Privacy Policy
Effective July 3, 2026
This Privacy Policy explains how Pixlburst, LLC (“fdbck,” “we,” “us”), a Delaware limited liability company, collects, uses, and shares information in connection with the fdbck website, dashboard, embeddable feedback widget, feedback API, public board, and the fdbck worker (together, the “Service”). fdbck is built to hold as little data as possible; the sections below are the load-bearing facts, not marketing.
Two roles. fdbck plays two different roles depending on whose data is involved, and this Policy is organized around that split:
- As a controller, for data about the developers and teams who sign up for and administer an fdbck account (“Account Owners”) — e.g. your email, GitHub identity, and project configuration.
- As a processor (service provider), for the feedback that an Account Owner's own end users submit through the widget or API on the Owner's application (“End-User Feedback”). Here the Account Owner is the controller; fdbck only processes that data on the Owner's behalf and under their instructions. If you submitted feedback through a product that embeds fdbck, that product's privacy policy governs your relationship — please contact them for requests about your data.
1. The privacy guarantees that don't change
- No model keys. fdbck never stores Anthropic, OpenAI, Google, or any other AI-provider credentials. All triage and code generation runs on your machine via the fdbck worker, using your own AI subscription and credentials.
- No source code. fdbck never clones, stores, or reads your repository. The worker checks out and edits code locally on your machine with your own
gitandghcredentials; only the resulting pull request appears on GitHub, under your account. - We don't sell your data or End-User Feedback, and we don't use it to train AI models.
2. Information we collect
2.1 Account Owner data (fdbck is the controller)
- Account & identity. Your email address, and — if you sign in with GitHub — your GitHub username, user ID, and avatar URL, used to authenticate you and link your installation.
- Project configuration. The repositories you connect, your widget and board settings, automation thresholds, and notification preferences.
- Operational state. The queue and run state needed to coordinate your worker (which item is being triaged or fixed, PR status pulled from GitHub, timestamps, error messages), and a hashed worker token that authenticates your worker to our API.
- Communications. Emails you send us, and email you opt into (e.g. the daily digest or magic-link sign-in).
2.2 End-User Feedback (fdbck is the processor)
- The submission. The message an end user types, the page URL and route, and page context the widget captures to help locate the relevant code (the current page title, visible UI text, framework, and component identifiers the Owner declares).
- Optional identifiers. A
user_idthe Owner's app passes. Opaque to fdbck. - Reporter email. An email address a submitter may voluntarily enter in the widget — collected only when they provide it, and used solely to send them a single “your feedback was fixed” notification when the fix ships. It is stored separately from the feedback content, never displayed publicly, and never included in the context given to the Owner's AI agent. The notification email contains a one-click link that removes the address; we retain it only until the item is deleted or that link is used.
- Optional repro capture. If the Account Owner enables it, a submitter may attach a screenshot of the current page — captured only after they explicitly opt in, with a preview and the ability to remove it, and with password fields always masked — and the widget may include recent console errors and failed network requests (method, path, and status only; never headers, cookies, request bodies, or query strings). Both are PII-scrubbed, visible only to the Account Owner, and never shown on any public surface.
- Technical metadata. The submitting browser's user-agent string. The widget does not set advertising or cross-site tracking cookies; a small first-party token may be stored in the visitor's browser only to deduplicate votes on a public board.
PII scrubbing. Before storage, the captured page context is scrubbed for obvious personal data (email addresses, phone numbers, payment-card numbers, and IP addresses), and we compute a separately-scrubbed copy of the feedback message that is the only version ever shown on any public surface. The raw message the end user typed is retained for the Owner and their code agent, since the Owner needs it to act on the report.
2.3 Website & logs
Our hosting and infrastructure providers automatically process standard server logs (IP address, request time, user-agent) to operate and secure the Service. We keep our marketing site deliberately light and do not run third-party advertising trackers on it.
2.4 Cookies & local storage
- Dashboard. When you sign in to the fdbck dashboard we set a first-party, strictly-necessary session cookie to keep you logged in. It is not used for advertising or cross-site tracking.
- Widget. The embeddable feedback widget sets no cookies and no cross-site trackers on your users' browsers.
- Public board. If a visitor votes on a public board, we store one small first-party token in their browser's local storage solely to remember their vote and prevent duplicates. It is a random identifier, contains no personal information, and is not shared or used to track across sites.
- Product analytics. On fdbck's own website and dashboard we use Vercel Web Analytics, a privacy-focused, cookie-less analytics service provided by our hosting provider. It records aggregate page views and a small number of anonymous product-milestone events (for example that an account was created — never who), does not use cookies or persistent identifiers, and does not track visitors across sites. No analytics run inside the embeddable widget on your own site.
3. How we use information
- To provide, operate, secure, and improve the Service.
- To route End-User Feedback to the correct Account Owner, triage it, and coordinate the Owner's worker — strictly on the Owner's behalf and instructions.
- To authenticate you, prevent abuse, and enforce rate limits and our Terms.
- To send transactional and service messages (sign-in links, status updates a submitter opts into, digests you enable). We do not send marketing email you didn't ask for.
- To comply with law and respond to lawful requests.
AI processing. The AI that classifies feedback and drafts fixes runs on the Account Owner's own machine, under the Owner's own AI-provider account and that provider's terms — not on fdbck's servers. fdbck treats submitted feedback as untrusted data to be analyzed, never as instructions to be followed.
4. Legal bases (GDPR / UK GDPR)
Where the EU or UK GDPR applies to Account Owner data, we rely on: contract (to provide the Service you sign up for); legitimate interests (to secure the Service, prevent abuse, and operate our business, balanced against your rights); and consent where required (e.g. optional emails), which you may withdraw at any time. For End-User Feedback, the Account Owner is the controller and is responsible for establishing a lawful basis and providing any notice or consent to their end users; fdbck processes it only under the Owner's instructions, as described in our Terms, which include our data-processing commitments. Account Owners who require a signed Data Processing Agreement (including Standard Contractual Clauses) can request one at privacy@fdbck.app.
5. How we share information
We share information only as follows, and never sell it:
- With the Account Owner. End-User Feedback is shared with the Owner whose widget key it was submitted to — that is the point of the Service.
- Sub-processors. Vendors that host and run the Service on our behalf, under contract and confidentiality obligations — currently our application host and serverless platform, our managed Postgres database provider, our transactional email provider, and GitHub (for authentication, repository access to open pull requests, and PR status). A current list is available on request at privacy@fdbck.app. We will make a reasonable effort to notify Account Owners before adding or replacing a sub-processor that handles personal data, so you have an opportunity to object.
- Legal & safety. When required by law, to enforce our Terms, or to protect the rights, safety, and security of fdbck, our users, or the public.
- Business transfer. In connection with a merger, acquisition, or sale of assets, subject to this Policy.
Your GitHub connection is a GitHub App you install and can revoke at any time from your GitHub settings. It reads pull-request status and, only if you enable it, performs auto-merge.
6. The public board & status links
- Private by default. Feedback is never public unless an Account Owner turns on their public board and explicitly publishes an individual item.
- What appears publicly. Only the title the Owner chooses (or a PII-scrubbed summary), the item's status, and its vote count — never the raw message, a submitter's email, or the captured page context.
- Status links. Each submission may generate a private, unguessable status link the submitter can use to follow their own item. That page is not indexed by search engines and shows only the scrubbed message and a simplified status.
7. Data retention
We retain Account Owner data for as long as your account is active and as needed to provide the Service. We retain End-User Feedback on behalf of the Account Owner until the Owner deletes it, deletes the project, or closes their account, after which it is deleted or anonymized within a commercially reasonable period, except where a longer period is required by law. Short-lived tokens (sign-in and status tokens) are stored only as one-way hashes.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Account Owners can exercise many of these directly in the dashboard (editing settings, deleting feedback, or deleting the account and its data). For anything else, contact privacy@fdbck.app; we will respond within the timeframe the applicable law requires. We will not discriminate against you for exercising these rights.
End users: because fdbck processes your feedback on behalf of the app you submitted it to, please direct access or deletion requests to that app's operator. We will assist them in fulfilling your request.
8.1 California (CCPA / CPRA)
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not in the preceding 12 months. The categories of personal information we collect, the purposes, and the disclosures for a business purpose are described in Sections 2–5. California residents have the rights to know, delete, correct, and to non-discrimination, exercisable via the contact above.
8.2 European Economic Area & UK
You have the right to lodge a complaint with your local supervisory authority. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Security
We use technical and organizational measures appropriate to the risk: encryption in transit (TLS), secrets and tokens stored as one-way hashes or encrypted at rest, least-privilege access, per-tenant isolation, and strict content-security and framing policies. No method of transmission or storage is perfectly secure, but the architecture is deliberately designed so that a compromise of fdbck cannot expose your AI keys or your source code — because we never hold them. If we become aware of a data breach affecting your personal data, we will notify affected Account Owners without undue delay and provide the information the applicable law requires.
10. Children
The Service is intended for developers and businesses and is not directed to children under 16. We do not knowingly collect personal information from children. Account Owners are responsible for ensuring their own widget is not used to knowingly collect such information.
11. International
We operate from the United States, and information we process may be stored and handled in the United States and other countries where we or our sub-processors operate. By using the Service you understand your information may be transferred to and processed in those locations, subject to the safeguards in Section 8.2.
12. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify Account Owners. Your continued use of the Service after an update means you accept the revised Policy.
13. Contact
Pixlburst, LLC — a Delaware limited liability company. Questions or requests about privacy: privacy@fdbck.app. General inquiries: hello@fdbck.app.
This Policy is provided for transparency and is not legal advice. If you are an Account Owner subject to specific regulatory obligations, review it against your own requirements.