Privacy Policy

Last updated: 30 June 2026.

SortedResearch is operated by The Future Mill LLC ("SortedResearch", "we", "us", "our"), a US limited liability company. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our card-sorting research platform at sortedresearch.com (the "Service").

We collect as little personal data as we can. Study participants are anonymous by default. The platform does not collect participant names or contact details unless a researcher deliberately adds a screener question that asks for them.

If you have any questions, contact us at privacy@sortedresearch.com.


1. Who this policy covers

The Service has two main types of user:

  • Researchers: people and organizations who create accounts to build and run card-sorting studies.
  • Participants: people who take part in a study by sorting cards into groups.

This policy applies to both, but the rights and protections differ depending on the role and on who controls the data (see Section 3).


2. The data we collect

Account data

  • Email address.
  • Optional display name.
  • Password (stored only as a secure hash via our authentication provider, Supabase Auth. We never see or store your plain-text password).

Billing data

  • Billing handled by Stripe. We do not store full payment card numbers. We may store limited billing metadata such as plan, billing status, and the last four digits / card brand surfaced by Stripe.

Usage and analytics data

  • How you use the Service (e.g. studies created, features used, device and browser type, log and diagnostic data).

Support and AI assistant ("Graham") data

  • Conversations you have with our in-app AI assistant, Graham, and other support communications. Graham messages are sent to our AI provider (Anthropic) to generate responses.

Participant study data

When a participant takes part in a study, we process on the researcher's behalf:

  • Card placements and group names the participant creates.
  • Screener question answers (only the questions the researcher chose to ask).
  • Timing and quality metadata (e.g. completion time, basic quality signals).
  • Where a participant is sent from a recruitment panel (for example a survey sample marketplace), a panel-supplied transaction identifier. It is an opaque code, not a name or contact detail, and is used only to report the outcome of the participant's session (completed, screened out, quota full, or removed for quality) back to that panel so it can credit or replace the participant.

Participants are anonymous by default. We do not ask participants for names or contact details. If a researcher adds a screener question requesting identifying information, that is the researcher's decision and the researcher is responsible for it (see Section 3).

Cookies

  • A functional "one-response-per-device" cookie used to prevent duplicate submissions.
  • Authentication / session cookies for signed-in researchers.

See our Cookie Policy for full details.


3. Data roles: controller vs processor

Privacy law separates the controller (who decides why and how data is processed) from the processor (who processes data on the controller's instructions).

  • SortedResearch is the controller for researcher account data, billing data, usage/analytics data, and support/Graham chat data. This policy governs how we handle that data.
  • SortedResearch is a processor for participant study data collected through a researcher's studies. In that case, the researcher (or their organization) is the controller. We process that data on their instructions to provide the Service. The researcher's own privacy notice and lawful basis govern that data; our processing terms are set out in our Data Processing Agreement, available to paid customers on request.

If you are a participant and have questions about how your study data is used, please contact the researcher or organization that invited you. We will assist them in responding.


4. Why we process data and our lawful bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies and we act as controller, we rely on the following lawful bases:

Purpose Data Lawful basis
Create and operate your account Account data Contract (Art. 6(1)(b))
Process payments and prevent fraud Billing data Contract; Legitimate interests
Provide and improve the Service Usage/analytics data Legitimate interests
Provide support and run Graham Support/Graham data Contract; Legitimate interests
Send service/transactional emails Account data Contract; Legitimate interests
Comply with legal obligations As applicable Legal obligation (Art. 6(1)(c))
Non-essential cookies Cookie data Consent (Art. 6(1)(a))

For participant study data, the researcher (as controller) is responsible for establishing the lawful basis.


5. Sub-processors and sharing

We share data with vetted third-party service providers ("sub-processors") who help us run the Service:

Sub-processor Purpose Location
Supabase Database, authentication, hosting US
Vercel Application hosting US
Anthropic Powers the Graham AI assistant and AI features US
Stripe Payment processing US
Resend Transactional and support email US

We may also disclose data where required by law, to enforce our terms, to protect rights and safety, or in connection with a corporate transaction (e.g. merger or acquisition). We do not sell personal data.


6. International data transfers

We are based in the United States, and our sub-processors process data in the US. Where we transfer personal data from the EEA, the UK, or Switzerland to the US or other countries, we rely on appropriate safeguards, including the Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum.


7. Data retention

  • Account data: retained while your account is active and for up to 12 months after the account is closed, then deleted or anonymized.
  • Billing data: retained as required for tax, accounting, and legal purposes (typically up to 7 years).
  • Usage/analytics data: retained for up to 24 months.
  • Graham/support data: retained for up to 24 months.
  • Participant study data: retained according to the researcher's instructions; deleted or returned on termination as set out in our Data Processing Agreement.

We delete or anonymize data when it is no longer needed for the purposes above or as required by law.


8. How we keep data secure

We use appropriate technical and organizational measures, including:

  • Encryption in transit (TLS) and encryption at rest.
  • Row-level security that scopes each customer's data so that one customer can only access their own data.
  • Access controls limiting internal access to data on a need-to-know basis.
  • Use of reputable infrastructure and sub-processors with their own security programs.

No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.


9. Your rights

Depending on where you live, you may have rights to:

  • Access a copy of your personal data.
  • Export / portability of your data.
  • Correct inaccurate data.
  • Delete your data.
  • Object to or restrict certain processing.
  • Withdraw consent (where processing is based on consent).
  • Lodge a complaint with a supervisory authority (in the EEA/UK).

To exercise these rights as a researcher, contact privacy@sortedresearch.com. As a participant, please contact the researcher who invited you, since they are the controller of your study data; we will assist them. We will not discriminate against you for exercising your rights.


10. California privacy rights (CCPA / CPRA)

If you are a California resident, you have the right to know, access, correct, and delete personal information we hold, and to be free from discrimination for exercising these rights.

We do not sell or "share" (as defined under the CPRA) your personal data, and we do not use it for cross-context behavioral advertising. We do not knowingly process the personal information of consumers we know to be under 16 for sale or sharing. To exercise your rights, contact privacy@sortedresearch.com.


11. Cookies

We use a small number of cookies, described in our Cookie Policy. For non-essential cookies in jurisdictions that require it, we obtain consent via a banner.


12. Children

The Service is not directed to children. Researchers must be 18 or older to hold an account. Researchers must not use the Service to collect personal data from children (under 16, or the applicable local age of digital consent) without obtaining proper, verifiable consent from a parent or guardian and meeting all applicable legal requirements as controller. We do not knowingly collect personal data from children. If you believe a child's data has been collected, contact privacy@sortedresearch.com.


13. Availability

The Service is available globally, except in jurisdictions subject to OFAC sanctions or comprehensive US embargoes, which are excluded.


14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, notify you of material changes.


15. Contact us