Data, privacy & security
Your data is yours
Every researcher only ever sees their own studies and data. Access is enforced at the database level, with row-level security scoped to the study owner, so there is no way to reach another account's studies, even through the API.
Participants are anonymous by default
- Participants never sign in. Each session uses a random, unguessable token, sent only in the request body (never in the URL).
- By default the platform doesn't ask participants for their name or contact details, and responses are analyzed in aggregate. If you add screener questions that collect personal information, that becomes your responsibility to disclose and handle.
- The default consent notice tells participants their answers are for research, voluntary, and analyzed together with everyone else's. You can customize it and link a privacy policy.
Data-subject requests
You can export an individual participant's data as JSON from the Participants tab (their screener answers, placements, groups, timing, and quality metadata, but not the internal session token). You can also delete any response permanently, which removes it from all analysis. An admin can export the whole workspace as one JSON file (your organization, members, and every study with its data); this covers both card sort and pairwise projects, with session tokens stripped.
Feedback
The optional end-of-study feedback box is anonymous: it's tied to a valid session but gives you no way to identify the participant. You review and dismiss feedback in your dashboard.
Reliability
- The app logs errors so issues can be diagnosed; you can view your recent error log from your account area.
- A scheduled health check verifies the database and Graham's AI services regularly and alerts the team if something needs attention.
- Participant submissions are safe to retry: a dropped connection won't double-count or corrupt a response.
What Graham can and can't see
Graham (the assistant) is given your current page, your plan, and your active study's setup and aggregated results so he can help specifically. He is not given individual participants' personal data, other accounts' data, or any secrets, and he can't take actions on your account.
Our policies
The full Terms of Service, Privacy Policy, and Cookie Policy are published on the site. You agree to the Terms and Privacy Policy when you create an account, and again before you start a paid subscription.