Privacy Policy
Last updated: August 27, 2026
This policy covers UserWants, a bug report and feedback widget you add to your website. It is written to be read rather than to cover us, so it says what we actually hold and who it belongs to.
If you reported a bug on somebody else's website and ended up here, section 1 is the part that matters to you.
1. We play two different roles
For your account with us — your email, your billing, your settings — we decide what is collected and why. In data protection terms we are the controller, and this policy governs it.
For the reports your users send through your widget, you decide what is collected and why. You are the controller and we are only the processor: we store and serve that data on your instructions, and we do not use it for anything of our own. If one of your users wants their report deleted, they ask you, and you delete it.
That distinction is the whole shape of this document. Everything below says which of the two it applies to.
2. What we hold about you, our customer
We are the controller for all of this.
- Your email address, which is required to have an account.
- Your name, if you choose to give one. There is no public profile anywhere on this service, so it is only ever shown to you and to people you invite to your projects.
- Your password, hashed by our authentication provider. We never see or store it in readable form. If you sign in with a provider instead, we hold the identifier they give us, not your credentials.
- Your subscription status and billing history. Payments run through Stripe and card numbers never reach our servers.
- Ordinary server logs from our hosting, kept briefly for security and debugging.
- Page views, through Vercel Analytics. It sets no cookie and no cross-site identifier.
3. What the widget collects from your users
You are the controller for all of this, and the exact field list is on the widget data page — written so you can copy it into your own privacy policy.
In short: what the person wrote, how to reach them, the page they were on, and their browser language. For bug reports, and only while you leave technical collection switched on, also the browser and device details, up to ten JavaScript errors with their stack traces, and up to fifty recent actions — which elements were clicked, which forms were submitted, which pages were visited.
The widget never collects the contents of anything anybody types into a field, on your site or in ours. It reads no console output and no network traffic. It sets no cookies and uses no browser storage, so it cannot follow anyone between sites. Nothing leaves the page at all until the person presses send.
IP addresses are used for rate limiting only, and the raw address is never stored: it is hashed with a secret salt before it reaches our database, and the hash cannot be reversed.
4. Screenshots
A screenshot is only ever taken when the person reporting asks for one, and it is shown back to them before sending so they can discard it.
Screenshots are held in private object storage, are not publicly addressable, and are served only through short-lived signed links to people with access to your project. They are deleted after ninety days; the rest of the report stays until you delete it.
5. The MCP server
If you connect an AI coding tool — Claude Code, Cursor, VS Code, Zed — you authorise it in a browser, and from then on it can read reports from that project as you, with your permissions.
Be aware of what that means: the report, including its description and any personal data your user put in it, is sent to that tool and to whichever model provider it uses. We do not choose that provider and we do not send anything to it ourselves; your editor does, on your instruction. If your users' reports contain data you would rather not hand to a third party, do not connect an editor to that project.
We never use anything in your account to train a model, ours or anyone else's.
6. Who else processes this data
We use a small number of providers, each for one job:
- Supabase — database, authentication and file storage.
- Vercel — application hosting, and cookieless page-view analytics.
- Cloudflare R2 — screenshot storage.
- Stripe — subscriptions and payments.
- Resend — transactional email, including the notifications sent to people who reported something.
7. Where the data goes
Some of those providers operate outside the European Economic Area, principally in the United States. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent approved mechanism.
8. Cookies
On this website we set a session cookie so you stay signed in, and one that remembers your language choice. Both are strictly necessary and neither tracks you anywhere else.
The widget, on your website, sets nothing at all. There are no advertising cookies, no third-party trackers, and no cross-site profiling anywhere in this service.
9. How long we keep things
- Your account and its contents: while your account is open.
- Reports and feature requests: until you delete them, or until you close your account.
- Screenshots: ninety days.
- Billing records: as long as tax and accounting law requires, which is longer than the rest.
- Server logs: a short rolling window.
- If you close your account we delete your data. We may keep the minimum needed for legal obligations, and backups age out on their own schedule.
10. Your rights
Under the GDPR you can ask us for a copy of your data, correct it, have it deleted, take it elsewhere in a machine-readable form, or object to a particular use. Write to us and we will answer within one month.
If you reported a bug or sent an idea through somebody else's website, we are only the processor and we cannot act on your data without their instruction. Ask the operator of that website. If you cannot reach them, write to us and we will pass it on.
You can also complain to a supervisory authority. In Spain that is the Agencia Española de Protección de Datos.
11. Security
Data is encrypted in transit and at rest. Access to your project is limited to the members you invite and enforced at the database level rather than only in the interface. Screenshots are private and reachable only through signed links. Widget keys are public by design — what restricts them is the domain allowlist you configure, which refuses every domain until you add one.
No system is perfect. If we ever have a breach affecting your data, we will tell you and the relevant authority as the law requires.
12. Changes
If we change this policy we update the date at the top. If a change materially affects you, we will email you rather than rely on you noticing.
13. Contact
UserWants is operated from Spain. For anything in this policy, including exercising your rights, write to userwants@pampabit.com.