iterateToBack to home

Legal

Privacy Policy

Last updated July 24, 2026

iterateTo helps website and app owners collect user feedback. This policy explains what the service collects, why, and the choices available to the people whose feedback we process.

Template. This document is a starting point, not legal advice. Review it with legal counsel and tailor it to your business before relying on it in production.

Overview

This policy describes how iterateTo (“we”) handles personal data. For feedback submitted through the widget or API, our customer — the website or app owner who installed iterateTo — is the data controller. iterateTo acts as a data processor, handling that feedback on the customer’s behalf and under their instructions. Where our customer is the controller, please also read their own privacy notice.

What we collect

When someone submits feedback through the widget, iterateTo receives only what the panel showed the reporter before they hit send:

  • Feedback text — the message the reporter typed, and an optional category (problem, idea, or praise).
  • Optional contact email(s) — supplied by the reporter only if they want a reply.
  • Host-page context— the page’s origin and pathname (query strings and URL fragments are stripped before anything is sent), plus the page title and heading.
  • Environment — viewport size, device pixel ratio, browser, operating system, color-scheme and reduced-motion preferences, and locale.
  • Screenshots — only when the reporter chooses to add one. Screenshots are captured and masked client-side, in the reporter’s own browser: elements marked as sensitive are hidden and reporters can paint additional redactions before sending. Redactions are baked into the pixels locally, so the masked regions never leave the device.
  • Selected elements — when a reporter points at part of the page, we record labels and stable selectors for that element (not its live contents).
  • Identify metadata — optional key/value data the host site attaches (for example a plan tier or an app version) via the identify API.
  • Technical signals— the request origin and a one-way hash of the sender’s IP address (used for spam rate-limiting). We do not store raw IP addresses.

We do not collect form field values, keystrokes, full-session recordings, or the contents of pages the reporter did not choose to capture.

Why we process it

Feedback data is processed to deliver the service our customer asked for: routing reports into their inbox, letting their team triage and respond, and exposing the same queue over the REST and MCP APIs. Contact emails are used solely to let the customer follow up on a specific report. Hashed IPs and timing signals are used to prevent spam and abuse of the ingest endpoint.

Data retention

Customers can configure a retention window per project. When a window is set, feedback older than the configured number of days — together with its screenshots — is deleted automatically by a scheduled job. If no window is set, feedback is kept until the customer deletes it or closes their account. Deleting a project cascades to delete all of its feedback and stored screenshots.

Data-subject rights

Depending on where they live, data subjects may have rights to access, correct, export, or erase their personal data. Because our customer is the controller, requests are usually directed to them; we support them with the following mechanisms:

  • Access & export— customers can export a project’s feedback (CSV or JSON) from the dashboard and via GET /api/v1/feedback/export.
  • Erasure— customers can erase a specific person’s feedback by email from the “Data & privacy” section of project settings, or via POST /api/v1/erasure and DELETE /api/v1/feedback/{id}. Erasure removes the matching feedback and its screenshots.

To exercise a right, contact the site or app owner who collected your feedback. If you are unsure who that is, or to reach us directly, email privacy@iterateto.example and we will route your request to the appropriate controller.

Subprocessors

We use a small set of vetted vendors to run the service (database hosting, transactional email, and hosting/CDN). The current list, with each vendor’s purpose and location, lives on our Subprocessors page.

Security

We describe our technical and organizational safeguards — including encryption in transit, access controls, and the client-side screenshot-masking model — on the Security page.

Contact

Questions about this policy or our data practices can be sent to privacy@iterateto.example. For processing terms, see our Data Processing Addendum.