Trust
Privacy
A plain-language account of how Fidibeki treats data: what is collected, why, how long it lives, and who can get it out.
Effective date: 23 July 2026
This is the current version of the privacy notice. Previous versions will be archived here when the notice changes materially.
Who is the controller?
Fidibeki is a service operated by ACIDINEY ALVARO CARVALHO SOARES DIAS, an independent service provider established in Portugal, who acts as the data controller for the Fidibeki website, accounts, and business administration data, except where Fidibeki processes personal data on behalf of its customers as a processor. Fidibeki is the name of the service, not a company or a separate legal entity. In this notice, “we”, “us”, and “our” mean that operator.
For feedback collected through the widget on a customer’s product, the customer is the controller and we act as a processor under that customer’s instructions. If you submit feedback through a Fidibeki widget, the privacy notice of the company operating that site is the first place to look for information about your data.
What the widget collects and refuses to
The widget collects only what a reporter deliberately submits: their message, optional rating or reaction, and any screenshots, audio, or session replay they choose to add. Targeting decisions are computed locally from interaction signals like active time and scroll depth. The widget never reads input values, private page text, or network payloads, and it never builds a personal fingerprint. Session replay, where enabled, masks inputs by default and is never sent to any AI provider.
Widget analytics and storage consent
The widget loads only the code needed to render and respond to a feedback rule until the end user makes a privacy choice. Any durable storage — such as a pseudonymous visitor identifier, visit or scroll state, or funnel-event queue — is created only after the user consents to analytics or targeting for that specific purpose. Consent for analytics does not cover session replay, and neither covers reporter email updates. Fidibeki does not use these mechanisms to follow users across different customer sites.
Session replay and consent
Session replay is disabled by default for every project and rule. When a rule enables replay, Fidibeki does not start rrweb capture, buffer events, create a session, or upload a DOM snapshot until the end user gives explicit, affirmative consent. We offer two consent models:
- Fidibeki-managed consent. We show a localized, accessible prompt on your behalf before capture begins. Accept and reject have equal prominence, and the user can withdraw permission as easily as it was granted.
- Customer-managed consent. The recorder stays dormant until your consent manager calls our runtime API with a structured grant that includes purpose, notice version, locale, source, and a consent reference. Revocation immediately stops capture, discards buffered events, and prevents new sessions.
Even after consent, replay stays anonymous: inputs are masked, identity-bearing attributes and unsafe URLs are stripped, canvas pixels are suppressed, and replay identifiers are isolated from other reporter data. We also reject unsafe rrweb events server side. Replays are never sent to any AI provider.
AI processing
On eligible plans and only for projects where AI analysis is enabled, Fidibeki may transmit the reporter's free-text message and the attachments they chose to submit — screenshots, audio, video, or element captures — to Google Gemini for cleaning, transcription, sentiment scoring, and moderation flags. This happens only for submissions that enter the AI pipeline. Session replays are never sent to any AI provider.
Free-text and media may contain highly personal categories such as health, political, religious, biometric, sexual, employment, or child-related information. We are building project-level processing instructions and sensitive-category handling so AI use is an explicit privacy decision rather than a plan default. Derived AI output participates in the same retention, export, and rights workflows as the original submission.
What information we collect
We collect information in three main ways:
- Information you provide. When you sign up for a workspace, contact us, or subscribe to updates, you may give us your name, email address, workspace name, and billing details. Payment information is handled directly by Stripe and is not stored by Fidibeki.
- Information from your device and usage. When you use our site or service, we collect technical data such as your IP address, browser type, operating system, referring URL, pages visited, and feature usage. We use this for security, abuse prevention, product improvement, and support.
- Information from widget submissions. When a reporter uses a Fidibeki widget on a customer’s site, the customer decides what to collect. The widget only submits what the reporter deliberately provides, plus minimal technical context such as the page origin and interaction signals. Optional reporter email is collected only with a clear, specific opt-in for updates about that feedback.
How we use your information
We use personal information to:
- Provide, maintain, and improve the Fidibeki service;
- Manage your account and send service-related messages such as security alerts;
- Respond to questions and provide support;
- Detect, investigate, and prevent abuse, fraud, and security risks;
- Communicate product news or offers where you have consented;
- Comply with legal obligations and protect our rights.
Legal basis for processing
If you are in the European Economic Area or another region with similar laws, we process personal data only where we have a legal basis. The bases we rely on are:
- Performance of a contract. To provide the service you signed up for;
- Legitimate interests. For security, abuse prevention, and product improvement, balanced against your rights;
- Consent. For optional marketing emails and for analytics cookies on this marketing site;
- Legal obligation. Where the law requires us to process or retain data.
You can withdraw consent at any time by using the unsubscribe link in emails or by declining analytics in the consent banner. Withdrawing consent does not affect the lawfulness of processing that happened before the withdrawal.
Subprocessors
We use a limited set of subprocessors to run Fidibeki. Their roles are recorded in our Data Processing Addendum, which also states openly which provider-side facts — locations, legal entities, and transfer mechanisms — are not yet verified. The current list includes:
- Stripe. Payment processing;
- Resend. Transactional email delivery;
- Sentry. Error and performance telemetry;
- Cloudflare Turnstile. Bot protection on signup;
- Google Gemini. AI analysis, only when AI is enabled for a project, and never for session replays;
- Managed hosting, database, queue, and object storage providers. Infrastructure and storage;
- Umami. Privacy-friendly analytics on this marketing site, with your consent.
We do not sell personal information. We notify customers before adding or replacing a subprocessor that processes widget data, in line with the DPA.
International transfers
Some subprocessors process data outside the country where you are located, including outside the European Economic Area. A transfer like that needs an approved safeguard — an adequacy decision, Standard Contractual Clauses, or another lawful route — together with a transfer impact assessment.
We are still verifying which mechanism applies to each provider, and we would rather say so than imply coverage we have not confirmed. The Data Processing Addendum lists this among the items that are not yet settled. We do not claim EU data residency for flows that do not actually support it.
Cookies and tracking on this site
This marketing site uses Umami analytics. Umami does not use cookies, does not collect personal data, and does not track you across sites. Analytics only loads after you accept it in the consent banner. You can change your choice at any time by clearing the consent choice in your browser for this site.
This site also runs our own Fidibeki feedback widget, the same product we sell, so we can collect feedback directly from visitors. Like analytics, it only loads after you accept in the consent banner, and any feedback you submit through it is processed the same way as feedback submitted through a customer's widget.
The Fidibeki application may use essential session cookies and similar technologies to keep you signed in. Optional widget storage and analytics are gated behind purpose-specific consent where applicable.
Your data protection rights
Depending on where you live, you may have the right to:
- Access, correct, update, or delete your personal information;
- Object to or restrict certain processing;
- Request a portable copy of your data;
- Withdraw consent for processing based on consent;
- Complain to a supervisory authority.
Workspace members can manage their profile data in their account settings. Reporters who submitted feedback through a widget should contact the company that operates that site, or email us at [email protected] and we will route the request to the relevant customer.
Data retention
We retain data only as long as needed for the purpose for which it was collected, or as required by law. Replays and attachments follow the plan storage window (30, 90, or 365 days). Raw widget analytics events are kept for 90 days; daily aggregates for two years. Workspace deletion starts a seven-day grace period, after which data is removed.
We are completing a full retention register for authentication, delivery, audit, telemetry, and workflow data. Until it is published, contact us for current retention details.
Children
Fidibeki is not intended for children under 16. The widget must not be used to collect personal data from children. If you believe a child has provided personal data through a widget without appropriate consent, contact the site operator or email us at [email protected] and we will help route and remove it.
Updates to this privacy notice
We update this notice as the product and legal context change. We will inform you of material changes through the service or by email where required by law. The effective date of the latest version is shown at the top of this page.
How to contact us
For privacy questions, data-rights requests, or DPA inquiries, email us at [email protected]. General support is available at [email protected]. Every contact route, and the operator’s details, are on the contact page.
Questions about data handling?
Ask us directly. The people answering are the people who built the retention jobs.