Privacy
Embed-only feedback. You assert identity. You own moderation.
Bootstrapware Feedback is not a public roadmap site. The widget lives inside your product. Your app asserts who is posting. Storage depends on BYO vs Hosted.

Identity
We do not authenticate end users. Pass a user object with an opaque stable id from your session. Optional name, email, and avatarUrl are display metadata only.
BYO vs Hosted content
- BYO: post title and body never leave your systems via the Bootstrapware data path. We host board configuration only.
- Hosted: posts and votes are stored on Bootstrapware. Plain text. You moderate; you are responsible for content.
- Local demo: adapters keep posts in the browser (e.g. localStorage).
What MCP never receives
MCP configures boards only. Do not send post title, body, or votes through MCP tools.
Cancel Hosted
If you cancel Hosted: writes freeze, you can export for 30 days, then Hosted posts are deleted.
What you still own
Authentication, authorization, rate limits on your app, and (for BYO) retention of posts. For Hosted, moderation and lawful content remain your responsibility.
See also security and the company privacy policy.