Privacy Policy
Last updated: July 7, 2026
FeedbackGraph is built privacy-first: reports are redacted for personal information twice before any AI touches them, enrichment runs locally by default, tenants are isolated at the database, and you stay in control of what is captured and how long it is kept.
This Policy explains, in plain terms, what we collect, why, who we share it with, how we protect it, and the rights you have — wherever in the world you are.
1. Overview
This Privacy Policy explains how FeedbackGraph ("FeedbackGraph", "we", "us", or "our") collects, uses, discloses, and safeguards personal data when you visit our website, create an account, or use the FeedbackGraph products, widget, APIs, and related services (together, the "Service"). It also describes the choices and rights you have.
FeedbackGraph is a bug- and feedback-intelligence platform. An embeddable widget captures reports from an end user's browser, our pipeline enriches them with AI that runs privacy-first by default, and the results are routed to your team's tools. Because of this, we handle two very different kinds of data — data about you and your team, and data your end users submit — and we play a different legal role for each. Section 2 explains the distinction; please read it first.
This document is provided for transparency and general information. It is not legal advice and does not create any right or obligation beyond those in your agreement with us. Where this Policy and a signed data processing agreement conflict, the signed agreement controls for the data it covers.
2. Who we are and the roles we play
The applicable data-protection law (for example, the EU/UK GDPR) distinguishes the "controller" — who decides why and how personal data is processed — from the "processor," who processes it on the controller’s behalf. We act in both capacities depending on the data:
- We are the controller
- For personal data about our customers, account holders, website visitors, prospects, and billing contacts — for example, when you create an account, contact us, or browse our site. This Policy is our controller-facing notice for that data.
- We are the processor (or service provider)
- For the reports, media, and technical context that end users submit through a customer’s widget or that a customer imports ("Customer Data"). Here, our customer is the controller and decides what is collected and why; we process Customer Data only on the customer’s documented instructions to provide the Service. If you are an end user, please direct privacy requests to the organization that deployed the widget; we will support that organization in responding.
The processing of Customer Data is governed by our Terms of Service and, where applicable, a Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses and the UK Addendum. To request our DPA, contact privacy@feedbackgraph.com.
3. Key terms
- Personal data
- Any information relating to an identified or identifiable person. "Personal information" under US laws is treated equivalently here.
- Processing
- Any operation performed on personal data — collection, storage, use, disclosure, or deletion.
- Customer
- The organization or individual that subscribes to or uses the Service under an account.
- End user
- A person who submits a report through a customer’s widget or reporter page.
- Customer Data
- Reports, media, technical context, and other content submitted to or through the Service by a customer or its end users.
- Sub-processor
- A third party we engage to process personal data on our behalf to run the Service (see Section 9).
- Sensitive data
- Special-category or sensitive personal data (e.g., health, precise geolocation, government IDs, payment card numbers, credentials). The Service is not intended to collect sensitive data; see Sections 4 and 6.
4. Personal data we collect
A. Account, profile, and organization data
- Your name and email address.
- Authentication data: we use passwordless email one-time codes and optional Google or Apple single sign-on; if you enable it, a time-based one-time-password (TOTP) multi-factor secret.
- Your organization, team membership, and role/permissions.
- Preferences and settings you configure.
B. Authentication and security logs
To secure accounts and detect abuse, we keep an audit trail of sign-in and sensitive actions that includes IP address, browser/device (user-agent), timestamps, and success/failure reasons.
C. Billing data
Payments are handled by Polar acting as our Merchant of Record. Polar collects your billing name, email, billing country, IP address (for tax and fraud purposes), and the transaction, tax, and invoice records; card and other payment-instrument details are handled by Polar and its PCI-DSS-compliant payment processors, not stored by us. We receive confirmation of your plan, status, and non-sensitive transaction metadata.
D. Customer Data captured by the widget (processed as processor)
When an end user files a report, the widget can capture — subject to the customer’s configuration, consent settings, and the redaction described in Section 6:
- The description text the reporter writes.
- A screenshot, a screen recording (video only — no microphone or audio is ever captured), and/or a session replay of the reporter’s own session.
- Diagnostic context: recent console logs, failed network requests, JavaScript errors, and interaction breadcrumbs (including rage-click signals).
- Environment and device signals: browser, operating system, device type, language, time zone, viewport and color depth, user-agent, platform, approximate device memory and CPU hints, connection type, and orientation.
- Page context: the URL, path, referrer, and page title of the page the report was filed from.
- Cookies present on the host page (with credentials, tokens, and other secrets redacted — see Section 6).
- Optional sentiment and satisfaction (CSAT) scores, and the consent state recorded at capture.
The widget does not, by itself, capture the reporter’s identity. A customer may choose to associate a reporter’s name or email with reports. Uploaded media is stored in object storage and served only through short-lived, signed URLs.
E. Website and product usage data
When you use our website and dashboard we may process pages viewed, features used, referring pages, and approximate location derived from IP address. Where we use analytics, we use a privacy-first, cookieless tool by default (see Section 7).
F. Communications
If you contact support, request a demo, or submit a lead or contact form, we process the information you provide (such as name, email, company, and message) to respond and follow up.
G. Data from third parties
We receive limited data from single sign-on providers (Google, Apple) when you use them, from payment/billing (Polar), and — at your direction — from integrations you connect (such as Jira, Linear, GitHub, Slack, Intercom, or Zendesk) and from files you import.
5. How and why we use personal data
We use personal data for the purposes below. Where the GDPR or similar laws apply and we are the controller, the corresponding legal basis is shown. Where we are a processor, we act only on the customer’s documented instructions and the customer is responsible for establishing a legal basis toward end users.
| Purpose | Legal basis (where GDPR applies) |
|---|---|
| Provide, operate, maintain, and support the Service; authenticate you; deliver reports and notifications. | Performance of a contract |
| Process payments, billing, invoicing, and prevent payment fraud. | Contract; legal obligation; legitimate interests |
| Secure the Service, keep audit logs, prevent, detect, and investigate abuse or security incidents. | Legitimate interests; legal obligation |
| Enrich reports with AI (classification, summarization, deduplication, embeddings) on the customer’s behalf. | Performance of a contract (as processor, on customer instructions) |
| Improve and develop the Service and understand usage through privacy-first analytics. | Legitimate interests (or consent where required) |
| Send service, security, and transactional messages. | Performance of a contract; legitimate interests |
| Send marketing communications (which you can opt out of at any time). | Consent and/or legitimate interests |
| Comply with law and respond to lawful requests; establish, exercise, or defend legal claims. | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to that processing as described in Section 13. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
6. AI processing, redaction, and automated decisions
Privacy is built into the enrichment pipeline, not bolted on. Before any AI processing, report descriptions, OCR text, transcripts, and captured context pass through two independent layers of PII redaction — once in the end user’s browser before data leaves the page, and again on our ingestion service. Screenshots additionally mask sensitive form fields (such as passwords, emails, and card numbers) before they are rasterized, and customers can force-redact any element they choose.
By default, enrichment runs on a local, self-contained AI path with no external AI calls: classification uses heuristics and a local embedding model. A hosted large-language-model (LLM) provider is called only on paid plans that have "Full AI" enabled, and only on already-redacted content. You choose and configure that provider; the current sub-processors are listed in Section 9.
We do not use personal data to train third-party or public foundation models, and we do not sell personal data. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement; AI outputs (such as suggested type or severity) are advisory and reviewable by your team, and always shown alongside the evidence they were derived from.
9. Sub-processors
We engage the sub-processors below to help provide the Service. Those marked "only when configured" process data solely if you or your plan enable the corresponding feature. We impose data-protection obligations on each sub-processor and remain responsible for their processing on our behalf.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel Inc. | Hosting and content delivery for the web dashboard and marketing site | Account data, usage/technical data, IP address | United States (global edge network) |
| Render Services, Inc. | Application hosting (ingestion API, background workers, scheduler) and managed Postgres + key-value datastores | All service data, including account and report data | United States / European Union (region-dependent) |
| Cloudflare, Inc. (R2 object storage) | Storage of uploaded media (screenshots, screen recordings, session replays) | Report media and associated metadata | United States / European Union (region-dependent) |
| Aiven Ltd. | Managed event-streaming (Apache Kafka) that moves reports through the processing pipeline | Report data in transit through the pipeline | European Union / United States (region-dependent) |
| Polar Software Inc. | Merchant of Record: checkout, payment processing, invoicing, tax (VAT/GST), and subscription management | Billing contact, transaction and tax data, IP address; card data is handled by Polar and its PCI-DSS payment processors, not by us | United States / European Union |
| Resend (Plentymarkets Inc.) | Transactional email delivery (sign-in codes, invitations, digests, notifications) | Recipient email address and message content | United States |
| Your configured AI/LLM provider | Enrichment (classification, summarization, vision) — invoked only on paid plans with "Full AI" enabled, and only after PII redaction (only when configured) | PII-redacted report text and images | Depends on the provider you configure |
| Your configured transcription (ASR) provider | Speech-to-text for audio/video attachments — only when configured and enabled (only when configured) | Audio extracted from report media | Depends on the provider you configure |
| Sentry (Functional Software, Inc.) | Application error and performance monitoring — only when configured (only when configured) | Diagnostic/error telemetry, which may include IP address and technical context | United States |
| Plausible Analytics | Privacy-first, cookieless product/marketing analytics — only when configured (only when configured) | Aggregated, non-identifying usage events (no cookies, no cross-site tracking) | European Union |
We may update this list as the Service evolves. To request advance notice of new sub-processors, email privacy@feedbackgraph.com.
10. International data transfers
We operate globally, so personal data may be transferred to, stored in, and processed in countries other than your own, including the United States and countries in the European Union. Data-protection laws in those countries may differ from those where you live.
When we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum — together with supplementary technical and organizational measures. You may request a copy of the relevant safeguards using the contact details in Section 20.
11. Data retention
We keep personal data only for as long as needed for the purposes in this Policy, then delete or anonymize it. Retention periods depend on the type of data and the reason we hold it, including the length of your relationship with us, our legal obligations, and our need to resolve disputes and enforce agreements.
- Account data is retained while your account is active and for a limited period afterward.
- Customer Data (including report media) is retained according to the customer’s configured retention settings; automated retention sweeps delete data on schedule.
- Security and audit logs are retained for a limited period for security and compliance.
- Billing records are retained as required by tax and accounting law.
- Backups are retained for a limited window and then overwritten; deletions propagate to backups within that cycle.
After account termination, customers may export their data for 30 days, after which we delete or anonymize Customer Data except where retention is required by law.
12. Security
We use technical and organizational measures designed to protect personal data appropriate to the risk, including:
- Encryption in transit (TLS) and encryption of credentials and integration secrets at rest using AES-256-GCM.
- Strict multi-tenant isolation enforced at the database with Postgres Row-Level Security, so one tenant cannot access another’s data.
- Two-layer PII redaction before AI processing, sensitive-field masking in screenshots, and secret redaction in captured network and cookie data.
- Access controls with role-based permissions, optional multi-factor authentication, and audit logging of sensitive actions.
- Origin allow-listing, rate limiting, payload size caps, and signed, short-lived URLs for media.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by law. Report a suspected vulnerability to support@feedbackgraph.com.
13. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal data. Region-specific details are in Sections 14–17.
- Access — obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data in certain circumstances.
- Restriction and objection — limit or object to certain processing, including profiling and direct marketing.
- Portability — receive certain data in a structured, machine-readable format.
- Withdraw consent — where processing is based on consent.
- Opt out — of "sale"/"sharing" or targeted advertising (we do not sell or share personal data).
- Non-discrimination — we will not treat you unfairly for exercising your rights.
- Complain — to your data-protection authority (see Sections 14 and 17).
To exercise these rights, email privacy@feedbackgraph.com. Account owners can also export all organization data as JSON and erase a reporter’s data directly from Settings. We will verify your request (which may require confirming your identity) and respond within the timeframe required by applicable law. You may use an authorized agent where the law allows. If you are an end user, contact the organization whose widget you used; we will assist that organization as its processor.
14. EEA, UK, and Switzerland (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, FeedbackGraph is the controller of the personal data described in this Policy for which we determine the purposes and means. Our legal bases are set out in Section 5, and our transfer safeguards in Section 10.
You have the rights in Section 13. You also have the right to lodge a complaint with your local supervisory authority — for example, the UK Information Commissioner’s Office (ICO), your national data-protection authority in the EEA, or the Swiss Federal Data Protection and Information Commissioner (FDPIC) — although we hope you will contact us first so we can help.
Where we are required to designate an EU or UK representative under Article 27 GDPR, that representative’s contact details will be published here and are available on request at privacy@feedbackgraph.com.
15. California (CCPA/CPRA)
This section is the notice required by the California Consumer Privacy Act, as amended by the CPRA, and applies to California residents. Terms used here have the meanings given in that law. When we process Customer Data on a customer’s behalf, we act as a "service provider" and use that data only for the business purposes set out in our contract.
Categories of personal information we may collect: identifiers (such as name, email, IP address); commercial information (such as subscription and transaction records); internet or other electronic network activity (such as usage and diagnostic data); geolocation (approximate, from IP); professional or employment information (such as company and role); audio, electronic, or visual information (such as screenshots or recordings submitted in reports); and inferences drawn from the above. We collect these from you, your devices, your organization, and the sources described in Section 4.
We disclose personal information to sub-processors and, at a customer’s direction, to connected integrations, for the business purposes in Section 5. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information: the Service is not intended to collect sensitive personal information, our redaction is designed to remove it, and we do not use or disclose any such information for purposes beyond those permitted by law (and therefore do not need to offer a "limit" right). Please do not submit sensitive information through reports.
California rights: to know/access, delete, correct, and opt out of sale/sharing, and not to be discriminated against for exercising them. Because we do not sell or share personal information, no opt-out action is needed, but we honor Global Privacy Control signals where applicable. To exercise a right, email privacy@feedbackgraph.com; we will verify your request and you may use an authorized agent. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct-marketing purposes.
16. Other US state privacy rights
If you are a resident of a US state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — you may have rights to confirm and access your personal data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data or use it for targeted advertising or profiling with legal or similarly significant effects.
To exercise these rights, email privacy@feedbackgraph.com. If we deny your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state attorney general.
17. Canada, Brazil, Australia, and other regions
- Canada (PIPEDA)
- We collect, use, and disclose personal information with your consent (express or implied) or as otherwise permitted by law, and you may request access to and correction of your personal information. You may complain to the Office of the Privacy Commissioner of Canada.
- Brazil (LGPD)
- We process personal data on the legal bases in Article 7 (and, for sensitive data, Article 11) of the LGPD, and you have rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing. You may contact the Brazilian data-protection authority (ANPD).
- Australia (Privacy Act / APPs)
- We handle personal information in line with the Australian Privacy Principles, including access and correction rights, and you may complain to the Office of the Australian Information Commissioner (OAIC).
- Other regions
- Where other national or regional privacy laws apply to you, we will honor the rights and protections those laws require. Contact us to exercise them.
18. Children's privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 16 (or the age set by your local law, and under 13 in the United States). If you believe a child has provided us personal data, contact us and we will delete it. Customers must not use the widget to knowingly collect personal data from children in violation of applicable law.
19. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice (such as by email or an in-product notice) as required by law. Your continued use of the Service after an update takes effect means you accept the revised Policy.
20. How to contact us
For privacy questions or to exercise your rights, contact our privacy team at privacy@feedbackgraph.com. For general support, contact support@feedbackgraph.com.