Who controls the answers?
“You own your data” is only useful when access, reuse, export, credential custody, and deletion are concrete.
Separate control from possession
A vendor can store response data while the survey owner retains contractual control. The practical questions are who may access the data, for which purposes, and whether the owner can retrieve and delete it without upgrading.
Do not treat an export button as the whole ownership answer. Backups, logs, abuse systems, support access, subprocessors, and model-training clauses can create additional copies or uses.
Read the operational boundary
Ask whether survey content or responses are used to train models, improve products, target advertising, or build cross-customer benchmarks. Ask which staff roles can access answers and whether that access is logged.
A small public-interest survey may need a different vendor boundary than a marketing poll. Match the tool to the consequence of exposure, not merely to the number of questions.
- Can we export without a paid upgrade?
- Can staff read response content?
- Are answers used for model training?
- Which subprocessors receive data?
- What remains in backups after deletion?
- Is access to results auditable?
Protect the owner credential
A private results link is a bearer credential: anyone who has the full link can read the responses. Keep it out of public documents, shared chat rooms, analytics parameters, screenshots, and issue trackers.
CandorKit places its owner key after the URL fragment so browsers do not send it in the normal HTTP path. The server stores only a hash. There is no recovery workflow, so losing the link also means losing owner access.
Put the boundary in the invitation
Tell respondents what is stored, what is not, who can read it, and when it disappears.
Create a bounded survey