Effective 28 July 2026
Privacy with a clock
Stored for the one survey
CandorKit stores the survey title, introduction, questions, answer text or ratings, creation and submission timestamps, a hashed private owner key, and an expiry timestamp. It caps a survey at five questions and 100 responses.
Deliberately not attached to responses
The application does not store names by default, IP addresses, user agents, cookie ids, account ids, or a cross-survey user history with a response. Cloudflare still processes ordinary connection metadata to deliver and protect the service. Answer content can itself reveal a person, so respondents must not include identifying or highly sensitive information.
Seven-day retention
Each survey receives a seven-day expiry. The service rejects expired access and runs a daily cleanup that deletes the survey and its responses. This does not delete CSV files, screenshots, or copies already exported by the survey owner.
Analytics separation
Cloudflare Web Analytics provides an all-visitor page-view denominator. Microsoft Clarity loads only after consent. Survey titles, descriptions, questions, answers, share links, and owner keys use masking classes and are never attached to named analytics events or dimensions. Events report only a role or bounded outcome such as creator, respondent, started, completed, failed, copied, pricing intent, contact intent, or return task.
Capability boundary
CandorKit is a probe for low-risk feedback. It is not suitable for regulated research, health or legal records, protected whistleblowing, emergency reports, child data, identity verification, employee-case investigation, or any workflow that needs guaranteed anonymity, legal privilege, advanced access control, or long-term audit retention.
Contact
Privacy or boundary questions: hello@candorkit.com.