Skip to main content
Security

Employee responses remain anonymous

No one in the organization will see who answered what. The original response text is deleted right after processing. Results for a question become visible only when five or more people have answered it.

  • You can't see who answered what
  • The original text is deleted
  • Results from 5 responses
  • The same rules apply to exports and AI agents
Response path After processing
Response text Deleted

"Ivan from sales keeps missing deadlines, and we stay up till night redoing reports!"

Processing AI model
Names removed Details removed
Remains From 5 responses

Delays in data handoffs between adjacent departments are noted, resulting in missed deadlines.

How it works

What happens to a response

Anonymity rests on what happens to the response text. It goes through three steps, and the original text is deleted at the third one.

  1. A person responds

    The employee gives a rating on the scale and writes a comment in their own words. The text is stored in the database while processing is underway, and during that time it is not shown to anyone.

  2. The AI model processes the response

    Processing is done by an external provider's model: it receives the response text without the person's name. The model identifies the topic and rewrites the response with an anonymized wording — without names, titles, or details that could reveal the author.

  3. The original text is deleted

    After processing, the text the employee wrote is deleted from the database. What remains is the anonymized wording and the topic of the response. The original response can no longer be read: it no longer exists.

That's why access to the original text doesn't depend on permission settings. Neither the manager, nor the organization admin, nor service support can read it.

Access

Who sees what

What an employee can see and what a manager can see.

The same rules apply everywhere: on screen, in exported results, and when an AI agent accesses via MCP.
Data Employee Manager and admin
Original response text Not stored not stored
Personal survey result Only own Only own
Growth points and recommendations Can see Can see
Survey results: distributions, answer groups, team results No access 5 or more responses
Retention

How long data is stored

Retention periods are set in the service and apply equally to all organizations.

24 months
If the organization is inactive and there is no subscription, the owner and all administrators receive a warning.
30 more days
The organization's data is permanently deleted. Deletion is canceled if the organization is used again or a subscription begins.
90 days
Technical logs. They contain no response texts — only which request was sent, to which model, and how many tokens it used.
24 months
Payment records and demo requests.

Documents

Run your first survey

See how employee responses become anonymized results and growth points the team can openly work with.

Request demo Start for free How it works →

15 ready-made methodologies · summary from 5 responses