Privacy Policy
Feedback Magic ("the Service", "we") is an embeddable feedback, survey, and annotation platform operated by Brincore. This policy explains what we collect, why, and the choices you have. Questions: info@feedback-magic.com.
Two kinds of people use Feedback Magic
- Customers — teams who sign up, embed our widgets on their sites, and triage responses in the dashboard.
- End users / submitters — visitors to a customer's site who submit feedback, survey responses, or annotations through a widget. For this data, the customer is the data controller and Feedback Magic is a processor acting on their instructions.
What we collect
- Account data (customers): your email address, workspace and project names, and billing status. We authenticate by emailed sign-in links — we never store passwords.
- Submission data (end users): whatever is entered into a widget — feedback text, survey answers, annotation notes — plus, where the widget is configured for it, an optional email address, an optional screenshot of the page, and automatically captured technical context (page URL, browser and OS, screen size).
- Billing data: payments are processed by Stripe. We store only your Stripe customer reference and subscription status — never card numbers.
- Anti-abuse signals: widget submissions pass through Cloudflare Turnstile and short-lived, per-IP rate-limit counters.
What we do with it
We use this data to run the Service: deliver submissions to the right dashboard, send sign-in links and one-time codes (via Resend), bill subscriptions, prevent spam and abuse, and (when a customer enables an integration) forward submissions to that customer's own ticketing system. We do not sell personal data, run advertising, or use tracking cookies — the site stores only your session and theme preference in your browser.
Pip, the in-app assistant
This one is worth reading if you use the dashboard. Pip is the AI help assistant inside the dashboard. When you ask it a question, we store your question, Pip's answer, which screen you were on, and basic performance data (response time, token counts), linked to your account and workspace. We review these conversations to improve the product — a question Pip could not answer is a gap in our documentation, and ten people asking the same thing tells us what to fix next. Conversations may also be summarised by AI to spot common themes.
We are being explicit about this because it differs from the rest of the Service: our internal admin tools otherwise show only counts and metadata, never the content of end-user feedback. Pip conversations are an exception, on the same footing as a support ticket you send us — they are you talking to us, not your end users' private submissions.
Two limits worth stating plainly. Pip does not read your end users' feedback content; it only knows the product's documentation and basic facts about your workspace such as project names, plan and widget types. And your questions are never used to train any AI model. We do no model training of any kind, and the questions are processed by Anthropic's Claude API, which under its commercial terms does not train models on API inputs or outputs. Pip conversations are deleted after 90 days. Please do not paste passwords, API keys or card numbers into Pip; if you do, rotate the credential.
Where it lives
Data is stored with Supabase (database and file storage, with row-level access controls) and served via Vercel. Screenshots are kept in a private storage bucket readable only by the workspace they belong to.
Retention & deletion
Pip conversations are deleted after 90 days. Submission data is retained until the owning customer deletes it or closes their workspace. Customers can delete individual submissions from the dashboard at any time. To request deletion of your account — or, as an end user, of a submission you made (we may route the request to the customer who controls that data) — email info@feedback-magic.com.
Your rights
Depending on where you live (e.g. GDPR or CCPA jurisdictions), you may have the right to access, correct, export, or delete your personal data, and to object to processing. Contact us and we will respond within the timelines the applicable law requires. End users can also review their own submissions on a widget's "My feedback" page using email verification.
Changes
We will post any changes to this policy on this page and update the effective date above. Material changes will be announced to customers by email.