Anonymity here isn't a promisewe ask you to trust. It is built intothe architecture.
Anyone can run an AI conversation. Far fewer can promise, and then actually enforce in code, that what a person says is never tied back to them. That second half is the real product.
What we keep, and what we throw away.
We keep
- An AI paraphrase of each answer
- A sentiment read on the paraphrase
- Themes pulled together across everyone
We never keep
- The word-for-word transcript. It is discarded once the themes are out.
- Any name, email or token sitting next to an answer
- Anything that could join a response back to a person
Four rules to protect your respondents.
Enforced in code, not promised in a policy.
01 Paraphrase only
We store the AI paraphrase and discard the word-for-word transcript once the themes are out. It isn't archived anywhere.
03 A minimum group size of five
No theme, slice or sample ever appears below five contributions. Thin groups stay hidden.
02 No identity on the row
No user, no email, no token that could be traced back from a response. The link is cut on purpose.
04 Cohort sizes are clamped
When you compare named groups, each one is held to the same minimum of five, and any group narrow enough to give away a headcount stays clamped.
The question every user asks.
No. We store paraphrases rather than actual words, we attach no identity to answers, and no report shows a slice smaller than five.
No. Named private shows who finished the conversation, never what they said. That completion record is never linked to the answers.
Everything runs in the London region, so your data stays in the UK from start to finish, in a schema kept separate from every other system.
No. Every group is held to the same minimum of five before any theme, sample or comparison appears. Name a group so narrowly that it points at individuals and we will warn you. And we never join answers across groups.