Security & privacy
Interviews and product sessions are sensitive. This page sums up how your data is handled. The full, current statement is on the security page and in the privacy policy.
How your data is protected
- Encrypted in transit. Every connection uses HTTPS. Passwords are hashed, and integration tokens and other secrets are encrypted before they are stored. Databases are backed up daily.
- Sign-in and access. Single sign-on with SAML or OIDC, two-step sign-in, and workspace roles that decide who can see and change what.
- Consent first. Participants agree to being recorded before an interview starts, and can withdraw at any time. See the participant consent notice.
- Sharing you control. Share links can expire and can be revoked at any time. Webhooks are signed, so your systems can check they came from us.
- GDPR for everyone. Access, correction and deletion on request for every workspace, not only EU customers. A data processing agreement is available.
Where data is hosted
With established cloud infrastructure providers in the EU and the US: the app server and new files are in the EU (every workspace's data region), and older files are in the US. To move all of a workspace's data to one region, an admin can ask from Settings → Security → Data region. The request goes to our support team, who reply by email; nothing moves until they do.
Data settings
Admins set these in Settings → Security. Other members can see them.
Keep recordings
Recordings are kept until you delete them. Keep forever is the default. An admin can pick a period of 30 to 400 days instead. Then, every night, interview recordings and Library recordings (video and audio) older than that are deleted, together with their transcripts. Study reports, their themes and quotes, and clips stay as text; the session or Library item shows Recording deleted. Documents such as PDFs, slides and CSVs aren't affected. Live sessions are never touched.
When a period is set, Dry run shows what the next nightly clean-up would delete, without deleting anything.
Delete recordings after the study report is ready
This is off by default. When it's on, a study's interview recordings are deleted as soon as the study has finished and its study report is ready (and any missed ones the next night). A study report generated while the study is still running doesn't delete anything. Transcripts stay, and so do quotes and clips in the study report, as text.
Each clean-up is written to the audit log with what it deleted (counts only), under Security. Deleted recordings and transcripts can't be brought back.
Remove personal details
- Transcripts (on unless you turn it off): email addresses, phone numbers and card numbers are replaced with
[email],[phone]and[card], and in study interviews the participant's name with[name]. It applies as transcripts are saved, and wherever transcripts are shown, Eva included, so transcripts saved before you turned it on are covered too. Other names (people or companies they mention) aren't detected. - CSV uploads: when a CSV is added to the Library, columns of email addresses and phone numbers are dropped.
Vendor reviews
We can complete your security questionnaire. Email it to us, and ask for a data processing agreement if you need one.
Contact
- Security questions, questionnaires and a data processing agreement: support@userevaluation.com
- Requests to access, correct or delete personal data: see the privacy policy.