Section 01
Who is responsible for personal data
Volovyk ENK, at Ytrebygdsvegen 11, 5251 Søreidgrend, Norway, operates PrioSmith and is responsible for personal data used to run the website, accounts, billing, support, and the service.
A PrioSmith customer controls the personal data it collects from its own users through feedback boards, widgets, and integrations. For that data, the customer decides why it is processed and PrioSmith acts as its service provider. Questions can be sent to support@priosmith.com.
Section 02
Data we collect
- Account data: name, email address, profile image, authentication identifiers, and workspace membership.
- Customer content: feature requests, votes, comments, reactions, attachments, roadmaps, changelogs, tags, and internal notes.
- Billing data: plan, subscription status, invoices, tax location, and payment-provider identifiers. Complete card numbers are handled by Stripe.
- Technical data: IP address, browser and device information, request timing, security events, session data, and service diagnostics.
- Communication data: support messages, notification choices, email delivery status, and integration configuration. When a customer enables Email-to-feedback, Resend temporarily supplies the received message so PrioSmith can create a moderated plain-text feedback request; PrioSmith stores that request but not the sender address, raw headers, HTML, or attachments.
- Optional connected data: identifiers and content received from tools you deliberately connect, such as Slack or a signed webhook destination.
Public posts, comments, roadmap entries, and changelogs are visible to visitors by design. Avoid putting confidential or sensitive personal data in a public field.
Section 03
Why we use data
- provide accounts, feedback workflows, public portals, widgets, APIs, notifications, and integrations;
- process subscriptions, prevent fraud, and maintain billing records;
- secure, monitor, diagnose, and improve the service;
- answer support, legal, privacy, refund, and cancellation requests;
- send service messages and requested product-update notifications;
- comply with tax, accounting, legal, and regulatory obligations.
Depending on the context and applicable law, these activities rely on performing a contract, legitimate interests in operating and securing the service, consent, or compliance with a legal obligation. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
Section 04
AI-assisted drafting
An authorized workspace member may choose to send selected feedback or release context to OpenAI to draft a changelog. PrioSmith does not send workspace content to the AI provider merely because it is stored in the service. The draft is a suggestion and must be reviewed before publication.
Do not include secrets, special-category personal data, or information that you are not authorized to send to an AI provider. PrioSmith does not use customer content to train a PrioSmith model.
Section 07
Optional website analytics
When optional analytics is available, it stays off until you select Allow analytics. You can decline without losing access to the service. Use Change analytics preferences at the bottom of a public page to withdraw consent. Browser Do Not Track and Global Privacy Control signals also keep this analytics off.
Vercel Web Analytics measures visits to public marketing pages, documentation, demonstrations, and free tools, plus selected product links and CSV exports from the RICE and MoSCoW tools. Those action events contain only fixed page, link, tool, and output categories, not tool text or scores. We remove query values and fragments, exclude private and customer-hosted pages, and do not send form content or account and workspace identifiers in these events. We skip collection when a referring URL contains a query, a fragment, or an unsafe path.
Vercel derives visitor counts from incoming requests and provides aggregate reports with browser, device, referring-site, and approximate location information. Its visitor session identifier expires after 24 hours. This does not mean that aggregate reports expire after 24 hours. Withdrawing consent stops new collection but does not remove earlier aggregates. See Vercel's analytics privacy details.
Vercel Speed Insights measures public-page load speed, responsiveness, and layout shifts after the same consent. It receives the cleaned public URL, fixed route, browser, device, network type, approximate country, performance values, and CSS element selectors. It does not receive tool text, scores, or account identifiers. Vercel states that these performance records do not identify visitors or reconstruct sessions across pages. See Vercel's performance privacy details.
We do not use session replay or advertising pixels. An optional fixed-choice source question during workspace creation is stored with the workspace, not sent to Vercel. With your analytics consent, the registered first and latest campaign IDs and the consent date/version are also attached to a new workspace. These are browser-reported sources, not proof of what caused signup. Clearing storage, withdrawing consent, or an expired choice stops that handoff. After a successful handoff, the local campaign record is cleared. The workspace source record is removed when the workspace is deleted; contact us to request removal earlier.
Section 08
Retention and deletion
Account and workspace data is retained while the account is active and for the period reasonably needed to provide the service. A confirmed account-deletion request has a 30-day grace period so the owner can reverse an accidental request. After that period, active service data is scheduled for deletion, subject to legal and technical limits.
Billing and tax records may be kept for the period required by law. Security logs, delivery suppression records, and dispute evidence may be retained for a limited period necessary to prevent abuse or establish legal claims. Public content remains until the controlling workspace removes it or the associated account or workspace is deleted.
Section 09
Security and international processing
PrioSmith uses access controls, tenant isolation, encryption in transit, protected provider credentials, signed callbacks, and operational safeguards designed to protect personal data. No online system can guarantee absolute security, so report a suspected incident promptly to the support address.
Providers may process data outside your country. Where the law requires it, the operator uses an approved transfer mechanism or relies on another lawful basis for the transfer. Provider locations and safeguards may change as the service evolves.
Section 10
Your privacy choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, and to complain to a data protection authority. You can change some profile and notification data in the service. For another request, email support@priosmith.com.
We may need to verify identity and authority before acting. If PrioSmith processes your data only for a customer, the request may be referred to that customer. We will respond within the period required by applicable law.
Section 11
Children
PrioSmith is a business service and is not directed to children. Do not create an account or submit a child's personal data unless a lawful customer use case, appropriate notice, and any required parental authorization are in place.
Section 12
Policy changes
This policy may be updated when data practices, providers, the service, or legal obligations change. The new effective date will appear here, and material changes will be communicated through the website, service, or account email when required.
Questions or notices
Contact the PrioSmith operator.
Use the published support address for account, billing, privacy, cancellation, legal, or dispute questions. Include only the information needed to identify the request.