Release notes

What's new in Pishik, newest first — plus material changes to our legal documents. This page is the canonical record: updates land here first, and we tell the fuller story behind the big ones on the blog.

July 28, 2026 — Correcting what we said about email delivery

We audited every published claim against the code that actually runs. Most held. This one didn't, and it ran through several pages at once, so it's worth stating plainly.

Email delivery is ours, not yours

Our Privacy Policy, DPA, product page, and several Support Center pages described email delivery as something your workspace configures — through your own Microsoft 365 tenant, your own Azure subscription, or an SMTP provider you designate. That was never true of the hosted service. Pishik sends all review, reminder, and notification email through a single channel we operate and configure, currently Azure Communication Services. Mail leaves from a Pishik address carrying your company name and logo, with replies routed to your team.

Nothing about the actual processing changed, and no new vendor was introduced — Microsoft was already named in Annex III as our email subprocessor, and still is. What changed is that the documents now describe it correctly, without a conditional that implied a choice the software never offered. We've also removed the "not a subprocessor, because you direct it" carve-out for customer-run mail, since no customer runs mail here. Privacy Policy §3 and §6, and DPA §3, §6 and Annex III are all effective July 28, 2026.

One consequence worth being direct about: if you were counting on review email arriving from your own domain, it does not, and that is not something the hosted service offers today. If it matters to your rollout, tell us and we'll give you an honest answer about the roadmap rather than an arrangement we can't deliver.

Reviewers: how to tell a request is genuine

Our reviewer guidance used to say a real request "comes from the company's own email." It doesn't — it comes from Pishik on their behalf. That mattered more than the other corrections, because it's an anti-phishing checklist: the old wording quietly trained reviewers to distrust genuine mail and to trust anything sent from the company's own domain. Fixed here. The best check hasn't changed: confirm out-of-band with the person who asked.

Smaller corrections, same audit

  • Enterprise seats. Billing help said Enterprise gets "as many seats as you need." Seat counts are set on your workspace by us, up to 100. Reworded.
  • Changing plans. We said your team carries over "unchanged" on any plan change. True going up; going down, a downgrade is only accepted once your team already fits the smaller tier. Now documented.
  • Price changes. Billing help promised notice before a price change and attributed that to the Terms — which say the opposite. The Terms govern; the support page no longer claims otherwise.
  • Enterprise support. The pricing page offered "priority help." There is no priority queue — every topic reaches the same team, as our contact page has always said. Removed.
  • Sign-in branding. The product page said your logo brands the sign-in screen. It doesn't, and can't — sign-in happens before we know which workspace you belong to. Removed.
  • Open-source notices. Our shipped notices file listed nodemailer as MIT; it's MIT-0, which our licenses page already said. The two now agree, and every package carries its own license.

July 27, 2026 — A Data Processing Addendum, and a more accurate Privacy Policy

New: Data Processing Addendum

There's now a Data Processing Addendum covering the personal information we handle on your behalf — your reviewers' details and your teammates'. It applies to every customer automatically, with no signature needed, and it's the document to hand your procurement or legal team. It carries the CCPA service-provider terms and the GDPR processor terms, plus two annexes worth reading on their own: Annex II lists our security controls one by one, and Annex III names every subprocessor and what it does. We'll give 30 days' notice before that subprocessor list changes. Need it signed, or a security questionnaire filled in? Ask us.

Privacy Policy updated

Privacy Policy — Effective July 27, 2026. Some of this is new disclosure; some of it is us correcting our own description of what the software does. We think the corrections matter more.

  • We don't log IP addresses — and the old policy said we did. We audited the policy against the code and found this claim was simply wrong: your IP is read while a request is in flight, used to rate-limit sign-in and form abuse, and never written to our database. There is no web access log. The policy now says so, and Section 1 also states plainly what we never collect at all — no government IDs, no card numbers, no health data, no biometrics, no location.
  • We store the emails we send, not just their delivery record. The old wording said we kept only recipient, subject, timestamp, and status. The sent-email record also keeps the message the Service generated, which is what makes Resend work. Corrected. What hasn't changed: we never read, sync, or store your mailbox.
  • Retention, by category, honestly. Section 7 is now a table instead of a paragraph, and it says the awkward part out loud: your workspace records don't disappear on a timer, and erasing a workspace leaves behind our own support tickets, account notes, trial-code records, and subscription timeline. You can ask us to remove those too.
  • Do Not Track, answered. New Section 5 states how we respond to browser DNT signals (nothing changes, because nobody is tracked) and confirms that no other party can track you through our site. California law requires that disclosure of every commercial website regardless of size, and ours was missing it.
  • Your California privacy rights. New Section 11 covers what you can ask us for, how to ask, how we verify it's you, how fast we answer, authorized agents, and Shine the Light. We honour access, correction, deletion, and portability requests for everyone — not only where a law compels it.
  • Who our vendors are. Section 6 now names them by category — hosting, payments, email delivery — instead of describing them in the abstract.

Terms of Service updated

Terms of Service — Effective July 27, 2026. Section 10 now incorporates the Data Processing Addendum by reference and confirms that Pishik receives reviewer information solely as a service provider, so routing it to us is not a sale or sharing of personal information.

Corrections to our Security page

The same audit checked every factual claim on Security & privacy against the code. Five were broader than what the software guarantees, and we've narrowed them: how two-factor enrollment is enforced on the sign-up path, what a minimum-password-length setting actually applies to, how much of a removed comment lands in the audit trail, which exports the server logs on its own, and the fact that restoring a backup also restores that backup's workspace name and idle-sign-out setting.

Fixed: personal exports carried live review links

Writing down the security guarantees turned one up that wasn't being kept. Export my data — the per-member export in Settings → My data — was including the single-use approval tokens for any review still pending on your contracts, so the downloaded file contained working approve/reject links. The server-built workspace and member exports have always stripped those; this one was assembled in the browser and missed the same treatment. It now strips them the same way, and the export still shows which reviews were decided and when. If you exported your own data previously and still have the file, treat it like a credential — or delete it; any review that has since been decided or has expired is closed regardless.

July 19, 2026 — Two-factor authentication for everyone, and clearer Terms

Two-factor authentication is now required

Every Pishik account is now protected by two-factor authentication — it's part of sign-in, not an option you can skip. You pair an authenticator app and save your backup codes; accounts that haven't enrolled yet are walked through it. The full picture is in Security & privacy.

Terms of Service updated

Terms of Service — Last updated July 19, 2026.

  • No refunds; no proration. Section 5 now says explicitly what was always the deal: fees are non-refundable once charged, there are no credits for partial billing periods or unused seats, and cancelling stops future renewal charges rather than refunding the current one — paid access runs through the end of the period you've paid for. Section 15 repeats the cancellation part where you'd look for it.
  • Paid subscription or trial, stated plainly. Section 5 now spells out that using Pishik requires an active paid plan or an active trial — the limited, unpaid state exists only to complete checkout, restore a lapsed plan, or export your data. It is not a free tier, because there isn't one.

How we announce updates

This page is the canonical record of what shipped and what changed in our legal documents — check back here, or read the story behind big releases on the blog. Questions about a change? We're glad to help.

Contact support