Privacy Controls

Privacy Controls: built in, not bolted on.

Administrators control which data is captured, how long it's kept, and how it's deleted: field-level capture settings, user-level deletion, per-form purges, project-wide retention, and account-wide deletion on request.

Choose which fields are not captured — including for anonymous users
Delete or anonymize individual users, purge a form's responses, or request account-wide deletion
Configurable retention periods with automated purging

Data field controls

Admin only
emailPII
not captured
full_namePII
not captured
user_id
captured
country
captured

Consent tracking

u_2841·grantedvia SDK
u_0944·grantedvia SDK
u_1192·pending—

User data deleted

u_3374 · all fields purged · logged

Done

How it works

Full control. Nothing hidden.

Privacy Controls gives administrators granular oversight over every piece of data encatch touches — from what is recorded in the first place to how long it is kept and who can act on it.

Decide exactly what gets recorded.

Administrators can inspect every field encatch collects and choose to include it on profiles, include it with responses, or leave it out entirely. Settings apply uniformly — including to anonymous visitors. No data should slip through because someone forgot to configure it.

  • Turn off any field and it won't be captured. Applies to all users, including anonymous.
  • Anonymous user data is subject to the same controls as identified users.
  • Changes take effect immediately across all future data ingestion.

User data field settings

emailPII
not captured
full_namePII
not captured
user_id
captured
plan
captured
ip_addressPII
not captured

Applies to all users, including anonymous visitors — no exceptions.

Accountability and identity

Keep control throughout the data lifecycle.

Review portal access, manage retention and exports, and protect the voice behind each response.

See who accessed your admin portal.

On Enterprise, the access log records who signed in to your encatch admin portal and when, giving compliance teams a clear record of portal access.

  • Each admin portal access is listed with the user and the time.
  • Available on Enterprise plans.
  • Pairs with role management, IP whitelisting, and SSO to control who gets in.

Access log

portal_access

priya@acme.com · Admin portal

2m ago

portal_access

admin@acme.com · Admin portal

14m ago

portal_access

sam@acme.com · Admin portal

1h ago

portal_access

admin@acme.com · Admin portal

6h ago

Enterprise: see who accessed your admin portal and when.

Zero-data segmentation · Segmentation Engine

Qualify users for feedback without their data touching encatch.

Pair the encatch Segmentation Engine with your CDP or identity system through the Admin API to run targeted feedback campaigns without ingesting personal data. Your first-party data stays where it belongs: encatch only receives segment membership, as a user trait or a manual-segment update, against an internal user ID.

Full capabilities

Every privacy lever. One place.

Privacy Controls gives administrators the tools to honour user rights, meet compliance requirements, and keep sensitive data under tight control — at every level of the system.

PII field controls

Choose which fields are recorded on user profiles and responses — turn off anything you don't need. Applies to anonymous visitors too.

Anonymous user controls

Control what is recorded even for users with no identity — device context, session data, and more.

Cookie-less mode

Manual feedback forms continue to work for visitors who decline cookies — no session tracking required.

User deletion

Delete or anonymize all of a user's data in one action.

Field-level capture

Choose which user fields are stamped on each response, and leave out anything you don't need.

Retention periods

Set how long response data is kept. When the window expires, records are purged automatically.

Daily data export (coming soon)

Schedule daily exports to your own storage before the retention window closes. Your data, your archive.

Access log (Enterprise)

See who accessed your admin portal and when.

Consent-aware SDK

Hold off the encatch session until a user consents. Until then nothing is stored on the device, a server-side ID rotates every 24 hours, auto-triggered forms pause, and manually launched forms still work.

CDP-driven segments

Let your CDP decide who's in a segment and send encatch only the membership, as a user trait or a manual-segment update through the Admin API. Use an internal user ID and no other customer data has to cross systems.

Admin-only controls

All privacy settings are gated to administrator roles — team members see only what they need to.

Fast, reliable deletion

Field settings apply to new data immediately; user deletions and purges run as background jobs you can track.

Stylometry anonymisation

AI neutralises writing style in free-text responses — protecting identity in small groups without losing a word of meaning.

Product journey

Keep following the signal.

A little more detail

Privacy Controls, answered

Common questions about data capture, retention, and deletion controls in encatch.

What do Privacy Controls let admins configure?

Which data is captured (field by field), how long it's kept (project-wide retention), and how it's deleted: per user, a form's responses, or the whole account on request through support.

Does encatch support cookie-less feedback collection?

Yes — Privacy Controls include a cookie-less mode so feedback collection still works without tracking cookies.

Can I control which fields are recorded?

Yes. Data Settings let admins decide exactly which automatic fields, such as device, browser, or country, are recorded on user profiles and responses for each project.

Your next step

Collect feedback with confidence.

Privacy Controls gives your team the tools to handle user data responsibly — from field-level capture settings to full account deletion on request, in your hands.