Privacy
This is a pre-launch draft. Counsel must review it before paid launch. It is not a substitute for a finished privacy policy.
AppFeedback and appfeedback.net are working choices pending the naming and domain gate. No support email is published here because none is in service.
Who this covers
This draft covers people who sign in to the AppFeedback dashboard and people whose in-app feedback is stored through Preview HTTP ingest. It does not assume we control a production domain yet.
What we collect now
If you join the waitlist, we store your email address and signup date to contact you about early access. Joining does not create a dashboard account. Waitlist addresses are not displayed publicly.
Sign-in uses an email address and a one-time magic link. We store the account, session, personal workspace, membership, project records you create, hashed SDK keys, pending workspace invites (email and a hashed invite token), and an optional current-workspace cookie (workspace uuid only). Preview HTTP ingest also stores in-app feedback title, body, kind, platform, optional app version, a SHA-256 reporter token hash scoped to the project, HMAC-SHA256 of (project id, external user id) when a customer-signed reporter JWT is used (raw sub is not stored), public JWK material operators upload for JWT verification (kty, crv, x, y — private keys are not stored), hashed idempotency keys, and append-only submission activity. Preview GET /api/v1/feedback/mine returns a reporter’s own stored submissions for that project (id, kind, title, body, platform, app version, semantic status, shippedInVersion, created and updated times). It does not return other reporters’ content, operator notes, member identity, staging flags, or merge-target data. We also store release version, title, notes, platforms, and state; which completed items were attached; shipped_in_release_id on those items and their merge sources at publish; and unread shipped-update rows keyed by reporter token hash until acknowledged. The dashboard also stores per-project status labels; each item’s status and updated_at; per-platform hidden, staged, or public visibility; vote rows (project, feedback item, reporter hash via reporter_id, created_at); an optional merge tombstone id; and operator internal notes plus append-only moderation activity (member user id, action, before/after snapshots). Dashboard /board shows published titles, bodies, and vote counts to signed-in members. Signed-in /inbox and /board show an optional assignee to workspace members only. Reporter identity remains a SHA-256 token hash with no name or email. Operator internal notes and status-change activity are stored as append-only feedback activity rows, visible to workspace members, and not returned on the Preview ingest or My requests responses. Optional assignee_id (workspace member user id) on feedback items, and assignee_changed rows on append-only moderation activity (member actor, before/after assignee id and display name). Assignee is not returned on Preview ingest, mine, or public board HTTP. The reporter token itself is not stored. Preview rate limits store a SHA-256 hash of a best-effort client IP; the raw IP is not stored in that table. The dashboard shows a new key once at creation or rotation; later views show only the prefix. We store Stripe customer id, subscription id, price id, plan, billing status, and Stripe event ids for Checkout and Portal. Card numbers and bank accounts are collected by Stripe, not stored here.
Members can also record feedback in the dashboard with a title, body, kind, platform, and optional app version. These manual items stay private by default, have no reporter identity, and record the member who created them in feedback activity.
What we plan to collect
Later tasks may store App Store reviews. Feedback is private by default. Public replies remain a future reviewed external effect. Other external effects will require a person to review them. Those pipelines are not live.
How we use it
Dashboard data is used to operate the workspace you signed into: authenticate you and isolate tenants. We will not sell reporter content. There are no advertising trackers on these pages.
Sharing
Hosting, email delivery, and future store or model providers may process data as processors. No processor list is final. Publishing to the Preview board discloses title, body, kind, platform, status label, vote count, and optional shipped version to anyone who holds that project’s SDK key. Internal notes, reporter identity, and the other platform’s visibility stay private. We will not share customer-authored content publicly unless you choose an external effect and review it.
Retention, export, and deletion
Signed-in members can download a workspace JSON export from /settings/data (product records; no SDK secrets, reporter token hashes, or other workspaces). The owner can delete from /settings/data. That delete removes application tenant rows and dashboard sessions at once. A redacted record that the delete happened is kept (workspace id, user id, counts — not titles, bodies, notes, or tokens). The sign-in email remains. Export stays available on that page until the workspace is gone. After downgrade, collected data stays readable and export stays available; paid ingestion and sync will pause. Backup restore has not been demonstrated; this page does not claim backup media is purged.
Cookies
The dashboard sets an HTTP-only session cookie after a verified magic link, and may set an HTTP-only af_workspace cookie with the current workspace uuid. These marketing pages do not need an account cookie.
Contact
Do not use a guessed mailbox. Until a reviewed privacy contact exists, treat this draft as informational and use the signed-in product for account data you already created.
Changes
This text will be replaced after legal review and before charging for Indie. If the working name or domain changes, this page will say so.