Skip to content

Privacy and data handling

Potloc’s privacy policy and terms of use are the governing documents, and the trust centre covers hosting, sub-processors and the controls around them. This page describes how those commitments show up in the product.

Your account carries your name, email address, language, the avatar you may have set, and the record of your sign-ins. The content you author (questionnaires, reports, comments) is attributed to you. Cookies on the platform are described in its cookie policy.

A respondent appears in your results under a Potloc reference, never a name or a contact detail. Attached to that reference are the answers they gave and the context of the interview: the country and language they answered in, when, and the weight they carry in the results. Reaching and screening respondents happens before a response reaches your survey, and any identifying data that involves stays on Potloc’s side.

One exception: an open-ended question can be answered with anything, and that text is returned to you as written.

Access is per survey. Potloc records a role for each person on each survey, and that role is the only thing that grants access, whether to the survey’s results in a browser, to its exports, or to it over MCP. There is no account-wide access. A role on one survey grants nothing on another, and connecting an assistant or forwarding a link grants nothing the role did not already.

Two things reach beyond the people you have given a role:

  • Report links. A report can be shared by link with people who hold no Potloc account. Anyone with the link can open that report and nothing else. The link can carry a password, and anyone who can share the report can turn it off at any time.
  • Connected apps. An AI assistant connected over MCP reads what the person who connected it can read, and stops the moment that person’s role or connection is revoked. See Permissions and data scope for the MCP side.

Results leave the platform in the shapes you choose: an export of a questionnaire, of a chart or of a report, a presentation built from a report, and a spreadsheet of respondent-level responses. The spreadsheet is rendered from a data layout Potloc publishes on your survey, so it carries the same columns every time, however the export is triggered. It is available once Potloc has released the survey’s raw data.

An assistant connected over MCP reads the same responses through the same layouts. It has no route to a respondent-level row that the spreadsheet does not have.

Ask support@potloc.com from the address on the account. Deletion ends every session and connected app at once and clears the traces of where the account signed in from. The content it authored stays in place for the colleagues who rely on it.

If you are exercising a right to erasure, say so. The account is then also stripped of the name, email address and avatar that identified the person, and the content they authored shows a deleted author in their place. That step cannot be undone.

How long Potloc keeps survey and account data, and what happens at the end of an engagement, is set out in the privacy policy and in your agreement with Potloc.