Privacy policy
How Feedbaq handles account details, participant answers, recordings and connected AI apps.
Updated 1 October 2026
Who is responsible
Feedbaq is operated by OneAthlete ApS, a Danish company registered under CVR 44345668. Business address: Jordbærvænget 2, 2880 Bagsværd, Denmark. Contact: peter@feedbaq.to.
This notice covers feedbaq.to, Feedbaq accounts, feedback studies and the Feedbaq connection for ChatGPT and other AI apps.
OneAthlete ApS is the data controller for its own account administration, billing, support, security and website analytics. A data controller decides why and how personal data is used.
For answers collected in a customer’s study, the organisation running the workspace is normally the controller. Feedbaq processes those answers on its instructions. Its study notice should explain the research purpose and its contact details. Contact peter@feedbaq.to to arrange data-processing terms for your workspace.
Data we handle
- Accounts and workspaces: email address, profile details, sign-in information, workspace name, membership and permissions. Google sign-in supplies the profile details you authorise.
- Studies and answers: questions, study settings, typed answers, selected choices, uploaded voice recordings, narrated screen recordings, transcripts, follow-up answers and response labels. We also record response status and timing information.
- Billing: subscription, usage, customer and invoice references, and billing contact details. Stripe handles payment details; Feedbaq does not receive your full card number.
- Support and operation: messages you send us, request and error logs, IP address, browser and device information, and website traffic records. Some accounts may contain campaign attribution saved before the X advertising pixel was removed.
- Connections: the workspace, permissions and tokens used to authorise a connected app, plus tool-call outcomes needed to operate and secure the connection.
A voice or screen recording can identify someone or reveal information visible on their device. Participants should close private windows and avoid recording information they do not want to share. An answer can be personal data even when a study does not ask for a name.
Purposes and legal bases
We use account and billing data to provide the service and carry out our contract with customers. Where a user acts for a company, our legitimate interest is administering that company’s account. We use billing records to meet accounting and tax obligations.
We rely on our legitimate interests in running and protecting Feedbaq to troubleshoot problems, respond to support requests, prevent misuse and understand website traffic. These uses must be balanced against your rights. When consent is the required basis, you can withdraw it without affecting earlier lawful use.
The organisation running a study is responsible for choosing a lawful basis for its research, giving participants the required information and obtaining consent where needed. Browser permission to use a microphone or share a screen does not replace that responsibility.
Account details are needed to sign in and manage a workspace. Checkout requires billing details. A study’s required questions are set by its organiser; you can choose whether to take part.
AI and connected apps
Feedbaq uses the OpenAI API to transcribe audio and generate follow-up questions when enabled. Transcription sends recorded audio for processing. Follow-ups use the relevant question, instructions and answer text, including transcripts and earlier replies where needed.
When answer classification is configured, Feedbaq sends question and answer text, including transcripts and relevant parent replies, to TypeSafe’s Jev API to generate research labels and insight scores.
OpenAI states that API inputs and outputs are not used to train its models by default, unless the customer opts in. Its API data controls describe retention for security and abuse monitoring. Feedbaq’s use of the API does not imply that every provider copy is deleted immediately.
Connecting ChatGPT or another AI app authorises access to your selected workspace under the permissions shown during connection. Depending on those permissions, the app can read studies and responses, create or edit studies and publish a study when instructed. Review what you ask it to do and only connect apps you trust with your research data.
The connected app receives the data returned by Feedbaq’s tools and handles it under its own terms and privacy policy. Disconnecting or revoking access stops future authorised access; it does not remove data the app has already received. Contact peter@feedbaq.to if you need help revoking a connection.
AI text can be wrong. Feedbaq’s generated follow-ups and labels support research; we do not use them to make decisions that produce legal or similarly significant effects on participants.
Service providers and other recipients
We use these providers for the parts of the service described below:
- Cloudflare: hosting, network security and media storage or delivery, including R2 and Stream where used.
- Supabase: account authentication and application databases.
- OpenAI: the AI processing described above.
- TypeSafe: Jev answer classification when configured.
- Resend: transactional email delivery.
- Stripe: checkout, subscriptions, invoices and payment administration. See Stripe’s privacy policy.
- Google: Google sign-in when selected, support email and fonts on study pages where configured.
Workspace members can access research data according to their permissions. We may also disclose data when required by law, to handle a legal claim or to protect the service and its users. We do not sell participant answers.
Providers may process data outside Denmark and the European Economic Area. Their data-processing agreements describe applicable transfer safeguards, including European Commission standard contractual clauses or an applicable adequacy decision. See the agreements for Cloudflare, Supabase and Resend. Ask peter@feedbaq.to for information about safeguards relevant to your workspace.
Storage and deletion
Uploaded voice recordings stay with the response until it is deleted. They do not have a fixed automatic expiry.
Uploaded screen recordings, transcripts, typed answers and choices stay with the response until it is deleted. They do not have a fixed automatic expiry.
A workspace member with permission can delete a response. A successful response deletion removes its media from active storage and deletes the response records. Workspace deletion removes its application records, but media cleanup is a separate process. Contact us if you need confirmation that remaining media has been removed.
We retain account and operational information for as long as needed to provide the service, investigate problems and meet legal obligations. Support correspondence is retained as needed to resolve the request and maintain a record of it. Billing records may need to remain after an account or workspace closes because of accounting, tax or legal requirements.
Deletion from the active service does not instantly remove copies in provider backups or security logs. Those copies follow the relevant provider’s retention process. Data already exported or returned to a connected app is controlled by its recipient.
Browser storage and website analytics
Feedbaq uses browser storage for sign-in sessions, participant access and resuming an answer. These functions keep the service working. Blocking or clearing that storage may sign you out or prevent you from resuming.
Our own website analytics record the visited path, referring site and traffic channel. A salted hash of IP address and browser information helps count visitors. We store that hash rather than the raw IP in the traffic table. It is pseudonymous data, and we use it to understand visits to Feedbaq.
The X advertising pixel has been removed. Feedbaq no longer loads it or sends signup conversions through it. Information already sent to X remains subject to X’s own privacy policy and deletion controls.
Your rights and requests
Depending on the applicable law, you can request access to your personal data, correction, deletion, restriction and a portable copy. You can object to processing based on legitimate interests and withdraw consent where consent is used. These rights have legal limits, including records we must keep by law.
Email peter@feedbaq.to. We may need information to verify your identity before acting. For a study answer, contact the study organiser first; Feedbaq will assist it with requests. If you cannot identify the organiser, send us the study link.
You can complain to the Danish Data Protection Agency, Datatilsynet, or the relevant supervisory authority where you live or work.
Updates to this notice
We will update this page when our practices change. The date at the top identifies this version. Where a change requires notice or consent under applicable law, we will provide it.
Questions? Get in touch through the Help center.