Privacy statement

What we do with your answers

You've taken part in a conversation on ScoreStory, or you're about to. Below is exactly what happens with your answers: what we store, who gets to see it, and how long it's kept.

Who is who

The organisation that invited you — your employer, your school, the research agency — decides why this research exists and what happens with the results. We build and run the tool.

We are:

ScoreStory B.V.
Generaal Vetterstraat 82
1059 BW Amsterdam, the Netherlands
Dutch Chamber of Commerce (KvK) 42132130

For questions about your data: welcome@scorestory.eu.

ScoreStory always acts as a processor for this data, never as a controller. The organisation that invited you is the controller, and decides on what legal basis it processes your data.

What we store

Your answers. The score you give, and the text of the conversation — both your messages and the assistant's.

Speech, if you use it. Your recording is converted to text and then not kept. Only the text remains. The recording is sent once to the party that does the conversion; see the table below.

Background characteristics, if the organisation supplied them or asked for them during the conversation. Think team, education, age bracket. You can see which ones apply in the conversation itself.

Your name and email address, but only if the organisation invited you personally and the research isn't anonymous. With a shared link or anonymous research, we don't have these.

Technical data: the type of device you took part on (phone, tablet or computer — not which specific device), and start and end times.

What the AI extracts: an estimate of sentiment and the topics you raised, per message. Those estimates are aggregated into the themes the organisation sees in its overview.

What we don't do

We don't track you across other websites. There are no advertising or analytics trackers. We don't sell anything on, and we don't use your answers to train AI models.

Where it's stored

Everything runs on servers in the Netherlands, at Leaseweb, which we manage ourselves. The database, the queue and the file storage all run there; there's no external database service in between that could access your data.

Who we share it with

This is the complete list. Nothing goes to a party that isn't on it.

PartyWhat they seeWhereWhy
Anthropic (Claude)The text of your conversation. In non-anonymous research your name may appear in it.United StatesRuns the conversation and analyses the answers
ScalewayYour voice recording, onceFrance (EU)Converts speech to text
LettermintYour name and email addressEUSends the invitation email
LeasewebEverything that's hostedNetherlandsHosting

We have a data processing agreement with each of these parties: agreements on paper about what they may do with your data, how long they keep it and what happens in the event of an incident. For Anthropic, this also means your data leaves the EEA; that transfer is covered by the EU Standard Contractual Clauses.

Our error logging runs on our own server, not with an external service. Email addresses, ID numbers and long strings of digits are automatically redacted before being stored.

The login service (Hanko, EU) is there for the staff of the organisation who view the results. As a participant, you never log in anywhere.

That Anthropic is on this list is not good enough for us

Your conversation text goes to a US company. That was a deliberate choice — the model is good enough to hold a real conversation — but it's one we want to reverse.

Where we stand: for converting speech to text, we've already switched to Scaleway in France. For the conversation itself, the European option has been built and tested, but not yet switched on — that happens once conversation quality is on par. A connection to Mistral (France) is also available.

We won't put a date here that we can't keep. What we do promise: if this table changes, this document changes with it, and the date at the bottom says when.

Who can see it

Within the organisation that invited you: the people with access to the results. What they see depends on the type of research.

In non-anonymous research they can link your conversation to your name.

In anonymous research they can't. As soon as your conversation ends, the link between your answers and the invitation is physically broken — the reference is deleted from the database, not just hidden. After that, there's no path back to your name.

Two things you should know about this, because they're genuinely true:

The unlinking happens in a batch every 72 hours, not immediately after you finish. That's deliberate: if it happened immediately, someone could match "John just finished" with "a conversation just appeared" and undo the anonymity after all. Everyone unlinked in the same batch gets the same timestamp, so the order within that batch can't be reconstructed.

But: if you're the only one unlinked in a batch, you're still identifiable through that batch. That can happen in slow-running research. And anyone who filters the overview tightly enough — a short time window, or a combination of characteristics that fits very few people — can shrink a group down to a single conversation. We've built in protection against combinations of characteristics, but not against date-range filters, because the trend chart reads per day.

Anonymous here means: not identifiable through the system, not "mathematically impossible to identify".

Separately: whatever you type yourself in the conversation stays exactly as you typed it. If you mention your own name or a colleague's, it stays in the text the organisation reads.

How long it's kept

The organisation sets this itself, in two steps:

  1. After the configured period, name, email address and external participant ID are wiped — those fields are cleared, and this is logged. Your answers continue to exist, but without being tied to you.
  2. After the second period, the entire conversation is deleted: messages, analysis and your score.

If no period is configured, it's kept until the organisation deletes it or discards the research. Ask whoever invited you if you want to know what applies to your research.

What you can ask for

You may request what's stored about you, have it corrected, or have it deleted. We have a deletion procedure built into the system that wipes your name and email address and removes your conversation.

Direct your request to the organisation that invited you — they decide what happens with the research. If you can't resolve it with them, you can approach us directly via welcome@scorestory.eu.

If you've kept the link to your own conversation, it remains yours, even after anonymous research.


Last updated: 2 September 2026. If anything changes about the table of parties, the retention periods, or how anonymity works, we'll update this document and this date along with it.