Privacy Policy
Last updated: September 2026
This policy explains what CoApprove collects and how we use it.
What we collect
- Account data — an administrator's email address, used to sign in and manage the account.
- Feedback — the reports, comments, and votes users submit.
- Technical context attached to a report, as configured by each Site: the page URL, browser/OS/device, app or build version, screen size, recent console errors, and (optionally) a screenshot.
- Vouched identity — when a Site signs a user in, it passes that user's id and display name (and, if the Site chooses, email). CoApprove does not create passwords for end users.
How we use it
Solely to provide the service — to display feedback, let teams triage it, and operate and secure the platform. We do not sell personal data and do not use it for third-party advertising.
Cookies
Signed-in users receive a single, HttpOnly session cookie so the site knows who
they are. We do not use third-party advertising or cross-site tracking cookies.
Sharing
We share data only as needed to run the service (e.g. with infrastructure providers acting on our behalf) and with the company operating the Site the data came from. We may disclose data where required by law.
Security
Signing secrets and API keys are held server-side and never exposed to the browser; session
cookies are HttpOnly; traffic is served over TLS. No system is perfectly secure,
but we take reasonable measures to protect data.
Retention
We keep data while the account is active or as needed to provide the service, and delete or anonymize it on request from the responsible company, subject to legal requirements.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your data. End users should contact the company whose Site they used; account administrators can contact us.
Changes
We may update this policy; the date above reflects the latest version.