Privacy & Anonymity
Privacy & Anonymity Policy
Last updated June 2026
Field Panel runs surveys at different sensitivity levels. Before you answer, each survey states its anonymity tier in plain language. This page explains what those tiers mean and the rights you keep over your data.
The two protected tiers
Anonymous
No link to your identity and no demographics collected. There is nothing in the response that could be traced back to you — Aaron literally cannot tell who said what. You manage these responses with a receipt token only you hold.
Confidential
No link to your identity, but the survey collects demographics (such as sector or age band). They are tied only to your anonymous profile token — never your name or account. Results are shared with the panel in aggregate, and your written answers may be shared with the panel anonymously — never attached to your name, account, or demographics. Also token-managed — never tied to your account.
A third tier, Identified, deliberately links responses to your account (for example, feedback on a specific class). You manage Identified responses by signing in. The tier is always shown before you answer.
Your key
The token system
Because anonymous and confidential responses are not linked to your account, the only way to manage one later is a token issued when you submit. Tokens are shown once, downloadable on your PDF receipt, never emailed, and unrecoverable by design — Aaron cannot look one up for you, because being able to do so would rebuild the very link the anonymity model removes. Save it somewhere safe.
Hold a token already? Manage your data.
Participation vs. content
For anonymous and confidential surveys, what you answered is unlinkable to you. But that you participated may be known — Aaron tracks completion (not content) to thank contributors, send reminders, and re-engage or retire inactive panelists. Content stays behind the wall; only the fact of participation is recorded against your account.
What you can do
Your data rights
View. See the full content of every response tied to your receipt token or account.
Withdraw. Exclude a response from future analysis without deleting the record.
Delete. Permanently remove a response. For anonymous and confidential surveys, your receipt token is the only key.
Manage your profile. Edit or delete your anonymous demographic profile with your profile token.
How submissions are held
Batched release and timing
For anonymous and confidential surveys, responses are not stored individually as they arrive. Instead, they are held and released as a group once enough have accumulated. When a batch is released, submission times and ordering are removed, and the list of who has responded is never stored alongside any answer — the two records are kept entirely separate by design.
What is recorded, separately from your answer, is the fact that you participated: a timestamp-free yes/no on your invitation, with no link to what you said. That lets Aaron thank contributors and stop reminding you once you have responded, while your actual answer stays held in the batch and is released with no connection to you.
This is a safeguard. The stored data contains no passive link between your identity and your answer.