Legal
Last updated: 30 May 2026
Feedbase is self-hosted. You run it on your own infrastructure — which means you own all your data. The only data we collect directly is your email address if you join the waitlist, processed via Resend.
Recent changes
The following sections were updated on 30 May 2026:
Feedbase is open-source, self-hosted feedback management software. Because you run it on your own infrastructure, you are the data controller — we have no access to anything stored on your instance.
This policy describes what data Feedbase processes locally, what limited data we collect through the waitlist, and how it is handled.
All data on your Feedbase instance — user accounts, feedback posts, votes, comments, and attachments — lives in your own database on your own servers.
Note
Feedbase maintainers have zero access to this data. You decide how it is stored, backed up, and deleted.
Feedbase processes the following data locally on your instance:
Tip
None of this data is transmitted to Feedbase maintainers or any third party by default.
If you join the Feedbase waitlist, your email address is collected and processed by Resend (resend.com), our transactional email provider. This is the only data we collect outside of your self-hosted instance.
Note
Resend acts as a data processor on our behalf. Their privacy policy is available at resend.com/privacy.
Tip
To be removed from the waitlist and have your email deleted from Resend, email data@breaddevv.cc at any time. We will action your request within 72 hours.
Warning
By submitting your email to the waitlist, you consent to it being processed by Resend as described above. If you are in the EU, this processing is based on your explicit consent (GDPR Article 6(1)(a)).
Feedbase may make outbound requests to the GitHub public API to check for software updates. These requests include only your current version number — no personally identifiable information is sent.
Note
All telemetry is opt-in only. No usage analytics, crash reports, or behavioural data is collected unless you explicitly enable it in your instance config.
Feedbase supports optional integrations with Discord, Slack, GitHub, and email providers. When configured, data may flow to those services under their own privacy policies.
Warning
You are responsible for ensuring your use of third-party integrations complies with applicable laws and those services' terms.
Feedbase uses session cookies strictly to keep users authenticated. These are necessary for the application to function and are not used for tracking or advertising.
Tip
No third-party analytics or advertising cookies are set by Feedbase.
As the instance operator, you have full control over all user data — you can view, export, or delete it directly from your database at any time.
If you are a user of someone else's Feedbase instance, please contact that operator regarding your data rights.
Note
For users in the European Union, rights including access, rectification, erasure, and portability apply under GDPR. For California residents, rights under the CCPA apply, including the right to know, delete, and opt out of sale (we do not sell data).
Tip
To exercise any of these rights, email data@breaddevv.cc. We will respond within 30 days as required by GDPR.
Instance data is retained for as long as your instance is running and you choose to keep it. There are no external retention schedules imposed by Feedbase.
Waitlist emails stored in Resend are retained until you request deletion or until Feedbase launches and the waitlist is closed, at which point all contacts will be deleted.
Tip
You may request deletion of your waitlist email at any time by emailing data@breaddevv.cc.
Resend may process and store your email address on servers located in the United States. If you are based in the EU or UK, this constitutes an international data transfer.
Note
Resend maintains Standard Contractual Clauses (SCCs) and other transfer mechanisms to ensure GDPR-compliant transfers. See resend.com/privacy for details.
We take reasonable technical measures to protect the software from known vulnerabilities. Security releases are published on the GitHub repository.
Warning
You are responsible for keeping your instance up to date. Running outdated versions may expose your instance to known vulnerabilities.
Danger
Never expose your database, environment variables, or admin credentials publicly. Feedbase maintainers will never ask for these.
We may update this policy from time to time. Changes will be reflected in the Feedbase repository and noted in the changelog.
Note
Continued use of the software after changes constitutes acceptance of the updated policy.
For questions about this privacy policy, email hello@breaddevv.cc, open an issue on the Feedbase GitHub repository, or reach out on Discord.
© 2026 Feedbase. MIT licensed.
Terms of service →