CCandorKit

Effective 28 July 2026

Privacy with a clock

Stored for the one survey

CandorKit stores the survey title, introduction, questions, answer text or ratings, creation and submission timestamps, a hashed private owner key, and an expiry timestamp. It caps a survey at five questions and 100 responses.

Deliberately not attached to responses

The application does not store names by default, IP addresses, user agents, cookie ids, account ids, or a cross-survey user history with a response. Cloudflare still processes ordinary connection metadata to deliver and protect the service. Answer content can itself reveal a person, so respondents must not include identifying or highly sensitive information.

Seven-day retention

Each survey receives a seven-day expiry. The service rejects expired access and runs a daily cleanup that deletes the survey and its responses. This does not delete CSV files, screenshots, or copies already exported by the survey owner.

Analytics separation

Cloudflare Web Analytics provides an all-visitor page-view denominator. Microsoft Clarity loads only after consent. Survey titles, descriptions, questions, answers, share links, and owner keys use masking classes and are never attached to named analytics events or dimensions. Events report only a role or bounded outcome such as creator, respondent, started, completed, failed, copied, pricing intent, contact intent, or return task.

Capability boundary

CandorKit is a probe for low-risk feedback. It is not suitable for regulated research, health or legal records, protected whistleblowing, emergency reports, child data, identity verification, employee-case investigation, or any workflow that needs guaranteed anonymity, legal privilege, advanced access control, or long-term audit retention.

Contact

Privacy or boundary questions: hello@candorkit.com.

← Back to CandorKit