FeedbackDropBeta

What FeedbackDrop collects — and what it never touches

You're about to put our script tag on your site, so you deserve specifics, not assurances. This page lists exactly what the widget captures when one of your users submits feedback, what it deliberately ignores, what gets scrubbed automatically, and who can ever see the data. The short version: we capture a lot of technical context — that's the product — and we work hard to capture as little personal context as possible.

What we capture when a user submits feedback

Nothing is sent anywhere until the user submits. Buffers fill locally in the page and are discarded if they never do.

What we never capture

What gets scrubbed automatically

Before data leaves the user's browser:

Your controls

Tag anything sensitive and the widget treats it accordingly:

(Equivalent CSS classes exist for each.)

Honest limits — read this part

Where your data lives

PostgreSQL (AWS RDS) and S3, in AWS us-east-1. Encrypted at rest (RDS storage encryption; S3 server-side AES-256) and in transit (HTTPS everywhere — the storage bucket rejects unencrypted connections). Screenshots and HTML snapshots are served to your dashboard through presigned URLs that expire after one hour; the storage bucket blocks all public access.

Who can see it

Retention and deletion

Captured feedback is retained while your account is active. Deleting a workspace — or your whole account — permanently deletes its captured data: the database records and the stored screenshots and page snapshots. You can also request deletion at any time via support@feedbackdrop.ai.

For the formal version of all of this, see our Privacy Policy and Terms of Service.