Data, privacy & security
Your data is yours
Your studies and data are visible only to your workspace (organization). Access is enforced at the database level, with row-level security scoped to your organization, so members of your workspace (for example your teammates on a Team plan) share access to its studies, and no other organization can reach them, even through the API. If you're a single-seat account, that workspace is just you.
Participants are anonymous by default
- Participants never sign in. Each session uses a random, unguessable token, sent only in the request body (never in the URL).
- By default the platform doesn't ask participants for their name or contact details, and responses are analyzed in aggregate. If you add screener questions that collect personal information, that becomes your responsibility to disclose and handle.
- The default consent notice tells participants their answers are for research, voluntary, and analyzed together with everyone else's. You can customize it and link a privacy policy.
Pictures you upload
A pairwise study can carry a picture on each item, and those files are stored for you. Three things worth knowing:
- They are private. The store is not public, and a picture is only ever reached through a link that expires. There is no address anyone can guess, and no permanently open link.
- Participants see them, because they have to. A respondent taking your study is handed a link that works for their sitting. That is the whole point of the feature.
- They go when the study goes. Delete an item and its picture is deleted. Delete the study, or the whole workspace, and every picture belonging to it is deleted too. A data export includes a working download link for each picture, valid for seven days.
Pictures are your content, and the same rule applies as to everything else here: don't upload something you would not be comfortable a respondent seeing, because showing it to respondents is what it is for.
Data-subject requests
From the Participants view under a study's Results tab, on all four study types, you can do both halves of an individual request.
Access. Download one participant's full record as a CSV. It opens in Excel or Numbers and holds everything kept about that person: their screener answers, what they did (card placements, pairwise choices, Best-Worst picks, or every tap through your menu), their timings, and the quality verdict with its reasons. The internal session token is never included, because it is the credential that would let somebody resume their session.
Erasure. Delete that participant's response permanently. It takes everything they did with it, and the analysis recomputes without them. An admin can export the whole workspace as one JSON file (your organization, members, and every study with its data); this covers all four study types (card sort, Findability, pairwise and Best–Worst) with every response, answer and tap, and session tokens stripped. Generated insight reports and cached analysis are left out, because both are rebuilt from the data that is in the file.
Feedback
The optional end-of-study feedback box is anonymous: it's tied to a valid session but gives you no way to identify the participant. You review and dismiss feedback in your dashboard.
Reliability
- The app logs errors so issues can be diagnosed; you can view your recent error log from your account area.
- A scheduled health check verifies the database and Graham's AI services regularly and alerts the team if something needs attention.
- Participant submissions are safe to retry: a dropped connection won't double-count or corrupt a response.
Two-factor sign-in
You can add a second step to your sign-in: a 6-digit code from an authenticator app (Google Authenticator, 1Password, Authy and the like) on top of your password. Turn it on under Account, scan the code with the app, and enter the code it shows. From then on every sign-in asks for a code.
- It is optional for everyone, and required for admins of a workspace on a paid plan, because an admin can download everything in the workspace. A paid workspace's admin is asked to set it up on their next sign-in.
- Lost your authenticator? Email support@sortedresearch.com from your account's email address. We check it is you, remove the old authenticator, and you sign in with your password and set up a new one. You can also turn it off yourself while signed in.
What Graham can and can't see
Graham (the assistant) is given your current page, your plan, and your active study's setup and aggregated results so he can help specifically. He is not given individual participants' personal data, other accounts' data, or any secrets, and he can't take actions on your account.
Our policies
The full Terms of Service, Privacy Policy, and Cookie Policy are published on the site. You agree to the Terms and Privacy Policy when you create an account, and again before you start a paid subscription.