Legal
Privacy Policy
DraftThis privacy policy explains how Voxly processes personal and technical data when you use accounts, lobbies, and live surveys.
Last updated: 17 August 2026
Voxly is a university project developed in a teaching and study context. This page is a draft for informational purposes only. It is not a final, legally reviewed privacy policy and does not claim completeness or legal compliance.
Controller
Details of the party responsible for this project are listed in the imprint. Because Voxly is a university project, the information there may still be incomplete or provisional.
Purpose of processing
We process data to operate live polls and lobbies, manage survey templates, support team workspaces, authenticate leaders, and let participants join sessions and submit answers.
Legal bases
Where the GDPR applies, we rely—as a draft—on the following bases for processing:
- Accounts, organizations, survey templates, and the lead function: Art. 6(1)(b) GDPR (use of the service).
- Guest join, display name, and answers: Art. 6(1)(f) GDPR (legitimate interest in operating the live poll).
- Strictly necessary cookies and localStorage (Clerk session, locale, sidebar, participant token, last used sign-in method): Art. 6(1)(f) GDPR. There is no tracking, so no consent is requested.
- Clerk CAPTCHA to protect sign-in: Art. 6(1)(f) GDPR (security of the service).
Categories of data
Account and organization data
If you sign in, authentication is handled by Clerk. Profile data such as name, email address, and profile image, as well as organization and membership information, may be synchronized into our application database (Convex).
Lobby and participation data
Display names are visible to participants in the lobby. A join code identifies the session. Optionally, participation can be linked to a user account so you can rejoin the same lobby later.
Survey content
We store survey titles, questions, options, answers, and result snapshots so leaders can run rounds and review outcomes.
Technical data
Clerk sets session cookies for authentication. The app may store a locale cookie, a sidebar preference cookie, a participant token in localStorage for reconnecting to a lobby, and a preference for the last used sign-in method. Access may also generate IP address, timestamp, and user-agent data in server or provider logs. We do not use first-party analytics tools.
Recipients and processors
Data is processed with the help of Clerk (authentication, sessions, and sign-in CAPTCHA), Convex Cloud (application database), Cloudflare (bot protection via Clerk), and—if you choose them—OAuth providers such as Google or GitHub via Clerk. There is no separate first-party analytics provider.
Privacy notices of these providers:
International transfers
Clerk, Convex Cloud, optional Google or GitHub (OAuth), and Cloudflare (Clerk CAPTCHA) may transfer personal data to the United States or other third countries. Where required, these transfers rely on adequacy decisions (such as the EU-US Data Privacy Framework) or the European Commission’s standard contractual clauses.
Hosting and logs
The Next.js frontend is provided on a Docker server operated by the project. Application data is stored in Convex Cloud, and authentication is handled by Clerk. IP address, timestamp, and user-agent data may appear in server or provider logs. There is no first-party analytics.
Anonymous mode
When anonymous mode is enabled for a survey round, the following principles apply:
- Display names remain visible in the lobby so participants can see who joined.
- Results shown to the survey lead do not disclose real display names or user identifiers. Neutral labels are used instead (for example “Anonymous Apple”).
- Stored result rows are not linked to a user identifier.
- Answer content may be retained, but without lasting attribution to a name or user account in the results.
- While a survey is in progress, a temporary technical reference is kept so answers can be saved and edited. After the round ends, that reference is removed from stored results.
- If anonymous mode is not enabled, answers may be shown to the survey lead together with the respective display name.
- While a survey is active, responses may be changed via the existing browser session. In anonymous mode, this does not create a lasting identity link in the stored results.
Retention
Where possible, the following periods currently apply. They may change as the university project evolves:
- Live answers are deleted when a survey round ends.
- Result snapshots remain stored with the lobby even after the session is ended (finished status, no full deletion).
- Participant records, including display names, remain stored with the lobby.
- Survey templates are kept until the lead deletes them.
- Accounts remain with Clerk until the account is deleted. Convex then performs a soft delete: profile fields are cleared, and the user row is kept with a deletion timestamp.
- The locale cookie is a session cookie and is removed when the browser is closed.
- The sidebar cookie is stored for 7 days.
- The participant token and last used sign-in method remain in localStorage until you leave the lobby, the session ends, or you clear the data in your browser.
Your rights
Where the GDPR applies, you may in particular have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW).
You can submit requests informally using the contact details in the imprint. Identity verification may be required. Because this is a university project draft, there are no fixed deadlines and no ticket process yet.
Changes
This privacy policy may be updated as Voxly develops. The version published on this page is the current draft.