Anonymous or confidential?
Anonymous and confidential are not interchangeable. The honest label depends on whether identity is absent, separated, restricted, or still inferable.
Anonymous means identity is not collected
An anonymous survey is designed so the response is not tied to a known person in the application data. It should avoid names, email addresses, employee ids, account ids, and combinations of questions that make a respondent obvious.
Network providers may still process connection metadata. A web survey should not promise that nobody anywhere can observe a request; it should state what the survey application itself stores.
Confidential means someone can know
A confidential survey may collect identity while restricting who can see it and how it is used. That can support follow-up or controlled research, but it is a different promise from anonymity.
Say who has access, whether identifiers are separated from answers, what exceptions exist, and when both records are deleted.
- Does the application store identity fields?
- Can the owner connect answers to a person?
- Are small groups easy to infer?
- What connection metadata is processed?
Use the narrower claim
If a team directory, single-use link, invitation token, or demographic combination can identify the respondent, do not label the survey anonymous. Use a precise confidentiality statement instead.
CandorKit removes identity fields from this probe and does not store IP addresses or user agents with responses. It still warns that Cloudflare processes ordinary network requests and that answer content itself can reveal a person.
Put the boundary in the invitation
Tell respondents what is stored, what is not, who can read it, and when it disappears.
Create a bounded survey