Privacy and anonymity
This page explains what we keep, what we never keep, and how we protect you. It also explains what we cannot protect you from. Please read it before you share a story.
Exit Interview is run by StandbyRoster (Mai Nazzal). Last updated: October 2026
In short
- We do not store your email address. We keep a one-way code made from it.
- We do not store your IP address or device details in our database.
- You choose a nickname for each story. We never ask for your name.
- Voice stories are read aloud by a computer voice. We delete your recording right after it is turned into text.
- Approved stories go live at a random time 1 to 7 days later.
- We never show small groups. Any count below 5 is hidden.
- You can delete your account and everything in it with one click.
What we collect
We keep only what we need to run the platform. This is the full list.
- A one-way code made from your email address, so you can sign in again. See "How sign-in works".
- Your profile nickname, your language choice, and whether you accept connection requests.
- The date your account was created. We use it to slow down spam and to decide when your "Me too" reactions start to count in the trends.
- What you write in a story: the nickname for that story, organisation, country, and the optional details you choose to add (city, contract type, grade band, what happened, year and quarter, gender, how you feel now).
- Your story text, or the text made from your voice recording, and the computer-voice version of it.
- Your comments, reactions, follows, connection requests, messages, blocks and reports.
- Counts of how many stories, comments and messages your account sent each day, so we can apply limits.
- Story view counts. These are totals per story. We do not record who viewed what.
- Visit counts: how many times each page was viewed per day, and from which country. We look up the country from your IP address and then discard the address at once. We store no IP address, no device details and nothing that links a visit to you. If your browser asks sites not to track you, we do not count your visit. Country data: DB-IP.
Gender and grade band are never shown on your story. We use them only inside totals that pass the small numbers rule.
We use cookies only to keep you signed in and to remember your language and display style. We do not use advertising, analytics or tracking cookies.
What we never collect
- Your email address in readable form.
- Your real name, phone number or postal address.
- Your IP address or browser and device details (user agent). We do not store them in our database.
- Your exact grade. We ask only for a broad grade band.
- Exact dates. We ask only for a year and a quarter, and we show only the month a story went live.
- Your exact location. We never use GPS or your device location.
- Your original voice recording, beyond the few minutes needed to turn it into text.
- Social media profile data. Google sign-in is optional; it gives us only an account number, never your Gmail address, name or photo. There is no sign-in with Facebook, LinkedIn or similar.
How sign-in works
You sign in with a one-time code sent to your email address, or with your Google account. For email, use any address you can read. It does not need to be your work address. In fact, we advise you not to use it.
When you type your address, our server turns it into a one-way code using a secret key that only the server holds. The same address always gives the same code, so you get the same account back. We cannot turn the code back into your address.
Your account is then registered under a made-up placeholder address built from that code. That placeholder cannot receive mail. Your real address is used once, to send you the code, and is then forgotten. The code works once and expires after one hour. With Google, we ask Google only for an account number (the openid permission). We turn that number into a one-way code in the same way, and we never receive your Gmail address or name.
Before we send the link, Cloudflare Turnstile checks that you are a person and not a bot. We run the same check when you send a story. Turnstile runs in your browser. We receive only a pass or fail answer.
- We cannot email you, send newsletters, or warn you about anything. We do not have your address.
- If you lose access to that email address, you lose access to your account. We cannot recover it.
- A one-way code is strong but not perfect. Someone who had both our secret key and your email address could check whether that address has an account. We keep the key outside the database.
Nicknames
Your public identity is a nickname. You can type one or generate a random one, for example "Quiet Kestrel 42". You can change it at any time.
Each story carries its own nickname. We fill in your profile nickname, and you can change it for that story only. Use a different nickname if you do not want readers to link two stories.
When you share a story, you choose whether to show it on your profile. If you turn this off, the story has no link to your profile. Readers and followers cannot see it next to your other stories.
Profiles never show an email address, an organisation history or a location beyond what is in your published stories.
Voice stories
You can record a story of 30 to 90 seconds in your browser. This is what happens to the recording:
- The recording goes to private storage that the public cannot reach.
- Our AI provider, OpenAI, turns it into text.
- The text is checked like any written story.
- A computer voice reads the text aloud. We use one fixed, neutral voice for everyone.
- We delete your original recording right after it is turned into text, and we check that it is gone.
- As a safety net, an automatic clean-up deletes any original recording older than 24 hours, for example if processing failed.
Listeners only ever hear the computer voice. Moderators read the text of your recording; they never hear it. The computer voice is created only after a moderator approves the text. The text is published with the story.
The computer voice says your words exactly. Your choice of words can still be recognised. See "What we cannot protect you from".
Publishing delay
After a moderator approves your story, we choose a random day between 1 and 7 days later. Your story goes live on that day in a daily batch, together with other stories, at the same fixed time.
This means the time a story appears does not match the day you wrote it, the day you resigned, or the day your contract ended. We show only the month a story went live, never the exact date.
Location
We ask for the country of your duty station. On the globe, each story appears at country level, moved by a random distance of up to about 150 kilometres. A point on the globe never marks a real office or city.
City is optional. We show it only when at least 5 published stories name the same city. Until then, the city is stored but not shown. If you think a city could identify you, leave it empty.
The small numbers rule
Small groups can identify people. If a chart shows "1 story from a junior woman at agency X in country Y", colleagues may know who that is.
So every chart, count, map label and downloadable file hides any group with fewer than 5 stories. It shows "Not enough stories yet to show this safely" instead. If hiding one group would still let someone work out its number from a total, we hide the next smallest group too.
This applies to every combination of filters, such as organisation, country, grade band and gender. We also collect only broad grade bands and only the year and quarter of events, so the groups stay large.
AI checks
Before a person reviews your story, an automated check runs. It looks for names, contact details and other identifying details, hate, threats, spam and confidential information. It also suggests themes, writes a one-line summary and translates the story for readers of other languages.
For these checks we send text to OpenAI. This includes stories, voice transcripts, comments, messages, and drafts when you ask us to check them for names. Voice recordings are sent to OpenAI to be turned into text, and the approved text is sent to make the computer voice. We do not send your email address or IP address, because we do not have them.
OpenAI may keep data sent to its API for up to 30 days to detect abuse, unless a zero data retention agreement is in place. OpenAI states that it does not use API data to train its models by default.
The AI cannot publish anything. It can only reject clear spam or clear hate, or pass the story to a person. If the check fails or is unavailable, the story waits for a person. If a story suggests that someone may be at risk of harm, we never block it for that reason. We show support resources and review it first.
Moderators
A small team of moderators and administrators appointed by StandbyRoster reviews every story before it goes live. They also review reported comments and messages.
- They see the story text, the details you entered (including the optional ones), the nickname, the AI findings and suggested edits, and any reports.
- Administrators can link posts to the same account, so they can stop repeated abuse. An account holds no email address, name or IP address.
- They cannot see your email address or IP address. We do not hold them.
- They can approve, reject with a reason, ask you for changes, or remove identifying details. Every action and every edit is recorded in an audit log.
Deleting your account
You can delete your account at any time from your profile settings, with one click. Deletion is permanent and cannot be undone.
It removes your account, your stories and their audio, your comments, reactions, follows, connections and messages, your blocks and reports, and your notifications.
- Totals that were already published, such as a trend chart or a weekly digest, may still include your story as one number among many.
- We cannot remove copies that other people made, such as screenshots or shared images.
- Our database provider keeps backups for a limited time. Deleted data disappears from them when the backups expire.
Service providers
We use a few companies to run the platform. Each one processes only what it needs.
- Supabase: our database, sign-in system and file storage.
- Vercel: hosts the website.
- OpenAI: AI checks, translation, voice to text, and the computer voice.
- Cloudflare Turnstile: the bot check on sign-in and story submission. It processes your IP address and browser signals under its own privacy policy.
- Resend: sends the sign-in email. It processes your email address to deliver the message.
Supabase and Vercel keep technical logs of their own infrastructure. These logs may contain IP addresses for a short time. They sit outside our database. We do not copy them into our database or use them to identify people.
A court or authority can only obtain what we hold. We do not hold your email address, name or IP address.
How to contact us and request a takedown
If you think a story identifies you or another person, use the Report button on that story. Moderators review reports.
You can also write to us. Give the link to the story and explain the concern. You do not need an account. If a story identifies a person, we remove it or remove the identifying details.
Write to StandbyRoster through its website: StandbyRoster (Opens another website.)
What we cannot protect you from
We remove what we can. Some risks stay with you. Please read this list before you write.
- Your writing style. Colleagues may recognise how you write, phrases you often use, or a story you have told before.
- Details only you or a few people know. A specific meeting, a specific number, an unusual job title or a small team can identify you, even without a name.
- Your device and network. A work computer, work phone, office network or work VPN may be monitored by your employer. Browser history and open tabs can be seen by others.
- Your email account. If you sign in with a work address, your employer may see the sign-in email.
- Your own words elsewhere. If you post the same story on social media or tell colleagues that you wrote it here, people can connect the two.
- Copies. Anyone can take a screenshot of a published story.
How to stay anonymous:
- Use a personal device and a personal or new email address.
- Do not use an office network or work VPN.
- Change small details that do not matter to the story, such as the month or the size of the team.
- Write "my manager" or "a colleague" instead of names or job titles.
- Leave optional fields empty if they narrow you down.
- Use a new nickname for a story you do not want linked to your others, and turn off "show on profile".
- Wait a while before you tell anyone that you shared a story, or do not tell anyone.
Changes to this page
If we change how we handle data, we update this page and the date at the top. We will not start collecting your email address, name or IP address in our database.