Privacy Policy
Effective date: July 19, 2026
This Privacy Policy explains how 2morrow.ai, LLC ("2morrow.ai," "we," "us," or "our") collects, uses, and discloses information in connection with the yrFeedback service.
yrFeedback is a feedback-collection tool that businesses ("Vendors") embed inside their own applications (each a "Calling App," e.g., Zcope) so that the Calling App's end-users ("End-Users") can submit product feedback. Please read this policy alongside the Vendor's own privacy policy, since the Vendor — not 2morrow.ai — is generally responsible for how it uses your feedback.
1. Who This Policy Covers
This Policy applies to:
- End-Users of a Calling App who submit feedback through the yrFeedback widget.
- Vendors and their authorized personnel who access the cockpit to view and triage feedback.
2. Our Role: Processor, Not Controller (for End-User Feedback)
For feedback data submitted by End-Users, the Vendor is the data controller and 2morrow.ai is the data processor (or "service provider," under CCPA terminology). This means:
- The Vendor determines why and how End-User feedback is collected and used.
- 2morrow.ai processes that data only on the Vendor's instructions and as described in our agreement with the Vendor and this Policy.
- Requests to access, correct, or delete End-User feedback should generally be directed to the Vendor first. See Section 8 below.
Exception for First-Party Applications: If you are submitting feedback through a Calling App that is also owned and operated by 2morrow.ai, LLC (such as Zcope), then 2morrow.ai, LLC acts as the data controller for your feedback and your personal data. In these instances, you may direct your privacy requests directly to us.
3. Information We Collect
The yrFeedback service is built to be privacy-preserving by design. We collect only what is necessary to route, classify, and de-duplicate feedback — we do not perform session replay, do not collect console logs, and do not engage in deep behavioral tracking.
3.1 Information from End-Users
| Category | What it includes | When it's collected |
|---|---|---|
| Feedback content | The free-text feedback the End-User submits | Always, when feedback is submitted |
| Screenshots | Image files (PNG, JPEG, or WebP) the End-User chooses to attach | Only when the End-User attaches them; stored in a private bucket, accessible to the relevant Vendor via short-lived signed links |
| Identity information | Email address and display name | Only when the Calling App marks the End-User as authenticated via a signed token |
| Contact email (updates opt-in) | An email address the End-User provides, with a consent timestamp | Only when the End-User switches on "Keep me posted about this"; used solely for status updates on that feedback and Vendor follow-up questions; consent is withdrawable at any time |
| User reference | An opaque identifier supplied by the Calling App (not a real name or contact detail on its own) | Always, via the signed token |
| Environment metadata | Operating system, browser, viewport size, and locale | Always, alongside feedback submission |
| IP address | Processed transiently for rate limiting and abuse prevention; recorded in security audit logs | On submission and security-relevant actions |
We do not independently authenticate End-Users. Identity is "vouched for" by the Calling App through a signed token; we rely on that token and do not verify identity ourselves.
3.2 Information from Vendors
When a Vendor and its personnel use the cockpit, we collect account information (such as name, work email, and login credentials) and usage data needed to operate the cockpit (e.g., which feedback items were viewed, triaged, or actioned).
3.3 Information We Do Not Collect
We do not collect session recordings, screen captures, keystroke logs, browser console output, or any tracking data beyond the basic environment metadata described above.
4. How We Use Information
We use the information described above to:
- Deliver, operate, and maintain the yrFeedback service;
- Route submitted feedback to the correct Vendor;
- Classify, summarize, and score feedback (estimated impact and effort) and detect duplicate submissions (see Section 5, Gemini API);
- Screen submissions with an automated keyword check for spam and abuse (performed on our own servers, without AI, before any AI processing; it annotates submissions for Vendor review and never deletes them);
- Send status updates about a feedback item to End-Users who opted in, and enable Vendor follow-up questions (opt-in only, withdrawable);
- Authenticate and support Vendor cockpit users;
- Maintain the security and integrity of the service;
- Comply with legal obligations; and
- Communicate with Vendors about their account and the service.
We do not sell End-User personal information, and we do not use End-User feedback content to build advertising profiles.
5. Third-Party Subprocessors
We use a limited number of subprocessors to operate the service. The current subprocessors for feedback content are:
- Google Gemini API — Submitted feedback text is sent to Google's Gemini API for automated classification, a short neutral summary, and impact/effort estimation used in the Vendor's triage. Google processes this content on our behalf under its own data processing terms. We do not use feedback content to train AI models. Submissions flagged at the highest level by our keyword screening are not sent to the AI at all. Attached screenshots are not currently sent to any AI provider.
- Supabase — database, authentication, and private file storage.
- Vercel — application hosting.
- Resend, Inc. — transactional email delivery for platform notifications and user status updates.
A current list of subprocessors is available on request via support@yrFeedback.com. We do not share End-User feedback content with any other third party for their own independent use.
5a. Cookies
The service uses functional cookies only: a short-lived session cookie for the feedback widget and, for Vendor cockpit users, sign-in session cookies. We set no tracking, analytics, or advertising cookies.
6. Data Retention
We retain feedback data and related metadata for as long as necessary to provide the service to the Vendor, or as otherwise instructed by the Vendor, subject to applicable law. Specific retention periods are set out in our agreement with the Vendor and/or Vendor-configurable settings.
7. Data Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Privacy Rights
Depending on your location, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), including the right to:
- Access the personal information we (or the Vendor, as controller) hold about you;
- Correct inaccurate personal information;
- Delete your personal information, subject to legal exceptions;
- Opt out of non-essential update or marketing notifications; and
- Object to or restrict certain processing, where applicable.
Because 2morrow.ai typically acts as a processor for End-User feedback, we ask that you first direct requests to the Vendor whose Calling App you used. If you are unable to reach the Vendor, or your request relates to Vendor account data, contact us at support@yrFeedback.com and we will assist or route your request appropriately.
9. International Data Transfers
Where information is transferred across borders (including to subprocessors such as Google), we rely on appropriate safeguards required by applicable law, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, where applicable.
10. Children's Privacy
The Service is not directed to children and is intended for use in connection with business software products. If you believe a child has submitted personal information through our widget, contact us at support@yrFeedback.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above, and, where required by law, we will provide additional notice.
12. Governing Law
This Policy is governed by the laws of the State of Colorado, USA, without regard to conflict-of-law principles, except where applicable law (such as the GDPR for individuals in the EU/UK) requires otherwise.
13. Contact Us
For questions about this Privacy Policy or our data practices, contact us at support@yrFeedback.com.
Company: 2morrow.ai, LLC
Address: 2730 S Wadsworth Blvd Ste B # 1013, Denver, CO 80227, USA