Privacy Policy

Last updated July 10, 2026

Who we are

FeedbackFlow (usefeedbackflow.com)(“FeedbackFlow”, “we”, “us”) provides a service that collects customer feedback, triages it with AI, and files it as tickets in tools like Jira and Linear. This policy explains what data we collect, how we use it, and the choices you have. Questions? Email info@usefeedbackflow.com.

Information we collect

Widget submissions. When an end user submits feedback through the in-app widget, we collect the feedback text along with technical context captured automatically to help our customers reproduce issues:

  • Browser user agent
  • Browser language and locale
  • Screen size, viewport size, and device pixel ratio
  • The page referrer (with query strings and fragments redacted)
  • A rolling buffer of recent browser console errors and warnings
  • A rolling buffer of recent failed network requests (method, URL, and status code)

Customers can disable technical context capture. We do not intentionally collect sensitive personal information through the widget, and we truncate and size-limit captured context on our servers.

Connected integrations. When a customer connects Slack, Intercom, or Zendesk, we ingest the message and ticket content the customer chooses to route to FeedbackFlow so it can be triaged and filed.

Account data. When you create an account we collect your email address and, if you sign in with Google or GitHub, the OAuth identity those providers return. Authentication is handled by Supabase.

Triage tool. Our public triage tool lets anyone paste feedback text without creating an account. That text is sent to Anthropic for processing so it can be grouped into themes and scored. We do not store what you paste unless you choose to press Share, in which case the resulting report is stored and is deleted automatically after 30 days. For rate limiting, we keep a salted cryptographic hash of the IP address used to access the tool. We never store the raw IP address itself.

How we use information

  • To triage feedback with AI and file it as tickets in connected tools
  • To operate, secure, maintain, and improve the service
  • To communicate with account owners about their account and the service

We do not sell personal information.

Subprocessors

We rely on a small number of third parties to run the service:

  • Supabase for database and authentication
  • Anthropic for AI processing of feedback
  • Vercel for hosting
  • Stripe for billing, once paid billing is enabled

How we protect data

Integration credentials are encrypted at rest using AES-256-GCM. API keys are never stored in plain text: we store only a SHA-256 hash, and the raw key is shown to you once at creation and never again. Access to production data is limited to what is needed to operate the service.

Data retention and your choices

We retain data for as long as your account is active. You can request access to, or deletion of, your data at any time by emailing info@usefeedbackflow.com. When an account is closed, we delete or anonymize its data within a reasonable period, except where we are required to retain it to comply with legal obligations. If you use the public triage tool without an account, nothing is retained unless you press Share, and a shared report is deleted automatically 30 days after it is created.

Cookies

Today we use only essential cookies required for authentication. We do not use advertising or analytics cookies, so there is no cookie banner. If that changes, we will update this policy and add the appropriate controls.

Changes to this policy

We may update this policy from time to time. When we make material changes we will update the date at the top of this page.

Contact

For any privacy question or request, contact us at info@usefeedbackflow.com.