Privacy is not a feature — it's the product

AI Adoption Pulse is a behavioral diagnostics tool built on a simple premise: employees will only share honest feedback if they trust that their responses cannot be traced back to them. Every architectural decision we make starts from this principle.

Identity and responses are cryptographically separated

When an employee receives an invitation, their email is stored separately from their survey answers. The link between "who was invited" and "who said what" is permanently severed at the moment of survey completion:

  • The invitation record is marked "completed" — nothing more.
  • The survey response is written to a separate data store with no name, email, user ID, or invitation reference.
  • The diagnostic write contains only: campaign ID, optional department/role cohort, and the answers themselves.
  • No manager or administrator can ever retrieve an individual's answers.

Minimum group-size protection

Results are only shown for groups that meet a minimum reporting threshold. Our default minimum is 8 respondents, and the hard floor is 5. This prevents anyone from identifying an individual through small-group results.

  • Groups below the minimum show "suppressed for privacy" — never a fake zero or null.
  • We prevent differencing attacks: overall scores may be withheld if visible department results could be subtracted from the total to reveal a small group.
  • Open-text comments appear only as redacted summaries from sufficiently large cohorts.

What we don't collect

  • We do not store raw IP addresses. If abuse controls require one, we use a rotating keyed hash with short retention.
  • We do not expose exact response timestamps to organization users.
  • We do not log survey answers, invite tokens, or result tokens.
  • We do not use browser fingerprinting.
  • Optional Google Analytics runs only on public marketing pages after you explicitly allow it. We never measure surveys, private reports, authentication pages, customer workspaces, or the support console, and reported page paths omit query strings.

What managers see

Organization administrators see only aggregated, privacy-protected results: completion counts, construct scores for qualifying groups, and deterministic recommendations. They can see how many people completed the survey and what the group patterns are — never who said what.

Cookies, and the one that protects your report

We do not use tracking or advertising cookies anywhere in a survey or a private report. Analytics is limited to public marketing pages, is denied until you allow it, and is switched off entirely on surveys, reports and sign-in pages.

When you finish a survey we set one small cookie, and it exists to protect you rather than to observe you. Your report link alone is not enough to open your results: the browser you completed the survey in also holds a secret that we check every time the report is opened. Without it the report is refused — including for whoever sent you the invitation.

  • It contains no name, no email, and nothing about your answers.
  • It cannot be read by scripts on the page, and it is never sent to anyone else.
  • It expires by itself after 7 days, at the same time as your report link.
  • The trade-off is deliberate: because we keep no link between you and your answers, we cannot reopen your report on a different device or browser — not for you, and not for your employer.

Data retention and deletion

Retention periods are configuration-backed and documented. Account and invitation data support export and deletion workflows. Truly severed anonymous responses may be impossible to locate by email after completion — we disclose this transparently before you submit a privacy request.

AI and LLM boundaries

Our scoring and recommendation selection are deterministic and versioned. An LLM may help explain verified aggregates in report prose, but it:

  • Never calculates scores or makes privacy decisions.
  • Never receives invitation emails, tokens, IPs, user IDs, or small-cohort data.
  • Only receives minimized, anonymized aggregate payloads.
  • If LLM generation fails, a deterministic non-LLM report is always produced as fallback.

The documents themselves

This page describes how the product is built. These are the agreements that govern it:

  • Privacy Notice — what we process, the role we play for each kind of data, and your rights.
  • Data Processing Addendum — the GDPR Article 28 contract, including our sub-processors.
  • Terms of Service — how the Service may be used, including the rules that forbid using it to monitor individuals.

Have questions about how we protect your team?

Start your free diagnostic