Privacy Policy

Last updated: September 2026 ยท Committed to transparency and data minimization.

1. Roles and Responsibilities

When utilizing UX Testbench, data protection roles are distinct:

  • Researchers (Account Holders): Act as the Data Controller for any participant data collected through their studies. Researchers determine the purpose of the study, the consent wording, and what information is solicited.
  • Platform Operator: Acts as the Data Processor providing hosting, isolation, and processing infrastructure.

2. Participant Privacy & Isolation

We take exceptional precautions to protect participants who complete usability evaluations:

  • No Cross-Study Profiling: Each study operates in a dedicated, isolated SQLite database file. Data is not joined across studies.
  • No Ad Trackers: Participant pages load no advertising pixels, behavioral trackers, or external profiling scripts.
  • Anonymous Modes: Studies default to pseudonymous random codes (e.g. ABC4-DEF7) or anonymous sessions.

3. Researcher Account Data

For researchers creating accounts, we store only:

  • Full Name and Email Address.
  • Cryptographically salted and hashed passwords (using industry-standard Argon2/PBKDF2 algorithms).
  • Authentication session timestamps and IP address for session security and abuse prevention (truncated after 30 days).

4. Retention & Deletion

When a researcher deletes a project or account, the associated SQLite database files and prototype assets are purged from the server filesystem. We do not retain shadow copies of participant responses.

5. Self-Hosting Freedom

Organizations with strict data residency regulations (e.g. Indonesian UU PDP cross-border limitations or European GDPR requirements) are encouraged to deploy UX Testbench on their own sovereign infrastructure using our open-source release.