Privacy

Last updated: 7 October 2026

What we collect, why, and who else touches it. Plainly, and without the fog.

What we collect

  • Your account: your email address, and the name of your workspace.
  • Your sites: the name and the origins (domains) you register for each site.
  • Reviewers: the name a reviewer gives when they sign in.
  • What reviewers leave: notes, screenshots, voice or screen recordings, attachments, and details about the page such as its address, the browser and the viewport size.
  • Billing: handled by Stripe. We keep your plan and the status of your subscription, and we never see or store card numbers.
  • Server logs: technical records such as IP addresses and request details, kept to run and protect the service.

Why we collect it

To run Nitpick: to sign you in, to store and deliver the notes your reviewers leave, to bill you, to keep the service secure, and to answer you when you write. We do not sell your data and we do not use it for advertising.

Who processes it

  • Stripe handles payments and subscriptions.
  • Resend sends our email, including the sign-in links.
  • Our hosting provider runs the servers and the database.
  • Destinations you connect, such as your webhook or ClickUp, receive your notes because you asked them to. What happens to them there is between you and that service.

How long we keep it

  • Notes and screenshots are kept for as long as the account exists.
  • Recordings are kept for your plan’s window: Solo 30 days, Studio 90 days, Agency 1 year. Older recordings are removed.
  • Deleting a site removes its data.
  • Closing an account is done on request, and removes the workspace and what is in it. Some records, such as invoices and server logs, are kept for a limited time where we need them for accounting, security or the law.

Cookies

Nitpick sets one cookie, to keep you signed in. We do not use tracking or advertising cookies. The site remembers your light or dark choice in your browser, and nothing else.

If you are a reviewer

If you left a note on someone’s site, that site’s owner is the one who asked you to and who decides what happens to it. To see, correct or delete what you left, ask them. We act on their instruction, and where you write to us instead, we will point you to them or pass your request on.

Security

Connections use TLS. Sign-in tokens and review PINs are stored hashed. Links to screenshots and recordings are signed and expire. No system is perfectly safe, but we take care with this one, and we will tell affected customers promptly if something goes wrong.

Contact

Questions, or a request about your data: [contact email].

Changes to this policy

We may update this policy. When the change matters, we will email the account owner. The date at the top says when it was last updated.