CCandorKit

Collect sensitive feedback carefully

Anonymity begins by minimizing what you ask, but the consequence of exposure determines whether a lightweight survey is appropriate at all.

1

Define sensitive before collecting

Feedback can feel sensitive because it criticizes a manager, discusses team conflict, or describes an unpopular opinion. It can also contain legally protected, medical, financial, safety, or identifying information. Those categories do not carry the same consequence if exposed.

CandorKit is intended for bounded, low-consequence feedback. It is not suitable for protected whistleblowing, complaints requiring a formal duty to act, emergencies, regulated research, or highly sensitive personal data.

  • Could disclosure harm a respondent?
  • Is a formal response duty triggered?
  • Does the owner need to follow up?
  • Would a regulated system be required?
2

Ask less than you could

Remove names, email addresses, employee ids, exact locations, and unnecessary demographics. Prefer one clear task and a few focused questions rather than collecting a profile around each answer.

Warn respondents not to name themselves or other people in free text. Small-group combinations can identify someone even when no explicit identity field exists, so aggregate or reframe questions where possible.

3

Plan access and deletion

Choose one responsible owner for the private results link, state how findings will be summarized, and decide whether raw answers need to be exported at all. Every downloaded CSV becomes a separate copy outside automatic expiry.

CandorKit rejects new responses after seven days and schedules expired room cleanup. That short boundary reduces forgotten live data, but it cannot delete copies the owner has already downloaded or pasted elsewhere.

Put the boundary in the invitation

Tell respondents what is stored, what is not, who can read it, and when it disappears.

Create a bounded survey