Polls
Your answer is never linked to a person.
The code is the identity, and the code is linked to nobody. A poll is a one-time questionnaire you open with an access code: no account, no sign-in, nothing asks for your name, and no user ID is ever stored with your answer. Results are only ever shown in aggregate — always, to everyone, including whoever organized it.
Before you start
The join screen tells you the rules up front
You see the numbers the poll runs under before you answer, because a promise you only learn about afterwards is not worth much.
Wording taken from the product itself, not written for this page.
Polls and audits
How a poll differs from an audit
An audit can be made anonymous. A poll is anonymous by construction and cannot be anything else.
| Property | Audit | Poll |
|---|---|---|
| Who fills it in | AuditA signed-in member of the organization | PollAnyone holding a one-time access code. No account, no sign-in |
| Anonymity | AuditOptional, display-level | PollAlways on, storage-level, cannot be disabled |
| Identity stored | AuditYes, hidden everywhere when the audit is anonymous | PollNo user ID is ever stored with an answer |
| Recurrence | AuditRecurring or one-time | PollAlways one-time, with a mandatory closing date |
| Changes after publication | AuditFrozen at publication | PollEditable while it runs, or frozen per poll. Participants are told which |
| Results | AuditPer-person transcripts, unless the audit is anonymous | PollAggregate only, always, for everyone |
| Where you find it | AuditIn your list of assignments when you sign in | PollNever listed anywhere. The code link is the only way in, even for employees |
| Reminders and alerts | AuditYes | PollNo. They would identify somebody |
| Score shown to the person filling it in | AuditOptional | PollNever |
The guarantees
Eight things you can check
Not principles — mechanisms. Each of these is something the product does or refuses to do, described plainly enough that you can hold us to it.
-
The code is the identity
Your answer is linked to a random code, and the code is linked to nobody. No name, no email address and no IP address is captured at any point. When you submit, even that link is cut: the code record only says it was used, and nothing connects it to your answers any more.
-
We cannot recover the code either
Codes are 32 characters generated from 20 bytes of cryptographic randomness, and only a one-way hash is stored. The readable code exists exactly twice: on the screen where it was generated, and in the invitation email if one was sent.
-
The code never reaches our servers
The join link carries it after the #, which browsers never transmit, so it cannot appear in access logs, traces or proxy records. Opening the link does not spend it either — only an explicit click does, so an email scanner cannot burn your code.
-
Results are locked until enough people answer
The threshold is the greater of a fifth of the codes actually redeemed and the organizer's own minimum, with a built-in floor of five. The organizer can raise it, never lower it, and once the poll is live it is frozen.
-
Nothing is ordered by time
Every ordering on every poll screen comes from a hash or from the question definition, so the order in which people answered leaks nothing.
-
The export has no respondent axis
No identifiers, no pseudonyms, no timestamps, and rows shuffled by hash. A per-respondent export is foreclosed by design; it is not a missing feature waiting to be built.
-
What is shown back is deliberately limited
Free-text answers show at most five samples, chosen deterministically, so refreshing the page cannot harvest the full set. Files, photos, signatures and dates are counted and never shown — a photo can identify its author through its metadata.
-
For votes, the supply of codes can be capped
Set the cap to the number of people entitled to vote, and the system guarantees that no more ballots can ever exist than that.
Honest limits
What we will not claim
Anonymity is engineering, not magic. These are the edges, written down so you can weigh them yourself.
Five things to know
- Your answers are saved. We store anonymised data only. We promise that nothing is ever linked to a person, and that results stay locked below the threshold.
- The organizer sees participation volume. How many codes were generated, redeemed, wasted and submitted. Content stays hidden; counts do not.
- An emailed invitation briefly pairs an address with a link. Those outbox rows are pruned on a short retention schedule, and the code table itself never stores a recipient.
- A cap bounds the supply, not the organizer's honesty. Someone holding unissued codes could cast a few answers themselves. Our mitigation is transparency: every participant is told both numbers and that they were fixed at publication.
- Timing correlation on a very small poll remains possible. If four people answer and one of them is on holiday, arithmetic does the rest. The threshold helps; it is not a proof.
Where polls fit
Questions people only answer honestly when nobody is watching
-
Employee sentiment and culture
The answers worth having are the ones nobody would sign.
-
Safety-climate checks
Asking whether people feel able to stop a job only works if naming names is off the table.
-
Works-council and committee votes
Cap the codes at the number of people entitled to vote and the ballot count is bounded by construction.
-
Near-miss and whistleblowing intake
A channel that cannot identify the reporter is a channel people actually use.
-
Post-incident reviews
What went wrong is easier to collect when nobody is protecting themselves.
Anonymity in audits, and how it differs Talk to us about running a poll