Privacy Policy

Last updated: March 2026

This policy explains what personal data questionnaires.ai collects, how we use it, who we share it with, and what rights you have. Please read it carefully. If you have questions, email privacy@questionnaires.ai.

1. What Data We Collect

When you use questionnaires.ai we collect the following categories of data:

  • Account information — your name and email address when you sign up, and any changes you make in your profile settings.
  • Survey content — the questionnaires you create, including titles, descriptions, questions, and configuration settings.
  • Survey responses — answers submitted by your respondents, including optional respondent email addresses if they choose to provide them.
  • AI-generated insights — summaries, themes, and recommendations generated by the Claude API based on your survey responses. These are stored in your account so you can access them later.
  • Usage and technical data — basic logs of features used, error reports, and device/browser information to help us diagnose issues and improve the service. We do not use third-party analytics trackers.
  • Payment information — billing details including name, email, and payment method are collected and stored securely by Stripe. We never store card numbers or full billing details on our own servers.
  • Cookies and preferences — small values stored in your browser to keep you signed in, remember your dark mode preference, and record cookie consent.

2. How We Use Your Data

We use the data we collect solely to provide and improve questionnaires.ai:

  • To create and maintain your account and authenticate you securely
  • To store and serve your questionnaires and their responses
  • To process payments and manage your subscription via Stripe
  • To send transactional emails — including email verification, password reset links, and optional survey response notifications — via Resend
  • To generate AI-powered question suggestions and response insights by sending your survey content to Anthropic's Claude API (see Section 4 for details)
  • To diagnose bugs, monitor uptime, and improve performance
  • To enforce our Terms of Service and prevent abuse

We do not sell your personal data. We do not use your data to train AI models. We do not serve advertising.

3. Third-Party Services We Use

We share data only with the third-party services required to operate the platform. Each has its own privacy policy linked below.

Firebase / Google Cloud

Stores your account, questionnaire, and response data. Handles authentication. Data is hosted in Google Cloud infrastructure.

Stripe

Processes all payments and manages subscriptions. Stripe stores your payment method and billing history. We only receive a Stripe customer ID and subscription status.

Resend

Delivers transactional emails such as verification emails, password reset links, and survey invitation emails. Your email address is transmitted to Resend for delivery purposes only.

Anthropic (Claude API)

When you use the AI question generator or request AI insights, your survey topic, questions, and — for insights — your respondents' answers are sent to Anthropic's Claude API for processing. Anthropic acts as a data processor on our behalf. Per Anthropic's API usage policy, data submitted via the API is not used to train their models. Anthropic has its own privacy policy that governs how they handle API data.

Vercel

Hosts the questionnaires.ai web application and serves it globally via a CDN. Request logs (including IP addresses) may be retained briefly for security monitoring.

We do not share your data with advertisers, data brokers, or any other third parties not listed above.

4. AI Processing of Survey Responses

When you request AI Insights on a questionnaire, the questions you created and the answers your respondents submitted are transmitted to Anthropic's Claude API. This means respondent data leaves our servers and is processed by Anthropic in order to generate the summary, key themes, standout responses, and recommendations you see in your dashboard.

What you should know as a survey creator:

  • You are responsible for ensuring your respondents are aware their data may be processed by AI tools as part of your research or feedback process.
  • Anthropic does not use API inputs to train its models and does not retain data beyond the period needed to generate a response, per their API terms.
  • AI Insights is an opt-in feature — responses are only sent to Anthropic when you explicitly click "Generate AI Insights." Responses are never sent automatically.

5. Data Retention

We retain different types of data for different periods:

Data typeRetention period
Account information (name, email)Until account is deleted, then within 30 days
Questionnaires and questionsUntil you delete the survey or close your account
Survey responsesUntil you delete the survey or close your account
AI-generated insightsStored with the questionnaire; deleted when survey is deleted
Payment and billing records7 years (required for financial compliance)
Server/request logsUp to 30 days on Vercel infrastructure
Anthropic API call dataNot retained by Anthropic beyond the API response

When you close your account, all account data, questionnaires, and responses are permanently deleted within 30 days. Payment records held by Stripe may be retained longer for legal and compliance reasons.

6. Your Rights and How to Exercise Them

Depending on where you are located, you may have the following rights regarding your personal data:

  • Right to access — request a copy of the personal data we hold about you. We will respond within 30 days.
  • Right to correct — update your name or email directly in your profile settings, or contact us to correct any other inaccurate data.
  • Right to delete — close your account at any time from the billing settings page. You can also email us to request deletion of specific data without closing your account. We will process deletion requests within 30 days.
  • Right to export — download your survey responses as a CSV file from the analytics page (Pro and Business plans). To request a full export of all your account data, email us.
  • Right to restrict processing — in certain circumstances, you may request that we limit how we use your data while a dispute is resolved.
  • Right to object — you may object to processing of your data where we rely on legitimate interests as the legal basis.
  • Right to withdraw consent — where processing is based on consent (such as cookie usage), you may withdraw consent at any time.

To exercise any of these rights, email privacy@questionnaires.ai with "Privacy Request" in the subject line. We will respond within 30 days. We may ask you to verify your identity before processing the request.

7. International Data Transfers

questionnaires.ai is operated from the United States. If you access the service from outside the United States, your data will be transferred to, stored, and processed in the United States and in any other country where our service providers (Firebase, Stripe, Vercel, Resend, Anthropic) maintain infrastructure.

These countries may have data protection laws that differ from your home country. By using questionnaires.ai, you acknowledge that your data may be processed outside your country of residence. We take steps to ensure that any cross-border transfers are handled in accordance with applicable law, including through the use of standard contractual clauses where required.

If you are located in the European Economic Area (EEA) or the United Kingdom and have concerns about international data transfers, please contact us at privacy@questionnaires.ai.

8. Children's Privacy

questionnaires.ai is not intended for use by children under the age of 13, and we do not knowingly collect personal data from anyone under 13. If you are under 13, please do not create an account or submit any personal information through this service.

If we become aware that we have collected personal data from a child under 13 without verifiable parental consent, we will take steps to delete that information promptly. If you believe we may have collected data from a child under 13, please contact us at privacy@questionnaires.ai.

9. Security Measures

We take the following steps to protect your data:

  • Encrypted connections — all data is transmitted over HTTPS/TLS. Connections to questionnaires.ai over unencrypted HTTP are automatically redirected.
  • Session security — authentication uses Firebase session cookies with short expiry windows, validated server-side on every protected request.
  • Firestore security rules — database access rules ensure that users can only read and write their own data. No user can access another user's questionnaires or responses.
  • Secrets management — API keys and service credentials are stored as environment variables and never committed to source code.
  • Email verification — users must verify their email address before accessing AI features, reducing the risk of fraudulent account creation.
  • Payment security — all card data is handled exclusively by Stripe, which is PCI DSS Level 1 certified.

No method of transmission over the internet is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.

10. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Investigate and contain the breach as quickly as possible
  • Notify affected users by email within 72 hours of becoming aware of the breach, where feasible, describing what data was affected, what we believe happened, and what steps we have taken
  • Notify relevant supervisory authorities as required by applicable law (such as GDPR for users in the EEA)
  • Take steps to prevent recurrence and improve security practices

If you believe your account has been compromised, change your password immediately and contact us at privacy@questionnaires.ai.

11. Business Transfers

If questionnaires.ai is acquired, merged with another company, or if its assets are sold, user data — including personal information and survey content — may be transferred to the acquiring entity as part of that transaction. In such an event:

  • We will notify you by email and via a prominent notice on this page at least 30 days before your data is transferred and becomes subject to a different privacy policy.
  • Any acquiring party will be required to honour the privacy commitments made in this policy, or provide you with the opportunity to delete your data before the transfer takes effect.
  • You will have the right to close your account and request deletion of your data before any transfer takes place if you do not agree to the new terms.

12. Cookies

We use the following cookies:

CookiePurposeDuration
sessionKeeps you signed in between page loads5 days (refreshed on activity)
themeRemembers your light/dark mode preferencePersistent (localStorage)
cookie_consentRecords that you accepted this cookie noticePersistent (localStorage)
demo_countLimits anonymous demo uses on the landing page24 hours

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.

13. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to all registered users at least 14 days before the changes take effect
  • Display a notice in the dashboard for signed-in users until they acknowledge the update

Your continued use of questionnaires.ai after changes become effective constitutes your acceptance of the revised policy. If you do not agree to the changes, you may close your account before the effective date.

14. Contact and Data Deletion Requests

For any privacy questions, data access requests, or to request deletion of your account and data, contact us at:

questionnaires.ai

Email: privacy@questionnaires.ai

Please include "Privacy Request" in your subject line and describe your request. We will respond within 30 days.

To delete your account directly, go to Dashboard → Billing → Close account. This will permanently delete your questionnaires and responses within 30 days.