Privacy and store forms
The component only captures something after the user opens it, points at something and taps Send. Here is what that means for the forms you fill in. This page is information to help you, not legal advice, and the store rules change: check the current wording before you submit.
What the component sends, and when
When the app starts. The component asks Nitpick for your feedback settings (which kinds are on, and two texts). It asks again when the app comes back to the foreground, if the last successful request is more than an hour old. The request carries your public app key and nothing about the user or the device. As with any internet request, the operating system adds the IP address and a User-Agent. Nitpick uses them only to answer the request and does not store them. SwiftUI keeps the last answer in UserDefaults on the device; Expo keeps it in memory while the app runs. With dryRun on, nothing is requested.
Only after the user opens the form and taps Send:
- A screenshot of your own app screen, made by your app. The user sees a preview first and can remove it. Masked parts are black.
- The tap position, and the screen and element names you marked.
- The user's comment.
- Device model identifier, OS version, language, app version and build number.
Never: screen recordings, other apps, the photo library, the device name the user chose, the serial number, a name, an email or any account or device identifier of the user. The feedback is anonymous.
Apple: App Privacy ("nutrition label")
Feedback stored on Nitpick's servers counts as data collected from the app. Apple lets you decide the categories; these are our suggestions. Check them against what your own app does.
| Question | Suggested answer |
|---|---|
| Data type: Other User Content (comments, screenshots) | Collected: yes |
| Data type: Product Interaction (tap position) | Collected: yes |
| Data type: Device ID | Not collected (we send a model identifier, no ID) |
| Linked to the user's identity? | No, feedback is anonymous |
| Used for tracking? | No |
| Purpose | App Functionality |
Apple also asks for a privacy policy link in App Store Connect and in the app (guideline 5.1.1), and wants a clear indication when something is captured (2.5.14) and mention when data goes to third parties, including AI (5.1.2(i)). The preview, the Send button and the line "Your feedback goes to the maker of this app." are there for this. If you let an AI tool read reports, say so in your privacy policy. Whether this satisfies a reviewer is an interpretation: Apple does not state it for a one-time screenshot that the user starts.
The iOS package ships its own privacy manifest. Xcode merges it into the privacy report of your app.
Google Play: Data safety
| Section | Suggested answer |
|---|---|
| Data collected: App activity, App interactions (tap position, screenshots taken) | Yes, collected |
| Data collected: Other user-generated content (comments) | Yes, collected |
| Device or other IDs | No |
| Shared with third parties | No, except processors acting for you |
| Is collection optional? | Yes, the user chooses to send it |
| Data encrypted in transit | Yes, HTTPS |
| Can users request deletion | Yes, through you (see below) |
"Screenshots taken" appears in Google's own wording of App interactions. That it covers our image exactly is an interpretation. Under Google's User Data policy you need a prominent in-app disclosure when collection goes beyond what users expect. The form with its preview and Send button is that disclosure.
A paragraph for your privacy policy
Adapt this and put it in your own policy:
Feedback. If you choose to send feedback from the app, we collect what you send: your comment, an optional screenshot of the app screen you were on, the position where you tapped, and technical details such as device model, operating system version, language and app version. We do not collect your name, email address or any device identifier with it. Feedback is only sent if you press Send in the feedback form. When the app starts, it asks Nitpick for the feedback settings; this request contains no information about you and is not stored. Your feedback and account information are stored at Supabase on servers in the European Union. We use this to fix and improve the app. We use a service provider (Nitpick) to store feedback for us, and we may use an AI tool to read and act on it. Contact us at [your contact address] to ask us to delete feedback you sent.
Your checklist
- A coding agent writes these texts to
NITPICK_PRIVACY.mdand checks that the sentence "When the app starts, it asks Nitpick for the feedback settings; this request contains no information about you and is not stored." is in it. - Mark sensitive views with the mask.
- Mention in your policy that the app asks Nitpick for its feedback settings at start-up (the sentence in the paragraph above does this).
- Add the paragraph above to your privacy policy and link the policy in both stores.
- Fill in App Privacy and Data safety with the tables above.
- Keep the note under Send, or one like it.