Legal

Privacy Policy

Last updated: May 2026

Field Read ("Field Read," "we," "us," or "our") is a qualitative feedback platform operated by [Company Legal Name], [registered address]. This Privacy Policy explains what personal data we collect, why we collect it, and what rights you have over it.

We serve two distinct groups of people, and this policy treats them separately:


1. Data We Collect

Platform Users

When you create an account or use the platform, we collect:

Respondents

When someone submits a response to a Question:

Respondents do not create accounts. We do not attempt to re-identify respondents beyond the metadata above.


2. How We Use Your Data

PurposeLegal basis (EU/UK)Legal basis (US / other)
Providing the platform and its featuresContract performanceNecessary to provide the service
AI report generation and chat (on demand)Contract performanceNecessary to provide the service
Fraud prevention and rate limitingLegitimate interestLegitimate interest
Product analytics and improvementLegitimate interestLegitimate interest
Transactional emailContract performanceNecessary to provide the service
Compliance with legal obligationsLegal obligationLegal obligation

We do not sell personal data to third parties. We do not use personal data for advertising targeting.


3. AI Processing

Field Read uses AI to generate reports and power conversational chat features. Here is exactly what happens:

What data is sent to the AI: When you trigger a report or send a chat message, we send the relevant response text, the original Question and Prompt text, and contextual metadata (e.g., response count, date range) to an AI model. We do not send your account credentials, billing data, or data from unrelated Questions.

Which AI provider we use: We currently use Amazon Web Services (AWS) Bedrock, running models including Claude Sonnet and Claude Haiku from Anthropic. AWS Bedrock processes data in accordance with AWS's standard data protection commitments.

AI training: By default, AWS Bedrock does not use customer inputs or outputs to train or improve foundation models. Your response data and question data are not used to train AI models. If we ever add a non-Bedrock AI provider, we will update this policy and notify users before that change takes effect.

Human control: AI report generation is always user-initiated. No report is generated automatically. You click "Generate Report" — we do not run analysis in the background without your action.


4. Workspace Data Sharing

If you are a member of a workspace, be aware of the following:

If you are a Guest seat user, your ability to see other members' Questions is determined by your Workspace Owner, not by Field Read.


5. Sub-processors

We use the following third-party service providers to operate the platform. Each has been assessed for appropriate data protection commitments.

ProviderPurposeData processed
Amazon Web Services (Bedrock)AI model inferenceQuestion text, response text
VercelHosting and CDNAll platform traffic, request logs
Prisma Accelerate / NeonDatabaseAll platform data at rest
Upstash RedisRate limiting, sliding-window countersPer-user request timestamps (no content)
MastraPersistent chat memoryChat history, associated question context
PostHogProduct analyticsUsage events, anonymized user IDs
MailgunTransactional emailEmail address, email content
StripePayment processingBilling data (card details processed by Stripe directly)
Google reCAPTCHA v3Bot protection on response submissionDevice signals on the /q/[id] respondent page
GoogleOAuth authenticationPublic profile data when you choose Google sign-in
Google Tag Manager / AnalyticsMarketing site analyticsAnonymized usage events on marketing pages (consent-gated)

We review sub-processor data protection commitments periodically. If we add or change a sub-processor that materially affects how your data is handled, we will notify platform users by email and update this list.


6. Data Retention

Data typeRetention period
Account dataDuration of active account + 90 days after deletion
Question and Prompt dataDuration of active account + 90 days after deletion
Raw response submissionsDuration of active account + 90 days after deletion
AI-generated reportsDuration of active account + 90 days after deletion
AI chat history (Mastra)Deleted when the associated Question is deleted, or when the account is deleted (whichever comes first)
Exported files (PDF, CSV)Deleted 30 days after export generation
Billing records7 years (legal obligation)
Analytics events (PostHog)12 months
Rate-limiting counters (Upstash)Rolling 24-hour window; not persisted beyond that
Respondent submission metadata (IP, user-agent)90 days

When you delete your account, we begin the deletion process immediately. Most data is purged within the 90-day window above; billing records are retained only as required by law.


7. Respondents: Anonymous Submissions and Deletion Rights

Respondents submit responses without creating an account. Because submissions are not linked to a verified identity (name, email, or account), we cannot fulfill individual deletion requests for respondent submissions.

We cannot match a deletion request to a specific submission because we have no persistent identifier that connects a submission to the person who made it. Storing such an identifier would require collecting more personal data from respondents, which we have chosen not to do.

What we do instead:

If you submitted a response and have concerns about your data, you can contact us at [privacy@fieldread.ai]. We will do our best to address your request within the limits described above.


8. Your Rights

If you are in the EU or UK (GDPR / UK GDPR)

You have the right to:

If you are in California (CCPA/CPRA)

You have the right to:

To exercise any of these rights, contact us at [privacy@fieldread.ai]. We will respond within 30 days (GDPR) or 45 days (CCPA).


9. Automated Decision-Making

Field Read does not make solely automated decisions that produce legal or similarly significant effects about you.

The AI features on our platform — report generation and chat — are tools that help you analyze data you have collected. Report generation is always triggered manually by a platform user clicking "Generate Report." No analysis of your responses occurs automatically or without user action. Because a human decision to initiate processing is required, these features fall outside the scope of GDPR Article 22 (automated individual decision-making).


10. International Data Transfers

Field Read is operated from the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States, which does not have a data protection adequacy decision from the European Commission.

We rely on Standard Contractual Clauses (SCCs) as the legal mechanism for these transfers. SCCs are model contract terms approved by the European Commission that require us to protect your data to EU standards even when it is processed in the US. If you would like a copy of the applicable SCCs, contact us at [privacy@fieldread.ai].

We require our US-based sub-processors (see Section 5) to maintain equivalent transfer mechanisms where required.


11. Cookies and Tracking

We use cookies and similar tracking technologies on fieldread.ai. This includes tools operated by PostHog, Google Analytics, Google Tag Manager, and Google reCAPTCHA. Some of these tools run on pages accessible to respondents who do not have a Field Read account (including the /q/[id] response submission page).

For full details on what cookies we use, their purpose, retention periods, and how to manage your preferences, see our Cookie Policy.


12. FERPA Notice

Field Read is a general-purpose qualitative feedback platform. Field Read is not FERPA-compliant and is not designed for use with protected student education records as defined under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g).

If you are an educator, administrator, or institution subject to FERPA, you should not use Field Read to collect, store, or analyze responses that constitute student education records. We do not execute FERPA data handling agreements and do not offer the data governance controls required for FERPA-covered data.


13. Children's Privacy

Field Read is not directed at children under 13 years of age (or under 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has submitted data through our platform, contact us at [privacy@fieldread.ai] and we will delete it promptly.


14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify platform users by email and post the updated policy on this page with a revised "Last updated" date. Continued use of the platform after the effective date of a material change constitutes acceptance of the updated policy.


15. Contact

For privacy-related questions, requests, or complaints:

Email: [privacy@fieldread.ai]

Mailing address: [Company Legal Name], [Street Address], [City, State, ZIP]

For EU/UK users, our designated representative for GDPR purposes is [EU/UK Representative Name and Contact — to be appointed if required based on user volume].