testymo.

The paperwork — 2 of 2

Privacy Policy

Updated 15 September 2026 Terms of Service →

The short version

We collect what a login-and-billing product needs, and nothing more. No data sales, no AI training, no advertising — not on this site, not in the app, and not in the widget embedded on anyone else's site. These marketing pages and the app behind sign-in measure their own audience (section 04); the form your customers answer and the widget on anyone else's site carry no Google tag. What we hold about you depends on which hat you're wearing; each has its own section below.

Testymo is operated by Anton Bakinouski, based in Poland — the data controller for everything described here, except testimonial submissions, where the business whose form you answered decides and we act on their instructions (§02). One address for all of it: [email protected].

01 You have an account

We store your name, your email address (we send one verification email so we know it's yours) and your password — hashed, so we couldn't read it if we wanted to. If you sign in with Google instead, Google tells us your name, email and profile picture, and that's all the access we get. Each active session records the IP address and browser it came from, so we can tell a hijacked session from a real one; that record goes when you sign out, and it never outlives your account.

If you upgrade to a paid plan, Stripe handles the payment as merchant of record — your card number goes to Stripe and never touches our servers. All we keep is your subscription's plan, status and billing dates, plus a billing email if you set one for receipts. The only emails we send are the ones the product requires: verification, password reset, invitations, and a heads-up when your paid plan is ending or has ended. There is no marketing list.

02 You answered someone's form

The business that sent you the form decides what it asks and where your answer appears; we store and display it on their behalf. What we keep: your answers exactly as you submitted them — words, name, rating — plus, if you added a photo, a small resized copy of it with its hidden metadata (like where it was taken) stripped out. We also keep which version of the form you saw, and — if the form asked — your choice from the permission step: usable publicly, or only privately. That choice is stored with your submission, shown to the business, and our Terms of Service require them to honor it.

Your submission record holds no IP address, and answering needs no account. The form page carries no Google tag, so nothing about your visit is joined to what you wrote; the one thing that does reach it is the cookieless page-view count our network provider adds to the pages it serves (§04), which records that a page loaded and nothing about your answers. To have a testimonial taken out of use, ask the business first — they know you, and for them it's one click. To have it fully deleted, or if you can't reach them, email [email protected] and we'll take care of it.

03 You saw a Testymo widget on some website

The widget is one static script with the testimonials already inside it. It draws them and stops: no cookies, no local storage, no fingerprinting, no analytics, nothing phoning home. Loading the script and its photos appears in ordinary server logs (IP address, URL, time) like any request on the web; we use those only to keep the service running and secure.

One thing is counted beyond that, and it describes the website rather than you: the first time a widget is served to a page outside our own domain, we keep that site's domain and mark the widget as live for the business that made it. Once per widget, ever — no cookie, no record of who was reading, and nothing about the page it loaded on beyond the domain.

04 You're just browsing testymo.com

Two tools measure this site. Cloudflare Web Analytics counts page views without cookies — on these marketing pages and on every other page our network serves, form pages included: which page loaded, what linked to it, how fast it rendered, plus the country and browser your request already tells any server. Nothing is stored on your device, there is no profile, and it does not follow you elsewhere.

Google Analytics does more: it sets its own cookies to tell a returning browser from a new one, records the pages and events of a visit, and reports them to Google, who processes that data for us. It runs on these marketing pages and in the app once you sign in — the same tag, the same cookies — and never on the form pages your customers answer or inside the widget embedded on someone else's site. We use it to see which pages bring people in and where new accounts get stuck; we have not linked it to any advertising product, and we don't sell what it collects. An ad blocker will stop it, and nothing on this site needs it to work.

In the app the tag records the screens you open and the setup steps you finish, and once your session resolves it stamps our own internal ids — your account, your organization and your role in it — on what it sends, so one person on two devices is not counted as two. Our server reports a few account milestones to Google directly, carrying those same ids: an account created, a form published, a widget created, a widget's first load on a site that isn't ours, a checkout started or completed, a subscription cancelled. No name, no email, and nothing you or your customers typed goes to Google.

Fonts are served from our own domain. Apart from Google's cookies above, the app's cookies are all functional — the session that keeps you signed in, plus short-lived helpers for the sign-in flow — and none of them track you.

05 Who else touches your data

The third parties involved in running Testymo, in full:

  • Cloudflare — network and content delivery, page-view counting on this site, transactional email, and file storage.
  • Stripe — payments, as merchant of record for paid plans.
  • Google — Analytics on the marketing pages and in the app, including the account milestones our server reports to it directly (§04), and sign-in, only if you choose it.

That's the whole list. No ad networks, no data brokers, and no tag of ours on a form page or inside the widget. We have never sold personal data, and we won't.

All three are American companies, so some data crosses the Atlantic — each transfer runs under the EU–US Data Privacy Framework or the EU's standard contractual clauses, the mechanisms GDPR accepts for exactly this. If a breach ever touches your data, you'll hear about it from us without spin or delay, and we'll notify the authorities where the law requires it.

06 How long we keep it

As long as your account or organization exists. Deleting a form deletes its submissions and uploads; deleting an organization deletes everything in it, and its embeds stop rendering immediately. Copies can persist in backups for a short period afterwards before they age out. To delete your account entirely, email [email protected].

07 Your rights

GDPR applies. You can ask for a copy of your data, have it corrected or deleted, object to or restrict its processing, and take it with you. Email [email protected] — from your account address, or with enough detail to find your submission — and you'll have an answer within a month. If you think we've handled your data badly, you can complain to your local data-protection authority, or to Poland's UODO. The legal bases, since GDPR asks for them: your account and billing run on contract, security logs on our legitimate interest in keeping the service safe, and the permission step on consent.

08 Changes to this policy

The date at the top names the current version, and small clarifications happen without fanfare. If a change meaningfully affects what we collect or who touches it, you'll get an email or a clear notice in the app before it takes effect.