Legal
Privacy Policy
What we collect, why we collect it, and what you can ask us to do about it. We don't sell personal data and we don't run advertising or analytics trackers.
Last updated 29 July 2026. English is the authoritative version of this document.
1. Who is responsible for your data
[ADD: registered legal entity], [ADD: registered address] is the controller for personal data about account holders — the people who sign up, own or join a workspace, and pay us.
For content posted on a customer’s public board (posts, comments, votes, submitter emails), the workspace owner is the controllerand we act as their processor: we host it on their behalf and follow their instructions. If you submitted feedback to someone’s board and want it removed, contact that workspace first; we will help them, or act ourselves where the law requires.
2. What we collect
From account holders
- Name, email address and password (stored only as a bcrypt hash — we cannot read it).
- Optional profile details: contact number and profile picture.
- Workspace details you create: name, subdomain, logo and brand colour.
- Billing status: plan, billing interval, subscription state and current period end. Card details go straight to Paddle and never reach our servers.
- Support chat messages you send us, and our replies.
From board visitors
- Post and comment text, and any attachments you upload.
- A contact email if you submit without an account, so the team can reply about your submission. It is stored but never displayed publicly.
- An optional display name. If you leave it blank we show a generated pseudonym instead.
- A random browser identifier (fb_guest_id) so your submissions share one pseudonymous identity and votes can be limited per browser.
Automatically
- Device sessions: a session identifier with your IP address, browser user-agent, and first/last-seen times — used to keep you signed in and to enforce the one-device limit on Free and Pro.
- Audit records of significant workspace actions, including the acting user, IP address and user-agent.
- Password-reset requests: the requesting IP and a hashed, single-use token valid for one hour.
- Server access logs containing IP address, request path, response status, timestamp and user-agent, kept for security and debugging.
We do not collect special-category data, we do not run advertising or analytics trackers, and we do not build profiles or make automated decisions with legal effects about you.
3. Why we use it, and our legal basis
| Purpose | Data | Basis |
|---|---|---|
| Create and run your account and workspaces | Account, workspace and content data | Performance of a contract |
| Deliver a public board and show submissions on it | Content, display name, pseudonymous id | Contract (customer) / legitimate interests (visitor) |
| Take payment and manage subscriptions | Email, plan and billing status | Performance of a contract |
| Transactional email — invitations, password resets, and telling a submitter their feedback shipped | Email address, related content | Contract / legitimate interests |
| Keep accounts secure, prevent abuse and vote manipulation, enforce plan limits | Session data, IP, user-agent, pseudonymous id, audit records | Legitimate interests |
| Remember your language choice | Language cookie | Legitimate interests |
| Answer support requests | Support chat content | Contract / legitimate interests |
| Comply with law and respond to lawful requests | As required | Legal obligation |
We send only transactional email. We do not send marketing email unless you ask us to.
5. International transfers
Our providers may process data outside your country. Where data leaves the UK/EEA we rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards. Ask us at privacy@feedboardapp.com for details of the transfers relevant to you.
6. How long we keep it
- Account and workspace data: for as long as your account exists, and then as described below.
- Board content: until you or the workspace owner deletes it, or the workspace is deleted.
- Device sessions: revoked when you sign out or when another device takes over; abandoned sessions become eligible for takeover after 15 minutes of inactivity.
- Password-reset tokens: one hour, single use.
- Support conversations: retained after a chat is closed so we have a record of what was asked and advised. You lose access to a closed chat but we keep the transcript.
- Server access and audit logs: kept for a limited period for security and debugging, then discarded.
When you delete your account: the workspaces you own are deleted along with their posts, comments, roadmap and changelog, your device sessions are revoked, and any live subscription is cancelled. Workspaces you only joined are not deleted — content you posted there remains but is no longer attributed to you. Deletion requires your password and is irreversible. Backups may retain copies for a short period before being overwritten.
7. Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to our use of it, receive it in a portable form, and withdraw consent where we relied on it.
- Access and correct most data yourself in Settings → Profile.
- Delete everything you own from Settings → Profile → Danger zone.
- For anything else, email privacy@feedboardapp.com. We aim to reply within 30 days and will not charge you for a reasonable request.
If you are unhappy with how we handled a request you can complain to your local data-protection authority. We would rather you told us first so we can put it right.
8. How we protect it
- Traffic is encrypted with TLS. Passwords are stored as bcrypt hashes, never in plain text.
- Access to the application uses short-lived bearer tokens tied to a server-side device session that can be revoked.
- Uploads are validated by type and size, re-encoded before storage, and scoped to the workspace that owns them.
- Workspace data is separated per tenant, and every authenticated read and write is scoped to the caller's workspace.
- Internal administrative access is limited to the operator of the platform and is used to run and support the service.
No service can promise perfect security. If a breach affects your personal data and creates a real risk to you, we will notify you and any regulator we are required to inform.
9. Children
The service is not intended for children. Do not create an account if you are under 16 (or the age of digital consent where you live, if higher). If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change and revise the “last updated” date. For material changes affecting account holders we will give notice by email or in the app.
Questions
Email support@feedboardapp.com for general questions, or privacy@feedboardapp.com for anything about your personal data.