Last updated September 4, 2026
We collect as little as we can, we never sell it, and the data your users send through the SDK stays yours.
SuggestKit ("we", "us") is operated by Firat Tamur. SuggestKit is a feedback platform for software teams: you embed our widget or SDK in your product, your users submit and vote on feature requests, and we show you which requests carry the most revenue.
This policy covers two groups of people. Customers are the teams who create an account and install the SDK. End users are the customers' own users who vote and comment through the widget. Most of this policy applies to both; section 4 is specific to end users.
We collect the following.
We use personal data to:
We do not sell personal data and we do not use it for advertising.
When a customer calls identify() in the SDK, they send us data about their own users. The customer is the controller of that data and we are their processor: we act only on the customer's instructions and only to provide the service. What the SDK typically sends:
We keep end-user data for as long as the customer's project exists. Customers can delete individual users or a whole project from the dashboard, and the data is removed within 30 days. If you are an end user and want to access, correct or delete your data, contact the company whose product you used; we will assist them. If you cannot reach them, email us and we will help.
Customers are responsible for having a lawful basis to share their users' data with SuggestKit and for describing this processing in their own privacy notice. Our Terms include the processing commitments we make to customers.
We share personal data only with the providers below, each bound by a data processing agreement, and with authorities where the law requires it. We will notify customers by email before adding a new subprocessor that handles end-user data.
The dashboard uses strictly necessary cookies for sign-in and preferences, plus a PostHog analytics cookie. The marketing site uses PostHog only. We do not use advertising cookies or cross-site tracking, and we honor the Global Privacy Control signal.
The feedback widget sets no cookies of its own on your users' browsers; it identifies users through the data the customer passes to the SDK.
Account and feedback data is kept while your account is active. When you delete your account or a project, we delete the associated data within 30 days, except for invoices and records we must keep for tax and accounting purposes, which are kept for the period the law requires. Backups roll off within 35 days.
Error and analytics data is retained for 90 days and then deleted or aggregated.
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting providers. Access to production is limited to the people who operate the service, and API keys are hashed before storage so we cannot read them back. If we learn of a breach affecting your data we will notify you without undue delay, and within 72 hours where the GDPR applies.
Our providers store data in the United States and the European Union. Where data leaves the EU or UK we rely on the providers' Standard Contractual Clauses and Data Privacy Framework certifications.
Depending on where you live, including under the GDPR, UK GDPR, CCPA and KVKK, you have the right to:
To exercise any of these, email support@suggestkit.app. We answer within 30 days and never charge for a reasonable request.
SuggestKit is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.
We may update this policy as the product changes. For material changes we will email account holders at least 14 days before they take effect. The date at the top shows the current version.
Questions? Email support@suggestkit.app.