Skip to main content

Confidentiality

I wanted people to be able to say what they actually think.

Somewhere in the middle of a survey, someone stops and wonders who is going to read this. I have sat on community nonprofit boards, and I know how carefully people weigh what they are about to write down, particularly when the question is about how well the organization is actually run. That pause is the moment an assessment either earns the truth or settles for the polite version.

So we tried to put the promise into the system rather than into a paragraph. Everything below is enforced by code that runs whether or not anyone is watching, and I have tried to describe it here in plain terms, including the places where it stops. It seemed to me this is the page I would want to read before answering somebody else's survey.

The three numbers that do most of the work

Each of these is a line in the code rather than a habit, so it holds on a Tuesday afternoon when nobody is thinking about it.

3
before a group counts. Fewer than 3 people from your board or your staff, and that group is set aside before scoring begins.
5
before disagreement is mentioned. Below 5 respondents in total, the report will not tell you that views differ, and above it, it will never tell you whose.
10
before a cohort slice appears. The starting floor for any slice of a funder's cohort. A funder can raise it, and can never take it below 5.

What happens to the answer you give

In order, from the moment you press submit to the moment somebody reads the report.

No screen shows your survey answers on their own

There is no page in KindTru that displays one person's assessment answers, including the pages only we can reach. Scoring runs on groups, and the report is written from group patterns. This is the same design that keeps your answers private from your own executive director, which I think is the part that matters most.

Below 3 people in total, there is no report

If fewer than 3 people have completed the survey, KindTru declines to build a report at all, and tells you so rather than handing you a document. I would rather say that plainly than give you something drawn from two answers, which would carry the look of a finding without being one. A closed survey can be reopened for 7 days, so the remedy is usually to invite a few more people and wait a little longer.

A group of fewer than 3 does not count as a group

If fewer than 3 people from a group (your board, or your staff) complete the survey, that group's average is never calculated and never stored, to protect the confidentiality of the people in it. With one or two people in a group, a group average is a personal one. Where another group did reach 3, the small group sits out of the scoring entirely. Where no group reached 3, everybody's answers still count toward a single organization-wide score with no group labels attached to it, because a number that belongs to everyone points at nobody.

A small response set gives you the picture and not the comparison

When no group has reached 3, the report is still written from everyone who answered, and what it leaves out is the comparison between your board and your staff. It seems to me that is the right trade, since the comparison is the part that could be walked back to a person and the overall picture is not. If you want the comparison, the remedy is to get a third response into any one group rather than to lower the line.

Between 3 and 4, the report stays general

With 3 or 4 respondents in total, the report gives organization-wide scores and stops there. It will not tell you that opinions differ, because in a group that small, naming a disagreement comes very close to naming a person.

At 5 or more, the gap appears without a direction

Once 5 or more people have responded in total, the report may note that your board and your staff see a category differently, and show how wide the gap is. Then it stops. It does not say which of the two scored it higher, and no screen in the report puts a number beside a group's name. In my experience the places where a board and its staff see things differently are the most useful pages in the whole report, and they stay useful without a direction attached.

Two screens over the written findings

The written sections are drafted with AI assistance, and I did not want to rely on good behaviour. More than a dozen patterns are checked before a section is accepted, so anything resembling “the board rated this lower” is sent back to be written again. A second set of more than a dozen runs again when the report is displayed, when the report PDF is built, and inside the emails that carry findings out to other people. These screens catch the phrasings we have seen. I would not call them exhaustive, and the floors above them are where the protection really sits.

If your funder gathers a cohort

Some community foundations use KindTru to see how a group of the organizations they fund is doing as a whole. That arrangement makes people nervous, reasonably, so it carries its own floors and they are stricter than the ones above.

A category needs at least 5 organizations to have opted in before any statistic for it is computed, and that number cannot be set below 5 by anybody, including us. Slices of a cohort (by budget range, mission, region or organizational age) start at 10, and the system refuses to let a slice floor sit below the category floor, because a slice is easier to recognize than the whole group it came from. Below either line a funder sees a locked placeholder rather than a partial signal.

A foundation never sees an individual organization's scores and never learns which categories any organization chose to share. And you can withdraw whenever you like, at which point your data leaves the aggregation.

Where our protection stops

I would rather tell you the limits than let you find them.

Once you submit, we cannot pull your answers back out

There is no screen that can isolate your responses, which is exactly what keeps them private from everyone else, and it also means we cannot go and retrieve them for you. If you have been invited but have not answered yet, we can remove your invitation while the survey is still open, and we will. I would rather say this before you answer than discover it with you afterward.

Your administrator can see who answered, but not what they said

Whoever is running the survey sees which invitations are still outstanding and how many people from each group have finished, which is how they know when to close it. What they cannot see is any individual's answers. I mention it because in a small organization, knowing who answered is itself a piece of information, and you should know that much before you decide how candid to be.

In a very small organization, arithmetic is arithmetic

If four people answer and everyone knows which four were asked, a determined reader can narrow things down. The floors above exist to make that harder, and I want to be straight with you that they cannot make it impossible.

We can protect the data, but not the conversation

If somebody asks around the office what people said, no system of ours reaches that room. The way to handle it is the ordinary human one, which is to agree beforehand that the answers stay in the report. It works better when the agreement is made out loud, before the survey goes out.

One more thing, and then the fine print

My hope is that this page turns out to be boring, and that nothing on it surprises anyone who reads it after they have already answered. If something here is unclear, or if you are weighing whether to answer somebody's survey honestly and this page did not settle it, I would like to hear about it. What would you need to know before you told the truth on a survey like this one?

The full legal version, including how long we keep things and how findings are drafted, lives in our Privacy Policy (the section on drafting is at /privacy#ai). This page is the plain-language companion to it, and where the two ever seem to disagree, please write to us and we will fix it.

hello@kindtru.org