Open beta — everything is free.

See pricing
Sentriment

Legal

Privacy Policy

Last updated: 8 August 2026

This policy explains how Sentriment (“we”, “us”) collects, uses and protects personal data when you visit sentriment.com, create an account, or use the Sentriment service. We wrote it to be read, not skimmed past — it is short because our data practices are simple.

1. Who is responsible (the controller)

Sentriment
Viale Cirene 4, Milan, Italy
Email: hello@sentriment.com

Sentriment acts in two distinct roles, and this policy covers both:

2. What we collect, and why

Data we control

DataPurposeLegal basis
Account data — name, email address, password (stored only as a salted hash)Creating and securing your account; transactional email (verification, password reset)Contract performance (Art. 6(1)(b))
Onboarding answers — role, company size, goal, referral source (all optional)Understanding who uses Sentriment and improving the productLegitimate interest (Art. 6(1)(f))
First-touch attribution — UTM parameters and referrer, stored in a first-party cookieKnowing which channel brought you hereLegitimate interest (Art. 6(1)(f))
Audit and security logs — actions in your workspace, IP addressSecurity, abuse prevention, an audit trail for your own workspaceLegitimate interest (Art. 6(1)(f))
Aggregate traffic counts on our public website — page address, referring site, approximate country, browser and device type. No cookie, no persistent identifier.Knowing how many people reach our site and which pages they readLegitimate interest (Art. 6(1)(f))

Data we process on behalf of customers

Feedback text and optional end-user identifiers that customers send to their workspace via the widget, REST API, connectors or CSV import. Personally identifiable information inside feedback text — emails, names, phone and card numbers — is automatically redacted before storage and replaced with typed placeholders, in two steps: deterministic pattern matching, followed by an AI redaction pass (Anthropic) that removes personal data the patterns miss, such as names or obfuscated emails. The raw values are not written to our database. Customers are responsible for having a lawful basis to collect this data from their own users.

If a customer connects an analytics destination (such as Mixpanel or Amplitude), Sentriment sends that customer's own user identifiers together with sentiment-derived health properties to that destination — on the customer's instruction and under the customer's configuration. We never send feedback text through this channel, and disconnecting stops the flow immediately.

3. What we don't do

4. Where data lives, and who touches it

Sentriment is hosted in the European Union: our database runs in Frankfurt, Germany, and our application compute — both the dashboard and this website — runs in Frankfurt too. Two exceptions are noted in the table below: anonymous website traffic counts are processed by Vercel in the United States, and — only if you choose to sign in with Google — your name and email address are exchanged with Google in the United States. Your workspace data (your users' feedback) always stays in the EU. We use a small number of subprocessors:

SubprocessorPurposeRegion
Neon (Postgres)Primary databaseFrankfurt, Germany 🇪🇺
VercelWeb hosting, application serving, and cookieless website traffic measurementHosting and application compute: EU (Frankfurt). Website traffic measurement: United States, under Vercel's data processing agreement.
Fly.ioBackground processingFrankfurt, Germany 🇪🇺
ResendTransactional emailEU region
GoogleOptional “Continue with Google” sign-in. Used only if you choose it: Google confirms your email address and name to us. Your users' feedback is never involved, and signing in with a password avoids Google entirely.United States †
MixpanelProduct analytics about how Sentriment's own users use the product (account identifiers and usage events — never your users' feedback content), and, only with your consent, masked session replaysEU data residency 🇪🇺
AnthropicAI analysis of feedback (themes, sentiment, summaries)United States *
Voyage AIText embeddings for clustering and searchUnited States *

* AI providers receive only feedback text that has already been PII-redacted (see section 2) — the AI redaction step itself operates on text already stripped by pattern matching, in order to remove any remainder — under data-processing agreements incorporating Standard Contractual Clauses, and with no retention for model training. Account data — your name and email — never reaches them.

† Google is involved only if you choose “Continue with Google” to sign in. In that case Google confirms your email address and name to us, in the United States, under Standard Contractual Clauses — this is the account you already hold with Google, and it is the only account data that leaves the EU. Signing in with an email address and password avoids Google entirely, and you can add a password to a Google-created account at any time from Account settings.

5. How long we keep data

6. Your rights

Under the GDPR you can access, rectify, export, delete and restrict the processing of your personal data, and object to processing based on legitimate interest. Most of this is self-serve:

For anything else, email hello@sentriment.com — we respond within 30 days. You also have the right to lodge a complaint with a supervisory authority; ours is the Italian Garante per la Protezione dei Dati Personali (gpdp.it), and you may also contact the authority of your own country.

7. Cookies, analytics and session replays

Strictly necessary — a session cookie that keeps you signed in, a first-party cookie that remembers which campaign or referrer first brought you here, and a first-party cookie storing your consent choice. These require no consent and are always on.

Product analytics — we measure how Sentriment itself is used (which features, how often) with events sent from our own servers to Mixpanel (EU). These events contain account identifiers, feature usage, and approximate location (country and region, derived from your IP address at request time — the IP address itself is not sent to the analytics processor), along with browser and device type — never the feedback content in your workspace, and never identifiers of your own users. This stream sets no cookie and uses no third-party script. We do not run advertising or cross-site tracking of any kind.

Traffic measurement (no cookie, always on) — on our public website only, we count page views using Vercel Web Analytics. This is deliberately not behind the consent banner, because it stores nothing on your device: there is no cookie and no persistent identifier, visitors are counted using a hash derived from the incoming request which is discarded within 24 hours, and the data cannot be used to follow you across sites or to single you out. What it records is the page address, the referring site, approximate country, and browser and device type. We use it for one thing: knowing how many people actually reach the site, which the consented analytics below cannot tell us, because everyone who declines is invisible to it. The signed-in dashboard is deliberately excluded — this counting does not run there at all. Inside the product the only third-party code we ever load is the opt-in session replay described below; decline that and no third-party script runs on your workspace pages. Note that, unlike the rest of our infrastructure, this one measurement is processed outside the EU (see section 4). Our lawful basis is legitimate interest (Art. 6(1)(f)).

Website analytics (cookie — opt-in only) — on sentriment.com, if, and only if, you accept the cookie banner, we set one first-party cookie holding a random identifier so we can count returning visits and see which pages lead people to sign up. The events (page path, campaign parameters, referring site, approximate country, browser family) are forwarded by our own server to Mixpanel (EU). If you later create an account, that random identifier is linked to it so we know which pages preceded the signup. Decline and the cookie is never set, nothing is linked to you, and the site works identically — only the cookieless traffic count described above continues. The choice is shared across sentriment.com and its subdomains and expires after 180 days.

Session replays (opt-in only) — if, and only if, you accept the in-app prompt, we record masked replays of your Sentriment sessions to understand where the product is confusing. Masking happens in your browser before anything is transmitted: all text is replaced with blanks and images are blocked, so neither your data nor your users' feedback is ever readable in a recording — we see clicks, movement and page structure only. Declining changes nothing about how Sentriment works, and you can withdraw at any time in Account settings, which stops recording immediately. Replays are processed by Mixpanel under EU data residency.

8. Security

Data is encrypted in transit and at rest. Passwords are stored only as salted scrypt hashes. Secret API keys are stored only as SHA-256 hashes. Stored integration credentials are encrypted with AES-256-GCM. And — the measure we're proudest of — PII in feedback is redacted before it is ever written to disk.

9. Changes

If we materially change this policy we will update this page and, for significant changes affecting account holders, notify you by email. The “last updated” date at the top always reflects the current version.