Privacy policy
Last updated June 16, 2026
Candor exists so people can be honest. That only works if feedback is genuinely private, so we collect as little as possible and make anonymity structural - not a promise we ask you to trust.
Who this covers
This policy explains how Candor handles information for the people who use it: recipients (account holders who collect feedback), givers (anyone who responds to a feedback link, with no account required), and members of an organization that uses Candor. We collect as little as possible, and the product is built so that anonymous feedback stays anonymous.
If you use Candor as part of an organization, your organization administers your account and sets policies (including who can see your feedback); for that data the organization is the controller and Candor is its processor. This policy describes our own practices.
Information we collect
- Account (recipients): your email, name, chosen link slug, optional profile photo and context blurb, notification preferences, and timezone.
- Feedback (givers): the responses you submit. In named mode, the name (and email, if you choose to share it) you provide. In sealed (anonymous) mode, no identifying information is collected.
- Organization: if you belong to an organization, your membership, role (owner/admin/manager/member), reporting line (who your manager is), and the org's plan and visibility settings.
- Billing: if you subscribe, a Stripe customer and subscription identifier and your plan/interval and renewal date. Card details go directly to Stripe - we never see or store full card numbers.
- Calendar (optional): if you connect Google Calendar, read-only event metadata (titles, times, attendee emails). See the Google Calendar section below.
- Referrals & product feedback: if you arrive via someone's referral link we note who referred you and record the click; any feedback or bug reports you send us are stored with your email so we can follow up.
- Technical: a short-lived, salted hash of your IP address for rate limiting and abuse prevention. We never store raw IP addresses against feedback, and the public giver form sets no cookies.
How anonymity works
For sealed responses, the connection between a comment and who wrote it is never stored - not hidden, not encrypted, never recorded at all. Timestamps shown to recipients are rounded to the week, and responses are released in batches, so no single response can be traced back to a moment or a person.
This is enforced at the database level, not by policy alone. We cannot reveal the author of a sealed response because that link does not exist in our systems.
Organizations & shared feedback
When you belong to an organization, an owner or admin sets a feedback-visibility policy - private (each person sees only their own), managers (your management chain can see yours), everyone, or specific grants. Within that policy, named feedback you receive may be visible to other members; sealed feedback is shown to others only as anonymized totals unless your organization explicitly enables individual sealed sharing.
Even when an organization enables individual sealed sharing, the author of a sealed response is still never stored or revealed - others may see the words, never who wrote them, and small groups are shown only as totals. Givers are told on the form when feedback is shared and when sealed feedback is org-visible, so they can decide what to write.
Your organization also sets your plan and can manage your membership. Where an organization connects single sign-on or directory provisioning (SSO/SCIM), we process the identifiers needed to create, update, and deactivate accounts on its instruction.
How we use information
- To provide the service: host your link, deliver feedback, send the requests, follow-ups, and digests you've enabled, and administer organizations.
- To process payments and manage subscriptions through Stripe.
- For AI summarization within your account only: feedback content may be processed to generate themes, sentiment, and suggested actions for you. It is not used to train third-party models and is not shared across accounts.
- To keep Candor safe and working: abuse prevention, rate limiting, debugging, and product analytics (metadata only - never feedback content).
- We do not sell personal information, and we do not use feedback content for advertising.
Google Calendar data
If you connect Google Calendar, Candor requests read-only access to your events (the calendar.events.readonly scope) and reads only recent event metadata - titles, times, and attendee email addresses - so you can send a feedback request after a meeting. We never modify your calendar, we never access your calendar lists or sharing settings, and we never read event notes, attachments, or conferencing details.
We use this data solely to show you your recent meetings in the app and to send the feedback requests you choose to send. The connection's access token is stored encrypted, and you can disconnect at any time in Settings, which deletes it. Candor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Payments
Subscriptions are processed by Stripe, our payment processor. When you upgrade, you enter card details directly with Stripe over its hosted checkout; Candor receives only a customer and subscription reference, your plan and billing interval, and status - never your full card number. Stripe processes your payment data under its own privacy policy.
Service providers (subprocessors)
We share data only with vendors who process it on our behalf, under contract: Supabase (database, authentication, storage), Vercel (hosting), Resend (transactional and request email), Stripe (payments and subscriptions), Cloudflare (bot protection), Google (only if you connect Calendar), Anthropic (AI summarization and abuse classification - answer text only, never identities), and PostHog (product analytics - metadata only, never feedback content).
Cookies & analytics
The public feedback form uses no cookies and no client-side tracking. The signed-in dashboard uses strictly necessary cookies for your session, and a single first-party cookie when you click someone's referral link toward signing up (so we can credit the referral). Product analytics record metadata only (event types, counts, buckets) - never the content of feedback, and giver-side events are anonymous.
Data retention & deletion
- Givers can delete their own response for 30 minutes after submitting, via the link on the confirmation screen - this is a permanent hard delete. During that window the response is held and not shown to the recipient.
- Recipients on the free plan see 60 days of history; older responses are hidden, not deleted, and return if you upgrade. Deleting your account permanently removes your links, questionnaires, and every response you've received.
- Recipient email addresses captured for a feedback request are encrypted and purged after the reminder window. Hashed abuse-prevention data (rate-limit and opt-out hashes) is retained only as long as needed for that purpose.
- Billing records are retained as required for tax and accounting. When you delete your account we cancel any active subscription.
Your rights & choices
Depending on where you live (including under GDPR and CCPA/CPRA), you may have the right to access, export, correct, or delete your personal information, to opt out of certain processing, and not to be discriminated against for exercising these rights. Recipients can export and delete from the app; anyone can email us to make a request. Givers who provided an email can use their confirmation link, or contact us. If your account is administered by an organization, we may direct your request to that organization.
International data transfers
Candor and its providers process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for transfers of personal information out of your region.
Security
We use encryption in transit, encryption at rest for sensitive tokens, row-level access controls, and least-privilege access. No system is perfectly secure, but anonymity is protected structurally - there is no stored link to expose.
Children
Candor is not directed to children and is not intended for anyone under 16. We do not knowingly collect information from children.
Changes & contact
We'll update this policy as the product evolves and note the date above; material changes will be communicated where appropriate. Questions or requests: privacy@withcandor.app.