Privacy Policy
Last Updated: September 29, 2026
What information FeedLab collects, how we use and share it, and the choices you have.
1Who We Are
FeedLab is operated by Lync Systems ("FeedLab", "we", "our", or "us"). This Privacy Policy explains how we handle information when you use our website, web dashboard, mobile apps, embedded feedback widget, public feedback forms, test management tools, API, and MCP server (together, the "Service").
It should be read together with our Terms of Service.
2Our Role
For account and billing information (for example, your name, email address, and payment records), FeedLab decides how that information is used and acts as the data controller.
For content our customers collect or create in FeedLab (feedback submitted through a customer's widget or public form, screenshots, comments, and test cases and results), FeedLab processes that information on the customer's behalf and acts as a data processor. The customer who owns the workspace decides what is collected and how it is used.
If you sent feedback to a company that uses FeedLab and want to access or delete it, please contact that company first. We will help them respond to your request.
3Information We Collect
3.1 Account and workspace information
When you create an account or join a workspace, we collect:
- Your name, email address, and password (stored only in hashed form by our authentication provider)
- Your profile photo, if you add one
- Workspace and project details, your role, and team invitations, including the email addresses of people you invite
3.2 Feedback submissions
When someone sends feedback through a FeedLab widget, public feedback form, or our mobile apps, we collect what they choose to provide:
- Name and email address (optional on the widget and public form)
- Feedback text, type, and title
- Screenshots, photos, and annotations
3.3 Technical details sent with feedback
To help teams reproduce an issue, the widget automatically sends:
- The page URL and referring page
- Browser, operating system, and user agent
- Screen resolution and viewport size
- The time of submission
- The sender's IP address, which we use for rate limiting and abuse prevention. It is stored with the report and may be visible to the workspace that received it.
3.4 Work you do in FeedLab
This includes comments, assignments, statuses and tags on feedback; test suites, groups, and cases; test sessions, including build names, results, and notes; and notifications about this activity.
3.5 API tokens and integrations
- API tokens: we store a one-way hash of each token, never the token itself, along with its name, a short prefix, and when it was created, last used, or revoked.
- GitHub: if you connect GitHub, we store an access token so we can list your repositories and create issues from feedback.
- Webhooks: if you add a webhook, we store its URL and send new feedback to it.
3.6 Mobile apps
Our mobile apps store a push notification token for your device so we can alert you about new feedback. The apps access your camera or photo library only when you choose to attach an image.
3.7 Payments
Payments are handled by our payment provider, PayChangu. We do not receive or store your full card or mobile money details. We keep records of purchases, amounts, credits, and storage packs.
3.8 Website analytics, cookies, and local storage
- Essential cookies keep you signed in and remember your active workspace. The Service does not work without them.
- Analytics (optional): with your consent, we use Google Analytics to understand how our website and dashboard are used. It sets cookies and collects information such as the pages you view, your device and browser, and your approximate location. Analytics only loads after you accept it in our cookie banner. You can change your choice at any time from "Cookie settings" in the site footer. We never use analytics on the public feedback forms our customers share with their users.
- Local storage: your browser saves preferences such as your theme and whether the sidebar is collapsed. This stays on your device.
3.9 Newsletter and support
If you subscribe to product updates, we store your email address. If you contact us, we keep your message and our reply.
4How We Use Information
We use information to:
- Provide, operate, and maintain the Service
- Deliver feedback, test results, and notifications to the right workspace and people
- Send service emails, such as invitations, notifications, and account messages
- Process payments and manage credits and subscriptions
- Keep the Service secure, prevent spam and abuse, and enforce our Terms
- Understand usage and improve the Service
- Send product updates to people who subscribed, who can unsubscribe at any time
- Comply with legal obligations
FeedLab does not sell personal data, and we do not use customer content to train AI models.
5AI Agents and API Access
You can connect Claude Code or another MCP client to FeedLab with a personal API token. That tool then acts as you: it can read the projects and test cases you have access to, and create or update test cases.
Information your AI tool reads from FeedLab, and code it reads on your computer, is processed by that tool and its provider under their own terms and privacy policy, not ours. FeedLab does not send your content to AI providers. Review what your tool does before connecting it, and revoke tokens you no longer use from Settings → API Tokens.
6How We Share Information
We share information only as described here:
- Within your workspace: feedback, comments, and test data are visible to members of the workspace that owns them.
- Service providers that help us run FeedLab, under confidentiality and data protection obligations: Supabase (database, authentication, and file storage), Vercel (hosting), Resend (email), Google Firebase Cloud Messaging (push notifications), Google Analytics (analytics), and PayChangu (payments).
- Services you connect: GitHub, your webhook endpoints, and AI tools you authorise with an API token receive the data needed for the connection to work.
- App stores: Apple and Google handle app downloads under their own policies.
- Legal reasons: when required by law, or to protect the rights, safety, and security of our users, FeedLab, or others.
- Business transfers: if FeedLab is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
7Screenshots and Public Links
Screenshots attached to feedback are stored at shareable file addresses. Anyone who obtains a screenshot's address may be able to view it. Please review screenshots before submitting them and leave out passwords, payment details, and other sensitive information.
A project's public feedback form can be used by anyone who has its link. Workspace owners decide where to share it.
8International Transfers
Our service providers may store and process information in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards for these transfers.
9Data Retention
- Account information is kept while your account is active.
- Feedback, screenshots, comments, and test data are kept until the workspace deletes them or the account is closed. How long feedback is kept may also depend on the workspace's plan.
- Revoked API tokens stop working immediately. A record that the token existed may be kept for security.
- Payment records are kept as long as tax and accounting law requires.
- Deleted data may remain in backups for a limited period before it is overwritten.
10Data Security
We use reasonable technical and organisational safeguards, including encrypted connections (HTTPS), database access rules that limit data to the workspace it belongs to, and hashed passwords and API tokens. No system is completely secure, so we cannot guarantee absolute security. If we become aware of a breach that affects your personal information, we will notify you and the relevant authorities as required by law.
11Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and get a copy
- Correct inaccurate information
- Delete your information
- Object to or restrict certain processing
- Withdraw consent where we rely on it, for example for the newsletter
You can update most account details in Settings. For other requests, email developers@lyncsystems.tech. We may need to confirm your identity before acting on a request. You can also complain to your local data protection authority.
12Account Deletion Requests
You can ask us to permanently delete your account and associated personal data at any time. Email developers@lyncsystems.tech with the subject line "Account Deletion Request". We will verify and process your request promptly and as required by applicable law. Content that belongs to a workspace you are a member of, but do not own, remains with that workspace.
13Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
14Changes to This Policy
We may update this Privacy Policy from time to time. We will post changes on this page with a new "Last Updated" date. For significant changes, we will give additional notice, such as by email or in the dashboard.
Questions about privacy or account deletion? Contact us at developers@lyncsystems.tech