Legal

Privacy Policy

What we collect, why we collect it, and what you can ask us to do about it. We don't sell personal data and we don't run advertising or analytics trackers.

Last updated 29 July 2026. English is the authoritative version of this document.

1. Who is responsible for your data

[ADD: registered legal entity], [ADD: registered address] is the controller for personal data about account holders — the people who sign up, own or join a workspace, and pay us.

For content posted on a customer’s public board (posts, comments, votes, submitter emails), the workspace owner is the controllerand we act as their processor: we host it on their behalf and follow their instructions. If you submitted feedback to someone’s board and want it removed, contact that workspace first; we will help them, or act ourselves where the law requires.

2. What we collect

From account holders

  • Name, email address and password (stored only as a bcrypt hash — we cannot read it).
  • Optional profile details: contact number and profile picture.
  • Workspace details you create: name, subdomain, logo and brand colour.
  • Billing status: plan, billing interval, subscription state and current period end. Card details go straight to Paddle and never reach our servers.
  • Support chat messages you send us, and our replies.

From board visitors

  • Post and comment text, and any attachments you upload.
  • A contact email if you submit without an account, so the team can reply about your submission. It is stored but never displayed publicly.
  • An optional display name. If you leave it blank we show a generated pseudonym instead.
  • A random browser identifier (fb_guest_id) so your submissions share one pseudonymous identity and votes can be limited per browser.

Automatically

  • Device sessions: a session identifier with your IP address, browser user-agent, and first/last-seen times — used to keep you signed in and to enforce the one-device limit on Free and Pro.
  • Audit records of significant workspace actions, including the acting user, IP address and user-agent.
  • Password-reset requests: the requesting IP and a hashed, single-use token valid for one hour.
  • Server access logs containing IP address, request path, response status, timestamp and user-agent, kept for security and debugging.

We do not collect special-category data, we do not run advertising or analytics trackers, and we do not build profiles or make automated decisions with legal effects about you.

4. Who we share it with

We do not sell personal data. We share it only with providers who help us run the service, each bound to protect it and to use it solely on our instructions:

ProviderWhat it handles
PaddleOur Merchant of Record: processes payments, subscriptions, sales tax/VAT and invoices as the seller of record. Receives your email and billing details directly; we never receive card numbers.
Hosting providerThe servers and database that run the application and store content and uploads.
CloudflareDNS, TLS and reverse proxy for our domains; bot and abuse protection.
Email providerDelivery of transactional email such as invitations and password resets.

We may also disclose data where legally required, to enforce our terms, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

Separately, remember that a workspace owner and their team can see everything submitted to their board, including a guest submitter’s contact email on paid plans.

5. International transfers

Our providers may process data outside your country. Where data leaves the UK/EEA we rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards. Ask us at privacy@feedboardapp.com for details of the transfers relevant to you.

6. How long we keep it

  • Account and workspace data: for as long as your account exists, and then as described below.
  • Board content: until you or the workspace owner deletes it, or the workspace is deleted.
  • Device sessions: revoked when you sign out or when another device takes over; abandoned sessions become eligible for takeover after 15 minutes of inactivity.
  • Password-reset tokens: one hour, single use.
  • Support conversations: retained after a chat is closed so we have a record of what was asked and advised. You lose access to a closed chat but we keep the transcript.
  • Server access and audit logs: kept for a limited period for security and debugging, then discarded.

When you delete your account: the workspaces you own are deleted along with their posts, comments, roadmap and changelog, your device sessions are revoked, and any live subscription is cancelled. Workspaces you only joined are not deleted — content you posted there remains but is no longer attributed to you. Deletion requires your password and is irreversible. Backups may retain copies for a short period before being overwritten.

7. Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to our use of it, receive it in a portable form, and withdraw consent where we relied on it.

  • Access and correct most data yourself in Settings → Profile.
  • Delete everything you own from Settings → Profile → Danger zone.
  • For anything else, email privacy@feedboardapp.com. We aim to reply within 30 days and will not charge you for a reasonable request.

If you are unhappy with how we handled a request you can complain to your local data-protection authority. We would rather you told us first so we can put it right.

8. How we protect it

  • Traffic is encrypted with TLS. Passwords are stored as bcrypt hashes, never in plain text.
  • Access to the application uses short-lived bearer tokens tied to a server-side device session that can be revoked.
  • Uploads are validated by type and size, re-encoded before storage, and scoped to the workspace that owns them.
  • Workspace data is separated per tenant, and every authenticated read and write is scoped to the caller's workspace.
  • Internal administrative access is limited to the operator of the platform and is used to run and support the service.

No service can promise perfect security. If a breach affects your personal data and creates a real risk to you, we will notify you and any regulator we are required to inform.

9. Children

The service is not intended for children. Do not create an account if you are under 16 (or the age of digital consent where you live, if higher). If you believe a child has given us personal data, contact us and we will delete it.

10. Cookies

We use a small number of cookies, all of them necessary or functional — no advertising or analytics trackers. See the Cookie Policy for the exact list, purposes and lifetimes.

11. Changes to this policy

We will update this page when our practices change and revise the “last updated” date. For material changes affecting account holders we will give notice by email or in the app.

Questions

Email support@feedboardapp.com for general questions, or privacy@feedboardapp.com for anything about your personal data.