Privacy Policy

Last updated: August 2026

This English version is a translation for convenience only. The German version of this page is legally binding.

1. Controller

Dynamic Frameworks UG (haftungsbeschränkt), represented by its managing director Christian Castro Büch, Bad Nauheimer Straße 3, 64289 Darmstadt, Germany. Email: christian@dynamic-frameworks.com

2. Hosting and Infrastructure

Feedbapp is operated on Vercel Inc. (web hosting/CDN). When you visit the website, Vercel processes technically necessary server log data (IP address, timestamp, requested URL, user agent) to deliver and secure the service (Art. 6(1)(f) GDPR). The database, authentication and file storage run on Supabase in the Frankfurt (EU) region. Data processing agreements including the EU Standard Contractual Clauses are in place with both providers, insofar as data is transferred to third countries.

3. Registration and Login (Dashboard)

For the operator dashboard, we process your email address to sign you in via magic link or one-time code (Art. 6(1)(b) GDPR). Emails are sent via Resend (email delivery provider). Session cookies are technically necessary; no tracking or analytics cookies are set.

4. Feedback Widget on Our Customers' Websites

Website operators can embed the Feedbapp widget on their pages. If you submit feedback there, the following data is transmitted to and stored by Feedbapp:

  • your feedback text and the category you chose,
  • a screenshot of the visible page area (you can review it before submitting),
  • technical diagnostic data from the page you visited: the most recent console messages, the URLs of failed network requests (without content), an excerpt of the page text, the page URL, and browser/viewport information. Recognizable credentials (e.g. tokens or keys in URLs) are automatically redacted before transmission,
  • optionally your email address, if you want us to follow up,
  • a random session ID, which is only stored in your browser (localStorage) once you submit.

The respective website operator is the controller for this processing; Feedbapp processes the data as a processor under Art. 28 GDPR. We provide business customers with a data processing agreement (DPA) upon request.

5. AI-Assisted Processing (OpenAI)

Incoming feedback is automatically classified and grouped by topic. For this, we transmit the following to the OpenAI API (sub-processor): the feedback text, and the name, description, goals and priorities of the affected project, plus, for bug reports, an excerpt of the technical details of the clicked element (first 300 characters). When a project owner summarizes a topic, up to 50 feedback texts from that topic are transmitted for this purpose.

OpenAI processes this data in the USA. The transfer is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as an appropriate safeguard within the meaning of Art. 44 et seq. GDPR. A data processing agreement is in place. OpenAI does not use this data to train its models.

Screenshots are not transmitted to OpenAI. The AI evaluation works exclusively on text; no image analysis takes place. Also not transmitted: the page URL, browser identifier, email address, name and session identifier of the person giving feedback.

6. Error Monitoring and Traffic Analytics

We do not use advertising cookies or advertising tracking. A cookie banner is therefore not required. We use two services for our operations, both of which work without storing anything on your device:

Sentry (error monitoring). So that we notice crashes and errors without affected users having to report them, we collect technical error reports: the error message, the location in the code, browser and device type, and the URL called within Feedbapp. Inputs, feedback content, credentials and email addresses are technically stripped before submission. The legal basis is our legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR). The provider is Functional Software, Inc. (Sentry), USA; a data processing agreement is in place, and the transfer is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Session replay recording does not take place.

PostHog (traffic analytics, public pages only). On our public pages, homepage, pricing, legal notice and this privacy policy, we count page views to understand which content is read. Measurement is cookieless: nothing is stored on or read from your device, and there is no recognition across multiple visits. In the logged-in area (dashboard), no traffic analytics take place. We process the page visited, any campaign parameter (e.g. utm_source), browser type and an approximate country-level location. The legal basis is our legitimate interest in shaping our offering to meet user needs (Art. 6(1)(f) GDPR). The provider is PostHog, Inc.; processing takes place exclusively on servers within the European Union (PostHog EU Cloud); no transfer to third countries takes place.

7. Retention Period

Feedback data (including screenshots and diagnostic data) remains stored until the respective project owner deletes it or the project is removed. Account data is removed when the account is deleted. You can send deletion requests to the email address named above at any time.

8. Your Rights

Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may also lodge a complaint with a data protection supervisory authority: the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wiesbaden.

9. Waitlist

On our homepage you can join the waitlist for the closed beta with your email address. We use this address exclusively to notify you about your beta access (Art. 6(1)(b) GDPR: taking pre-contractual measures at your request). Emails are sent via Resend (email delivery provider). The address remains stored until your access is activated or you remove yourself from the waitlist: a short message to the email address named above is sufficient for that.