Last updated: 28 March 2026
Chisquare is built for organisations that handle sensitive survey data — including data collected from vulnerable populations. We take data protection seriously and are committed to GDPR compliance.
Chisquare ("the Platform", "we", "us") is an AI-powered survey data analysis platform operated for NGOs, research firms, academic institutions, and policy units.
For the purposes of the UK and EU General Data Protection Regulation (GDPR), we act as a data controller for account and usage data, and as a data processor for survey datasets you upload.
Contact: privacy@chisquare.app
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the analysis service | Contract performance (6(1)(b)) |
| User authentication and account management | Contract performance (6(1)(b)) |
| Sending email confirmation and password reset | Contract performance (6(1)(b)) |
| AI-assisted analysis (Gemini API) | Contract performance (6(1)(b)) — see §6 |
| Security monitoring and fraud prevention | Legitimate interest (6(1)(f)) |
| Service improvement and bug fixing | Legitimate interest (6(1)(f)) |
| Legal compliance and responding to lawful requests | Legal obligation (6(1)(c)) |
We do not sell, rent, or share your data with third parties for marketing purposes.
All data is stored in Supabase, a PostgreSQL-based platform with the following protections:
We conduct periodic security reviews and apply security patches promptly.
Survey datasets may contain personal data about respondents (names, locations, demographic characteristics). As the uploader, you are the data controller for this data. We act as your processor under a Data Processing Agreement (DPA).
Your responsibilities as data controller:
We process your survey data only to provide the analysis service you requested. We do not use your survey data to train AI models or for any other purpose.
| Processor | Purpose | Data transferred | Location |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage | All platform data | US/EU (selectable) |
| Google LLC (Gemini API) | AI analysis planning, interpretation, report drafting | Column names, aggregated statistics, project context — NOT raw respondent data | US |
| Vercel Inc. (optional) | Frontend hosting | Request logs, IP addresses | US/EU (Edge) |
| Data type | Retention period |
|---|---|
| Account data | For the life of the account + 30 days after deletion request |
| Survey datasets (uploaded files) | Until project is deleted by the user, or account closure + 30 days |
| Analysis results and reports | Same as survey datasets |
| Security logs (IP, timestamps) | 90 days |
| Error logs | 30 days |
You can delete individual projects (and their associated data) at any time from the dashboard. Account deletion requests are processed within 30 days.
Under the UK and EU GDPR, you have the following rights regarding your personal data:
Right of access
Request a copy of all personal data we hold about you
Right to rectification
Correct inaccurate or incomplete personal data
Right to erasure
Request deletion of your account and associated data
Right to data portability
Receive your data in a machine-readable format (JSON/CSV)
Right to object
Object to processing based on legitimate interests
Right to restrict processing
Pause processing while a dispute is resolved
Right to withdraw consent
Where processing is based on consent, withdraw it at any time
Right to lodge a complaint
Contact your national data protection authority (e.g. ICO in the UK)
To exercise any of these rights, email privacy@chisquare.app. We will respond within 30 days.
We use the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| sb-auth-token | Supabase authentication session | Session / 1 week |
| sb-refresh-token | Supabase session refresh | 1 week |
We do not use tracking, analytics, or advertising cookies. No third-party cookies are set without your consent.
We may update this policy to reflect changes in our practices or legal requirements. When we do:
For any questions, concerns, or data subject requests related to this policy:
Email: privacy@chisquare.app
We respond to all data protection queries within 5 business days, and to formal GDPR requests within 30 calendar days.
If you are unsatisfied with our response, you have the right to lodge a complaint with your national supervisory authority. In the UK: Information Commissioner's Office (ICO).
© 2026 Chisquare · Home · Setup Guide