Security and data handling

Feedbaq collects voice answers, narrated screen recordings and typed answers for the teams that run studies. This page explains where that data goes, who processes it, how long it stays and who can reach it. The privacy policy is the legal notice.

Recordings and transcripts

  • Voice answers are recorded in the participant's browser after they allow the microphone, then uploaded and transcribed. An answer can run up to 10 minutes.
  • Screen recordings start only after the participant chooses a window or their whole screen to share. They see a live preview while they record, and they narrate as they go. No camera is used.
  • Transcripts are stored with the response, with a timing for every word, so a quote links to its moment in the recording.
  • Participants need no account. Each response gets its own access token, so one person cannot open another person's answers.

Participants choose which window or screen to share, and see a live preview while they record, so they stay in control of what is captured.

AI processing

AI providers and what they receive
ProviderWhat it doesWhat it receives
OpenAI APITranscribes voice and screen narrationThe recorded audio
OpenAI APIWrites AI follow-up questions, when a question has themThe question, the researcher's instructions and the answer text
TypeSafe (Jev)Labels answers by topicThe question and the answer text, including transcripts

OpenAI states that API inputs and outputs are not used to train its models by default. Follow-up questions and labels support the research team; Feedbaq does not use them to make decisions about participants.

An AI agent you connect, such as Claude or ChatGPT, receives the studies and responses its tools return, and handles them under its own provider's terms.

Storage and providers

Where Feedbaq keeps data
ProviderRole
CloudflareHosting, network security, and storage of recordings and study media (R2)
SupabaseSign-in and the application database
StripeCheckout, subscriptions and invoices. Feedbaq never receives full card numbers
ResendEmail delivery

Traffic to Feedbaq is encrypted with HTTPS. Recordings are private: they play through signed links that expire after an hour, and only for members of the workspace that collected them. Providers may process data outside the European Economic Area under the safeguards in their data-processing agreements.

Retention and deletion

  • Kept until you delete them. Recordings, transcripts, typed answers and choices stay with their response. They have no fixed automatic expiry.
  • Deleting a response removes its recordings from storage and deletes its records at once.
  • Deleting a workspace removes its records. Media cleanup is a separate process; write to us if you need confirmation that the remaining media is gone.
  • Unused study images and videos, uploaded but never attached to a saved study, are removed after 7 days.

Copies in provider backups and security logs follow each provider's own retention. Data you export, or that a connected agent has already read, is controlled by whoever holds it.

Access and permissions

  • Sign-in uses a one-time code sent by email, or Google, so there is no password to manage.
  • Roles. Every workspace member can build, publish and close studies, read responses, and delete studies and responses. Admins can also invite people, change roles, manage billing and set the monthly response cap. The owner can also delete the workspace.
  • AI agents connect over OAuth with PKCE, with no API key. An agent works in one workspace with its user's role, cannot delete studies or responses, and loses access at once when you revoke it under Settings → AI agent.

Report a problem

Send security reports and privacy requests to peter@feedbaq.to. Describe the affected page and how to reproduce the problem, using sample data rather than real participant answers. Our security.txt has the same contact. To arrange data-processing terms for your workspace, write to the same address.

Questions people ask

Does Feedbaq use answers to train AI models?

No. Feedbaq sends answers to OpenAI's API for transcription and follow-up questions. OpenAI states that API inputs and outputs are not used to train its models by default.

Who can see the recordings in a study?

Members of the workspace that runs the study. Recordings are played through signed links that expire after an hour, and an AI agent can read them only through the workspace its user chose.

How long are recordings kept?

Until you delete the response. Recordings, transcripts, typed answers and choices have no fixed automatic expiry.

Where is the data stored?

Recordings and study media are stored in Cloudflare R2. Accounts and study data are in Supabase. Providers may process data outside the European Economic Area under standard contractual clauses or an adequacy decision.