Privacy Policy
Last Updated: September 12, 2026
1. Introduction
1.1 Who We Are
ByRequest is a feedback board. Through our platform and tools, we let teams collect feature requests from the people who use their products, and let those people file requests, vote on them, and follow what happens next. Our Services include byrequest.app and all subdomains, the boards our customers host on their own domains pointing at our servers, and everything offered through them — including the MCP server that lets a team triage their board from a coding agent.
The Services are provided by ByRequest ("ByRequest," "we," "us," or "our").
1.2 Who is Who
When this Privacy Policy uses the term "Team," we mean the people who run a board: those who create a workspace, sign in to the admin, and triage requests. "Contributors" are the people who use a Team's board — filing requests, commenting, voting, or subscribing to updates. Teams, Contributors, and anyone else using our Services are referred to collectively as "Users," "you," or "your."
Our role depends on the Personal Data in question:
- As a data controller: When you create a ByRequest account, we are the data controller for the Personal Data in that account and your use of the Services. We decide how and why that data is processed.
- As a data processor: When a Contributor files a request, votes, or comments on a Team's board, we provide the tools the Team uses. The Team decides what to collect and how to use it, and is the data controller for that board's content. We process it on the Team's behalf and on their instructions.
One consequence is worth stating plainly: a Team can add Contributors to their board by importing a list of names and email addresses. If your details are on a board you never visited, the Team who runs that board put them there, and they are the controller for that data. You can ask us and we will tell you which board it is and remove you.
If you have questions or concerns, contact us at support@byrequest.app.
2. Personal Data We Collect
2.1 All Users
Information you provide to us: We collect Personal Data you give us voluntarily, such as when you register, contact us, or use parts of the Services. This may include:
- Name and email address
- Account credentials (passwords are stored hashed, never in readable form)
- Two-factor authentication settings
- Communication and notification preferences
- Anything else you choose to write into a request, comment, or board
Information we collect automatically: We collect limited technical data through your use of the Services, including IP address, browser and device information, and the pages you visit. Our hosting provider also collects request logs as part of serving the Services.
We do not use advertising trackers, and we do not sell Personal Data.
2.2 Teams
As a Team member, we additionally collect:
- Workspace information: your workspace name, boards, tags, settings, and any custom domain you connect.
- Integration credentials: if you connect your own email provider, we store the credentials needed to send on your behalf. If you connect an agent over MCP, we store the API keys it uses.
- Payment information: if and when we offer paid plans, payment details are handled by our payment processor; we do not store full card numbers.
2.3 Contributors
As a Contributor, we additionally collect:
- What you contribute: the requests you file, the comments you write, the posts you vote on, and the boards you subscribe to.
- Your identity on that board: your name and email address, held separately for each board you take part in. An identity on one board is not shared with, or visible to, any other board — even when the same address is used on both.
- How you arrived: whether you signed in yourself, filed a request as a guest, were added by the Team through an import, or were created by an agent acting for the Team. We record this because it determines whether we believe the address is really yours.
Unverified addresses. If a Team imports you, or someone files a request as a guest using your address, we hold that address without proof it belongs to you. We record such addresses as unverified. If you receive email from a board you never signed up for, every message carries a one-click unsubscribe link that works without signing in.
3. How We Use Your Personal Data
3.1 Service Provision
- To provide and maintain the Services
- To create and manage your account and your identity on each board
- To send sign-in links, which is how signing in to a board works
- To show requests, votes, and comments attributed to the people who made them
- To notify you about requests you filed, commented on, voted for, or subscribed to
- To respond to your questions and support requests
3.2 Service Improvement
- To diagnose errors and fix them
- To understand which features are used, in aggregate
- To develop new features
3.3 Communications
- To send administrative messages about your account or a board
- To send the notifications you are subscribed to, each with an unsubscribe link
- To send product updates, where you have asked for them
3.4 Legal and Safety
- To comply with legal obligations
- To enforce our terms and prevent abuse
- To protect the rights, safety, and property of ByRequest, our Users, and others
3.5 Legal Bases for Processing (EU/EEA/UK)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract: to create and manage your account and provide the Services you asked for.
- Consent: for activities that require it, such as optional product emails. You can withdraw consent at any time.
- Legal obligation: to comply with applicable law and lawful requests.
- Legitimate interests: to operate, secure, and improve the Services, prevent fraud and abuse, and provide support, where those interests are not overridden by your rights.
4. How We Share Your Personal Data
4.1 With the Team who runs a board
If you file a request, comment, or vote on a board, the Team who runs that board can see it, along with the name and email address held for you on that board. Teams can export their board's data.
Some boards are public: requests, comments, and the names attached to them may be visible to anyone with the link. Voter email addresses are never shown publicly — only to the Team.
4.2 With Service Providers (Sub-processors)
We share Personal Data with third-party providers who perform services for us, such as hosting, email delivery, and error monitoring. They may only process Personal Data on our instructions and under contractual obligations consistent with this Policy.
The current list is on our Sub-processors page.
If a Team connects their own email provider, messages for that board are sent through it, and that provider is the Team's sub-processor rather than ours.
4.3 For Legal Reasons
We may disclose Personal Data where required by law or in response to valid requests by public authorities, and to protect our rights, our Users, or the public.
4.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, Personal Data may be transferred as part of that transaction.
4.5 With Your Consent
We may share Personal Data with third parties where you have consented.
5. Cookies and Similar Technologies
We use cookies for things the Services cannot work without: keeping you signed in, remembering which workspace you were last in, and protecting forms against automated abuse. We do not use advertising or cross-site tracking cookies.
You can set your browser to refuse cookies, but signing in will not work if you do.
6. Data Retention
We keep Personal Data as long as needed for the purposes in this Policy, unless a longer period is required by law.
While your account is active, we keep your account, your workspaces, and their boards so the Services work as expected.
Leaving one board. You can remove yourself from a single board without touching anything else. Your name and address on that board are replaced and you stop receiving its email. What you wrote stays, so the Team's counts and history remain intact, but it is no longer attributed to you by name or address.
Deleting your account. You can delete your ByRequest account from your account settings. This removes your ability to sign in to the admin. It does not automatically remove identities you hold on boards as a Contributor, because those are separate and belong to different Teams' boards — you can remove each of those individually, or ask us and we will do it.
If you want everything we hold about you removed across every board, email support@byrequest.app and we will do it.
Certain records may be kept longer where required for legal, tax, or accounting reasons, or to prevent fraud and abuse.
7. Data Security
We implement appropriate technical and organizational measures to protect Personal Data. Passwords are hashed. Sign-in links are stored only as a hash, are single-use, and expire. Session cookies are host-only and stored hashed. Provider credentials are encrypted at rest.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the Personal Data we hold about you
- Correct inaccurate or incomplete information
- Delete your Personal Data in certain circumstances
- Restrict how we process it
- Port a copy in a structured, machine-readable format
- Object to processing in certain circumstances
You can stop email from any board immediately using the unsubscribe link in any message, or by removing yourself from that board — neither requires contacting us.
To exercise any other right, email support@byrequest.app and we will respond within the timeframes required by law.
If you believe we have not handled your Personal Data lawfully, you may lodge a complaint with your local data protection authority. We would appreciate the chance to address your concerns first.
9. International Data Transfers
Your Personal Data may be transferred to and processed in countries other than where you live, and those countries may have different data protection laws. Where Personal Data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses.
10. Children's Privacy
Our Services are not directed to children under 16, and we do not knowingly collect their Personal Data. If you believe a child has given us Personal Data, contact us and we will delete it.
11. Changes to This Privacy Policy
We may update this Policy from time to time. The updated version is indicated by the "Last Updated" date and takes effect as soon as it is accessible. We encourage you to review it periodically.
12. Contact Us
Email: support@byrequest.app
13. GDPR Compliance
We process Personal Data lawfully, fairly, and transparently, collect it for specific and legitimate purposes, limit collection to what is necessary, keep it accurate, retain it only as long as needed, and protect it with appropriate security measures.
The GDPR gives you control over your Personal Data: you can ask what we hold, correct inaccuracies, request deletion, restrict processing, receive a portable copy, and object to certain processing.
Processing on behalf of a Team
If you are a Team using ByRequest, you are processing other people's Personal Data as soon as anyone contributes to your board, and we process it on your behalf and on your instructions. If you need a data processing agreement for your own compliance, contact us at support@byrequest.app.
If you have questions about your GDPR rights or wish to exercise them, contact us at support@byrequest.app.