DemocrezGet the app

Read this one properly

Student privacy.

A session collects one thing from a participant: a phone verification confirming they are a distinct person. That confirmation is not attached to their answers. There is no record anywhere linking a student to what they chose, which is why neither the institution nor Democrez can produce one — it does not exist to be produced.

During the session

What is collected,
and what never is.

Every item in the second column is absent by construction rather than by policy. Nothing here is a setting that could be switched on for a particular institution.

 CollectedNever collected
IdentityA phone verification, confirming one distinct personName, roll number, email, department, year
The answersWhich option was chosen, and the locked predictionAny link from an answer back to a person
The deviceNothing beyond what a browser needs to load a pageDevice identifiers, advertising IDs, location
BehaviourNothingTyping patterns, time spent per option, hesitation, revisions
AfterwardsNothing. The session endsFollow-up contact, marketing, or any use of the number

A student should be able to answer as themselves. Every item above exists to make that possible, and a session that collected more would collect worse answers.

The one thing we ask for

Why a phone number,
and what happens to it.

It is the only piece of information a session requires, and the reason is arithmetic rather than identity.

One person, one answer

Without verification, a single participant could answer several times and shift the batch's split on their own. Every figure in your report would then measure persistence rather than judgment.

It is not attached to answers

Verification happens before the answering and is not carried into the response record. The two are separated at the point of collection, not filtered apart afterwards.

The institution never sees it

No number appears in your report, in any export, or in any conversation with us. There is no list of participants that the institution receives.

It is not used for anything else

No follow-up messages, no marketing, no app prompts, and no addition to any contact list. The session ends and nothing continues.

How long the verification is kept

The retention period is set out in the privacy policy: Raw verification documents: up to 30 days after successful verification. Verification result / compliance logs: up to 1 year unless a longer period is legally required.

Three parties

Who sees what.

These three views never overlap. There is no fourth view with more in it.

The student

Their own reading

Their choice, their locked prediction, the verified figure and the distance between them. Nothing about any classmate, and nothing anybody else can see.

  • Private to their screen during the session
  • Not stored against them afterwards
  • Not visible to a teacher, ever

The institution

The group, as a group

How the batch split, where it agreed, and where it collectively misread the wider public. Every figure is an aggregate with nothing underneath it.

  • No names, no roll numbers, no per-student output
  • No list of who took part or who declined
  • No subgroup small enough to identify anybody

Democrez

Answers without people

The same aggregate, plus the operational record needed to run a session. No view that connects a verification to a response exists on our side either.

  • Cannot look up how a participant answered
  • Cannot supply that to an institution on request
  • Cannot supply it to anybody, because it is not recorded

Before anybody answers

Consent has to be real,
or the data is worthless.

This is not only an ethical point. A batch that felt required to participate produces compliant answers, and compliant answers are indistinguishable from honest ones in an aggregate.

What we ask of you

Explain it, and mean the opt-out

Participants are told what the session is, what is collected, and that declining carries no consequence. We supply the wording. If declining would in practice cost a student something at your institution, tell us — that changes whether the session is worth running.

What a student can do

Sit it out, at any point

Before the session or partway through. A participant who stops answering is not recorded as having declined, is not listed anywhere, and their partial answers do not enter the aggregate.

What a student can ask for afterwards

Less than you might expect, and for a reason that works in their favour. There is no per-student record to request a copy of, and nothing linking their answers to them that could be deleted — the link was never created. What they can ask about is the verification, and that is covered by the same retention decision under review above.

Full detail sits on delete your data and in the privacy policy, both of which apply to session participants as well as app users.

Questions

Straight answers.

Can the college find out how a particular student answered?

No. Verification confirms a distinct person and is not carried into the response record, so there is no link between a student and their answers anywhere in the system. This is not a permission that could be granted on request — there is no record to hand over.

Can Democrez find out?

No, for the same reason. There is no internal view that connects a verification to a response, because the two are separated at the point of collection rather than filtered apart later.

What exactly do you do with the phone number?

Confirm that a participant is one distinct person, so the batch's split cannot be shifted by somebody answering repeatedly. It is never shown to the institution, never used for messages or marketing, and never added to any contact list.

How long is the phone number kept?

The retention period is in the privacy policy, which is under legal review, and we are not stating a figure here until that is settled. A number published on a marketing page has to match the number in the legal document, and quoting a provisional one would be worse than saying this.

Do you collect anything about the device or how students answer?

No. No device identifiers, no advertising IDs, no location, and nothing about typing, hesitation, time spent per option or changed answers. A session that recorded how somebody arrived at a choice would be recording a different thing entirely.

Can a student refuse without it being noticed?

Yes. There is no list of who participated or who declined, so nothing exists for a coordinator to compare against a register. A participant can also stop partway through, and their partial answers do not enter the aggregate.

Will students be contacted afterwards?

No. The session ends and nothing continues — no follow-up, no app prompt, no newsletter. There is deliberately no mechanism for it, which is a stronger guarantee than a policy against it.

Do these rules apply if we pay for the session?

Yes, without variation. Nothing on this page is a default that an institution can negotiate, and a request for per-student output is declined regardless of what the session cost.

Ask us the awkward questions.

If something on this page is not enough for your institution, we would rather hear it before a session than after.