1. Operator & Scope
This Privacy Policy describes how TellBack (referred to as "Tellback", "we", "us", or "our") collects, uses, and discloses information when you use our website, developer dashboards, public widget scripts, and related feedback-collection tools.
Our services are designed to help developers and software teams capture, triage, and diagnose feedback from site visitors and clients, converting unstructured bug reports into formatted developer tasks and prompts.
2. Data We Collect
We collect information in three ways: information you provide directly, information collected automatically, and billing details processed by our payment processors.
| Category | Data Points Collected | Purpose |
|---|---|---|
| Profile | Name, email address, profile picture (photoURL), auth provider ID. | Identity verification, login authentication. |
| Workspace | Settings, project names, whitelisted domains, site API keys, team member lists. | Workspace management, API request validation. |
| Feedback Logs | Submitted reviews, voice notes, screenshots, visible text snippets, click timelines, and navigation paths. | Triage and generate AI developer tasks. |
| Diagnostics | Console errors, uncaught exceptions, network failures, rage clicks, dead clicks, browser context, OS type, device model, and viewport size. | Provide friction context to developers. |
| IP Geo Lookup | Raw IP (processed in memory then immediately discarded). | Determine country/region context. |
IP Address Privacy Note
Visitor IP addresses are processed temporarily in server memory to determine geographic regions. Raw IP addresses are **discarded immediately** after lookup and are never stored in databases or server logs.
3. How We Use Data
We use the collected information for the following business purposes:
- Providing, maintaining, and protecting the TellBack dashboard and widget integrations.
- Generating structured developer tasks, bug summaries, and prompt specifications using AI model integrations.
- Tracking subscription usage, enforcing plan boundaries, and processing payments securely via Stripe.
- Diagnosing performance issues, resolving server exceptions, and securing workspaces against unauthorized access.
- Preventing malicious script injections, tracking rage-click rates, and monitoring widget abuse.
- Analyzing website traffic and usage behavior via Google/Firebase Analytics to optimize outreach and interface layout (respecting user-configured cookie preferences; no feedback text, screenshots, voice notes, or AI prompts are tracked for analytics).
4. AI Processing Boundaries
We use enterprise-grade **Google Cloud Vertex AI endpoints** to analyze captured feedback descriptions, click events, console logs, and element states, converting them into structured markdown tasks.
Our AI Privacy Pledge:
- Your data is never sent to public or consumer-facing AI models.
- Google Cloud is contractually prohibited from retaining or using your data to train foundational models.
- Workspace owners can toggle off specific context variables (such as voice notes, screenshots, or timelines) from being sent for AI analysis.
6. Sensitive Data & Redaction Controls
TellBack provides built-in client-side safeguards to prevent data leaks. The widget automatically masks password input fields and filters typical credentials from URL query strings before upload.
Developer Guidelines: You must not configure the widget to capture pages containing sensitive financial credentials, medical history, or government identifiers. Developers should use the data-tellback-ignore attribute on subtrees to explicitly prevent sensitive input content from being recorded.
Product Analytics Protection:
We apply client-side safeguards intended to prevent sensitive product content—such as Stripe transaction IDs, customer feedback text, invite or authentication tokens, and raw AI queries—from being sent to analytics events. Users can adjust or revoke consent for analytics cookies at any time via the Cookie Settings trigger in the footer.
7. Retention & Deletion
We enforce deterministic data cleanup loops based on active subscription tiers:
| Tier | Retention Schedule |
|---|---|
| Free (Solo) | Session logs deleted after 7 days. Tasks, screenshots, and audio reviews deleted after 30 days. |
| Paid (All Tiers) | Session logs deleted after 30 days. Tasks, screenshots, and audio reviews deleted after 365 days. |
Workspace owners can trigger complete, immediate deletion of individual records, projects, or the entire workspace directly from the settings panel.
8. Your Rights & Contact
You may request access to, correction of, export of, or permanent deletion of your personal account details by contacting us.
For questions regarding security practices, Vertex AI boundaries, or billing integrations, contact us at: hello@tellback.io.