Anonymous survey without login
No login removes one obvious identity trail. A trustworthy invitation also explains the two links, the seven-day clock, and the limits of application-level anonymity.
Remove the account requirement
A survey without login lets a creator set up a short room and lets respondents answer without registering an account. That reduces account history and identity fields, but it does not erase everything that can reveal a person.
Question wording, free-text answers, small groups, unique events, and distribution lists can still make a respondent inferable. Network providers also process ordinary connection requests even when the survey application does not store IP addresses with answers.
- Is creator registration required?
- Must respondents enter an email?
- Are IP addresses attached to answers?
- Could the answer text identify someone?
Separate the two links
After creation, CandorKit produces a public respondent link and a different private owner link. The respondent link can be shared with the intended group; it does not expose the results.
The owner link includes a secret after the URL fragment. Anyone with the complete owner link can view and export answers, so treat it like a password and do not paste it into the invitation, public documents, or screenshots.
State the boundary before answers
Tell respondents that the survey does not ask for an account or identity fields by default, how many responses are allowed, when the room expires, and who will receive the owner link.
Use a higher-assurance system for protected reporting, regulated research, legal or medical confidentiality, emergencies, or highly sensitive personal data. An account-free survey is a narrower tool, not a universal anonymity system.
Put the boundary in the invitation
Tell respondents what is stored, what is not, who can read it, and when it disappears.
Create a bounded survey