Privacy Policy

Last updated: February 19, 2026

Overview

TellSafe is an anonymous feedback platform. Privacy isn't a feature — it's the foundation. This policy explains what data we collect, why, and how we protect it.

What We Collect

  • Account information: Email address and password (for admins who sign up).
  • Organization data: Name, slug, branding settings, and survey configuration.
  • Feedback submissions: The content of feedback, selected category, and privacy mode. For identified submissions, the submitter's name and email. For anonymous submissions, no identifying information whatsoever.
  • Relay data: For relay-mode feedback, we store an encrypted email address to enable two-way anonymous communication. This email is encrypted at rest and never visible to admins.
  • Usage data: Basic analytics like page views and feature usage to improve the product. No tracking cookies are used.

What We Don't Collect

  • We do not collect IP addresses from feedback submitters.
  • We do not use third-party tracking or advertising cookies.
  • We do not sell, rent, or share your data with third parties.
  • We do not store plaintext email addresses for relay-mode submissions.

How We Protect Your Data

  • All data is transmitted over HTTPS/TLS encryption.
  • Relay email addresses are encrypted using AES-256 before storage.
  • Authentication is handled via Firebase Auth with industry-standard security.
  • Database access is restricted by role-based security rules.
  • We use Stripe for payment processing — we never see or store your full card number.

Anonymous Feedback

When a member submits feedback in anonymous mode, we store only the feedback content, category, and timestamp. There is no technical mechanism to trace anonymous feedback back to an individual. In relay mode, the submitter's email is encrypted and used solely to facilitate anonymous two-way conversation. Admins never see the submitter's email.

Data Retention

Feedback data is retained as long as your organization account is active. If you delete your organization or account, all associated data (including feedback, relay threads, and encrypted emails) is permanently deleted within 30 days.

Your Rights

  • Access: Request a copy of data associated with your account.
  • Deletion: Request deletion of your account and all associated data.
  • Correction: Update your account information at any time.
  • Portability: Export your feedback data via CSV from the admin dashboard.

To exercise these rights, email us at hello@tellsafe.app.

Third-Party Services

  • Firebase (Google): Authentication and database hosting.
  • Stripe: Payment processing for paid plans.
  • SendGrid (Twilio): Email delivery for relay communication and notifications.
  • Vercel: Application hosting.

Each of these providers has their own privacy policy and maintains SOC 2 compliance.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered admins. Continued use of TellSafe after changes constitutes acceptance of the updated policy.

Contact

Questions or concerns? Reach us at hello@tellsafe.app.