Privacy Policy
How Open Lab handles your personal data — in plain language. Last updated June 2026.
Last updated: June 2026
Open Lab is an online platform that helps researchers run studies and helps participants take part in them. This policy explains, in plain language, what personal data we handle, why, and what choices and rights you have.
The most important thing to understand is that we play two different roles. For your account, billing, payouts, product analytics, marketing and security, Open Lab decides how your data is used — we are the "controller". But for the study data a researcher collects from you when you take part in their study, the researcher (and/or their institution) is in charge, and we only store it on their behalf. Researchers can also choose to encrypt their study's responses with their own key — and where they do, not even Open Lab can read them.
This policy supersedes our previous version (last updated 11 September 2025).
The controller responsible for your personal data (in the senses described below) is:
Open Lab Online UG (haftungsbeschränkt) Authorised representative: Yury Shevchenko Friedrichstrasse 6b, 78464 Konstanz, Germany Email: info@open-lab.online Phone: +49 178 418 81 54
Our full legal notice (Impressum) is available at /legal-notice. We have not appointed a Data Protection Officer; for any privacy matter you can always reach us at info@open-lab.online.
Open Lab runs across a few related websites: app.open-lab.online (where participants manage their account and find studies), research.open-lab.online (where researchers build and manage studies), run.open-lab.online (where you take part in a study), and builder.open-lab.online (the study design tool).
We are the controller
for the data tied to being on the platform: your account and profile, billing and payouts, product analytics, marketing emails, and our security and audit logs. For all of that, this policy applies and we are responsible.
The researcher is the controller
for the data they collect from you inside their study — your responses, screening answers, and anything else their study asks of you. There, Open Lab is only the researcher's processor: we store the data on their instructions and nothing more. Researchers can enable end-to-end encryption for their study, in which case the responses are encrypted with the researcher's own key and Open Lab cannot read them. Where a researcher has not enabled this option, your responses are stored without that extra encryption — still protected by the safeguards described below (encryption in transit, secured EU storage, and strict access controls), but technically accessible to Open Lab in our role as the researcher's processor.
What this means for you as a participant: if you have a question about a specific study — what data it collects, why, how long it is kept, or how to have it deleted — please look at that study's consent form or contact the researcher directly. The researcher's contact details are shown in the study. We can help you reach them, but we cannot answer for the contents of a study we cannot see.
- Account basics: username, email address, and password (stored only as a secure hash — never in readable form).
- Optional profile: year of birth, country, native and other languages, gender, education, occupation, the devices you use, your weekly availability, timezone, and research interests. You choose whether to fill these in; they help match you to suitable studies.
- Consent records: which terms you accepted and when (with version), your confirmation that you are 18 or older, and your per-study consents.
- Participation data: the studies you've joined, your screening answers, and completion status.
- Payments: reward amounts, wallet balances, and payout requests. When you cash out, your name and email are sent to our payout provider (Tremendous) so they can deliver the payout to you.
- Messages and preferences: messages you exchange with researchers, your notifications, and your email preferences.
- Technical data: a salted hash of your IP address (we never store your raw IP), plus device, browser, and locale information.
- Your study responses: stored on the researcher's behalf. If the researcher has enabled end-to-end encryption for their study, these are encrypted with the researcher's key and we cannot read them; otherwise they are protected by our other security measures.
- Account and profile: name, email, password (hashed), affiliation, bio, research interests, and profile image.
- Sign-in identity: if you sign in with Google or ORCID, the user ID provided by that service.
- Security: your two-factor authentication secret (stored encrypted).
- Billing: your customer and subscription records held via Stripe.
- Payouts: your payout wallet.
- Consent and preferences: your consent records and your marketing preferences.
- Technical and audit data: a salted hash of your IP address, and audit-log entries recording key actions.
- Providing your account and running the service — your account, profile, messages, preferences and technical data. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- Storing the data a researcher collects when you take part in a study — study responses, screening answers, per-study consent. Legal basis: consent (Art. 6(1)(a)), and explicit consent or the scientific-research basis for any special-category data under Art. 9 — obtained by the researcher through the study's consent form.
- Processing payments, invoices and tax records — reward amounts, wallet balances, payout requests, billing records, and the name and email shared with our payout provider. Legal basis: contract and legal obligation (Art. 6(1)(b) and (c) GDPR).
- Sending marketing emails to researchers — email address and marketing preference. Legal basis: consent (explicit opt-in, which you can withdraw at any time; Art. 6(1)(a)).
- Sending study-match and follow-up emails to participants — email address, profile, participation data and opt-in preference. Legal basis: consent (your opt-in; Art. 6(1)(a)).
- Product analytics — usage events and device/browser/locale information. Legal basis: consent, only if you accept analytics cookies (Art. 6(1)(a)).
- Security, fraud prevention, audit logging and IP hashing — salted IP hash, audit-log entries and account activity. Legal basis: our legitimate interests in keeping the platform safe and accountable (Art. 6(1)(f)).
We do not make automated decisions that produce legal or similarly significant effects about you.
We work with a small set of trusted service providers ("sub-processors") who help us run the platform. Each handles only the data needed for their part, and only on our instructions:
- DigitalOcean — EU hosting and file storage (Frankfurt)
- Stripe — researcher billing and subscriptions
- Postmark — sending email
- Tremendous — delivering participant payouts
- Google and ORCID — researcher sign-in
- PostHog — EU-hosted product analytics (only with your consent)
We also share data with researchers where you take part in their study, and with authorities where the law requires it. We do not sell your personal data — to anyone, ever.
Your core data — the database and file storage — stays in the EU, hosted in Frankfurt, Germany. Some of the providers above are based in the United States. Where data reaches them, those transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, which are recognised safeguards under EU law.
- Study datasets collected in a study — Free plan: 12 months. Paid plan: 36 months by default. A researcher can set a different period for their own study, and free-plan data gets a 30-day warning before deletion.
- Accounts and profiles — kept until you delete them.
- Audit logs — 18 months.
- Consent records — kept for the life of your account, as proof that consent was given.
For study data specifically, the researcher may set a shorter or longer retention period — check that study's consent form. When data reaches the end of its retention period, we delete it.
Keeping your data safe is something we take seriously, in practice and not just on paper:
- Encryption in transit: everything travels over TLS/HTTPS.
- Optional end-to-end encryption of study data: researchers can encrypt their study's responses with their own key, so that not even Open Lab can read them.
- Hashed passwords: passwords are stored only as bcrypt hashes, never as readable text.
- Encrypted 2FA secrets: two-factor authentication secrets are stored encrypted.
- Hashed IP addresses: we never store your raw IP — only a salted hash.
- Short-lived file links: files are served through signed links that expire quickly.
- Access controls: role-based access control limits who can see what.
- Audit logging: important actions are logged so we can detect and investigate problems.
- Backups: backups are encrypted and tested.
Under the GDPR you have the following rights, and we've built tools so you can exercise most of them yourself:
- Access — see what data we hold about you.
- Portability — get a copy of your data in a portable format. Use "Download my data" in your account to export it as JSON.
- Rectification — correct your data by editing your profile.
- Erasure — have your data deleted. Use "Delete account"; as a participant you can also withdraw from a study and optionally delete its data.
- Restriction — ask us to limit how we use your data.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — at any time, without affecting what came before. You can withdraw from a study, use one-click unsubscribe in any marketing email, adjust your email preferences, or change Cookie settings.
For anything the in-app tools don't cover, email info@open-lab.online. We respond within one month.
If you have a concern we haven't resolved, you have the right to lodge a complaint with a supervisory authority. Our lead authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW), Stuttgart — the independent data-protection regulator for our region. You can also contact the authority where you live or work.
Remember: for data inside a specific study, the researcher is the controller, so direct erasure or access requests about study responses to the researcher (or use the in-app study-withdrawal tools).
Open Lab is for adults. You must be at least 18 years old to use the platform, and you confirm this when you sign up. We do not knowingly collect or process the personal data of children. If you believe a child has used the platform, please contact us at info@open-lab.online and we will take appropriate steps.
We may update this policy as the platform evolves or the law changes. We version our Terms and Privacy Policy, and when we make a material change, we'll ask you to re-accept the new version before you continue using the service. The "Last updated" date at the top always tells you which version is current.
For any privacy question, request, or concern:
Open Lab Online UG (haftungsbeschränkt) Friedrichstrasse 6b, 78464 Konstanz, Germany Email: info@open-lab.online Phone: +49 178 418 81 54
If you'd like to raise the matter with a regulator, you can contact the LfDI Baden-Württemberg (Stuttgart) or the data-protection authority where you live or work. For data collected inside a particular study, please contact the researcher named in that study, or consult its consent form.
Questions about your privacy?
We're happy to help with any request or concern.
Email info@open-lab.online