Privacy policy
Last updated:
Your research and your privacy choices matter. This policy explains what ClarifyWhy collects, why we use it, who receives it, and how you can stay in control.
At a glance
- You can answer a study without an account. The creator receives your research response and any follow-up details you choose to share.
- We process microphone audio to run the conversation, but ClarifyWhy does not save an audio recording. We keep the written transcript.
- Optional analytics requires your choice and stays off on participant pages.
- If you allow analytics, Microsoft Clarity provides heatmaps and session replays on public pages. Microsoft also uses Clarity data to improve its own products and services. Form content is masked; creator workspaces and interviews are excluded.
- Advertising audience matching is not active. Any future Meta or Google matching would use separately authorised, hashed creator or waitlist emails, never research responses.
On this page
Who is responsible
ClarifyWhy is an independently operated product based in the United Kingdom. “ClarifyWhy”, “we”, and “us” refer to the individual operating it under that name. For privacy questions or requests, email hello@clarifywhy.com or visit our contact page.
We decide how to handle our own website, creator accounts, service security, waitlist, and optional feedback about ClarifyWhy. For these purposes, we are the data controller: the party responsible for deciding why and how information is used.
For a creator’s research, the creator decides the research purpose, recruitment, and use of responses. We process that research on their behalf. Their study invitation or notice should identify them and explain their use of the data. Our creator data-processing schedule describes this relationship. When ClarifyWhy runs its own study, we are its controller.
Information we collect
Website visitors
Our hosting and security providers process IP addresses, browser details, request logs, and security-check results to deliver and protect the site. If you allow analytics, Google Analytics receives limited page and event information, browser and device details, approximate location, and the IP address needed to receive the request. It does not receive your form entries, email, account identifier, study identifier, transcript, or private URL parameters from our analytics integration.
If you allow analytics, we also collect page-performance measurements, error categories, application file locations, and request identifiers on public and creator pages. Grafana receives these diagnostics through our backend to help us investigate failures. They exclude form entries, error-message contents, transcripts, and private URL parameters. Diagnostics stops when you withdraw analytics consent and stays off on participant pages.
If you allow analytics under this updated notice, Microsoft Clarity receives public-page interactions such as clicks, scrolling, and page layout to produce heatmaps and session replays. It also receives browser and device information, public-page URLs and referrers, session identifiers, and the IP address needed to receive requests. Form content is masked before collection. We exclude creator workspaces, sign-in pages, study invitations, interviews, and interview-management pages from replay recording. We also skip pages with URL query data or a private same-origin referrer. We do not send account identifiers or research content to Clarity. Its advertising storage is disabled. See Microsoft’s privacy statement.
Microsoft acts as an independent data controller for Clarity data, meaning it decides how to use that data for its own purposes. Under the Clarity terms, it may use personal data to provide Clarity and improve Microsoft products and services, and non-personal data for research and development, including AI training and evaluation. Our integration keeps advertising consent denied; Microsoft’s consent documentation says this prevents Clarity data from being shared with Microsoft Ads.
Creators
Google sign-in, through Amazon Cognito, supplies your account identifier, verified email, and available display name. We store these with your account status, login times, study ownership, usage information, and session records to operate your workspace. Study briefs and Designer conversations become part of the research you manage.
Participants
Study creators can use named invitation links to group their interviews into cohorts. We keep aggregate counts of invitation opens, including repeat visits, and record which cohort link started each interview. Creators see cohort labels with responses and exports. These counts do not use visitor profiles, tracking cookies, or third-party analytics.
We collect your choice of voice or text, age confirmation and participation permission, answers or transcript, interview identifiers, status, and timestamps. You may separately provide follow-up contact details for the purpose the creator states. Optional ratings or comments about the ClarifyWhy experience stay separate from the research shown to the creator.
An interview identifier replaces the need for a participant account; it does not make the response anonymous. What you say or choose to share may identify you or another person.
Waitlist and direct contact
Resend manages waitlist email addresses, signup source, consent details, subscription status, and requested updates. ClarifyWhy does not keep a second waitlist copy in its application database. If you email us, we also receive your address, message, and any information needed to handle your request.
Why we use information
Under UK and EU data-protection law, our purposes and legal bases are:
- Accounts and requested services: to perform our contract with you, or pursue our legitimate interest in serving the organisation you represent.
- Research for a creator: to follow the creator’s lawful instructions. The creator must explain their lawful basis. When we run our own voluntary study, we rely on the participant’s consent.
- Optional follow-up, beta emails, and analytics: consent for the specific purpose you choose. A follow-up choice belongs to that study’s creator; it is not permission for ClarifyWhy advertising.
- Service security, troubleshooting, support, and optional platform feedback: our legitimate interests in protecting and improving the service, balanced against your rights.
- Rights requests and legal compliance: the applicable legal obligation, or our legitimate interest in verifying and responding to requests where no obligation applies.
- Proposed email audience matching and advertising measurement: separate consent before activation, as explained below. Current beta-email and analytics choices do not authorise it.
You can withdraw consent for future processing. You can also object to use based on legitimate interests; we will stop unless applicable law permits us to continue. An objection to direct marketing does not require you to give a reason.
Research conversations and follow-up
In a voice conversation, your audio passes through our hosted real-time infrastructure to OpenAI so the agent can understand and respond. In a typed conversation, OpenAI processes the study instructions and submitted answers to generate follow-up questions. You can also dictate an editable text message. ClarifyWhy does not store an audio recording of these conversations or dictation, but it stores the submitted text and written transcript.
The creator can review research and download permitted exports. Follow-up contact details are optional, stored separately with their stated purpose, and encrypted in the application database. The creator can use details you agree to share for that purpose. Platform experience feedback is used by ClarifyWhy and is not included in the creator’s research view.
The AI adapts questions to the conversation. It can make mistakes, and it does not make legal, employment, credit, health, or similarly significant decisions about you. Do not share passwords, confidential material, or sensitive personal information. You can skip a question or stop at any time.
We do not use research audio, transcripts, answers, study topics, participant identifiers, or creator-collected follow-up details for advertising audiences. We do not use research content to train general-purpose AI models.
Providers and other recipients
These providers support the current service, receiving information needed for their role:
- Cloudflare: website delivery, network security, and Turnstile anti-abuse checks.
- OVHcloud: application, database, and self-hosted LiveKit infrastructure for real-time conversations.
- OpenAI: AI study design, live speech, transcription, and typed questions and replies.
- Google and Amazon Web Services: creator authentication through Google and Amazon Cognito.
- Google Analytics: optional website analytics through Google Tag Manager. Advertising features remain disabled.
- Microsoft Clarity: optional heatmaps and session replays on public pages, with form content masked and advertising storage disabled. Microsoft is an independent controller and also uses Clarity data for the purposes explained under Information we collect.
- Grafana Cloud: operational metrics, sanitised logs and traces, and optional browser performance diagnostics.
- Resend: waitlist contacts, subscription records, and requested beta emails.
Cloudflare, OVHcloud, and OpenAI support research processing where their service is involved. Account authentication, waitlist email, and optional website analytics serve separate ClarifyWhy purposes. A provider may also handle information for its own security or legal duties under its terms.
OpenAI’s API data controls state that API data is not used for model training unless the customer opts in. Default abuse-monitoring logs may contain content and may be retained for up to 30 days, subject to its stated exceptions. See OpenAI’s API data controls. Our no-recording statement describes ClarifyWhy’s storage, not a promise that every provider retains no data.
We may also disclose relevant information to comply with a legal requirement, establish or defend a legal claim, prevent serious harm, or support a business transfer with appropriate confidentiality and data-protection safeguards. A transfer does not authorise a new, incompatible advertising use of existing research.
Advertising and hashed email addresses
Current status: email audience matching and advertising trackers are not active in the current beta. This policy describes the separate choices we would require before introducing them; it does not enrol you.
We may offer creators and ClarifyWhy waitlist subscribers the choice to receive more relevant ClarifyWhy ads through Meta, including Facebook and Instagram, and Google. If you separately agree, we may use your verified email, supplied directly to ClarifyWhy, to create or update an advertising audience.
What hashing means
For email matching, we would standardise the email address and convert it into a one-way code using SHA-256 before sharing that code with the selected platform. We would share the hash for matching, rather than the readable email address. The platform compares it with hashes of account emails it already holds.
A hashed email is still personal data in this context. Matching can link the code to your platform account. It is not anonymous data, and hashing does not replace your privacy rights or the need for a lawful basis.
How an audience would be used
With the permission described at the time, matching could help show relevant ClarifyWhy ads, avoid showing ads to existing subscribers, measure campaign results, or find similar audiences using the platform’s tools. The platform also uses information it holds under its own privacy terms. The separate choice would identify the platform, purpose, and applicable data-handling arrangements.
Any future advertising pixels or event measurement would need their own clear notice and required consent before loading. We would describe the event data involved, such as a page visit or signup, and keep research content and private interview information out of those events.
Your choice comes first
Meta and Google choices would be separate, optional, and off by default. Signing in, joining the waitlist, agreeing to the Terms, allowing analytics, or sharing study follow-up details does not give this permission. Existing contacts would need a new choice before inclusion. We would identify any additional advertising platform and obtain the required permission before sharing with it.
You can object to advertising use or ask to withdraw a choice by emailing hello@clarifywhy.com. If matching is introduced, we will provide a way to withdraw as readily as opting in, stop future use, and request removal from affected audiences. We may retain a minimal suppression record to honour your choice.
We do not sell personal data for money. Some US laws treat audience matching or cross-context advertising as “sale”, “sharing”, or targeted advertising even without payment. Where those laws apply, we will honour the relevant opt-out rights, including recognised Global Privacy Control signals. No such advertising sharing is active in the current beta.
Browser storage and analytics choices
Essential storage supports sign-in, security, your privacy choices, microphone preferences, and interview continuity. The creator session uses a secure, HTTP-only cookie. It expires after 24 hours without activity or seven days from sign-in, whichever comes first; signing out revokes it.
Your browser stores private interview access for resuming or managing a response. That access becomes invalid 24 hours after the interview is created. Expired entries are removed when accessed or during application startup where browser storage is available. The management URL contains an interview identifier, while the private access credential stays in the browser. Microphone preferences remain in this browser until replaced or cleared.
Our self-hosted Silktide Consent Manager keeps your choice in browser local storage; it does not send it to Silktide. We keep only your latest analytics choice, when you made it, and the notice version you saw, with no visitor identifier or choice history. We do not keep a separate server record of that choice. Google Tag Manager and Google Analytics load only after you allow analytics, and stay off on participant pages, private interview-management pages, and the interview entry route.
Microsoft Clarity also loads only after you allow analytics, and only on eligible public pages. Its first-party cookies link permitted page visits into sessions. Returning visitors receive a fresh choice under this notice explaining Microsoft’s own uses of Clarity data; earlier choices do not automatically enable analytics. Changing pages into a private area removes the replay code before private content is displayed.
| Storage | Purpose | Lifetime |
|---|---|---|
_clck | Clarity visitor identifier and preferences | Up to one year |
_clsk | Links page views into a Clarity session | Up to one day |
_ga, _ga_MDSM2N881N | Google Analytics visitor and session identifiers | Two-year default, subject to shorter browser limits |
| Consent preferences (local storage) | Remembers your latest choice and notice version | Six calendar months from your explicit choice |
Analytics cookies may refresh on permitted visits. Browsers may shorten their lifetime; for example, Chrome limits cookies to 400 days and Safari may apply shorter limits. Cookie expiry is separate from how long a provider retains information it has already received.
Your consent choice does not renew just because you visit again or open or close preferences. Only choosing Allow analytics, Only essential, or saving preferences starts a new six-month period. We check the choice when the consent manager starts: after expiry, or when the notice changes, we remove the old choice and accessible analytics cookies and ask again before enabling analytics. Clearing browser storage also removes the record. If storage is unavailable, a new choice applies only to the current page and cannot be restored on a later visit.
Our Google Analytics integration uses controlled page names and normalised paths and referrers, excluding private identifiers, query strings, and fragments. The limited product events are successful waitlist signup, choosing to experience an interview, and starting Google sign-in. Analytics consent does not grant advertising consent.
Change your choice using Cookie preferences in the public-site footer, creator workspace, login page, or below. Withdrawing analytics stops future collection, removes accessible analytics cookies, and reloads the page to remove active optional code. Earlier lawful processing is unaffected.
Retention and deletion
Retention depends on the purpose, whether the information is still needed, and any legal duties. We apply these criteria:
- Creator accounts and support: while needed to provide the account or resolve a request, and afterwards only as reasonably needed for security, disputes, or legal obligations. Account deletion is currently requested by email.
- Research: while the creator keeps it in ClarifyWhy. The private deletion control, a verified deletion request, or creator deletion removes the response from the live service.
- Follow-up contact: until consent is withdrawn or the related interview or study is deleted.
- Platform experience feedback: until the related interview is deleted, or we fulfil an applicable deletion request.
- Waitlist records: while needed for requested updates, until unsubscribe or closure of the list. A minimal suppression record may remain to prevent unwanted re-enrolment.
- Authentication and security records: for the period reasonably needed to prevent abuse, investigate incidents, or meet legal obligations. Session expiry prevents access; it does not immediately erase every security record.
- Analytics and provider records: according to the configured provider retention periods and the purpose of the record. Contact us for the applicable setting; a cookie’s expiry is not the retention period for information already received by a provider.
Deletion from the live service is different from expiry of browser access. Where a backup or legally required record must remain, it should be restricted to that purpose and deleted through the applicable retention cycle. This policy does not promise immediate erasure from every provider or backup.
A creator may already have exported research. We cannot directly erase copies from their systems; the creator is responsible for their lawful retention and handling of rights requests. We will help route a request where appropriate.
International processing
ClarifyWhy is based in the UK, and providers may process information in other countries, including the United States and countries in the European Economic Area. The locations involved depend on the provider and service. Different countries may have different privacy laws.
Where a transfer is restricted by UK or EU data-protection law, it requires an applicable adequacy decision or appropriate safeguards, such as approved contractual clauses and any necessary supplementary measures. A provider’s location or a statement in this policy is not itself a transfer safeguard. Contact us for information about the arrangements relevant to your data and how to obtain a copy where available.
Your choices and privacy rights
Depending on applicable law and the circumstances, you may have rights to access, correct, delete, restrict, or receive a portable copy of your information; withdraw consent; and object to certain uses. We may need to verify your request using proportionate information. We will explain any lawful reason we cannot fulfil it.
- Interview response or follow-up: use the private management control while your browser’s access is valid, or contact us and the study creator. Without that access, we need enough information to locate the response and verify the request.
- Creator account: email us to request account access, correction, or deletion. You can also close or delete studies in the workspace.
- Beta emails: use the unsubscribe link in the email. This does not prevent essential service or requested support messages.
- Analytics: use the cookie control above. Clearing browser storage removes saved choices, so you may be asked again.
- Advertising: email us with an objection or withdrawal request. Future advertising choices would include their own withdrawal control.
UK users can complain to the Information Commissioner’s Office. People in the European Economic Area can contact their local data-protection authority. You do not have to contact us first.
Where US state privacy law applies to our processing, you may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling; use an authorised agent; and appeal a refused request. Email us to exercise a right or appeal. We do not discriminate against you for exercising an applicable privacy right. These rights depend on the law’s scope and exceptions; this policy does not claim every state law applies to the beta.
Adults only
The current beta, creator workspace, and waitlist are intended for people aged 18 and over. We do not knowingly invite children to participate or use their information for advertising. Contact us if you believe a child has submitted information so we can investigate and take appropriate action.
Changes and contact
We will update this notice as our practices change and publish the revised date. We will provide prominent notice of material changes and seek a fresh choice before a new use where consent is required. Updating this page does not turn an existing email subscription into advertising consent.
For questions, rights requests, or an advertising objection, contact hello@clarifywhy.com.
