collects only aggregated, non-identifying usage data. Because our default analytics are cookieless, no consent banner is required for that setup; if you deploy an analytics tool that uses cookies, you are responsible for obtaining any required consent.

The widget honors the browser "Do Not Track" signal and consent state: diagnostic context is always PII-redacted, and visual capture (screenshots, recordings, and DOM replay) is suppressed when a user has not consented or has Do Not Track enabled. We respond to Global Privacy Control (GPC) signals as an opt-out of "sale"/"sharing" where required by law (see Section 15).

8. How we share personal data

We do not sell your personal data. We disclose personal data only as described here:

  • Sub-processors. Vendors that process personal data on our behalf to run the Service, under contracts that require appropriate safeguards (see Section 9).
  • Integrations you connect. When a customer connects a destination such as Jira, Linear, GitHub, Slack, Intercom, Zendesk, Zapier, or a custom webhook, report data is sent there at the customer’s instruction. Those services are controlled by the customer under the customer’s own agreements, and this Policy does not govern them.
  • Professional advisors and payment partners. Auditors, lawyers, accountants, and our Merchant of Record, as needed to run the business.
  • Legal and safety. To comply with law, enforce our agreements, or protect the rights, property, or safety of our users, the public, or us — and only to the extent required.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor with equivalent protections.
  • Aggregated or de-identified data. Which cannot reasonably be used to identify you.

9. Sub-processors

We engage the sub-processors below to help provide the Service. Those marked "only when configured" process data solely if you or your plan enable the corresponding feature. We impose data-protection obligations on each sub-processor and remain responsible for their processing on our behalf.

Sub-processorPurposeData processedLocation
Vercel Inc.Hosting and content delivery for the web dashboard and marketing siteAccount data, usage/technical data, IP addressUnited States (global edge network)
Render Services, Inc.Application hosting (ingestion API, background workers, scheduler) and managed Postgres + key-value datastoresAll service data, including account and report dataUnited States / European Union (region-dependent)
Cloudflare, Inc. (R2 object storage)Storage of uploaded media (screenshots, screen recordings, session replays)Report media and associated metadataUnited States / European Union (region-dependent)
Aiven Ltd.Managed event-streaming (Apache Kafka) that moves reports through the processing pipelineReport data in transit through the pipelineEuropean Union / United States (region-dependent)
Polar Software Inc.Merchant of Record: checkout, payment processing, invoicing, tax (VAT/GST), and subscription managementBilling contact, transaction and tax data, IP address; card data is handled by Polar and its PCI-DSS payment processors, not by usUnited States / European Union
Resend (Plentymarkets Inc.)Transactional email delivery (sign-in codes, invitations, digests, notifications)Recipient email address and message contentUnited States
Your configured AI/LLM providerEnrichment (classification, summarization, vision) — invoked only on paid plans with "Full AI" enabled, and only after PII redaction (only when configured)PII-redacted report text and imagesDepends on the provider you configure
Your configured transcription (ASR) providerSpeech-to-text for audio/video attachments — only when configured and enabled (only when configured)Audio extracted from report mediaDepends on the provider you configure
Sentry (Functional Software, Inc.)Application error and performance monitoring — only when configured (only when configured)Diagnostic/error telemetry, which may include IP address and technical contextUnited States
Plausible AnalyticsPrivacy-first, cookieless product/marketing analytics — only when configured (only when configured)Aggregated, non-identifying usage events (no cookies, no cross-site tracking)European Union

We may update this list as the Service evolves. To request advance notice of new sub-processors, email privacy@feedbackgraph.com.

10. International data transfers

We operate globally, so personal data may be transferred to, stored in, and processed in countries other than your own, including the United States and countries in the European Union. Data-protection laws in those countries may differ from those where you live.

When we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum — together with supplementary technical and organizational measures. You may request a copy of the relevant safeguards using the contact details in Section 20.

11. Data retention

We keep personal data only for as long as needed for the purposes in this Policy, then delete or anonymize it. Retention periods depend on the type of data and the reason we hold it, including the length of your relationship with us, our legal obligations, and our need to resolve disputes and enforce agreements.

  • Account data is retained while your account is active and for a limited period afterward.
  • Customer Data (including report media) is retained according to the customer’s configured retention settings; automated retention sweeps delete data on schedule.
  • Security and audit logs are retained for a limited period for security and compliance.
  • Billing records are retained as required by tax and accounting law.
  • Backups are retained for a limited window and then overwritten; deletions propagate to backups within that cycle.

After account termination, customers may export their data for 30 days, after which we delete or anonymize Customer Data except where retention is required by law.

12. Security

We use technical and organizational measures designed to protect personal data appropriate to the risk, including:

  • Encryption in transit (TLS) and encryption of credentials and integration secrets at rest using AES-256-GCM.
  • Strict multi-tenant isolation enforced at the database with Postgres Row-Level Security, so one tenant cannot access another’s data.
  • Two-layer PII redaction before AI processing, sensitive-field masking in screenshots, and secret redaction in captured network and cookie data.
  • Access controls with role-based permissions, optional multi-factor authentication, and audit logging of sensitive actions.
  • Origin allow-listing, rate limiting, payload size caps, and signed, short-lived URLs for media.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by law. Report a suspected vulnerability to support@feedbackgraph.com.

13. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal data. Region-specific details are in Sections 14–17.

  • Access — obtain confirmation of, and a copy of, the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data in certain circumstances.
  • Restriction and objection — limit or object to certain processing, including profiling and direct marketing.
  • Portability — receive certain data in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent.
  • Opt out — of "sale"/"sharing" or targeted advertising (we do not sell or share personal data).
  • Non-discrimination — we will not treat you unfairly for exercising your rights.
  • Complain — to your data-protection authority (see Sections 14 and 17).

To exercise these rights, email privacy@feedbackgraph.com. Account owners can also export all organization data as JSON and erase a reporter’s data directly from Settings. We will verify your request (which may require confirming your identity) and respond within the timeframe required by applicable law. You may use an authorized agent where the law allows. If you are an end user, contact the organization whose widget you used; we will assist that organization as its processor.

14. EEA, UK, and Switzerland (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, FeedbackGraph is the controller of the personal data described in this Policy for which we determine the purposes and means. Our legal bases are set out in Section 5, and our transfer safeguards in Section 10.

You have the rights in Section 13. You also have the right to lodge a complaint with your local supervisory authority — for example, the UK Information Commissioner’s Office (ICO), your national data-protection authority in the EEA, or the Swiss Federal Data Protection and Information Commissioner (FDPIC) — although we hope you will contact us first so we can help.

Where we are required to designate an EU or UK representative under Article 27 GDPR, that representative’s contact details will be published here and are available on request at privacy@feedbackgraph.com.

15. California (CCPA/CPRA)

This section is the notice required by the California Consumer Privacy Act, as amended by the CPRA, and applies to California residents. Terms used here have the meanings given in that law. When we process Customer Data on a customer’s behalf, we act as a "service provider" and use that data only for the business purposes set out in our contract.

Categories of personal information we may collect: identifiers (such as name, email, IP address); commercial information (such as subscription and transaction records); internet or other electronic network activity (such as usage and diagnostic data); geolocation (approximate, from IP); professional or employment information (such as company and role); audio, electronic, or visual information (such as screenshots or recordings submitted in reports); and inferences drawn from the above. We collect these from you, your devices, your organization, and the sources described in Section 4.

We disclose personal information to sub-processors and, at a customer’s direction, to connected integrations, for the business purposes in Section 5. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.

Sensitive personal information: the Service is not intended to collect sensitive personal information, our redaction is designed to remove it, and we do not use or disclose any such information for purposes beyond those permitted by law (and therefore do not need to offer a "limit" right). Please do not submit sensitive information through reports.

California rights: to know/access, delete, correct, and opt out of sale/sharing, and not to be discriminated against for exercising them. Because we do not sell or share personal information, no opt-out action is needed, but we honor Global Privacy Control signals where applicable. To exercise a right, email privacy@feedbackgraph.com; we will verify your request and you may use an authorized agent. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct-marketing purposes.

16. Other US state privacy rights

If you are a resident of a US state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — you may have rights to confirm and access your personal data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data or use it for targeted advertising or profiling with legal or similarly significant effects.

To exercise these rights, email privacy@feedbackgraph.com. If we deny your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state attorney general.

17. Canada, Brazil, Australia, and other regions

Canada (PIPEDA)
We collect, use, and disclose personal information with your consent (express or implied) or as otherwise permitted by law, and you may request access to and correction of your personal information. You may complain to the Office of the Privacy Commissioner of Canada.
Brazil (LGPD)
We process personal data on the legal bases in Article 7 (and, for sensitive data, Article 11) of the LGPD, and you have rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing. You may contact the Brazilian data-protection authority (ANPD).
Australia (Privacy Act / APPs)
We handle personal information in line with the Australian Privacy Principles, including access and correction rights, and you may complain to the Office of the Australian Information Commissioner (OAIC).
Other regions
Where other national or regional privacy laws apply to you, we will honor the rights and protections those laws require. Contact us to exercise them.

18. Children's privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 16 (or the age set by your local law, and under 13 in the United States). If you believe a child has provided us personal data, contact us and we will delete it. Customers must not use the widget to knowingly collect personal data from children in violation of applicable law.

19. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice (such as by email or an in-product notice) as required by law. Your continued use of the Service after an update takes effect means you accept the revised Policy.

20. How to contact us

For privacy questions or to exercise your rights, contact our privacy team at privacy@feedbackgraph.com. For general support, contact support@feedbackgraph.com.