Privacy policy

Last updated: September 11, 2026

The privacy of your data, and it is your data, not ours, is a big deal to us. In this policy we lay out what data we collect and why, how it is handled, and your rights with respect to it. We never sell your data, and we never use research recordings for anything other than providing the service to the organization that made them.

This policy covers three kinds of people:

  • Researchers: the people and organizations that hold a LetsFindWhy account and use it to run interviews.
  • Respondents: the people who sign up for a study or take part in an interview. Respondents do not have LetsFindWhy accounts.
  • Visitors: anyone who reads this website.

If you are a respondent

If you were invited to an interview, LetsFindWhy is the video software the interview runs on. It is not the organization doing the research. That is whoever sent you the invitation, and we call them the researcher below.

The researcher decides what is recorded, what the recording is used for, how long it is kept, and who sees it. Under privacy laws such as the GDPR they are the "data controller" of your interview, and LetsFindWhy is their "data processor": we store and process your recording on their instructions and for no other purpose. Any consent form, information sheet, or privacy notice for the study comes from them, and they are the right people to ask about it, ideally before you join.

Here is what we hold about you as a respondent, and where it came from:

  • Sign-up details. If you filled in a "Sign Up for Study" form, we store the name, email address, phone number, time zone, language and country you entered, and your answers to the study's screening questions. If the researcher added you themselves, they entered your name and contact details on your behalf.
  • Your invitation. A personal join link, when it was sent, and whether you used it.
  • The interview itself. The display name and email address you gave on the join screen, and, when the session is recorded, your video, audio and any messages you send in the meeting chat. Recording is announced with an on-screen countdown and a red REC marker that stays visible for as long as it runs.
  • The transcript. A written transcript of who said what, produced automatically from the recording, and any AI-generated summaries, question matches or answers the researcher generates from it afterwards.
  • Technical data. Your IP address, browser and device details, and connection quality metrics, which we log to run the call and to keep the service secure.

Some interviews are run by an AI moderator rather than a person. In those interviews your audio is transcribed and sent to our AI providers in real time so the moderator can listen and reply. It is recorded and stored the same way a human-run interview is, and a person reviews it afterwards. See AI features below for exactly which providers are involved.

You can leave an interview at any time, and you do not have to answer a question you would rather not answer. If you want your recording or your sign-up details deleted, or want a copy of them, ask the researcher who invited you: they control that data and can delete it in LetsFindWhy themselves. If you cannot reach them, email us at [email protected] and we will pass your request on and help them act on it. Our own guide to joining an interview explains the whole process in plain language.

What we collect and why

Our guiding principle is to collect only what we need. In practice that means:

Identity and access

When you sign up for a LetsFindWhy account we ask for your email address and name, and we record the time zone, language and country you choose so we can show you times and text correctly. You can add a profile picture if you like. We use your email address to sign you in (we send sign-in links rather than requiring a password), to tell you about interviews you are invited to observe, and to send you essential information about your account.

We will never sell your personal information to third parties, and we will not use your name or company in marketing statements without your permission.

Billing information

If you subscribe to a paid plan you will be asked for your payment details and billing address. Card details are entered directly into Stripe, our payment processor, and never touch LetsFindWhy servers. We store a record of the subscription and its invoices, and we count the interview minutes your organization uses, because that is what the plan meters.

Research content

We store the content that you and your organization create or upload: projects, discussion guides, screeners, respondent lists and their sign-up details, session recordings, uploaded audio and video files, transcripts, bookmarks, and the summaries and chat threads our AI features produce from them. This is the work you use LetsFindWhy for, and we keep it as long as your organization's account is active or until you delete it. Where this content contains personal data about respondents, we process it on your behalf and on your instructions, as described in the section above.

Live interviews

During a session, video and audio flow between participants through our real-time media provider. When recording is on, every participant's audio and video is captured and saved to the organization that owns the session. When it is off, media passes through and is not retained. Chat messages sent in a meeting are stored with the session.

AI features

Several features send content to AI providers to do their work. Transcripts are produced by sending session audio to a speech-to-text provider. The AI moderator sends live audio and the transcript to a language model to decide what to say next, and its voice is synthesized by the same provider. Question matching, project summaries and "Ask AI" send transcript text to a language model. In every case the content is processed to provide the feature to your organization and for nothing else. These providers are listed under subprocessors below, and our contracts with them prohibit using your content for advertising or selling it.

Technical and security data

We log the IP address and browser used to sign in, and the time of each sign-in, to detect fraud and unauthorized access. You can see the devices signed in to your account under Settings and sign any of them out remotely. Sign-in sessions expire on their own after seven days. We also keep application logs, which include IP addresses and error details, for a limited time to diagnose problems.

Website analytics

We use Simple Analytics to count visits to this website and to see which features are used. It sets no cookies, uses no fingerprinting, and collects no personal data: it records page views and aggregated events such as "sign-up submitted", not who did them.

Cookies

We set only the first-party cookies our sign-in system needs to keep you signed in. We set no advertising or tracking cookies, and we load no third-party ad scripts. A few preferences, such as which camera and microphone you last used, are kept in your browser's local storage and never leave your device. If you block cookies, signing in will not work.

Correspondence

When you email us with a question or a support request, we keep that correspondence, including your email address, so we have a history to refer to if you get in touch again. If we contact you as a prospective customer, we hold your business contact details for that purpose; every such message carries an unsubscribe link, and once you use it we suppress your address and will not write again.

When we access or disclose your information

To provide the service. We use a small number of third-party subprocessors to run LetsFindWhy. They are listed below, together with what each one handles.

No LetsFindWhy human looks at your content except for limited purposes with your express permission, for example when an automated process fails partway through and needs a person to fix it, or when you ask us to help with a support case that requires looking at your account. These are rare, and when they happen we look for root-cause fixes so they do not recur.

To investigate abuse. Accessing an account to investigate potential misuse of the service is a measure of last resort. If we find LetsFindWhy being used to harass, deceive or harm people, we will take action, including notifying appropriate authorities where warranted.

Aggregated and de-identified data. We may aggregate or de-identify information collected through the service, for example the number of interviews run per month, and use that for any purpose, including analytics and marketing. It never identifies you or a respondent.

When required under applicable law. LetsFindWhy is a US company.

  • Requests for user data. Our policy is to not respond to government requests for user data unless we are compelled by legal process or in limited circumstances in the event of an emergency request. However, if US law enforcement authorities have the necessary warrant, criminal subpoena, or court order requiring us to disclose data, we must comply. Likewise, we will only respond to requests from government authorities outside the US if compelled by the US government through procedures outlined in a mutual legal assistance treaty or agreement. It is our policy to notify affected users before we disclose data unless we are legally prohibited from doing so, and except in some emergency cases.
  • Preservation requests. Similarly, our policy is to comply with requests to preserve data only if compelled by the US Federal Stored Communications Act, 18 U.S.C. Section 2703(f), or by a properly served US subpoena for civil matters. We do not disclose preserved data unless required by law or compelled by a court order that we choose not to appeal. Furthermore, unless we receive a proper warrant, court order, or subpoena before the required preservation period expires, we will destroy any preserved copies of customer data at the end of the preservation period.
  • If we are audited by a tax authority, we may be required to disclose billing-related information. If that happens, we will disclose only the minimum needed, such as billing addresses and tax exemption information.

Finally, if LetsFindWhy is acquired by or merges with another company, we will notify you before any of your personal information is transferred or becomes subject to a different privacy policy.

Subprocessors

These are the third parties that handle personal data on our behalf. Each processes only what its role requires.

  • Hetzner Online GmbH (Germany): hosts our servers and database.
  • Cloudflare, Inc.: serves the website, protects it from attacks, and stores recordings and uploaded media in its R2 object storage in Western Europe.
  • LiveKit, Inc.: routes the real-time video and audio of a live session between participants and records it.
  • Deepgram, Inc.: converts session audio into transcripts, live and after the fact.
  • OpenAI, L.L.C.: powers the AI moderator's understanding and voice, question matching, project summaries and "Ask AI".
  • Stripe, Inc.: processes payments and holds card details.
  • Mailgun Technologies, Inc.: delivers the email we send, including sign-in links and interview invitations.
  • Simple Analytics B.V. (Netherlands): cookieless website analytics.

Your rights with respect to your information

We apply the same data rights to everyone, regardless of where they live. Some of these rights include:

  • Right to know. You have the right to know what personal information is collected, used, shared or sold. This policy sets out the categories and specific data we collect and how they are used.
  • Right of access. You have the right to access the personal information we hold about you, and to information about how it is shared, stored, secured and processed.
  • Right to correction. You have the right to have your personal information corrected.
  • Right to erasure. You have the right to ask that your personal information be erased from our systems and, by extension, from our subprocessors, subject to certain limitations under applicable law. Some deletion requests will stop the service working for you, in which case the request may result in closing your account.
  • Right to complain. You have the right to complain about our handling of your personal information to the appropriate supervisory authority.
  • Right to restrict processing. You have the right to ask us to restrict how and why your personal information is used, including opting out of any sale of it. (Again: we have never sold personal data and never will.)
  • Right to object. You have the right, in certain situations, to object to how or why your personal information is processed.
  • Right to portability. You have the right to receive the personal information we hold about you in a usable form. Researchers can download their recordings and transcripts from within LetsFindWhy at any time.
  • Right not to be subject to automated decision-making. You have the right not to have a decision with legal or similarly significant effects on you made solely by automated means. LetsFindWhy makes no such decisions: the AI moderator asks questions and the screener records answers, but whether anyone is invited to an interview is decided by the researcher.
  • Right to non-discrimination. We will not charge you more, offer you less, or give you worse service because you exercised any of these rights.

Many of these rights can be exercised by signing in and updating your account. If you are a respondent, the researcher who invited you holds your data and can act on your request directly; see the respondent section above. We may need to verify your identity before responding, which at a minimum means confirming your name and email address. To exercise any of these rights, email [email protected].

If we deny a request you may have the right to appeal, and we will tell you how in our response. You also have the right to lodge a complaint with a supervisory authority. If you are in the EU or the UK, your national data protection authority can take a complaint or tell you more about your local privacy laws.

How we secure your data

All data is encrypted with TLS in transit between your browser and our servers, and between our servers and every subprocessor. Recordings and uploads are stored encrypted at rest. Access to production systems is limited to the people who operate the service. Sign-in is passwordless by default (email links and passkeys), which removes the most common way accounts get compromised.

If you believe you have found a security problem in LetsFindWhy, please email [email protected] and we will respond quickly.

What happens when you delete content

Recordings. Deleting a recording removes the video and its transcript immediately and permanently from the service. There is no undo. The underlying files are purged from storage within 30 days.

Respondents. Deleting a respondent from a study removes their sign-up details, screener answers and invitations immediately. Their recorded interviews, if any, remain with the session until the recording itself is deleted.

Projects and organizations. A deleted project or organization is held for 30 days so it can be restored if the deletion was a mistake, then purged along with everything in it.

Your account. Deleting your account closes it for good: signing in is blocked and your credentials are removed. Recordings and sessions shared with your team stay with their projects, because they belong to the organization, not to you.

Data retention

We keep your information for as long as needed for the purposes for which it was collected. Research content is kept for as long as your organization's account is active or until you delete it. Sign-in records are kept while your account is active. Billing records are kept for as long as tax law requires. Application logs are kept for a short period and then rotated. We may also retain information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Location of site and data

LetsFindWhy is hosted in the European Union: our servers and database run in Germany, and recordings are stored in Western Europe. Some of our subprocessors operate from the United States, and content sent to them (payment details to Stripe, email to Mailgun, audio and transcripts to Deepgram and OpenAI, media to LiveKit) is processed there. Where personal data leaves the EU or the UK we rely on the safeguards those providers offer, such as Standard Contractual Clauses, so that it keeps the protection EU and UK law give it. By using LetsFindWhy you consent to this processing.

Changes and questions

We may update this policy as needed to comply with relevant regulations and to reflect new practices. Whenever we make a significant change we will refresh the date at the top of this page and take any other appropriate steps to notify account holders.

Have any questions, comments, or concerns about this policy, your data, or your rights? Email us at [email protected] and we will be happy to help. Our Terms of Service cover the rest of the relationship.

Adapted from the Basecamp open-source policies, licensed under CC BY 4.0.