Skip to content
Voxlyvoxly
Question typesFeaturesGet started

Legal

Privacy Policy

Draft

This privacy policy explains how Voxly processes personal and technical data when you use accounts, lobbies, and live surveys.

Last updated: 17 August 2026

Voxly is a university project developed in a teaching and study context. This page is a draft for informational purposes only. It is not a final, legally reviewed privacy policy and does not claim completeness or legal compliance.

Controller

Details of the party responsible for this project are listed in the imprint. Because Voxly is a university project, the information there may still be incomplete or provisional.

Purpose of processing

We process data to operate live polls and lobbies, manage survey templates, support team workspaces, authenticate leaders, and let participants join sessions and submit answers.

Legal bases

Where the GDPR applies, we rely—as a draft—on the following bases for processing:

  • Accounts, organizations, survey templates, and the lead function: Art. 6(1)(b) GDPR (use of the service).
  • Guest join, display name, and answers: Art. 6(1)(f) GDPR (legitimate interest in operating the live poll).
  • Strictly necessary cookies and localStorage (Clerk session, locale, sidebar, participant token, last used sign-in method): Art. 6(1)(f) GDPR. There is no tracking, so no consent is requested.
  • Clerk CAPTCHA to protect sign-in: Art. 6(1)(f) GDPR (security of the service).

Categories of data

Account and organization data

If you sign in, authentication is handled by Clerk. Profile data such as name, email address, and profile image, as well as organization and membership information, may be synchronized into our application database (Convex).

Lobby and participation data

Display names are visible to participants in the lobby. A join code identifies the session. Optionally, participation can be linked to a user account so you can rejoin the same lobby later.

Survey content

We store survey titles, questions, options, answers, and result snapshots so leaders can run rounds and review outcomes.

Technical data

Clerk sets session cookies for authentication. The app may store a locale cookie, a sidebar preference cookie, a participant token in localStorage for reconnecting to a lobby, and a preference for the last used sign-in method. Access may also generate IP address, timestamp, and user-agent data in server or provider logs. We do not use first-party analytics tools.

Recipients and processors

Data is processed with the help of Clerk (authentication, sessions, and sign-in CAPTCHA), Convex Cloud (application database), Cloudflare (bot protection via Clerk), and—if you choose them—OAuth providers such as Google or GitHub via Clerk. There is no separate first-party analytics provider.

Privacy notices of these providers:

  • Clerk
  • Convex
  • Google
  • GitHub
  • Cloudflare

International transfers

Clerk, Convex Cloud, optional Google or GitHub (OAuth), and Cloudflare (Clerk CAPTCHA) may transfer personal data to the United States or other third countries. Where required, these transfers rely on adequacy decisions (such as the EU-US Data Privacy Framework) or the European Commission’s standard contractual clauses.

Hosting and logs

The Next.js frontend is provided on a Docker server operated by the project. Application data is stored in Convex Cloud, and authentication is handled by Clerk. IP address, timestamp, and user-agent data may appear in server or provider logs. There is no first-party analytics.

Anonymous mode

When anonymous mode is enabled for a survey round, the following principles apply:

  • Display names remain visible in the lobby so participants can see who joined.
  • Results shown to the survey lead do not disclose real display names or user identifiers. Neutral labels are used instead (for example “Anonymous Apple”).
  • Stored result rows are not linked to a user identifier.
  • Answer content may be retained, but without lasting attribution to a name or user account in the results.
  • While a survey is in progress, a temporary technical reference is kept so answers can be saved and edited. After the round ends, that reference is removed from stored results.
  • If anonymous mode is not enabled, answers may be shown to the survey lead together with the respective display name.
  • While a survey is active, responses may be changed via the existing browser session. In anonymous mode, this does not create a lasting identity link in the stored results.

Retention

Where possible, the following periods currently apply. They may change as the university project evolves:

  • Live answers are deleted when a survey round ends.
  • Result snapshots remain stored with the lobby even after the session is ended (finished status, no full deletion).
  • Participant records, including display names, remain stored with the lobby.
  • Survey templates are kept until the lead deletes them.
  • Accounts remain with Clerk until the account is deleted. Convex then performs a soft delete: profile fields are cleared, and the user row is kept with a deletion timestamp.
  • The locale cookie is a session cookie and is removed when the browser is closed.
  • The sidebar cookie is stored for 7 days.
  • The participant token and last used sign-in method remain in localStorage until you leave the lobby, the session ends, or you clear the data in your browser.

Your rights

Where the GDPR applies, you may in particular have the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Lodge a complaint with a supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW).

You can submit requests informally using the contact details in the imprint. Identity verification may be required. Because this is a university project draft, there are no fixed deadlines and no ticket process yet.

Changes

This privacy policy may be updated as Voxly develops. The version published on this page is the current draft.

Back to homeGo to imprint
Voxly
Data protectionImprintAbout usContact
Voxlyvoxly© 2026 Voxly