FeedbackHiFeedbackHi

Privacy Policy

Last updated: 9 August 2026

FeedbackHi collects as little as it can get away with. Visitors leaving feedback need no account and are identified by a salted one-way hash, never by a stored IP address. There are no advertising trackers and no cross-site profiles, and nothing is ever sold.

Two kinds of people are covered here

FeedbackHi is a hosted feedback board. That means two different relationships, and this policy covers both:

  • Site owners — people with a FeedbackHi account who embed a board or widget on their own site. We decide how their account data is handled, so for that data we are the controller.
  • Visitors — people who leave feedback on someone else's board. That feedback belongs to the site owner who installed the board; we host and process it on their behalf. If you want a post removed, the owner of that board can delete it, and we can too.

What we store about site owners

  • Your email address, and — if you sign in with Google — the name and profile picture Google returns.
  • If you sign up with a password, the password is handled by our authentication provider and stored only as a hash. We never see it.
  • The projects you create: name, URL slug, description, website address, accent colour, and a project API key.
  • Ordinary server logs from our hosting provider, kept briefly for security and debugging.

What we store when someone leaves feedback

Nobody has to create an account to post or vote. What gets stored is what they typed, plus the minimum needed to keep a board usable:

  • The title and message of the post.
  • A name, if they chose to type one. It can be left blank, and posts then show as anonymous.
  • An email address, only if they chose to give one. It is never shown on the public board — only the board owner can see it.
  • A screenshot, if they attached one. Images are up to 5 MB, and are served from a public URL that is hard to guess but not secret.
  • A salted, one-way hash used to de-duplicate votes and rate-limit spam. We do not store the raw IP address alongside the post or the vote.

That hash is derived from a random identifier the widget keeps in the visitor's browser, falling back to their IP address and browser string, and it is salted per project — so the same person posting on two different boards cannot be matched across them, and the original values cannot be recovered from the stored hash.

What the widget puts in a visitor's browser

The embedded board and widget set no cookies at all. They use your browser's own local storage, on the site you are visiting:

  • fb_visitor_id — a random identifier so your upvote counts once. It is not tied to your name, email, or any account.
  • fb_prompt_… and fb_session_… — how many times you have visited and whether you already answered or dismissed a prompt, so a site does not ask you the same question twice.

Clearing your browser storage clears all of it. Nothing there is shared between different sites that use FeedbackHi.

Analytics on this website

Our own pages at feedbackhi.com use Microsoft Clarity to see which parts of the site people struggle with. It records page interactions and may set its own cookies. This runs only on our website — the SDK you embed on your site does not carry it, and never sends your visitors' behaviour to Clarity.

Who else processes the data

  • Supabase — database, authentication, and image storage.
  • Cloudflare — hosting, CDN, and the network the API runs on.
  • Google — only if you choose to sign in with Google.
  • Microsoft Clarity — analytics on feedbackhi.com only, as described above.

These providers process data to run the service and nothing else. We do not sell personal data, and we do not share it with advertisers.

How long it is kept

Feedback and votes are kept until they are deleted. Deleting a post removes it and its votes; deleting a project removes every post, vote, and screenshot belonging to it; deleting your account removes your projects and everything under them. Deletion is immediate and permanent — there is no undo, and no shadow copy kept afterwards, though backups may lag by a short period before ageing out.

Your choices

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to some processing. Site owners can do most of this themselves from the dashboard. For anything else — including a request from a visitor about a post on someone else's board — write to hello@feedbackhi.com and we will handle it. Tell us which board and which post, so we can find it.

Children

FeedbackHi is a tool for people building and running websites. It is not directed at children, and accounts are not intended for anyone under 16.

International transfers

Our providers operate globally, so data may be processed outside the country you are in, including in the United States. We rely on the safeguards those providers offer for such transfers.

Changes

If this policy changes in a way that matters, the date at the top changes with it and, for anything significant, we will tell account holders by email. Continuing to use FeedbackHi after a change means the updated policy applies.

Contact

Questions about privacy, or a request about your data: hello@feedbackhi.com. See also our Terms of Service.