CandorKit

Field note 07

Who controls the answers?

“You own your data” is only useful when access, reuse, export, credential custody, and deletion are concrete.

Separate control from possession

A vendor can store response data while the survey owner retains contractual control. The practical questions are who may access the data, for which purposes, and whether the owner can retrieve and delete it without upgrading.

Do not treat an export button as the whole ownership answer. Backups, logs, abuse systems, support access, subprocessors, and model-training clauses can create additional copies or uses.

Read the operational boundary

Ask whether survey content or responses are used to train models, improve products, target advertising, or build cross-customer benchmarks. Ask which staff roles can access answers and whether that access is logged.

A small public-interest survey may need a different vendor boundary than a marketing poll. Match the tool to the consequence of exposure, not merely to the number of questions.

  • Can we export without a paid upgrade?
  • Can staff read response content?
  • Are answers used for model training?
  • Which subprocessors receive data?
  • What remains in backups after deletion?
  • Is access to results auditable?

Protect the private results link

Anyone who has the full private results link can read the responses. Keep it out of public documents, shared chat rooms, analytics parameters, screenshots, and issue trackers.

CandorKit places the private part of the results link after the URL fragment so browsers do not send it in the normal HTTP path. The server stores only a hash. There is no recovery workflow, so losing the link also means losing results access.

Put the boundary in the invitation

Tell respondents what is stored, who can read it, when it is deleted, and where anonymity stops.

Create a short survey