Privacy & terms
What the survey stores
When you answer a team survey, we store: your ratings, your probe answers (why you hold back or what makes speaking up possible, and on what kind of power it depends), anything you type into the comment boxes, the date (never the time) of submission, roughly how long the survey took, and whether every rating was the same (so the report can flag it). That's the complete list.
We deliberately do not store your name, email address, IP address, device information, or any identifier that links a response to a person. There is no receipt or reference number, because a receipt is a handle and a handle is an identifier. Results are sealed until the survey closes with at least four responses, released once, and written comments are returned shuffled, detached from the ratings their author gave — so no individual's set of answers can be reassembled.
The individual self-check stores nothing about you unless you explicitly choose, at the end, to contribute your ratings to research. Your answers are never sent anywhere; they stay in your browser.
Organisers are known; respondents are not
Two different people use this service, under two different promises. If you respond to a survey, everything above applies: nothing about you is collected, ever. If you organise a survey, you're a customer initiating a service for other people, and we verify and keep your email address. It attaches to your surveys — never to any response, which carries nothing it could be joined to — and we use it to send your sign-in codes, remind you about a survey that's still open, tell you when a report is ready and, if you turn it on, when responses arrive. We also keep your time zone, so those messages reach you in your morning. We send marketing only if you tick the box saying so, and you can withdraw that any time. Organisers' GDPR rights are fully exercisable: ask and we can show you or delete everything we hold about you. The respond page tells your team this asymmetry plainly, because accountability on the organiser's side is part of what makes anonymity on the respondent's side credible.
Emails are delivered by SendLayer, whose infrastructure is in the United States. They pass each message through without storing its content, and keep delivery records (your address, timestamps, and whether it was delivered, opened or bounced) for 3 to 30 days. Transfers from the UK and EU are covered by Standard Contractual Clauses and the UK International Data Transfer Addendum. Respondents are never emailed.
Organisation licences
On an organisation licence we also hold the email addresses of the people given seats, and whatever the administrator puts in the panel their organisers see (a short introduction, contacts and links). The administrator sees who holds a seat and how many surveys each has run, and findings pooled across teams — never a team's own report, and never which team said what. Pooled findings appear only once at least two teams have finished, and change over time only once at least three have measured again. Results can be downloaded as data: the same counts and averages the pages show, never individual responses or comments. For this data we act on the organisation's behalf, and we'll sign a data processing agreement on request.
We also keep a record of activity on each organisation licence — who gave or removed a seat, who created, closed or released a survey (with how many responses, never what they said), edits to the organisers' panel, exports, and when the dashboard was opened. If we read one of the licence's reports for a quality check, that is recorded too. The organisation's administrator can see this record on request. It never contains a response.
Paying
Payments are handled by Stripe. Your card details go to Stripe and never reach us; we keep the licence itself, the email address it belongs to and Stripe's reference for it, so the licence works and can be renewed or cancelled.
What we can't promise — and say so
The database guarantees above are architectural: the anonymity cannot be undone by us changing our minds, because the identifying data was never collected. But two things sit outside the database. First, the infrastructure that serves this site and its API (Render and Supabase) keeps standard technical logs, which include IP addresses, for a limited period — we do not use them, cannot join them to responses, and keep their retention short, but they exist. Second, anonymity has arithmetic limits in very small teams: in a team of four or five, a colleague who knows you well may recognise your handwriting in a comment. The survey warns about this above every comment box; we repeat it here.
What the words you write become
Comments are shown to your team, verbatim and unattributed, in the released report. They are never summarised, paraphrased, or processed by AI. The report's "qualitative picture" is generated by fixed rules from the numbers alone. If you write something identifying — including someone's name — the team will see it, so write accordingly.
The research pool
If you opt in at the end of the self-check, your ratings (numbers only, plus any coarse, optional context you choose to give, like sector or team-size band) join an anonymous pool used for research on psychological safety across working life. This pool is never used to benchmark, rank, or compare individual teams — findings are published only at population level. There is no way to withdraw a specific contribution after the fact, because there is no way to find it: that is the anonymity working as designed, and it's why we ask before you contribute rather than after.
What we look at
We keep an admin view of how the service is being used, and it shows aggregates only: how many surveys exist, how many responses they've had, which questions get chosen, how often each reason for holding back is given across everyone. It does not show any individual response, or anything anyone wrote. We could technically query the database directly — any operator of any service can — but the tool we built for ourselves is deliberately limited, because a habit is harder to break than a rule.
One exception. We can't tell whether the report is describing teams fairly, or make it better, without reading some. So someone at Psych Safety may open a team's finished report — the same aggregate report the organiser and team see — to check the wording, the reasoning and the suggested actions hold up, and to improve the tool. Free-text comments are excluded from that view unless deliberately requested, and every such read is logged against the survey. Nothing about any individual is visible in it, because nothing about any individual exists to be seen. Respondents are told this on the first screen before they answer, and organisers are told when they build.
Each survey keeps the terms its respondents were shown. For surveys built from 27 September 2026 this is a standing part of the service. Surveys built between 9 and 26 September 2026 were told it would last only while the tool was in preview, so for them it ends when the preview does. Surveys built before 9 September 2026 are never read.
Self-check completions are counted by a bare daily tally: a number incremented by one, with no answers, addresses, or identifiers attached.
If something goes wrong in your browser, the page sends us the error message and which page it happened on — never your answers — and those reports are deleted after 30 days. If you send us feedback, we keep what you wrote and, only if you give one, your email address so we can reply.
Cookies and tracking
None. No analytics service, no advertising, no third-party scripts, no cookies, no fingerprinting. We keep two counters of our own, both of them tallies rather than trails: how many people opened each kind of page on each day, and which website sent them here — the address of the linking page, not anything about the visitor. Query strings are stripped from that address before it is stored, because links sometimes carry tokens or email addresses in them and we don't want those. Neither counter records who you are, and neither can be assembled into one person's path through the site. Fonts are served from this site, not from a font network. Your browser's own storage keeps you signed in if you organise surveys, and holds a survey you're part-way through building until you close the tab. The one piece of feedback instrumentation is the optional "does this ring true?" tap on the report's qualitative picture, which stores a single word (yes / partly / no) against the survey — not against you.
Doing due diligence? Security and data covers where everything lives, who the sub-processors are, who can see what, and why your employees' answers aren't personal data in the first place.
Who holds what, and your rights
Iterum Ltd is the data controller for the little that exists. Survey data lives in a database hosted by Supabase in the EU (Ireland region); the site is served by Render's CDN; organisers' emails are sent by SendLayer (United States, above); payments are taken by Stripe. Under UK GDPR you have rights of access, rectification and erasure — but note their honest limit here: because responses carry no identifier, we cannot locate your response to show, correct, or delete it. What we can do: delete an entire survey and everything in it at the request of whoever holds its keys, and answer any question about the design at psychsafety.com/contact. You also have the right to complain to the ICO.
Survey organisers: you are responsible for telling your team the truth about this survey — the respond page does most of that for you — and for releasing the report you said you'd release.
Retention
| What | Kept for |
|---|---|
| Surveys and their responses | Three years after the survey closes |
| Organiser accounts | Two years after last use, once no surveys remain and no licence is live |
| Organisation licence audit trail | The life of the licence, and 12 months after it ends; addresses of deleted accounts are removed |
| Licence and payment records | Six years, as UK accounting rules require |
| Sign-in codes | A week after they expire (automatic) |
| Error reports | 30 days (automatic) |
| Research contributions and page counts | Kept; they carry no link to anyone |
When a survey, an account or an audit trail reaches the end of its period, a person reviews it before anything is deleted. We keep something longer only for a reason — you're still an active client, say — and we note the reason, and it comes back for review when that time is up. Infrastructure logs follow provider defaults, set as short as their tooling allows.
Want something deleted sooner? Whoever holds a survey's keys can ask, and we'll delete the whole survey.
Terms of use, briefly
What this is
An instrument for understanding psychological safety in a team, provided as-is during a soft launch. The individual self-check is free, and so is a team's first survey; measuring again or running several teams is on a paid plan. It is a prompt for a conversation, not a clinical assessment, a medical or psychological evaluation, or an HR-grade appraisal, and it should never be used to evaluate, discipline, or make decisions about individuals — the design makes that impossible on purpose, and attempting to defeat that design is a breach of these terms.
Using it with clients
A Practitioner licence may be used with your clients' teams, and you may charge for that work — the licence is yours, the teams can be theirs. What you can't do is present the report as your own instrument or remove where it came from: every report says who built it, and that stays. Your clients' respondents get exactly the same anonymity as anyone else's.
Acceptable use
Don't attempt to de-anonymise respondents — including by combining exported data with anything else — or to work out a single team's results by comparing organisation views or exports over time; probe the system's security beyond your own surveys, scrape the item bank for a competing product, or misrepresent a report as something we certified. Survey creation may be rate-limited or gated; abuse gets surveys removed.
Intellectual property
The question bank is adapted from The Fearless Organization, © Amy Edmondson 2018, used with attribution; the sensemaking items, habitat framework, and this survey tool's design are © Iterum Ltd. Reports belong to the teams they describe — share yours however you like.
Liability
Provided without warranty; to the extent the law allows, Iterum Ltd isn't liable for decisions made on the basis of a report. Nothing here limits liability that cannot lawfully be limited. These terms are governed by the law of England and Wales.
Plain-language notice, drafted in-house. If you're a lawyer and something above makes you wince, we would genuinely like to hear from you.
