Privacy policy
Last updated 1 September 2026.
The short version
- If you are taking part in a study, the researcher running it decides what happens to your responses. We hold them on their behalf.
- Researchers never see your name or email — only a random participant ID.
- We do not sell data, and we do not use your study responses to train AI models.
- You can download everything we hold about you from your account settings.
Who we are
VibeMyExpt is operated by ALPHAKHOJ LLP, Hyderabad, Telangana, India. For anything in this policy, contact [email protected].
Our two different roles
This is the part institutions care most about, so we will be precise. We act in two capacities, and which one applies depends on the data.
We are the processor
For everything a study collects — responses, timings, recordings, device details. The researcher and their institution are the controller. They decide why it is collected, how long it is kept, and when it is deleted. We act on their instructions and nothing else.
We are the controller
For accounts on this platform — researcher accounts, participant portal accounts, wallet balances and payouts, billing, and our own service emails. We decide how those work, so those decisions are ours to answer for.
In practice this means a participant asking us to delete their study responses is asking the wrong party — we will point them to the researcher named on the consent form. It also means a university signing with us should sign our data processing agreement.
What we collect
| Whose | What | Why | Lawful basis |
|---|---|---|---|
| Researchers | Name, email, institution, department, bio, profile picture, Google account ID if you sign in with Google | Running your account and studies | Performance of our contract with you |
| Researchers | Billing name and address, GSTIN, payment records, invoices | Taking payment and meeting Indian tax law | Contract, and our legal obligations |
| Participants (portal accounts) | Email, name, participation history, wallet balance, payout bank or UPI details | Letting you find studies, take part, and be paid | Performance of our contract with you |
| Participants (in a study) | Responses and timings you produce, plus browser and device details (browser, operating system, screen and window size, timezone, language) | Delivering the study and letting the researcher analyse valid data | The researcher's lawful basis — we process this on their instructions |
| Participants (in a study) | Voice or video recordings, where the study collects them | The study design requires them | The researcher's lawful basis, with consent shown before the study starts |
| Everyone | IP address, used transiently for rate limiting | Preventing abuse | Our legitimate interest in keeping the service available |
We do not store your IP address against your account or your study responses. It is used only in memory, to rate-limit abuse.
Participants stay pseudonymous
A researcher sees a random participant ID and never your name or email address. No screen or export in the product joins the two.
Researchers are also barred by our acceptable use policy from asking for direct identifiers — names, personal email addresses, phone numbers, dates of birth, addresses, ID numbers — inside their own study materials, unless we have approved it in writing in advance. If a study asks you for something on that list, please tell us.
AI features and your data
Researchers can use AI to help build experiments and analyse results. We want to be exact about what that sends to an AI provider, because vague answers here are how platforms mislead people.
- Building experiments sends the researcher's own prompts and experiment code. No participant data is involved.
- Analysing results runs the actual analysis in the researcher's own browser, so the dataset itself is not uploaded to the AI provider. What is sent is a description of the data: column names and types, how complete each column is, summary statistics, and — for columns with fewer than 25 distinct values — the list of those values. A short excerpt of the analysis output can also be included so the assistant can correct its own errors.
- Free-text answers are never quoted to the AI provider. Only counts and average lengths are described.
This means participant-derived information can reach our AI providers in summarised form. Our providers are listed on the subprocessors page, and both state in their published terms that data submitted through their business APIs is not used to train their models. We do not train any models ourselves. A researcher whose ethics approval does not permit third-party AI processing should not use the analysis assistant.
Where your data is held
| Files, stimuli, recordings and exports (AWS S3) | India (AWS ap-south-1, Mumbai) |
| Outbound email (AWS SES) | India (AWS ap-south-1, Mumbai) |
| Application servers | India |
| Database (MongoDB Atlas) | India |
We are based in India, which the European Commission has not granted an adequacy decision. Where we handle personal data originating in the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses, annexed to our data processing agreement, together with a transfer impact assessment available to institutions on request.
Some of our providers process data in the United States, as marked on the subprocessors page. Those transfers rely on the same clauses.
How long we keep it
| Your account | Until you delete it |
| Study responses and recordings | Set by the researcher per study. Where no period is set, kept until they delete it |
| Generated data exports | 7 days, then deleted automatically |
| Analysis datasets | 7 days |
| Sign-in sessions | Up to 30 days |
| Payment webhook records | 180 days |
| Invoices | Kept as long as Indian tax law requires |
| Audit log | Retained for research-integrity and IRB reporting |
Your rights
Depending on where you live, you may have rights of access, correction, deletion, objection, restriction and portability. Here is how each works in practice.
- See and download your data. Account settings has a "Download my data" button that returns everything we hold about you as a JSON file, including your participation history and responses.
- Correct your data. Edit your profile in account settings, or email us.
- Delete your account. Also in account settings. Your study responses stay with the researchers who collected them, but are anonymised: relabelled with a random identifier that cannot be traced back to you, and your device details are erased.
- Delete your study responses. Contact the researcher named on that study's consent form. They control that data, not us, and we will not delete a researcher's dataset on our own initiative. We will help them action it.
- Stop emails. Every email has a one-click unsubscribe link.
You can also complain to your data protection authority. If you are in the EEA or UK and want to raise something with us first, use the contact address above.
Children
Accounts on this platform are for people aged 18 and over. Research with children does happen on the platform, but it is set up and supervised by the researcher, who is responsible for obtaining parental or guardian consent and the necessary ethics approval.
If you are in the United States
We do not sell or share personal information as those terms are used in California and similar state laws, and we do not engage in targeted advertising. The rights described above cover the access and deletion rights those laws grant, and we will not discriminate against you for exercising them.
We do not accept protected health information and will not sign a HIPAA business associate agreement. Where a study involves student education records covered by FERPA, the institution remains the responsible party and should raise that with us before the study runs so the right terms are in place.
Security
What we do to protect this data, and what we have not built yet, is set out on the security overview.
Changes
If we change this policy in a way that materially affects you, we will say so on this page and, for significant changes, by email. The date at the top always reflects the current version.