Privacy Policy
Last updated September 2026
FDBK exists so people can hear honest feedback from the people who know them. That only works if everyone involved can trust how their words and their data are handled. So this page explains, in plain language, what we collect, why we collect it, who else touches it, and what happens to it.
What we collect, and why
- Your account. Your email address and a display name, either from you directly or from Google or Apple if you sign in that way. We use these to run your account and send you the emails described below.
- Your forms. The name you show to respondents, your questions, and any intro message you write.
- Feedback responses. When someone answers a feedback form, we store their written answers. They exist for one purpose: to be combined with other responses and synthesized into a report. The person who created the form cannot read individual responses through any part of the product, ever. They only see the synthesized report.
- Relationship context. Respondents can optionally say how they know the person. Before anything reaches the AI those words are reduced to one broad category (friend, family, coworker, partner, or other), and only that category is used in the synthesis. The exact words are never shown to the person who asked and never reach any stage that writes the report. They remain in our database, where an administrator could read them; see “Who can see what” below.
- Payments. Payments are processed by Stripe. We keep a record of what was purchased and when, and, for coaching subscriptions, the status and renewal dates. Your card details never touch our servers.
- Coaching conversations. If you subscribe to coaching, your messages and the coach's replies are stored so the conversation is there when you come back.
- Reminder emails. If you ask us to remind you about creating your own form, we store the email address you give us for that purpose.
- Email history. We log the emails we send you so we never send the same one twice.
- Product statistics. We record counts of things happening: forms created, links copied, pages opened, reports generated, payments completed. These carry no message content. Events from the feedback page are never linked to an account, and events from your own use lose their link to you when you delete your account.
The feedback page is different
The page where people answer feedback forms carries no analytics scripts, no advertising or social pixels, and no fingerprinting, and it sets no cookies while someone reads, fills in or submits a form. Our application does not store the IP addresses of people submitting feedback; an address is held in memory briefly to rate-limit abuse and is never written down or connected to any answer.
Two things are worth stating precisely rather than rounding to “nothing.” When a valid link is opened, our server adds one to a count kept against that form, with no identity, link code or device information attached, and it is not visible to the person who asked. And if a respondent chooses to save a feedback form of their own after submitting, that opt-in sets a cookie so their draft survives signing up. Answering a form never does.
How anonymity is maintained
Responses are combined with others and synthesized by AI, so no individual response is shown to the person who asked. The report is written by a multi-stage pipeline we designed, running on standard Claude models from Anthropic. We have not trained a model of our own, and no response is used to train anyone else's. On top of that, the product is built so that:
- Form creators can never see individual responses, response counts, or which link was used. Not in the app, not in emails, not in the report. Their account has no read access to any of it in the database, so this holds regardless of what the interface does.
- Reports use aggregate language. The stage that writes a report never sees the individual responses, and every report is checked against them, by a reviewing model and by a mechanical scan, before it can be published. A report that fails is rewritten from scratch, and after three attempts we hold it back rather than publish it.
- Feedback links are one-time use and carry no identity, so a link can't be tied back to more than one submission.
If you want the longer version, including the limits we can't engineer away, How anonymity works walks through the whole process step by step.
Who can see what
No customer account can read another person's data, and no account can read feedback responses at all. The person who runs FDBK holds the administrative keys to the database, as the operator of any service does, and can reach stored data directly. Those keys are used to run and repair the product, not to browse what people wrote.
We don't sell your data and we don't share it with anyone for advertising. We may disclose data if the law requires it, and if that ever happens we will tell the people affected unless we are barred from doing so.
Who else touches your data
FDBK runs on a small set of providers. Each one processes only what it needs to do its job:
- Supabase hosts our database and handles sign-in.
- Vercel hosts and serves the application.
- Anthropic runs the Claude models that write and check reports and power the coach.
- Stripe processes payments and subscriptions and holds the card details we never see.
- Resend delivers our email.
- Sentry collects error reports so we can fix faults. Errors from the feedback page are stripped down to a fixed set of technical fields before they are sent, so no answer text, relationship text or link code goes with them.
- Google and Apple verify your identity if you choose to sign in with them.
How long we keep things
- Responses on unpaid forms: kept for 3 months after the most recent response. If a report isn't purchased in that time, the responses and any draft report are permanently deleted and the form is archived.
- Purchased reports and their responses: kept until you delete your account. There is currently no way to delete a single form or report; if you want one removed, email us and we'll do it by hand.
- Feedback links: expire 30 days after they are created. Unused expired links are deleted 30 days after that.
- Reminder email addresses: kept for 6 months, then deleted unless you've created an account.
- Coaching conversations: kept while your account exists, including after a subscription ends, so your history is still there if you come back.
- Email history and payment records: kept while your account exists. Stripe keeps its own transaction records independently, as it is required to.
- Product statistics: kept indefinitely as counts. They hold no message content, and they stop being linked to you when your account is deleted.
Your rights
From your Settings page you can download a copy of your data or delete your account. The download includes your profile, your forms and links, your unlocked reports, your coaching conversations and your payment history. It deliberately excludes the individual responses people wrote for you, because those are theirs and not yours to hold.
Deleting your account is immediate: there is no grace period and nothing is recoverable. It cancels any coaching subscription, then removes your profile, forms, links, responses, reports and payment records, and clears your address from our email logs and reminder list. Stripe keeps its own record of transactions, and our aggregate counts survive with no link back to you.
You can unsubscribe from optional emails with one click in any of them. Account and report emails are the only ones that always send. If you want to correct something, or want data removed that Settings doesn't cover, email us and we'll sort it out.
Changes to this policy
If we make a meaningful change we'll update this page and the date at the top, and we'll say so by email where the change affects something you have already given us.
Contact
Questions about any of this? Email us at [email protected].