CorpusLab

All studies

Privacy Notice

Version: 2026-08-04

Data controller: CorpusLab, operated by Noé De Rijck, a private individual based in Brussels, Belgium. For any question about this notice or your personal data, or to exercise your rights, contact us at privacy@corpuslab.be — or through the Support / Help page on the platform.

What we collect: to open your account we need your name, email address, a one-way hash of your password, and your date of birth. We use your date of birth to confirm that you are 18 or older (the platform is for adults only), to apply age-based study eligibility and per-age-group capacity limits, and — together with your language — to select the recipients of relevant service announcements; these details are required to use the platform. We also ask for a telephone number when you sign up, so that the research team of a session you have booked can reach you about it on the day — for example if the room changes or the session runs late. You can change or remove it at any time from your profile, and accounts created before this version of the notice took effect have no number on file: they are simply invited, once, to add one. You may also choose to add an optional eligibility profile — gender, handedness, main language, and education. Providing it is optional, but be aware that it is not merely used for suggestions: studies may restrict eligibility or cap per-group capacity by these characteristics, so a study that filters on a field you left blank cannot be booked until you fill it in (see 'Automated decisions'). As you take part, we also process your study bookings, your attendance status and the steps you take to confirm it on the day (including any reason you give when you withdraw from a session), the two-way ratings and reliability metrics produced by your participation, any support requests you send us, a record that a transactional email was sent to you, and the technical and security logs — including your IP address — that we need to run and protect the service. Some of this — your attendance status, the ratings researchers give you, and your reliability score — is produced by the platform's attendance verification, by human review, or by the researcher, rather than provided by you directly. Researcher-side accounts (responsible researchers and research assistants) additionally hold the institution and lab recorded for the account — entered by a researcher at sign-up, and inherited from the inviting researcher for an assistant. We also assign your account a permanent participant identifier: a short code, issued once and never changed, which is how research teams and our administrators refer to you when they are not shown your name. You will find it on your profile and in your data export.

Messages you send: the platform lets you exchange messages with the researcher of a study you are signed up to. Message content is end-to-end encrypted, so we store only unreadable ciphertext that our database alone cannot decrypt; we do not read your messages, as a matter of both design and policy. We do hold the surrounding information: who exchanged messages with whom, the study concerned, and the timestamps. If you report a conversation for review, your own device decrypts that conversation and discloses it to our administrators so they can act on your report. Study message threads are deleted automatically about 7 days after your session.

Attendance verification and location: your attendance at sessions is confirmed from your own device. During the session you scan (or type) the code rotating on the researcher's screen; that scan alone confirms your attendance. Only with your separate in-app consent — on top of your browser's own permission — the platform also reads your device's position, once, at the moment you check in or scan, to strengthen your proof of presence; on the researcher's side, position is read periodically while their code screen stays open. Positions are only ever processed for sessions held at a set venue, and declining location never prevents you from confirming attendance with the scan. Coordinates are encrypted, are never shown to the researcher or to other participants, and are deleted on the short schedules listed under 'How long we keep it'; only derived values — distance to the venue, reading accuracy — remain attached to the session. Maps shown on the platform are displayed with map tiles loaded by your browser directly from OpenFreeMap, a third-party tile provider — opening a page with a map therefore sends your IP address and browser details to that provider, like any image loaded from the web. No account data, and never your measured position, is sent to it.

Why we use it, and our legal basis: to provide the recruitment service, manage your bookings, and run the messaging feature (performance of our contract with you); to confirm you are old enough for the platform and eligible for a study (contract, and our interest in not enrolling minors); to verify attendance at your sessions via the code scan (contract, and our legitimate interest in attendance records both sides can rely on) and, only with your consent, via your device's position (consent, which you can withdraw at any time); to let the research team reach you about a session you have booked when something about it changes on the day (our legitimate interest in sessions that actually take place — you can remove your number at any time); to suggest studies that match your optional profile (your consent, which you can withdraw at any time — see 'Your rights'); to keep the platform secure, prevent abuse, apply our reliability and no-show rules, and stop an account that leaves with an active penalty from re-registering to escape it (our legitimate interests); and to meet any legal or accounting obligations we are subject to (legal obligation). We never sell your personal data and never use it for third-party marketing.

Who receives it: when you book a session (or request to take part in a pre-screened study), that study's research team — the responsible researcher and any co-researchers or research assistants they add — can view, and export to a file, your name, email address and telephone number, so they can run the session and contact you about it. That access is not open-ended: it ends 30 days after the researcher marks the study finished, and from then on the team sees your participant identifier in place of your name, email address and telephone number. The single exception is compensation you are still owed — a team that has not yet paid you keeps those details until it has, because nobody can be paid as a code. A study the researcher never marks finished keeps that access for as long as it stays open. Alongside these, the research team also sees your average rating, your number of ratings, and your reliability score; these reflect your participation across the whole platform, and for pre-screened studies they are visible at the moment the team decides whether to admit your request. The research team also sees an aggregate demographic composition of the people who took part in their own study — age band, gender, education, spoken language, and how you said you heard about CorpusLab when you signed up. This is shown as a breakdown by group — how many people fall in each age band, each gender, and so on — and never as a list naming you. The counts are exact, and they are shown whatever the size of the study: where a group contains only one person, the breakdown describes that person, so on a small study a team that knows who took part can work an individual answer out of it. It is never used to decide whether you may take part in a study. Transactional emails are sent through our processor Brevo (Sendinblue), based in the European Union; Brevo keeps its own technical delivery logs for a limited period under our data-processing agreement. All of your data is stored and processed on our behalf by our EU-based cloud hosting and database provider under a data-processing agreement. Our administrators are never shown your name, email address or telephone number: every administrative screen identifies you by your participant identifier instead, and the work of support, safety, dispute resolution and legal compliance is carried out against that code. Quote it if you contact us. This describes what the platform's own tools display; it is not a claim that data we must store in order to run the service — such as the address your emails are sent to — is technically beyond the reach of the people who operate it. If you click an 'add to calendar' or 'open in maps' link, or open a researcher's external pre-screening questionnaire, you are taken to a third party (such as Google or Microsoft, or the researcher's own tool) that then acts as an independent controller under its own privacy terms.

Cookies and local storage: we use only strictly-necessary and functional storage on your device — no advertising and no third-party tracking, so we do not need a cookie banner. This includes: a login session cookie (14 days, or up to 60 days if you tick 'remember me'); a cookie that remembers your interface language (up to 1 year); a cookie that remembers your light/dark theme choice (up to 1 year); a cookie that remembers you dismissed the 'complete your profile' prompt (up to 1 year); a short-lived cookie holding the email you just registered with, so the sign-in page can prefill it (30 minutes); a small in-browser note that you just booked, used to highlight the booking when the page opens (kept only until the tab closes); and, only if you use messaging, a session cookie plus a small encrypted key store in your browser that keep your messages readable to you. Researchers also have some interface-preference and draft-autosave storage for their own tools. You can clear all of it at any time through your browser.

Audience measurement: to understand how the site is used and keep it working well, we run our own first-party measurement — never an external analytics service, and it stores nothing on your device. For each page view our server records the page, the referring site, campaign codes, engagement time, scroll depth, technical performance timings, and a coarse device/browser/language class, plus whether a visit led to a sign-up or a booking. Visits are grouped using a pseudonymous fingerprint (a salted hash of your IP address and browser signature whose salt changes every day, so groups cannot be linked across days); your IP address itself is not stored. Detailed measurement events are deleted after 90 days; only anonymous daily totals are kept. Legal basis: our legitimate interest in understanding and improving the service — you can object (see 'Your rights').

International transfers: your personal data is stored and processed within the European Union / European Economic Area (EEA), and we do not transfer it outside the EEA. If that were ever to change, we would first put appropriate safeguards in place (such as the European Commission's standard contractual clauses), and you could request a copy using the contact details above.

Automated decisions: some decisions on the platform are automated. Eligibility checks — a study's age band and participation rules, its demographic requirements (gender, handedness, main language, education), per-group capacity limits set by the researcher (by gender, education, or age group), time-conflict checks against your other bookings, and reliability thresholds — together determine which studies and time slots you can book; where a study filters or caps by a profile field, leaving that field blank also prevents booking it. Attendance is also resolved automatically in the clear-cut cases: a valid code scan confirms your attendance by itself, and if you do nothing at all during a session you booked — no scan, no check-in, no problem report — an unexcused absence is recorded automatically. An unexcused absence temporarily pauses your bookings (30 days the first time, longer if repeated), releases your other upcoming bookings, and lowers your reliability score; it never closes your account by itself. Every case in between — a failed attempt, a problem report, a check-in without a scan — is decided by a person, never by the system. For any automated decision you can obtain human intervention, put your point of view, and contest the outcome: from the session's page, or by contacting support.

How long we keep it: we keep your account and participation data for as long as your account is active. An account whose email is never verified is deleted after 30 days. Audit and security logs are kept for up to 12 months. Study message threads are deleted automatically about 7 days after the session. Raw location coordinates from attendance verification are encrypted and deleted 72 hours after the session's attendance is settled; a case under review or contested keeps them until the decision, and they are in any event deleted within about 30 days unless your appeal is still open. The rotating session codes are deleted 7 days after the session; attendance attempt records then hold only derived values (distances, accuracy) and are deleted after 12 months. When you delete your account we act as described under 'Your rights'. If you leave while a penalty is still in force, we keep a one-way hash of your email for as long as needed to prevent re-registration to evade it. Encrypted database backups may retain a copy of deleted data for up to 30 days before they are rotated out. We keep certain records longer only where strictly necessary to meet legal, accounting, or security requirements.

How we protect it: we use appropriate technical and organisational measures — including password hashing, encrypted connections, access controls, rate limiting, and end-to-end encryption of message content — to protect your data against unauthorised access, loss, or misuse. Your IP address is used only to rate-limit and protect the service, and is stored only in salted, short-lived form, never in plain text.

Your rights: you have the right to access, rectify, export (data portability), and erase your personal data, and to request restriction of certain processing. You can do most of this yourself from your profile — including exporting your data and deleting your account. Where our processing is based on consent (your optional eligibility profile, and location for attendance verification), you can withdraw that consent at any time — profile fields by clearing them, location from the consent settings on your profile — or by deleting your account, without affecting processing carried out beforehand. You also have the right to object, at any time and on grounds relating to your particular situation, to processing we carry out on the basis of our legitimate interests. To exercise any of these rights, use your profile or contact us at privacy@corpuslab.be.

How to complain: if you believe we have not handled your data properly, you can lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be) or with the supervisory authority where you live or work.