Privacy Policy
Last updated: 30 June 2026.
SortedResearch is operated by The Future Mill LLC ("SortedResearch", "we", "us", "our"), a US limited liability company. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our card-sorting research platform at sortedresearch.com (the "Service").
We collect as little personal data as we can. Study participants are anonymous by default. The platform does not collect participant names or contact details unless a researcher deliberately adds a screener question that asks for them.
If you have any questions, contact us at privacy@sortedresearch.com.
1. Who this policy covers
The Service has two main types of user:
- Researchers: people and organizations who create accounts to build and run card-sorting studies.
- Participants: people who take part in a study by sorting cards into groups.
This policy applies to both, but the rights and protections differ depending on the role and on who controls the data (see Section 3).
2. The data we collect
Account data
- Email address.
- Optional display name.
- Password (stored only as a secure hash via our authentication provider, Supabase Auth. We never see or store your plain-text password).
Billing data
- Billing handled by Stripe. We do not store full payment card numbers. We may store limited billing metadata such as plan, billing status, and the last four digits / card brand surfaced by Stripe.
Usage and analytics data
- How you use the Service (e.g. studies created, features used, device and browser type, log and diagnostic data).
Support and AI assistant ("Graham") data
- Conversations you have with our in-app AI assistant, Graham, and other support communications. Graham messages are sent to our AI provider (Anthropic) to generate responses.
Participant study data
When a participant takes part in a study, we process on the researcher's behalf:
- Card placements and group names the participant creates.
- Screener question answers (only the questions the researcher chose to ask).
- Timing and quality metadata (e.g. completion time, basic quality signals).
- Where a participant is sent from a recruitment panel (for example a survey sample marketplace), a panel-supplied transaction identifier. It is an opaque code, not a name or contact detail, and is used only to report the outcome of the participant's session (completed, screened out, quota full, or removed for quality) back to that panel so it can credit or replace the participant.
Participants are anonymous by default. We do not ask participants for names or contact details. If a researcher adds a screener question requesting identifying information, that is the researcher's decision and the researcher is responsible for it (see Section 3).
Cookies
- A functional "one-response-per-device" cookie used to prevent duplicate submissions.
- Authentication / session cookies for signed-in researchers.
See our Cookie Policy for full details.
3. Data roles: controller vs processor
Privacy law separates the controller (who decides why and how data is processed) from the processor (who processes data on the controller's instructions).
- SortedResearch is the controller for researcher account data, billing data, usage/analytics data, and support/Graham chat data. This policy governs how we handle that data.
- SortedResearch is a processor for participant study data collected through a researcher's studies. In that case, the researcher (or their organization) is the controller. We process that data on their instructions to provide the Service. The researcher's own privacy notice and lawful basis govern that data; our processing terms are set out in our Data Processing Agreement, available to paid customers on request.
If you are a participant and have questions about how your study data is used, please contact the researcher or organization that invited you. We will assist them in responding.
4. Why we process data and our lawful bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies and we act as controller, we rely on the following lawful bases:
| Purpose | Data | Lawful basis |
|---|---|---|
| Create and operate your account | Account data | Contract (Art. 6(1)(b)) |
| Process payments and prevent fraud | Billing data | Contract; Legitimate interests |
| Provide and improve the Service | Usage/analytics data | Legitimate interests |
| Provide support and run Graham | Support/Graham data | Contract; Legitimate interests |
| Send service/transactional emails | Account data | Contract; Legitimate interests |
| Comply with legal obligations | As applicable | Legal obligation (Art. 6(1)(c)) |
| Non-essential cookies | Cookie data | Consent (Art. 6(1)(a)) |
For participant study data, the researcher (as controller) is responsible for establishing the lawful basis.
5. Sub-processors and sharing
We share data with vetted third-party service providers ("sub-processors") who help us run the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, hosting | US |
| Vercel | Application hosting | US |
| Anthropic | Powers the Graham AI assistant and AI features | US |
| Stripe | Payment processing | US |
| Resend | Transactional and support email | US |
We may also disclose data where required by law, to enforce our terms, to protect rights and safety, or in connection with a corporate transaction (e.g. merger or acquisition). We do not sell personal data.
6. International data transfers
We are based in the United States, and our sub-processors process data in the US. Where we transfer personal data from the EEA, the UK, or Switzerland to the US or other countries, we rely on appropriate safeguards, including the Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum.
7. Data retention
- Account data: retained while your account is active and for up to 12 months after the account is closed, then deleted or anonymized.
- Billing data: retained as required for tax, accounting, and legal purposes (typically up to 7 years).
- Usage/analytics data: retained for up to 24 months.
- Graham/support data: retained for up to 24 months.
- Participant study data: retained according to the researcher's instructions; deleted or returned on termination as set out in our Data Processing Agreement.
We delete or anonymize data when it is no longer needed for the purposes above or as required by law.
8. How we keep data secure
We use appropriate technical and organizational measures, including:
- Encryption in transit (TLS) and encryption at rest.
- Row-level security that scopes each customer's data so that one customer can only access their own data.
- Access controls limiting internal access to data on a need-to-know basis.
- Use of reputable infrastructure and sub-processors with their own security programs.
No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
9. Your rights
Depending on where you live, you may have rights to:
- Access a copy of your personal data.
- Export / portability of your data.
- Correct inaccurate data.
- Delete your data.
- Object to or restrict certain processing.
- Withdraw consent (where processing is based on consent).
- Lodge a complaint with a supervisory authority (in the EEA/UK).
To exercise these rights as a researcher, contact privacy@sortedresearch.com. As a participant, please contact the researcher who invited you, since they are the controller of your study data; we will assist them. We will not discriminate against you for exercising your rights.
10. California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to know, access, correct, and delete personal information we hold, and to be free from discrimination for exercising these rights.
We do not sell or "share" (as defined under the CPRA) your personal data, and we do not use it for cross-context behavioral advertising. We do not knowingly process the personal information of consumers we know to be under 16 for sale or sharing. To exercise your rights, contact privacy@sortedresearch.com.
11. Cookies
We use a small number of cookies, described in our Cookie Policy. For non-essential cookies in jurisdictions that require it, we obtain consent via a banner.
12. Children
The Service is not directed to children. Researchers must be 18 or older to hold an account. Researchers must not use the Service to collect personal data from children (under 16, or the applicable local age of digital consent) without obtaining proper, verifiable consent from a parent or guardian and meeting all applicable legal requirements as controller. We do not knowingly collect personal data from children. If you believe a child's data has been collected, contact privacy@sortedresearch.com.
13. Availability
The Service is available globally, except in jurisdictions subject to OFAC sanctions or comprehensive US embargoes, which are excluded.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, notify you of material changes.
15. Contact us
- Privacy questions: privacy@sortedresearch.com
- General / support: support@sortedresearch.com
- Postal address: The Future Mill LLC, 9461 Tiki Circle, Huntington Beach, California 92646.