Back to SuggFeed

Privacy Policy

Last updated: 28 September 2026

1. Introduction

SuggFeed is a feedback platform that lets anyone submit complaints, suggestions, or other feedback anonymously and track its progress. This policy explains what data we collect, why we collect it, and how we protect it.

2. What We Collect

2.1 Submissions

When you submit feedback, we store the text content, category, optional attachments, and a randomly generated anonymous tracking token. We do not store your name, identity, or any other personally identifiable information alongside your submission.

2.2 Tracking Tokens

A one-time tracking token is generated in your browser when you submit feedback. It is stored locally on your device and is the only way to look up the status of your own submission. We cannot link a tracking token back to you.

2.3 Authenticated Staff Accounts

Staff and admin users sign in with an email and password managed by Supabase Auth. We store your email address, hashed password (never plaintext), and role assignment. Login events are logged for security auditing.

2.4 Usage Data

We collect anonymised usage metrics (page views, error events) via our analytics provider. No cross-site tracking cookies are used.

3. How We Use Your Data

  • To display approved feedback in the public feed.
  • To allow you to track the status of your own submission.
  • To enable staff to review, respond to, and moderate submissions.
  • To detect abuse and enforce our acceptable-use policy.
  • To improve the platform through aggregated analytics.

4. Data Retention

Approved or actioned submissions are retained indefinitely as part of the public record. Rejected or spam submissions are deleted after 90 days. Tracking tokens stored in your browser expire after 12 months of inactivity.

5. Third-Party Services

  • Supabase - database, authentication, and file storage.
  • Cloudflare Turnstile - bot/spam protection at submission time.
  • Vercel - hosting and edge functions.

6. Your Rights

Because submissions are anonymous, we cannot locate records tied to a specific individual without a tracking token. If you have your tracking token and wish to request deletion of your submission, contact us at the address below and we will process your request within 30 days.

Staff account holders may request access to or deletion of their personal data at any time.

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest. We implement Row-Level Security on all database tables, HTTP security headers (CSP, HSTS, X-Frame-Options), and rate limiting on all public endpoints.

8. Contact

Questions about this policy? Email us at privacy@suggfeed.app.

Terms of ServiceHome
HomeIdeasRoadmapProfile