Privacy / effective 2026-07-25
Feedback++ Privacy Policy
This policy explains how Feedback++ handles data while providing website feedback, screenshots, the console, notifications, CLI/API access, and Agent Skill access.
Necessary data
Owner control
Sensitive areas excluded
1. Information we process
- Account details such as email, name, password hash, session data, and API token metadata.
- Website configuration such as name, URL, allowed feedback origins, widget settings, and notification bindings.
- Feedback text, optional contact details, page URL and title, browser/device context, viewport data, metadata, and optional screenshots.
- Operational data needed for security, rate limiting, service reliability, and abuse prevention.
2. How we use the information
- To receive, store, display, organize, and update feedback for the website owner.
- To deliver configured notifications and provide CLI, API, or Agent access requested by the owner.
- To protect the service, investigate failures, enforce access controls, and prevent abuse.
- To improve the service using aggregated operational information where appropriate.
3. Screenshots and sensitive content
Screenshots are optional. Website owners are responsible for excluding passwords, payment details, personal records, and other sensitive areas with data-feedback-private or an exclusion selector. Cross-origin content may not be captured completely.
4. Sharing and third parties
Feedback is shared with the website owner and the people or trusted Agents they authorize. Configured webhook providers receive notification payloads required for delivery. We do not treat an owner API token as public data; it should remain in a trusted terminal or server environment.
5. Retention, deletion, and export
Owners can manage feedback and websites from the console or supported API. Deleting a website or feedback can remove its associated content and screenshot. Retention may also be affected by backups, legal requirements, or operational logs.
6. Security
Feedback++ uses authenticated sessions, private API tokens, access checks, origin validation, rate limits, security headers, and protected screenshot access. No online service can guarantee absolute security.
7. Contact and updates
We may update this policy when the service or applicable requirements change. The effective date above identifies the current version.