Privacy Policy
Last updated: August 20, 2026
This policy explains what personal data Miqyas collects, why, and what happens to it — for five different groups of people, since Miqyas is used in five different ways. Read the section that applies to you.
Who is responsible for this policy
Miqyas ("Miqyas", "we", "us", "our") is, at the time of writing, a pre-company beta project operated by hhamad.net. We have not yet incorporated a separate legal entity for it. Until we do, hhamad.net is the controller responsible for the personal data described in this policy.
Postal address: [PLACEHOLDER: a postal address where legal correspondence can reach us]. Email: contact@miqyasdata.com.
We will update this section — and the effective date above — the moment this changes, for example once we incorporate a company. Who the controller is matters for how you exercise the rights described below, so we will not let it go stale.
Who this policy covers
Miqyas is a research data-collection platform: organizations ("customers") use it to design surveys, distribute them, and review the responses people submit. Personal data flows through Miqyas in five different ways, and this policy is organized around them — look for the section that applies to you:
- As a visitor to this website, browsing without an account.
- As a registered user — a researcher, study coordinator, or organization admin with a Miqyas account.
- As a field data collector — someone an organization has given a Miqyas collector account to gather survey responses in person, often on a mobile device using the ODK Collect app.
- As a survey respondent — someone who fills out a survey created by one of our customer organizations, via a public link or in person with a field collector.
- As someone who joins our pre-launch beta waiting list, an option offered on our homepage and after completing a survey.
If you visit our website
We do not run any third-party analytics, advertising, or marketing tracking on this website. There is no tracking pixel, no advertising network, and no behavioural profiling.
Like effectively every website, our hosting provider’s network handles standard connection information (such as your IP address and browser type) purely to deliver the page to you and keep the service secure from abuse. We do not use this information to identify or profile visitors.
The only personal information we ever ask a visitor to type in directly is an email address, and only for one purpose: joining our pre-launch beta waiting list, offered near the foot of our homepage and again after you complete a survey. See "If you join the beta waiting list" below.
If you use our contact page or email us, see "If you contact us" below.
If you have a Miqyas account (researchers and organizations)
If you sign up to use Miqyas on behalf of a research organization, we process:
- Your name and email address.
- Your password, stored as a one-way cryptographic hash — we never see or store your actual password.
- Which organization(s) you belong to, and your role within them.
- A profile image, if you choose to add one.
- Session information (see "Cookies and local storage" below) that keeps you signed in.
- Limited operational activity data (which action was taken, roughly how long it took) used only to run, secure, and troubleshoot the platform.
- The notifications we have sent you inside the app — what happened, when, the names it mentions, and whether you have read it. These are shown in your inbox and stay there until your account is deleted. They are never sent anywhere outside Miqyas: there is no email, push, or third-party notification service behind them.
About that operational activity data
To run and troubleshoot the platform, we collect a limited amount of technical trace data — for example, which action was taken and roughly how long it took — tagged with your account identifier. This data is hosted and managed by Miqyas itself, on our own EU infrastructure; it is not sent to any third-party analytics company. It only ever covers actions taken by signed-in staff and researcher accounts — it never includes anything about people filling out a survey.
If a member of our team acts on your account
A small number of Miqyas administrators can suspend an account, lift a suspension, and change what an account is allowed to do. A suspension blocks sign-in and ends any session that is already open. It does not delete anything you or your organization have created, and it can be reversed.
Whenever one of them takes such an action, we record who took it, which account it affected, what changed, the reason they gave, and when. We keep that record so that a decision affecting you can be explained and, if necessary, justified — including to you. The reason is written by our staff for our own accountability: it is not shown to the person whose account was acted on, and it is never included in any notification we send.
An administrator can also see where your account is currently signed in — the approximate device and the network address of each open session — and end any of those sessions, which signs that device out. Because that view discloses your addresses and devices to a member of our staff, opening it is itself recorded, in the same record and for the same 36 months: who looked, at whose account, and when. The list is never shown as a side effect of an administrator simply opening your account page; it appears only when one of them deliberately asks for it, so that each entry corresponds to a decision someone actually made.
An administrator can correct the details held on your account — your display name, your email address, and the country recorded against it — for example when an address was mistyped when the account was created. When one does, the record described above keeps the value that was replaced: your previous name or your previous email address is retained, for the same 36 months, as part of the record of what changed. If your email address is changed by our staff, we send a notice to both the old address and the new one, so that a change you did not ask for reaches you at an address you still hold. An administrator can also mark an address as verified, which is recorded in the same way.
An administrator can add your account to one of our customer organizations, remove it from one, or change the role you hold inside it. Being removed from an organization ends your access to that organization’s work; it does not suspend your account and does not sign you out, and you are told in the app when it happens.
If you hold a field-collector account, an administrator can also see, on one screen, the areas you have declared yourself available for, the organizations that have engaged you, the devices holding collection credentials for your work, and any organizations you have asked not to be contacted by. That is not new information about you — it is what your own collector portal already shows you, and what the sections below already describe — but it is now visible to our staff as well, which is why we say so here.
If your account is suspended, we tell you so when you try to sign in, rather than giving you a misleading message about your password. If your role changes, or a suspension on your account is lifted, you receive a notification in the app.
If you connect an AI assistant to your data
Miqyas lets you connect an external AI assistant — Claude, ChatGPT, LM Studio, or any other client that speaks the same protocol — so you can ask questions about your own survey data in plain language. You start from the assistant, it sends you to Miqyas, you sign in and approve it on a screen that names it, and you are sent back. No password, key, or token is ever created for you to copy, and none is ever shown to you or held by you. This is entirely optional, off by default for every organization, and only an organization owner or administrator can switch it on.
Before you can approve one, the assistant introduces itself to us and we store the name and web address it reports about itself. We do not verify either — anyone can register an assistant under any name — which is why the approval screen shows you what it claims to be and says plainly that we have not checked it. Alongside that we keep the date you approved it and the date it was last used, so you can recognise it later on your connections page.
Miqyas does not run, host, or call any AI model. Your assistant runs on your side and calls us; we only answer. That means we add no AI sub-processor and make no transfer to one — but it also means the assistant you choose, wherever it runs and whatever it does with what it receives, is your responsibility and outside our control. Before connecting one, satisfy yourself that sending your organization’s research results to it is something you and your organization are entitled to do.
A connection can read exactly what you can already read in that organization, and nothing more. It sees the same surveys, is bound by the same regional restrictions, and stops working by itself the moment you leave the organization or lose access to analytics — no one has to revoke it. It cannot change anything, and it cannot reach another organization’s data.
What it returns is aggregated results — counts, averages, totals grouped by a question’s answers — never individual responses, never free-text answers, and never anything identifying a respondent. Please note that aggregated is not the same as anonymous: a result computed from few enough people can still say something about them, and the "hide small groups" setting available on charts is a presentation option, not a privacy or anonymisation control. We do not present these results as anonymised or de-identified data, and neither should you.
We keep a record of every connection’s use — who used it, when, which capability, which survey, and the names of the questions involved. That record never contains the values you filtered by, because a filter value can itself be someone’s answer. You can read the full history of your own connections at any time on your connections page, and your organization’s owners and administrators can read the whole organization’s.
Three separate retention periods apply. Access records are kept for 12 months and then deleted automatically. The saved request behind a result link is kept for 30 days and then deleted — a shorter window, because unlike the access record it does contain the values you filtered by. A connection itself lasts until you withdraw it, or lapses on its own if it goes unused for a long time. If your account is deleted, your connections and any saved requests go with it, and your name is removed from the access records; the entries themselves remain, under a randomly-derived reference that identifies nobody, because they record data leaving the platform and that record has to survive.
You can withdraw any connection instantly from your connections page, and an owner or administrator can withdraw any connection in the organization or turn assistant access off entirely. A withdrawn connection is refused the very next time it is used — not when some token happens to expire — and withdrawing also clears your approval, so connecting that assistant again asks you afresh rather than resuming quietly.
If you are a field data collector
Some organizations gather responses in person, through trained field collectors, instead of or alongside public web links. If an organization has given you a Miqyas collector account, we process your name and email address, your password (stored only as a one-way hash, as above), the country you have been assigned to collect in, the surveys you have been engaged to collect, the fee terms the organization agreed with you for that work (a rate per accepted submission, its currency, and any deadline), and basic records of those engagements and when your device was last active — used to run the collection service and keep it secure. The fee terms are set and used by the organization that engaged you; we store and display them on its behalf.
When you gather a response, that response is labelled with your name and account so the organization can see who collected it. This attribution is recorded once, at the time of collection, and is kept alongside the response for as long as the organization keeps the response itself; because it records who collected the data at that moment, it is not erased if your account is later renamed or deleted. A collector account is a distinct kind of account — it is not an organization-member account and cannot see the researcher application.
When the organization accepts a response you collected, we record the fee it owes you for that response against your collector account, building a running record — in the currency agreed for the engagement — of what you have earned. This financial record is permanent: individual entries are never edited or removed, only corrected by adding a further entry, so your balance and its history are retained indefinitely as part of our financial records. When a payment is made to you, we record it against the same account: the amount, the method used (cash, for now), the date it physically changed hands, the receipt or voucher number identifying it, and which of our administrators recorded it. We keep the receipt number so that the same payment cannot be recorded twice; a payment recorded in error is corrected by recording a reversal, never by deleting it. Each earning is also linked to the survey it came from, so you can see which work produced which amount. This information is stored on our own EU infrastructure and is not shared with any advertiser or data broker.
Your collector account also has an in-app inbox. We write a notification to it when an organization offers you work on a survey, when it ends one of your engagements, and when submissions you collected for a survey are approved or rejected — the last of these tells you how many, not which ones. These notifications stay in your inbox until your account is deleted, and are shown only inside Miqyas — we do not email, text, or push them to you, and no third-party notification service is involved.
If you make yourself available for work as a collector
You can tell Miqyas which administrative areas you are able to collect data in — a governorate, a district, or any mix of them — and turn on a switch that makes you findable by organizations searching for collectors in those areas. Both are entirely your choice. The areas you declare are personal data about you, and nothing about you is searchable until you turn that switch on. You can turn it off, or change or remove your declared areas, at any time; doing so stops you appearing in future searches immediately, and never affects work you have already agreed to.
While the switch is on, an organization searching an area you have declared is shown that someone available covers it, together with a summary of your track record on the platform — a band rather than a figure, such as "high approval" or "experienced" — and a code name that is meaningless outside that one organization's own results. It is not shown your name, your photograph, your email address, your other declared areas, or which organizations you have worked for. Each organization sees a different code name for you, so two organizations cannot compare notes to work out that they are looking at the same person.
Your name and photograph become visible to a particular organization only when you accept an offer of work from it. Declining an offer, letting one expire, or having one withdrawn discloses nothing: in each of those cases the organization learns only that the offer ended. Your email address is never shown to an organization, in any state, however the relationship began.
The track record shown alongside your code name is drawn from your work across the whole platform, not only from the organization looking at it. It is based on decisions people actually made about your submissions — automatic acceptances are counted as work delivered but are not treated as anyone's judgement of it — and an approval rate is published only once more than one organization has assessed your work, so that no single organization's review habits define how you appear to everyone else.
When you decline an offer you may also tell us that the organization should not contact you again. We then keep a record that they may not reach you, which hides you from that organization's searches and prevents it offering you work. The organization is not told that you did this, and it does not affect any engagement already running with them. You can lift it at any time from your portal.
We keep a record of every collector search an organization runs — which organization, which member of it, the area searched (including the outline if they drew one on a map), how many collectors matched, and when. We do this to detect and investigate anyone attempting to map out collectors area by area, which is a real risk of making people findable at all. These records are readable only by our administrators, are never shown to any organization, and are deleted after 12 months.
If you are a survey respondent
If you are filling out a survey created by a Miqyas customer organization, that organization is the controller of your responses — they decide what to ask and why. Look to their own communications, and any privacy notice shown on the survey itself, for that context. What follows describes the structural guarantees Miqyas itself builds into every survey, regardless of which organization created it.
Every survey is set to one of two modes by the organization that created it, and the mode is disclosed to you before you answer:
- Anonymous (the default) — we do not store your name, device identifier, or any session/browser fingerprint alongside your response, not as a setting that could be switched off but structurally: the fields that would carry that information are stripped before your response is even saved. Given full access to every database behind Miqyas, there is no way to link a stored anonymous response back to a specific person.
- Identified — the organization has a specific reason to know who responded (for example, to follow up with participants). You are always told plainly, before you answer, when a survey works this way, and the organization must provide its own privacy notice before we let them publish it.
Some surveys show you records from an existing list
A small number of surveys ask a question by presenting a list the organization has already built up — for example, "which household is this a follow-up for?" drawn from an earlier registration survey. Answering that kind of question means the list of records (for instance, other households' names) is delivered to your device so you can pick from it — visible to anyone who opens that survey's link, not only to you. The organization that built the list is its controller, exactly as with any other survey content they configure; Miqyas stores and delivers it on their behalf, in the same region as the rest of that study's data (see "What we collect on every survey" below), and reaches you only through the survey link itself.
What we collect on every survey, regardless of mode
We ask you to self-declare your country at the start (we never infer it from your IP address). Depending on your answer, we may ask for your explicit consent — to your response being stored outside your own region, or to providing a sensitive category of information the survey has declared it collects. If your declared country is one we have determined we cannot lawfully accept responses from, we tell you plainly and do not collect anything.
Your response is stored in one specific region (for example, the European Union), decided by the organization before the survey opens and never changed afterwards. It is technically unreachable from any other region.
Some responses are gathered in person by a field collector using the ODK Collect mobile app rather than a web link. In that case your answers are held on the collector’s own device — the app is built to keep working without a connection — until the device is online and sends them to us, and the device and app also transmit the basic technical information needed to deliver the survey and receive your response. While your answers are on the device they are under the control of the organization running the survey and its collector, who is responsible for telling you, in person, how your data will be used; once we receive them, they are stored under exactly the same regional and anonymity guarantees described above.
To protect the integrity of survey data against automated and abusive submissions, we apply lightweight automated checks to responses submitted through public links: how long the response took to complete (measured on our own servers), whether the browser identifies itself as automated, and a hidden field that only automated form-fillers tend to fill in. These checks produce internal, advisory quality flags visible only to the research organization reviewing the responses — they never change, reject, or discard a response, and they involve no new third party. We do not store your IP address, a device fingerprint, or any similar identifier alongside your response for this purpose.
Every survey page offers you a way to report a problem with it — a confusing question, something displaying incorrectly, or a survey asking for information its privacy notice did not declare. What you write there is free text, so it can contain anything you choose to put in it, including details about yourself. Until now those reports were only written to our application log and were, in practice, lost. They are now kept as a record our own staff work through: we store the reason you selected, what you wrote, and which survey and organization it concerns, for 36 months and then delete it. We do not store your name, your IP address, or a link to the answers you submitted — nothing connects a report to a response, including for us. Reporting a problem is always optional, and it never affects the response you submit.
We do not run any third-party analytics or tracking on the survey-filling experience.
If you join the beta waiting list
On our homepage, and again after you complete a survey, we may offer you a place on the waiting list for the beta of our own platform — an account of your own, surveys you take part in yourself, and rewards for completing them. Joining is always optional; if you were offered it after a survey, declining does not affect the response you just submitted.
If you join, we store your email address, the interface language you were using, the day you joined — the day only, never the time — and which of those two pages you joined from. We do not store the survey you had just answered, the organization that ran it, or your IP address. No field in our systems could hold that link, so a signup cannot be traced back to a response, including by us.
Signups sit in the same EU database (Frankfurt, Germany) as the rest of our infrastructure, so no new sub-processor is involved. We will use your address for one thing only: a single invitation when the beta opens. Before it goes out, we will tell you plainly what a survey owner would be able to see about you as a registered respondent. You can leave the list at any time by emailing contact@miqyasdata.com.
Why we process this data, and our legal basis
- Providing the platform to registered users and their organizations — performance of a contract (Art. 6(1)(b) GDPR).
- Recording and displaying survey responses on behalf of a customer organization — as their data processor, under their instructions (Art. 28 GDPR); the organization’s own legal basis with their respondents governs the collection itself.
- Recording what a field collector has earned, their running balance, and any payments made to them — to carry out the payment arrangement for their collection work (Art. 6(1)(b) GDPR) and to meet our accounting and record-keeping obligations (Art. 6(1)(c) GDPR).
- Letting you connect an external AI assistant to your own organization’s analytics, and recording what it read — performance of a contract for the feature itself (Art. 6(1)(b) GDPR), and our legitimate interest in keeping an auditable record of data leaving the platform (Art. 6(1)(f) GDPR).
- Keeping the platform secure, preventing abuse, and diagnosing problems — legitimate interest (Art. 6(1)(f) GDPR).
- Responding to a message you send us — performance of a contract or our legitimate interest in dealing with correspondence (Art. 6(1)(b)/(f) GDPR).
- Special-category data a survey has declared it collects (for example, health information) — your explicit consent, collected before you answer (Art. 9(2)(a) GDPR).
- Storing a response outside your own region, once you have told us where you are — your explicit consent, given at the point of collection (Art. 49(1)(a) GDPR).
- Sending you a single invitation once the beta opens, if you asked to join our waiting list — your explicit consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
Who we share data with, and where it lives
We keep the list of parties who can access personal data through Miqyas short:
- Fly.io — our hosting provider. Our EU infrastructure, including the database and file storage (Tigris), runs in Frankfurt, Germany. Fly.io processes data on our behalf as a hosting sub-processor.
- ODK Central — the open-source survey engine each region runs. This is software we operate ourselves on our own EU infrastructure, not a separate company with access to your data.
- MapTiler AG (Switzerland) — our map-tile provider. When a page shows a map — the location picker while answering a survey, the map view of a submitted answer, or a map chart on an analytics dashboard — your browser requests map tiles directly from MapTiler, which necessarily receives your IP address in order to serve them. We use MapTiler only to display maps; the coordinates you record are stored on our own EU infrastructure and are not sent to MapTiler. MapTiler acts as a sub-processor under a data processing agreement, and Switzerland is recognised by the EU as providing an adequate level of data protection.
- Scaleway SAS (France) — our transactional email provider. We use it for one purpose only: sending account emails that you or an administrator have asked for, such as a password-reset link. It receives the recipient’s email address and the content of that one message, and processes both in Scaleway’s Paris region (fr-par), inside the EU. Scaleway acts as a sub-processor under a data processing agreement. We send no marketing email through it, and open- and click-tracking are switched off: an account-recovery email from us contains no tracking pixel and no rewritten links.
- Our own telemetry system — also self-hosted on our EU infrastructure, and not shared with any third party (see above).
- An AI assistant you choose to connect yourself — and only if you do. This one is not on the list in the same sense as the others: it is not our sub-processor, we have no agreement with it, and we neither run nor call it. If a registered user connects one, aggregated results from their own organization go to it at their instruction and under their responsibility. Nothing reaches it unless an owner or administrator has switched the feature on and a user has created a connection. See "If you connect an AI assistant to your data" above.
What we do not do
We do not sell personal data, and we do not share it with advertisers or data brokers. Beyond what is listed above, we only disclose personal data if required by law, or to protect the rights, property, or safety of Miqyas, our users, or the public.
Cookies and local storage
We use one cookie that is strictly necessary for the service to work: miqyas.session_token, which keeps you signed in after you log in. It is not used for advertising or tracking, and — because it is strictly necessary — it does not require a consent banner under EU cookie rules.
Your interface language and light/dark theme preference are stored in your browser’s local storage, not in a cookie. That information stays on your device and is never sent to us.
If you are filling out a survey, your in-progress answers are saved on your own device, in your browser’s storage, as you go — so you can close the page and continue later from the same device. This draft — your answers, the country you selected, and any files you have attached — stays on your device and is never sent to us before you submit. It is deleted automatically when you submit the survey, when you choose to start over, and in any case after 7 days.
When a survey is set to accept only one response per person, we place a small marker in your browser’s storage after you submit, so that the same browser cannot be used to send a second response. This marker records only that a response was submitted — never who you are, and no identifier or device fingerprint — and it never leaves your device. Clearing your browser’s storage or using a different browser removes it.
We do not use any analytics, advertising, or third-party tracking cookies today. If that ever changes, we will update this policy first and ask for your consent where the law requires it.
How long we keep data
- Account data: for as long as you or your organization have an active account, plus a limited period afterwards for legitimate administrative and legal purposes.
- Survey response data: for as long as the customer organization instructs us to keep it — as the controller of their own study’s data, they control its retention period.
- Field-collector attribution — which collector gathered a response — is kept together with that response, for as long as the response itself is kept, as part of the research record (and so may outlast the collector’s own account).
- Financial records — a field collector’s earnings, running balance, and the payments made to them (amount, method, date, receipt number, and who recorded it) — are kept as part of our accounting records and retained indefinitely: the ledger that holds them is permanent, and an entry is corrected only by adding a further entry, never by deletion.
- A collector’s declared operating areas and availability switch: for as long as the collector keeps them; removing an area or turning availability off takes effect immediately.
- Records of collector searches run by organizations: 12 months, then deleted. Readable only by our administrators and never shown to any organization.
- Records of administrative actions taken on an account — who acted, which account was affected, what changed, and the reason given. Where the action corrected an account holder’s details, this includes the value that was replaced: their former name or former email address. It also includes a record of each time an administrator viewed where an account is signed in. 36 months, then deleted.
- Problem reports submitted from a survey page, and the record of how our staff dealt with them: 36 months, then deleted — but only once the report has been closed. One still open past that point is kept rather than deleted, because destroying an unresolved problem destroys the evidence that it went unresolved.
- Records of what a connected AI assistant read: 12 months, then deleted automatically.
- The saved request behind an assistant’s result link: 30 days, then deleted. Deliberately shorter than the access record above, because this one does contain the values a query filtered by.
- Assistant connections: for as long as you keep them. Withdrawing one takes effect on its very next use, a connection left unused for a long time lapses on its own, and deleting your account deletes all of yours along with any saved requests.
- Messages sent through our contact page: for as long as needed to handle your enquiry, and not usually longer than 24 months.
- In-app notifications: kept in your inbox for as long as your account exists, and deleted with it. Marking one as read does not remove it; there is no separate retention period.
- Beta waiting list signups: kept until the beta launches and the one invitation is sent, or until you ask to be removed, whichever comes first.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion ("right to be forgotten"), subject to any legal reason we may need to keep it.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent — this does not affect processing that already happened.
- Lodge a complaint with a data protection supervisory authority.
How to exercise your rights
If you are a survey respondent, please contact the organization that ran the survey first — they are the controller of your responses and best placed to act on your request. We will support them in doing so.
For anything else, contact us at contact@miqyasdata.com and we will respond as quickly as we can.
Supervisory authority
You can lodge a complaint with the data protection supervisory authority of the German state (Land) where we are based — [PLACEHOLDER: name of the relevant Landesdatenschutzbehörde once our operating address is finalized] — or the authority in your own country of residence.
Children
Miqyas is intended for use by adults working on or participating in research studies. We do not knowingly collect personal data from children, and if we learn that we have, we will delete it.
Changes to this policy
We review this policy whenever something changes about what personal data we collect, process, store, or share — a new sub-processor, a new feature that touches personal data, a new hosting region — and update the date at the top when we do. We are currently a small, fast-moving beta project, so expect this page to change more often than a mature company’s would; we would rather keep it accurate than stale.
Contact us
Questions about this policy or your data: contact@miqyasdata.com, or use our contact page.