Last updated 11 September 2026
Privacy Policy
1. Introduction
Tellpin is an in-product feedback widget and dashboard, available at tellpin.com and app.tellpin.com. It is operated by MadeofIA, which is responsible for the brand and for the relationship with Tellpin users. MadeofIA is based in Brazil.
This Privacy Policy explains which personal data we collect, why we use it, who we share it with, how long we keep it, and your rights under Brazil’s Lei Geral de Proteção de Dados (Law No. 13.709/2018, LGPD). If you are in the EEA or the UK, we also describe rights that apply under the GDPR.
Questions and data-subject requests: hello@tellpin.com.
2. Who is responsible for your data
If you create a Tellpin account, MadeofIA is the controller of your account, billing, and product-use data.
If you install the widget on your website, you decide to collect feedback from your visitors. In that case you are the controller of visitor feedback, and MadeofIA processes it to provide the service. Please tell your visitors about that collection. The widget can show a privacy link that you configure.
If you are a visitor who left feedback on a site that uses Tellpin, you can contact the site owner or write to us. We will help with access and deletion requests together with the account owner.
3. Data we collect
3.1 Account and billing
- Email address and authentication data, through Supabase Auth.
- Session cookies that keep the dashboard signed in.
- Subscription state: plan (Free, Starter, or Growth), usage counts, and billing status.
- Stripe customer and subscription identifiers needed to run checkout and the customer portal.
Tellpin does not store full card numbers. Stripe collects and processes payment details under its own terms. Automatic tax collection is not enabled today.
3.2 Feedback content
- Ratings, comments, the AI interview transcript, generated insights, labels, and product areas.
- Optional visitor email, if the widget offers that field and the visitor chooses to leave it. The current widget does not show an email prompt; the database can still store one if a future version offers it.
- Technical session fields such as widget version, locale, and the website origin that loaded the widget.
3.3 Technical and security data
- A salted hash of the visitor IP, used for rate limits. Tellpin does not store the raw IP.
- Widget events (for example that the widget loaded, or that a request was blocked), including the website origin. These counters are pruned after about 30 days.
- Operational logs needed to run and debug the service.
3.4 Cookies
- Necessary: Supabase Auth session cookies for the dashboard, and a small consent cookie that remembers this choice. A project-selection cookie remembers which project you last opened.
- Analytics: PostHog, only after you accept. PostHog is planned and is not loaded until both consent and a PostHog project key are present.
You can change the analytics choice below, or with the banner when it is shown.
4. What we do not collect
- Full payment card data.
- Precise geolocation.
- Raw IP addresses.
- Special-category data as a product feature. Please do not submit health, biometric, or similar sensitive data in feedback.
5. How we use data
| Purpose | Data used | Legal basis (LGPD) |
|---|---|---|
| Create and manage your account | Email, authentication, project settings | Performance of a contract |
| Provide the widget and dashboard | Feedback content, session data, project configuration | Performance of a contract |
| Ask AI follow-ups and draft insights | Feedback text and transcript | Performance of a contract |
| Bill paid plans and show usage | Email, plan, Stripe identifiers, conversation counts | Performance of a contract |
| Prevent abuse and keep the service stable | Salted IP hash, origin, widget events, rate-limit counters | Legitimate interest |
| Send service messages (confirmation, password reset) | Performance of a contract | |
| Optional product analytics (PostHog) | Usage events after you accept | Consent |
| Answer support and rights requests | Email and the records needed for the request | Performance of a contract / legal obligation |
| Comply with law | Records required by applicable law | Legal obligation |
6. Sharing with processors
Tellpin does not sell personal data. We share data with operators who help us run the product:
- Supabase: authentication and the application database.
- OpenRouter: server-side AI requests that include feedback text, so the product can ask follow-ups and draft insights.
- Stripe: paid subscriptions, invoices, and the customer portal. Tellpin never stores full card data.
- Cloudflare: hosting (Workers) and transactional email SMTP. Service mail is sent from hello@tellpin.com.
- PostHog: only if you accept analytics and a project key is configured. It is not loaded today unless those conditions are met.
We may also disclose data when required by law, a court order, or a competent authority.
7. AI processing
When AI follow-ups run, feedback text is sent to OpenRouter from our servers. Tellpin does not use customer content to train Tellpin’s own models.
OpenRouter states that it does not train on customer inputs. It may still route the request to a model provider. Those providers have their own terms. Some may retain prompts or use them under their policies. Tellpin does not currently force OpenRouter’s zero-data-retention routing. Treat feedback as content that an AI provider will process.
8. International transfers
MadeofIA is based in Brazil. Our processors may handle data outside Brazil, including in the United States and other countries where they operate. We do not claim that Tellpin keeps all data in the EU. Transfers happen so we can provide the service, under each processor’s terms and safeguards.
9. Retention
Some periods below are how the product is built to operate (including scheduled database jobs). They are operational targets. We will shorten or extend them if the running system requires it, and we will update this policy when that change is material.
| Data | How long we keep it |
|---|---|
| Account email and project settings | While the account is active. After a deletion request we aim to delete account data within 30 days, unless a longer legal hold applies. |
| Feedback, transcripts, and insights | While the account is active. Transcript text is built to be cleared after about 180 days by a scheduled job. Account deletion also removes the related rows. |
| Widget interview session | About 30 minutes from creation, then the session expires. |
| Widget events | About 30 days. |
| Salted IP hash / rate-limit counters | Short operational windows, then cleaned up by the same scheduled jobs. |
| Stripe billing records | According to Stripe’s retention for payments and tax law. |
| Auth session cookies | For as long as Supabase Auth keeps the session, or until you sign out. |
| Analytics (PostHog), if enabled after consent | According to the PostHog project settings once it is connected. |
10. Your rights (LGPD)
You may request:
- Access: confirm that we process your data and receive a copy.
- Correction: fix incomplete, outdated, or inaccurate data.
- Deletion: erase personal data where the law allows.
- Portability: receive your data in a structured, commonly used format.
- Information about sharing: know which entities receive your data.
- Withdraw consent: stop optional analytics, or any other processing that relies on consent.
- Object: oppose processing based on legitimate interest, including by asking us to review that balance.
Email hello@tellpin.com. We aim to respond within 15 business days, as provided by the LGPD.
EEA and UK users
If GDPR applies to you, you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may lodge a complaint with your local supervisory authority. For Brazil, you may contact the ANPD at www.gov.br/anpd.
11. Security
We use HTTPS in transit, access controls on the database (including row-level security for account data), hashed IPs instead of raw addresses, and server-only secrets for AI and billing keys. No system is perfectly secure. If an incident is likely to cause risk or harm, we will notify as required by the LGPD and other applicable rules.
12. Children
Tellpin is not directed at children under 18, and we do not knowingly collect their data. If you believe we have collected a child’s data, contact us so we can delete it.
13. Changes
We may update this policy. Material changes will be announced by email or a notice in the product, with at least 15 days before they take effect where that notice is reasonable. The date at the top is the current version. Continued use after that date means you accept the updated policy.
14. Contact
MadeofIA, operator of Tellpin, based in Brazil.
Privacy and rights: hello@tellpin.com
Version 1.1, 11 September 2026. This policy replaces earlier versions.