Last updated 11 September 2026
Security
tellpin is built for product teams who put a feedback widget on a live product. This page is the plain-language security overview. The full legal detail lives in the Privacy Policy.
1. What we protect
Account data (email, auth sessions, project settings), visitor feedback (ratings, comments, interview transcripts, insights), and operational signals used for rate limits and abuse prevention.
2. Controls in place
- HTTPS in transit for the marketing site, app, and widget APIs.
- Supabase Auth for dashboard sign-in. Session cookies stay on the app host.
- Row-level security on account-owned rows in Postgres so one project cannot read another.
- Visitor IPs are stored as a salted hash for rate limits. Raw IPs are not kept.
- AI and billing secrets stay server-side. The widget never receives OpenRouter or Stripe secret keys.
- Paid checkout and card data go through Stripe. tellpin does not store full card numbers.
3. Who processes data
- Supabase: authentication and the application database.
- OpenRouter: server-side AI calls that include feedback text so follow-ups and insights can run.
- Stripe: subscriptions and the customer portal.
- Cloudflare: Workers hosting and transactional email from hello@tellpin.com.
- PostHog: only after analytics consent and a project key are present. It is not loaded otherwise.
MadeofIA does not sell personal data.
4. AI and data retention (honest status)
When AI follow-ups run, feedback text leaves our servers for OpenRouter, which may route to a model provider. tellpin does not use customer content to train tellpin’s own models.
OpenRouter states it does not train on customer inputs. Upstream model providers still have their own terms. tellpin does not currently force OpenRouter’s zero-data-retention (ZDR) routing. Treat feedback as content an AI provider will process. If your bar requires ZDR-only routing, say so at hello@tellpin.com before you put sensitive traffic on the widget.
5. Where data lives
MadeofIA is based in Brazil. Processors may handle data outside Brazil, including the United States. We do not claim that tellpin keeps all data in the EU.
6. Retention highlights
- Widget interview sessions expire about 30 minutes after creation.
- Widget event counters prune after about 30 days.
- Transcript text is built to clear after about 180 days by a scheduled job while the account stays active.
- Account deletion aims to remove related rows within 30 days unless a legal hold applies.
Exact tables and legal bases are in the Privacy Policy.
7. Incidents and contact
No system is perfectly secure. If an incident is likely to cause risk or harm, we notify as required by the LGPD and other applicable rules.
Security questions and reports: hello@tellpin.com. Operator: MadeofIA (Brazil). Product: tellpin.
Version 1.1, 11 September 2026.