Security
Privacy is structural, not a setting.
Anonymization runs on every interview — the one automatic step, fixed and non-configurable. Withdrawal always works. And we never train on your data.
A multi-model panel grades every transcript before the researcher sees it: two different-vendor graders, a head grader that merges and catches what both missed, and a strong expert on disputed sessions only. Regional variants route the panel by data residency.
Identity entities become reversible pseudonyms; toxic credentials and precise locators are hard-deleted, irreversibly; research content — including sensitive discoveries — is always kept. The map that decodes pseudonyms never leaves the platform and is never exported.
A per-respondent reading dies with its session. Any analysis kept on its own covers at least two distinct sessions, so it can never point back to one person. Deleting a session removes its content irreversibly.
Every selectable model passes a no-train, no-retain bar — this underwrites the deletion right. A training provider would weld raw respondent data into third-party weights, making withdrawal a lie.
Production runs on your own VPS — Next.js as a Node server with self-hosted Supabase. Your data doesn't sit in a shared cloud tenant.
Consent pins the version a respondent saw. Changing it appends a new version; existing sessions keep the terms they agreed to.