The locked box
We store your data and keep it safe, backed up, and available — but it stays locked. We can't open it.
Open Lab's end-to-end encryption keeps your participants' responses readable only by you — and the people you choose. Not even Open Lab can see inside. Here's how it works, in plain terms.
What "end-to-end encryption" means here
When encryption is on, your study responses are scrambled the moment they're collected and can only be unscrambled with your key. Open Lab stores the data for you — but to us, and to anyone without your key, it looks like meaningless characters.
We store your data and keep it safe, backed up, and available — but it stays locked. We can't open it.
Your key lives with you. It's the one thing that turns those scrambled characters back into readable responses.
Your vault and your key
Think of your vault as a personal keyring. It holds your keys, you unlock it when you sign in, and it does the unscrambling for you behind the scenes.
Your personal keyring
You unlock your vault when you sign in. How you unlock it depends on how you sign in to Open Lab:
When you set up encryption, we show you a one-time recovery code. It's your backup key — the way back in if you ever forget your password. We show it once, and we never keep a copy.
A password manager is ideal. Treat it like a spare key to your home.
Forgot your password? Your recovery code restores access to your encrypted data.
If you lose both your password and your recovery code, the data cannot be recovered — by anyone, including Open Lab. There's no back door. That's the trade-off for true privacy.
How a response gets protected
Four steps, all automatic. You and your participants don't do anything differently — it happens behind the scenes.
A participant sends in their responses, exactly as they always would.
The responses are locked with a one-time key as they're collected.
That one-time key is sealed so only your study's key can open it.
Everything is stored scrambled. Open your data and your unlocked vault un-scrambles it — no extra steps.
You don't manage keys or paste codes to read your data. Once your vault is unlocked for the session, everything you're allowed to see just reads normally.
Every study has its own lock
Each encrypted study gets its own key. So you can share one study with a collaborator without giving them access to any of your other studies.
Three studies, three separate locks. Hand someone the key to one and the others stay shut. Sharing one study never means sharing all of them.
What Open Lab can and can't see
Encryption hides the contents of your responses. To run the service, we still see some basic information about your study — and we'd rather say so plainly.
This is the whole point of turning encryption on.
This is true whether or not encryption is on.
Turning it on
You set up your vault one time for your account, then switch encryption on for any study you like.
Create your vault and save your recovery code somewhere safe.
Settings → SecurityOpen a study's encryption settings and pick Account encryption.
Study → Settings → EncryptionFrom then on, new responses for that study are encrypted — automatically.
Nothing else to doData collected before you turned encryption on keeps the protection it had when it was saved.
Prefer to hold your own key file? There's an advanced option to encrypt a study with a key you download and manage yourself. It works without a vault — but there's no recovery code, so if you lose that key file, the data can't be recovered. Most researchers should use the standard option above.
Short FAQ
Related concepts
Open Lab Onlineresearch.open-lab.onlineConcepts · How encryption works