Privacy Policy for Feedback
Last updated: August 30, 2026
Feedback ("we", "us", or "our") provides an iOS service for sharing and receiving anonymous feedback following real-world interactions. This Privacy Policy explains what information we collect, how we use it, and the choices available to you when you use the Feedback app, our supporting services, and our website (together, the "Services").
1. Information We Collect
Account and profile information
- Sign in with Apple information. When you create an account, we receive the name and email address that you choose to share through Sign in with Apple. We do not receive or store your Apple ID password.
- Profile information. We collect the profile information you provide or edit, such as your name or display name, email address, phone number, date of birth, gender, initials, and profile photo.
- Profile photo. If you choose a photo, the selected image is stored with your profile in CloudKit. We do not access your photo library unless you choose a photo or take one for your profile.
Location and proximity information
- Precise location. When you check in and grant permission, the app collects your latitude, longitude, and the time of the location update. If you grant Always location access, the app can update location in the background while you remain checked in.
- Nearby and encounter information. We use recent location updates to identify checked-in users who are near one another. Our service may create an encounter after two cumulative minutes within a 20 metre radius. Encounter records can include participant record identifiers, timestamps, duration, and the location associated with the encounter. A short location interruption may be tolerated so background delivery gaps do not immediately end an in-progress encounter.
- Location freshness. We store timestamps showing when location was last updated and, where applicable, when a location-related notification was sent. This helps us show nearby users and avoid acting on stale location data.
- Radar improvement comparison. If you choose Allow in the in-app Radar improvement prompt, we also send your checked-in precise location, accuracy, time, and technical installation/profile identifiers to a separate AWS-hosted service. It compares the developing Radar system with the existing proximity system to improve accuracy and reliability. It does not change the nearby experience, encounters, feedback eligibility, or notifications.
Feedback and interaction information
- Feedback content. We collect the message, rating, category (Work, Social, or Dating), timestamps, sender and recipient technical identifiers, and delivery/visibility information needed to send, release, display, moderate, and calculate feedback.
- Scores and history. We calculate and store feedback-score and score-history data from ratings you receive.
- Eligibility information. We store the information necessary to show an eligible encounter and enforce the feedback window and cooldown. Feedback eligibility normally expires after 24 hours, and the same pair cannot create a new feedback opportunity during the applicable 24-hour cooldown.
- Reports and blocks. If you report feedback or block a user, we store the report/block information. A reported item is immediately hidden on your device and marked in CloudKit so it remains hidden from you; the original feedback and its metadata are retained for moderation and service integrity.
Phone numbers, contacts, and SMS
- Your phone number. If you add and verify a number, we use it to confirm ownership by SMS and to enable phone-number feedback features.
- Contacts. If you grant Contacts permission or choose a contact, we process the selected contact name and phone number to let you select a recipient. We may retain locally cached, per-install salted hashes of phone numbers for up to seven days to improve contact results while offline; these cached hashes are not used as the final decision about whether a number belongs to a Feedback user.
- Feedback sent to a phone number. When you choose to send feedback to a number, we process that number to determine whether it belongs to a Feedback account. If it does not, we retain the feedback pending verification of that number. We ask for your consent before sending an SMS invitation to a non-user. The invite does not identify the sender.
- Verification and invitation SMS. We use Amazon Web Services (AWS) Simple Notification Service to send verification codes and consented invitations. AWS processes the destination phone number and message needed to deliver the SMS.
Device, notification, and technical information
- Push-notification token. If you allow notifications, we store an Apple Push Notification service (APNs) device token so we can send relevant alerts.
- Notification and service events. We process notification state and related timestamps to deliver encounter prompts, the weekly feedback summary, feedback-quota reminders, and, where relevant, location-session reminders. The weekly feedback summary is sent at 5 PM local time on Wednesday and is based on current CloudKit data.
- Technical identifiers and local data. We process CloudKit record identifiers, app state, timestamps, and locally stored caches and durable queues. These allow offline submissions, profile edits, report delivery, reliability, and performance.
2. How We Use Information
- To create, operate, and secure your Feedback account and profile.
- To identify nearby checked-in users, create eligible encounters, and provide proximity-based feedback features.
- To let you send, receive, release, view, filter, share, report, and block feedback.
- To calculate feedback scores and score history.
- To verify phone numbers, process consented SMS invitations, and support phone-number feedback.
- To deliver notifications and keep their badge/count information accurate.
- To maintain local caches and durable queues so the Services can recover from a loss of connectivity.
- To investigate reports, prevent abuse, enforce our rules, protect users, and maintain the security and integrity of the Services.
3. How Feedback Is Shared
Feedback is designed to be anonymous. The person receiving feedback is shown the feedback message, rating, category, and associated display information used by the product, but not the identity of the person who sent it. We retain technical identifiers internally to operate the service, enforce cooldowns, investigate reports, and protect against abuse.
Feedback sent to an existing Feedback user is ordinarily released in the recipient's app at the next Wednesday 5 PM release. Feedback that was sent to a phone number before the recipient joined may be made available when that number is verified, using the original submission time. These timing rules may change as the product evolves.
While you are checked in, other checked-in users may be able to see the profile information the app displays for nearby users, such as your display name or initials and profile image, together with your nearby/availability status. We do not display your exact coordinates to other users through the app.
4. Service Providers and Other Disclosures
We use service providers that process information on our behalf:
- Apple. We use Sign in with Apple, CloudKit to store and synchronize service data, and APNs to deliver push notifications.
- AWS. We use AWS Simple Notification Service to deliver verification and consented invitation SMS messages. We also use AWS-hosted endpoints to receive moderation reports and, when you opt in, to run the non-authoritative Radar improvement comparison.
When you make a moderation report, the report may include the feedback text, rating, relevant technical identifiers, report time, and location associated with the feedback so we can investigate it. We may also disclose information where reasonably necessary to comply with law, respond to valid legal process, protect the rights, safety, and security of users or the public, or investigate fraud, abuse, or violations of our terms.
We do not sell personal information and do not use third-party advertising networks or third-party analytics SDKs for advertising.
5. Data Retention
We retain account, profile, feedback, encounter, report, and related service records for as long as needed to provide the Services, maintain safety and integrity, resolve disputes, comply with legal obligations, and enforce our agreements. CloudKit records are not automatically deleted simply because feedback is reported or hidden. Radar-improvement exact-location records are set to expire after ten minutes; technical replay-protection records are set to expire after fifteen minutes; and non-authoritative comparison state is set to expire after twenty-four hours. Deletion from AWS after those periods is performed by DynamoDB's asynchronous TTL process. Local caches and queued operations remain on your device until they are no longer needed, you sign out, you delete the app, or iOS removes the relevant app data.
6. Your Choices and Rights
- Profile information. You can update eligible profile information in the app.
- Permissions. You can change Location, Contacts, Camera, Photos, and Notification permissions in iOS Settings. Turning off location or background location limits proximity features.
- Radar improvement comparison. When you are checked in, you can choose Allow or Not now in the Radar improvement alert. Choosing Not now means we do not send Radar-improvement location data, and we may ask again the next time you foreground the app or check in. Choosing Allow stops the alert; it does not affect the existing proximity experience.
- Reports and blocks. You can use in-app controls to report feedback and block users.
- Marketing. We do not use your information for third-party advertising.
- Access, deletion, and other requests. To request access to, correction of, export of, or deletion of personal information, contact us using the details below. We may need to verify your identity and may retain limited information where required or permitted by law.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. Communications with CloudKit, AWS, and APNs use encrypted network connections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children's Privacy
Feedback is not intended for people under 17. We do not knowingly collect personal information from children under 17. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to address the request.
9. International Processing
Your information may be processed in countries where Apple, AWS, or our service providers operate. Those countries may have data-protection laws that differ from the laws where you live.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Services, legal requirements, or our privacy practices. We will post the updated policy and revise the "Last updated" date. Where required, we will provide additional notice or obtain consent.
11. Contact Us
If you have questions, concerns, or requests about this Privacy Policy or your information, contact us at:
Email: feedback@thefeedbackapp.org