Legal

Privacy Policy

Last updated: August 4, 2026

This policy covers the WebPinch website, web app, Chrome extension, and the WebPinch mobile app for Android and iOS (package / bundle identifier com.webpinch.mobile). Effective August 4, 2026.

1. Introduction & Scope

WebPinch ("WebPinch", "we", "us", "our") provides a visual website feedback, bug-tracking, task-management, and site-auditing platform. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights and choices you have.

  • The WebPinch website and marketing pages at webpinch.com
  • The WebPinch web application and dashboard at app.webpinch.com
  • The WebPinch browser (Chrome) extension
  • The WebPinch mobile application for Android (Google Play package com.webpinch.mobile) and for iOS (App Store bundle identifier com.webpinch.mobile)
  • Guest feedback links, shared review links, and our public API

We refer to all of the above together as the "Service". The mobile app and the web app share one account and one backend: data you create in the app is the same data you see on the web, and everything in this policy applies to both unless a section says otherwise.

2. Who We Are & How to Contact Us

WebPinch operates the Service and is the party responsible for the personal data described in this policy. For your account, billing, and marketing data we act as the data controller (the Data Fiduciary under India's DPDP Act). For the projects, tasks, feedback, comments, and screenshots you and your team create inside WebPinch, we act as a data processor on your behalf — you or your organization remain the controller of that content. You can reach us about any privacy matter, including a request to access or delete your data, at info@webpinch.com or through the contact page at webpinch.com/contact. We respond to privacy requests within the timeframes required by applicable law.

3. Information We Collect

We collect only what the Service needs in order to work. The categories below are the complete list, and each maps to the declarations we file in the Google Play Data safety form and the Apple App Privacy questionnaire.

  • Account data — your name, email address, username, profile photo (if you set one), a securely hashed password, and the organization, team, and role you belong to. Provided by you at sign-up, or supplied by Google if you choose Sign in with Google.
  • Work content you create — projects, tasks, subtasks, checklists, comments and @mentions, labels, time entries, feedback pins, and the page URLs and DOM/element metadata attached to them.
  • Photos, files, and attachments — images you pick from your photo library, photos you take with the camera, and documents you upload, when you choose to attach them to a task or comment. The app accesses your photo library and camera only at the moment you tap to attach something, and only for the item you select.
  • Screenshots, screen recordings, and captured pages — created on the web app and Chrome extension when you capture or annotate a site under review.
  • Push notification data — when you enable notifications, an Expo push token identifying your device installation, plus the platform (iOS or Android), stored against your account so notifications reach the right device. We do not collect advertising identifiers (no IDFA, no Android Advertising ID).
  • Usage and diagnostic data — IP address, browser or app version, operating system and version, device model, screen size, pages or screens opened, feature interactions, and error and crash information, collected automatically to keep the Service secure, working, and improving.
  • Payment data — billing name, billing address, plan, and transaction identifiers. Card details are entered directly with our payment providers; we never receive or store full card numbers.
  • Integration data — the accounts, repositories, channels, issues, or calendars you authorize when you connect Google, GitHub, Slack, or Jira, and the OAuth tokens needed to keep that connection working. We request the narrowest scopes each integration needs.
  • Guest data — when someone leaves feedback through a guest link without an account, we collect the feedback they submit, the name or email they choose to provide, and basic technical data such as IP address and browser type.
  • Support and communications — the messages, attachments, and contact details you send us when you write to support or fill in a form on our site.

4. Mobile App Permissions

The WebPinch mobile app asks for a small set of device permissions, always at the moment you first use the feature that needs them, and always with an explanation on screen. Every one of them is optional — the app remains usable if you decline, minus that feature — and you can grant or revoke each at any time in your device settings (iOS: Settings › WebPinch; Android: Settings › Apps › WebPinch › Permissions).

  • Notifications (POST_NOTIFICATIONS on Android, user notifications on iOS) — to alert you about task assignments, comments, mentions, and due dates. Declining means you simply do not receive push alerts.
  • Photo library — to let you attach an existing image to a task or comment. We receive only the specific images you select; we never browse or index your library.
  • Camera — to let you take a photo and attach it. Nothing is captured unless you take the photo and confirm the attachment.
  • Files and documents — to let you attach a document you pick from your device's file picker.
  • Network access — to communicate with the WebPinch backend over an encrypted connection.

The app does not request access to your location, contacts, calendar, microphone, health data, SMS, call logs, or any other sensitive permission, and it does not run background collection of any kind.

5. How We Use Your Information

We use personal data for the following purposes, and for no others.

  • App functionality — to create and secure your account, sign you in, show your projects and tasks, deliver comments and mentions, store attachments, run site audits, and sync the mobile app with the web app.
  • Notifications and service communications — to send push notifications and transactional email about activity relevant to you, security events, and changes to the Service or its terms.
  • Payments and account management — to process subscriptions, seats, invoices, and refunds.
  • Security, fraud prevention, and abuse detection — to detect suspicious sign-ins, rate-limit abuse, keep audit logs, and protect the Service and its users.
  • Support — to answer your questions and troubleshoot issues you report.
  • Improving the Service — to understand which features are used and where the product fails, in aggregate or de-identified form wherever possible.
  • Legal compliance — to meet tax, accounting, and other legal obligations and to respond to lawful requests.

6. What We Do Not Do

Some commitments are easier to state as absolutes, and we hold ourselves to them.

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
  • We do not track you across other apps or websites. The mobile app contains no advertising SDKs, no ad identifiers, and no third-party analytics that follow you elsewhere — which is why it presents no App Tracking Transparency prompt on iOS.
  • We do not show ads in the Service.
  • We do not collect your device location, contacts, calendar, or microphone audio in the mobile app.
  • We do not use your private project content, screenshots, or comments to train our own machine-learning models, and our AI providers are contractually bound not to train on it either.
  • We do not require you to provide data we do not need in order to give you the Service.

7. Legal Bases for Processing

Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (providing the Service you signed up for and taking payment); our legitimate interests (securing the Service, preventing fraud and abuse, and improving the product, balanced against your rights); your consent (optional marketing messages, non-essential cookies, and device permissions such as notifications, camera, and photos, each of which you may withdraw at any time); and compliance with legal obligations. Where India's Digital Personal Data Protection Act applies, we process personal data on the basis of your consent or another legitimate use permitted by the Act, and you may withdraw consent at any time by writing to info@webpinch.com or deleting your account.

8. Captured Content, Screenshots & the Website Proxy

On the web app and Chrome extension, WebPinch lets you pin feedback and capture screenshots on live, staging, and local websites, and can load sites through a secure proxy for in-app review — which may involve storing and replaying session cookies you provide so that authenticated pages render correctly. This captured content can include personal data belonging to you or to third parties that appears on the pages you review. You are responsible for ensuring you have the right to capture, review, and store that content and to use any credentials you supply to the proxy. We process this content solely to provide the Service to you and your team, access is restricted to authorized members of your project or organization, and proxy sessions and their credentials are held only for the life of the session. These capture features are web-only; the mobile app does not capture or proxy websites.

9. AI Features

Some parts of the Service — the AI assistant, AI-generated task suggestions, and parts of site-audit analysis — send the relevant content you supply (such as your prompt, a task description, or audit findings) to our AI provider, OpenAI, so it can generate a response. That content is processed only to produce your result, is not used by the provider to train its models under the API terms we operate on, and is retained by the provider only for the limited period its abuse-monitoring policy requires. Do not paste credentials, payment details, or other sensitive personal data into AI prompts. If you would prefer not to use these features, simply do not invoke them; the rest of the Service works without them.

10. How We Share Information

We share personal data only in the situations listed here.

  • With your team — project, task, comment, and attachment content is visible to the members of the organization or project it belongs to, and to anyone you invite to it. Guest feedback is visible to the project members who receive it.
  • With sub-processors — vendors that run parts of the Service on our behalf, under contract, limited to what each needs: Vercel (application hosting), Amazon Web Services (file, screenshot, and recording storage in India), MongoDB Atlas (database), Stripe (payments), Zoho (transactional and notification email), Google (Sign in with Google, and Firebase Cloud Messaging for Android push delivery), Apple (Apple Push Notification service for iOS push delivery), Expo (push token issuance and push relay for the mobile app), and OpenAI (AI features). The current list, with each vendor's purpose and location, is maintained at webpinch.com/subprocessors.
  • With integrations you connect — when you link GitHub, Slack, Jira, or Google Calendar, we exchange the data needed to perform the action you asked for, such as creating an issue or posting a notification.
  • For legal reasons — where we must comply with applicable law, a valid legal request, or to establish, exercise, or defend legal claims, or to protect the rights and safety of our users or the public.
  • In a business transfer — if WebPinch is involved in a merger, acquisition, or sale of assets, your data may transfer to the successor, which will remain bound by this policy or give you notice of any change.

We do not share your personal data with anyone else, and none of the sharing above is a "sale" or "sharing" as those terms are defined by California law.

11. International Data Transfers

Our servers and primary storage are located in India. If you use WebPinch from the European Economic Area, the United Kingdom, the United States, or elsewhere, your personal data will be transferred to and processed in India and in the other countries where our sub-processors operate. Where such transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and we take account of the protection given to the data in the destination country.

12. Cookies, Local Storage & Similar Technologies

On the web, we use cookies and similar technologies to keep you signed in, remember preferences such as your theme, and understand how the Service is used so we can improve it. Strictly necessary cookies are required for the Service to function; you can control the rest through your browser, though disabling them may affect functionality. The mobile app does not use advertising cookies or trackers. It stores your session token in the device's secure keystore (iOS Keychain / Android Keystore) and keeps a local cache of your projects and tasks on the device so the app opens quickly and works with a poor connection. Both are cleared when you sign out or uninstall the app.

13. Data Retention

We keep personal data only as long as we need it for the purpose it was collected for.

  • Account and work content — for as long as your account is active. When your account is deleted, this data is deleted or irreversibly de-identified within 14 days.
  • Attachments, screenshots, and recordings — deleted along with the project or account they belong to, and within 14 days of account deletion.
  • Push tokens — deleted when you sign out, disable notifications, uninstall the app, or delete your account, and pruned automatically once the platform reports the token as no longer valid.
  • Security and audit logs — up to 12 months, to investigate abuse and security incidents.
  • Billing and transaction records — up to 8 years where tax and accounting law requires it. These records are kept even after account deletion, and are limited to what the law requires.
  • Support correspondence — up to 24 months after the matter is closed.
  • Encrypted backups — rotated on a rolling basis and fully overwritten within 90 days, after which deleted data no longer exists in any backup.

14. Account & Data Deletion

You can delete your WebPinch account and its data at any time, and you do not need our help to start it.

  • In the mobile app — open Profile › Delete account, confirm, and your account and data are permanently deleted within 14 days.
  • On the web — sign in and go to Dashboard › Settings › Profile › Delete account.
  • Without signing in — visit webpinch.com/account-deletion or email info@webpinch.com from the address on your account, and we will verify you and process the deletion.

Deletion removes your profile, your personal work content, your attachments and screenshots, your push tokens, and your integration tokens. Content you contributed to a shared organization — such as a comment on a colleague's task — may remain visible to that organization with your identity removed, so the team's record stays coherent. We retain only what the "Data Retention" section above says the law requires. Deleting the app from your device does not by itself delete your account; use one of the routes above.

15. Data Security

We protect your data with HTTPS/TLS encryption for all data in transit (the mobile app refuses unencrypted connections), encryption at rest for stored files and database contents, hashed passwords, session tokens held in the device's secure keystore, role-based access controls, and the principle of least privilege for our own staff. Screenshots and feedback data are scoped to your projects and reachable only by authorized members. No method of transmission or storage is completely secure, but we work continuously to protect your information using industry-standard measures, and we ask that you use a strong, unique password and keep your device locked.

16. Data Breach Notification

If we become aware of a personal data breach that is likely to affect you, we will notify the relevant supervisory authority and the affected users without undue delay and in accordance with applicable law, including within 72 hours where the GDPR requires it and as prescribed under India's DPDP Act.

17. Your Privacy Rights

Depending on where you live, you have some or all of the following rights over your personal data: to access it and receive a copy, to correct it, to delete it, to receive it in a portable format, to object to or restrict certain processing, to withdraw consent you previously gave, and not to be discriminated against for exercising any of them. EEA and UK residents hold these rights under the GDPR and may also lodge a complaint with their local supervisory authority. Residents of India hold rights under the DPDP Act, including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise their rights. California residents hold rights under the CCPA/CPRA to know, delete, correct, and opt out of any sale or sharing — and, as stated above, we do not sell or share personal information. To exercise any right, email info@webpinch.com or use webpinch.com/contact. We will verify your identity before acting and respond within the period the applicable law allows.

18. Children's Privacy

WebPinch is a business productivity tool intended for adults. It is not directed to children, is rated for a general adult audience in the App Store and on Google Play, and you must be at least 18 years old (or the age of majority where you live) to create an account. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact info@webpinch.com and we will delete it promptly.

19. Third-Party Sites & Content

The Service lets you review, audit, link to, and load third-party websites, and it can connect to third-party platforms you authorize. Those sites and platforms are governed by their own privacy policies, not this one, and we are not responsible for their practices. Review their policies before sharing personal data with them.

20. Changes to This Policy

We may update this Privacy Policy as the Service evolves or the law changes. The "Last updated" date at the top of this page always reflects the current version. When we make material changes, we will notify you by email or through a notice in the Service before the change takes effect, and — where the law requires it — ask for your consent. Continued use of WebPinch after a change takes effect means you accept the updated policy.

21. Contact Us & Grievance Officer

Questions, requests, or complaints about this Privacy Policy or how we handle your data go to info@webpinch.com, or to the contact page at webpinch.com/contact. In accordance with India's Digital Personal Data Protection Act, the same address reaches our Grievance Officer, who acknowledges and addresses grievances within the timelines prescribed by law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or, in the EEA/UK, to your local supervisory authority.