Privacy policy
Last updated:
This page explains what is actually stored in this platform, who can see it, and how long it stays. It covers two groups: registered researchers, and participants who answer surveys.
What we store about a registered researcher
Name, email, preferred language, space name, and a hash of the password (never the password itself).
An audit log of significant actions inside their space — who did what and when — kept as a linked chain that cannot be edited retroactively.
At registration and password reset we store a «hash» of the network address, not the address itself, solely to prevent abuse.
What is stored about a survey participant
The answers given, start and completion times, and per-question timings if the researcher enabled them.
The network address itself is not stored; only its hash, and for one purpose: preventing duplicate submissions in open surveys where the researcher asks for it.
If invited by email, that address is stored in the participant list of the researcher who invited them — not in a shared directory, and not visible to any other researcher.
If a participant asks for a copy of their answers, it is built in their browser at submission time and never stored.
Opting out
Every invitation carries an opt-out link. The opt-out is recorded by email hash and applies platform-wide, so no researcher on this installation will reach you again — not just the one who wrote to you.
How long data is kept
Each researcher sets a retention period for their survey’s responses; when it lapses they are deleted automatically.
Uploaded files are deleted with their responses.
An account never activated is deleted fourteen days after registration.
Who sees what
A researcher sees their own space and its responses only. Members of that space see according to their role and the per-survey permissions granted to them.
The platform administrator sees the list of accounts, space names, and how many surveys each holds — «not» survey content and not responses.
Data is never sold or shared with third parties for marketing.
Where data is processed
The platform’s servers are in Phoenix, Arizona, United States. The database, uploaded files, and backups all live there.
The transfer happens the moment a participant opens the link and types an answer — not when the researcher exports results. If you are answering from outside the United States, your answer is sent there.
Nothing else leaves that location except two things: an invited participant’s email address and the invitation text, sent to the email provider that delivers it; and five characters of the hash of a researcher’s password, sent to a service that checks for leaked passwords — never the password itself, never the full hash, and never any identifier of its owner.
The researcher and their university decide the purpose of the study and what it collects; the platform carries that out on their behalf. Which data-protection law applies therefore follows the university’s country and the participants’ countries, and it is for the researcher to state the place of processing in the consent text where their own law requires it.
Security
Traffic is fully encrypted, passwords are hashed with Argon2, and sensitive secrets (such as two-factor keys) are encrypted in the database.
To request a copy of your data or its deletion, contact the researcher running the study you took part in, or the system administrator of the operating institution.