Privacy
Last updated 6 September 2026. Plain English on purpose; the legal terms are on the terms page.
Two kinds of people
Owners sign up, install the widget on their site and read the inbox. Visitors are the owners' users who tap the widget. We process visitor data on behalf of the owner; the owner decides to install the widget and should mention it in their own privacy policy.
What the widget collects from a visitor, and only when they send feedback
- What they typed: the rating, the message, and an email or phone number if they choose to leave one.
- The page address (path and title) and the referring page.
- UTM tags from the page address (source, medium, campaign), if present.
- Browser type, language, timezone, viewport size and a device class (mobile, tablet, desktop).
- For problem reports and low ratings only: page load timing, the last 20 failed network requests as method, URL without the query string and status code (never request or response bodies, never headers), the last 50 console errors and warnings, the last 20 JavaScript errors, and the last 5 clicked elements as CSS selectors (never their text).
- A country code derived from the IP address on our server. The IP address itself is discarded and never stored.
Email addresses, tokens and card numbers inside any of the above are replaced with placeholders in the browser before sending and again on our server.
What the widget never collects
- No cookies, no local storage identifiers, no fingerprinting, no cross-page sessions.
- No form field values, no passwords, no keystrokes, no request or response bodies, no headers.
- No scroll depth, no clicks outside the widget, no page views tied to a person.
Counts
We count widget loads, opens and submissions per page, per campaign tag, per country and per device class, per day. These are totals with no per-visitor rows, the way privacy-focused analytics count. Most sites therefore do not need a consent banner for the widget; owners should confirm this for their own jurisdiction.
Owners
- We store your email address and your organisation and project settings.
- Sign-in is handled by Supabase Auth; we do not see your password.
- We send you email about reports (immediately for problems, daily for the rest) and can post to a Slack webhook you provide.
Retention
- Free plan: the technical context (requests, errors, clicks) is deleted 30 days after a report; the message and rating stay.
- Startup plan (coming soon): context kept for one year.
- Owners can delete any report permanently, export all project data as JSON, or delete their organisation, from the dashboard.
Where and with whom
Data is stored with Supabase (Postgres) and processed on Railway and Vercel. Email is delivered by Resend. Spam checks use Cloudflare Turnstile, which never sees the feedback content. We do not sell data and do not use it to train models.
Visitors: asking for deletion
If you left feedback on a site using BackWire and want it removed, contact the site owner, or email us at hello@backwire.io with the site and roughly when you sent it. We will locate and delete it within 30 days.
Contact
Asian Digital Mind LLC, Irvine, CA. hello@backwire.io