Updated 10 August 2026
Privacy with a clock
Stored for the one survey
CandorKit stores the survey title, introduction, questions, answer text, choices or ratings, creation and submission timestamps, a hashed private results credential, and an expiry timestamp. It caps a survey at five questions and 100 responses.
Deliberately not attached to responses
The application has no dedicated name or account field and does not automatically attach IP addresses, user agents, cookie ids, account ids, or a cross-survey user history to a response. It does store the answer content submitted by a respondent, which can include names or other identifying details. Cloudflare still processes ordinary connection metadata to deliver and protect the service, so respondents must leave identifying and highly sensitive information out of their answers.
Seven-day retention
Submitted responses stay in the private results view until the survey expires after seven days. At expiry, the survey and results links stop working. The next daily cleanup deletes the expired survey and its responses from CandorKit's live database. This cleanup does not delete CSV files, screenshots, or copies already exported by the survey owner.
Analytics separation
Cloudflare Web Analytics counts page views on public marketing and guide pages. After a creator completes a survey on the homepage, the site offers optional Microsoft Clarity analytics. Clarity loads only after consent, with advertising storage denied. Builder inputs, the respondent preview, and generated links use explicit masking. Neither Clarity nor Cloudflare Web Analytics loads on respondent or private-results pages. Named events contain only a bounded role or outcome such as creator, started, completed, failed, copied, pricing intent, contact intent, or return task. “Privacy settings” in the footer lets you change or withdraw the choice; withdrawal clears Clarity cookies and ends its current session.
Capability boundary
CandorKit is a lightweight service for low-risk feedback. It is not suitable for regulated research, health or legal records, protected whistleblowing, emergency reports, child data, identity verification, employee-case investigation, or any workflow that needs guaranteed anonymity, legal privilege, advanced access control, or long-term audit retention.
Plan the invitation and deletion
For practical guidance, read how to distinguish an anonymous survey from a confidential one and how to set a visible retention boundary before collecting answers.
Contact
Privacy or boundary questions: hello@candorkit.com.