Legal
Privacy Policy
How Feedi collects, uses, stores, and protects personal data — written to be precise and easy to inspect.
1.Who we are and scope
Feedi (“Feedi”, “we”, “us”) is a headless feedback service for mobile applications, operated by Daniel Munoz as an independent sole operator based in Germany. This Privacy Policy explains what personal data we handle, why, and the choices and rights you have.
It applies to our website, dashboard, APIs, and mobile SDKs (together, the “Service”). If you have any questions, contact us at [email protected].
2.Our two roles: controller and processor
Feedi handles personal data in two distinct capacities, and it matters which one applies to you:
- As a controller — for the account data of developers who sign up for Feedi (such as your email address, billing records, and project configuration). This policy governs that data.
- As a processor — for the feedback content that your app's end users submit through the SDK. Here, the developer who operates the app is the controller, and Feedi only processes that data on the developer's documented instructions.
If you are an end user who submitted feedback inside someone's app, the developer of that app is responsible for telling you how your feedback is used. Direct access or deletion requests for that feedback to that developer; Feedi will assist them as their processor.
3.Information we collect
Account data (we are the controller)
- Account details — the email address you use to sign in, and any name or organisation you choose to provide.
- Authentication data — magic-link tokens and signed session cookies used to keep you logged in.
- Project configuration — project names, settings, delivery destinations (such as webhook URLs), and write keys, which are stored hashed and never in plain text.
- Billing data — for paid plans, subscription status and records returned by our payment processor. Full card details are handled by the processor and are never stored by Feedi.
- Operational and security logs — limited technical records such as IP address, timestamps, and request metadata, used to keep the Service running and to prevent abuse.
Feedback data (we are the processor)
- Feedback content that an app's end users submit through the SDK — the message text and any optional metadata the developer chooses to attach.
- Delivery records needed to route that feedback to the developer's chosen destinations.
4.What we do not collect
Feedi is deliberately narrow about data. Through our SDKs and Service, we do not collect:
- Screenshots or screen recordings.
- Device identifiers, advertising IDs, or fingerprinting signals.
- Background location or sensor data.
- Analytics-style behavioural events or hidden tracking.
- Any data your app does not explicitly send to us.
5.How we use data and our legal bases
For account data we control, we rely on the following legal bases under the EU/UK GDPR:
- To provide the Service — creating your account, running your projects, and delivering feedback (Art. 6(1)(b), performance of a contract).
- To authenticate you — sending magic-link sign-in emails and maintaining your session (Art. 6(1)(b), contract).
- To secure the Service — preventing abuse, fraud, and unauthorised access, and keeping operational logs (Art. 6(1)(f), legitimate interests).
- To take payment — managing subscriptions and invoices for paid plans (Art. 6(1)(b), contract; Art. 6(1)(c) for tax and accounting obligations).
- To send essential service messages — such as security or material change notices (Art. 6(1)(f), legitimate interests). Any non-essential email would rely on your consent.
For feedback data, the legal basis is determined by the developer who operates the app, not by Feedi. We process it only to provide the Service to that developer.
6.Cookies and local storage
Feedi uses a single, strictly necessary signed session cookie to keep you authenticated after sign-in, and limited browser local storage for preferences such as your theme. We do not use analytics, advertising, or third-party tracking cookies, so no cookie-consent banner is required to use the dashboard.
7.Service providers (subprocessors)
We keep our vendor list short and use providers only where needed to run the Service. The current subprocessors we rely on are:
- Cloudflare — hosting, the application database (D1), and compute (Workers) that run the Service and store your data in your chosen region (EU or US).
- Mailgun (EU) — transactional email for magic-link sign-in and notification messages, sent through an EU email endpoint.
- Stripe — payment processing for paid plans, including subscription and billing records. Full card details are handled by Stripe and never stored by Feedi.
- GitHub — optional issue integration, used only when you choose to route feedback to a GitHub repository; data is shared only to fulfil the routing you enabled.
These providers operate internationally. Your chosen region (EU or US) determines where your feedback data is stored; it is not a claim that every provider, process, or onward subprocessor runs exclusively in that region. Where a transfer leaves the EEA or UK, we rely on a lawful transfer mechanism as described below.
Each provider acts as a processor or onward subprocessor under appropriate data-protection terms and may process data only to provide their service to us. We will give advance notice of material changes to the providers we rely on so that developer-controllers can object where they have grounds to.
Data Processing Agreement. For feedback data, Feedi acts as your processor. A Data Processing Agreement (DPA) reflecting this and listing the subprocessors above is available on request — email [email protected] and we will provide the current version.
8.Where your data is stored and international transfers
You choose your data region when you create your account — the EU or the US — and your feedback data is stored in that region. This describes where feedback data is stored; it is not a claim that every process or subprocessor runs exclusively in one region.
Where personal data is transferred outside the EEA or UK (for example, if you select the US region, or where a provider operates internationally), we rely on a lawful transfer mechanism — such as the EU–US Data Privacy Framework where the recipient is certified, and/or the European Commission's Standard Contractual Clauses with supplementary measures. We will provide details of the mechanism used on request.
9.Data retention
- Account data is kept for as long as your account is active and for a short period afterwards to handle wind-down, then deleted.
- Feedback data is retained according to your plan's history window and your instructions, and is removed when you delete the item, the project, or your account.
- Operational and security logs are kept only for a short period needed for reliability and abuse prevention.
- Billing records are retained as long as required to meet tax and accounting obligations.
10.Security
We protect data with measures including encryption in transit (TLS), hashing of public write keys, signed webhook delivery, magic-link authentication with signed session cookies, least-privilege access, and regional data isolation. No method of transmission or storage is perfectly secure, but we design the Service to minimise the data at risk in the first place.
11.Personal data breaches
If a personal data breach occurs, we will act on our legal obligations: as a controller, we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals, and affected individuals where the risk is high. As a processor, we will notify the affected developer-controllers without undue delay so they can meet their own obligations.
12.Your rights
If the EU/UK GDPR applies to you, you have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to rights regarding automated decision-making. You may also withdraw consent where processing is based on consent.
To exercise these rights over your Feedi account data, email [email protected]. We will respond within one month, extendable by a further two months for complex requests. You also have the right to lodge a complaint with your local data protection authority. For feedback data, please contact the developer whose app you used.
13.US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know, access, correct, and delete personal information, and to opt out of its sale or sharing for cross-context behavioural advertising. Feedi does not sell or share personal information for such advertising, and does not discriminate against you for exercising your rights. Your state may grant additional rights; contact us to exercise them.
14.Children's privacy
Feedi is a business tool and is not directed to children. We do not knowingly collect personal data from children through our account sign-up. Developers must not use Feedi to collect data from children without a valid legal basis and the consents required in their jurisdiction; that responsibility sits with the developer as controller of the feedback.
15.Automated decisions and AI
Feedi does not carry out automated decision-making that produces legal or similarly significant effects, and it does not use your feedback content to train AI models. If we ever introduce AI-assisted features, we will update this policy, disclose the processing, and keep the no-training commitment unless you are clearly told otherwise.
16.Changes to this policy
We may update this policy as the Service evolves. When we make material changes, we will update the date below and, where appropriate, notify account holders by email. Continued use of the Service after an update means you accept the revised policy.
17.Contact us
For any privacy question or to exercise your rights, email [email protected] or use the contact page.