Open Lab

Legal

Privacy Policy

How Open Lab handles your personal data — in plain language. Last updated June 2026.

For help, visit Support or check the documentation.
Last updated: June 2026

Open Lab is an online platform that helps researchers run studies and helps participants take part in them. This policy explains, in plain language, what personal data we handle, why, and what choices and rights you have.

The most important thing to understand is that we play two different roles. For your account, billing, payouts, product analytics, marketing and security, Open Lab decides how your data is used — we are the "controller". But for the study data a researcher collects from participants, the researcher (and/or their institution) is in charge, and we only store it on their behalf. By default a study's responses are end-to-end encrypted with the researcher's own key, so not even Open Lab can read them; researchers may opt a study out to server-side encryption (for pilots or testing), where we manage the keys.

This policy supersedes our previous version (last updated 11 September 2025).
The controller responsible for your personal data (in the senses described below) is:

Open Lab Online UG (haftungsbeschränkt)
Authorised representative: Yury Shevchenko
Friedrichstrasse 6b, 78464 Konstanz, Germany
Email: info@open-lab.online
Phone: +49 178 418 81 54

Our full legal notice (Impressum) is available at /legal-notice. We have not appointed a Data Protection Officer; for any privacy matter you can always reach us at info@open-lab.online.
Open Lab runs across a few related websites: app.open-lab.online (participants), research.open-lab.online (researchers), run.open-lab.online (taking part in a study), and builder.open-lab.online (the study design tool).

We are the controller for the data tied to being on the platform: your account and profile, billing and payouts, product analytics, marketing emails, and our security and audit logs.

The researcher is the controller for the data they collect inside their study — participants' responses, screening answers, and anything else the study asks. There, Open Lab is only the researcher's processor: we store the data on their instructions and nothing more. By default a study uses end-to-end encryption: responses are encrypted with the researcher's own key and Open Lab cannot read them; the researcher may also grant their project collaborators access to decrypt the study's data. For pilot studies, testing, or where they prefer it, researchers may opt a study out to server-side encryption — responses are encrypted with keys managed by Open Lab and protected by our other security measures, but are technically accessible to Open Lab as the researcher's processor.

As a researcher you are responsible for the lawful basis for your study data — typically participants' informed consent collected through your study's consent form — and for any required ethics approval. See our Data Processing Agreement for the details of that relationship.
  • Account and profile: name, email, password (hashed), affiliation, bio, research interests, and profile image.
  • Sign-in identity: if you sign in with Google or ORCID, the user ID provided by that service.
  • Security: your two-factor authentication secret (stored encrypted).
  • Billing: your customer and subscription records held via Stripe.
  • Payouts: your payout wallet.
  • Consent and preferences: your consent records and marketing preferences.
  • Technical and audit data: a salted hash of your IP address, and audit-log entries recording key actions.
  • Account basics: username, email, and password (stored only as a secure hash).
  • Optional profile: year of birth, country, languages, gender, education, occupation, devices, weekly availability, timezone, and research interests.
  • Consent records: terms accepted (with version and date), 18+ confirmation, and per-study consents.
  • Participation data: studies joined, screening answers, completion.
  • Payments: reward amounts, wallet balances, and payout requests (name and email shared with our payout provider, Tremendous).
  • Messages, notifications, and email preferences; technical data (a salted IP hash — never the raw IP — plus device/browser/locale info).
  • Study responses: stored on the researcher's behalf; by default end-to-end encrypted with the researcher's key (and unreadable by us), unless the researcher opts the study out to server-side encryption.
  • Providing your account and running the service — contract (Art. 6(1)(b) GDPR).
  • Storing the data a researcher collects in a study — consent (Art. 6(1)(a), and Art. 9 for special-category data), obtained by the researcher through the study's consent form.
  • Payments, invoices and tax records — contract and legal obligation (Art. 6(1)(b) and (c)).
  • Marketing emails to researchers — consent (explicit opt-in, withdrawable any time; Art. 6(1)(a)).
  • Study-match and follow-up emails to participants — consent/opt-in (Art. 6(1)(a)).
  • Product analytics — consent, only if you accept analytics cookies.
  • Security, fraud prevention, audit logging and IP hashing — our legitimate interests (Art. 6(1)(f)).
We use cookies in three categories: necessary (always on — sign-in, security, your session), functional (remember your choices), and analytics (help us improve the platform). Analytics run through PostHog, which is hosted in the EU, and only if you accept analytics cookies. You can change your choices any time via "Cookie settings"; see our Cookie Policy.
We work with a small set of trusted service providers ("sub-processors"), each handling only the data needed for their part and only on our instructions:
  • DigitalOcean — EU hosting and file storage (Frankfurt)
  • Stripe — researcher billing and subscriptions
  • Postmark — sending email
  • Tremendous — delivering participant payouts
  • Google and ORCID — researcher sign-in
  • PostHog — EU-hosted product analytics (only with your consent)

See our full sub-processor list for each provider's role, location, and transfer safeguards.

We also share data with researchers where a participant takes part in their study, and with authorities where the law requires it. We do not sell your personal data.
Your core data — the database and file storage — stays in the EU, hosted in Frankfurt, Germany. Some providers above are based in the United States; where data reaches them, those transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, recognised safeguards under EU law.
  • Study datasets — free plan 12 months; paid plan 36 months by default. A researcher can set a different period per study, and free-plan data gets a 30-day warning before deletion.
  • Accounts and profiles — kept until you delete them.
  • Audit logs — 18 months.
  • Consent records — kept for the life of your account, as proof that consent was given.
  • Encryption in transit: everything travels over TLS/HTTPS.
  • End-to-end encryption by default: a study's responses are encrypted with a key only the researcher — and collaborators they authorise — can unlock, so that not even Open Lab can read them. A one-time recovery code lets the researcher restore access if they forget their password; if both are lost, the data cannot be recovered. Researchers may opt a study out to server-side encryption (for pilots or testing), where Open Lab manages the keys. Other study data is protected by encryption in transit and at rest, access controls, and EU storage.
  • Hashed passwords (bcrypt) and encrypted 2FA secrets.
  • Hashed IP addresses — never the raw IP.
  • Short-lived signed links for files; role-based access control.
  • Audit logging of important actions; encrypted, tested backups.
Under the GDPR you have rights of access, portability, rectification, erasure, restriction, objection, and to withdraw consent. We've built tools so you can exercise most of them yourself:
  • Download my data — export your data as JSON (participant Privacy & Data tab; researcher Settings).
  • Edit your profile to correct your data.
  • Delete account to erase it; participants can also withdraw from a study and optionally delete its data.
  • Withdraw consent — study withdrawal, one-click unsubscribe in any marketing email, email preferences, or Cookie settings.

For anything the in-app tools don't cover, email info@open-lab.online; we respond within one month. You can also lodge a complaint with our lead supervisory authority, the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW), Stuttgart, or the authority where you live or work. For data inside a specific study, the researcher is the controller — direct requests about study responses to them.
Open Lab is for adults. You must be at least 18 years old, and you confirm this at signup. We do not knowingly process children's data. If you believe a child has used the platform, contact info@open-lab.online.
We may update this policy as the platform evolves or the law changes. We version our Terms and Privacy Policy, and when we make a material change we'll ask you to re-accept the new version before you continue. The "Last updated" date shows the current version.
Open Lab Online UG (haftungsbeschränkt), Friedrichstrasse 6b, 78464 Konstanz, Germany. Email info@open-lab.online, phone +49 178 418 81 54. To raise a matter with a regulator, contact the LfDI Baden-Württemberg (Stuttgart) or the authority where you live or work. For data inside a particular study, contact the researcher named in that study.

Questions about your privacy?

We're happy to help with any request or concern — email info@open-lab.online.