StatsPlease is provided by StatsPlease Limited, a private limited company registered in England and Wales, company number 17276823, registered office 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE ("StatsPlease", "we", "us"), which is the data controller for the personal data described in this policy. StatsPlease provides a publication-quality statistical-analysis tool for researchers. This policy explains what personal data we process, why, who we share it with, and the rights you have. We are built to handle as little personal data as possible.
1. The most important point: do not upload identifiable data
You must de-identify your datasets before uploading them. Do not upload direct identifiers or health-identifying information, including names, initials, addresses, emails, phone numbers, dates of birth, medical record numbers, national/insurance IDs, device IDs, or any field that can identify an individual. StatsPlease is designed to analyze de-identified research data only.
If you upload personal data in your dataset in breach of the Terms, you do so as the data controller for that data; StatsPlease processes it solely on your instruction, you are responsible for having a lawful basis, and you must indemnify us as set out in the Terms. We may delete such data.
2. Personal data we process
| Category | Data | Source |
|---|---|---|
| Account | Email address; authentication provider (email/Google/Microsoft); your country of residence. | You / your identity provider (Supabase). |
| Dataset content | The (required-to-be de-identified) tabular research data you upload, and the analysis outputs generated from it. | You. |
| Usage & diagnostics | Counts and timestamps of analyses; technical logs; IP address (processed transiently for security, abuse-prevention and rate-limiting); error reports. | Automatically. |
| Payment | Subscription status and plan. Card/billing details are collected and processed by Paddle, our payment provider and Merchant of Record; we never receive or store your card data. | Paddle. |
| Communications | Messages you send us (support, feedback). | You. |
We do not collect your date of birth, we do not show ads to you, and we do not sell personal data.
As part of usage and diagnostics, we record first-party product-usage events — the actions you take in the app, such as signing up, uploading a dataset, running an analysis, and exporting a report — with timestamps and non-identifying metadata (for example row and column counts, the kind of analysis or test, and the export format), so we can understand and improve how the product is used. These events record what you did, never your data — never your dataset contents or your results. This first-party product-usage stream stays within StatsPlease, is not shared with any third party, and is kept for no more than 12 months (or until you delete your account). Separately, we use Google Analytics 4 for general web and app analytics (see §3); that is the only analytics we share with a third party. It runs on by default outside the UK/EEA and, inside the UK/EEA, only if you accept it in the cookie banner; you can opt out at any time.
3. Browser storage
We use first-party browser storage necessary to run the app (not for advertising): your login session, and app state such as your active project, agreement acceptance, and your notes.
Analytics cookies. We use Google Analytics 4, a service provided by Google, to
understand how the site and app are used so we can improve them. If you're
visiting from the EU, EEA, UK, or a similar jurisdiction, we ask first: analytics
cookies are set only after you accept them in the banner, never before, on the
legal basis of your consent (GDPR/UK GDPR Art. 6(1)(a) and the Privacy and
Electronic Communications Regulations). Elsewhere, analytics runs by default under
our legitimate interest in understanding product usage, and you can opt out at
any time. When active, Google Analytics sets the cookies _ga and _ga_* to
measure usage; it never receives your datasets or your results. We record your
choice (or, where no upfront choice applies, that analytics is active) in a
strictly-necessary cookie named statsplease_analytics_consent_v1 so we can honor
it. Wherever you're visiting from, you can change your choice at any time using the
Cookie preferences link in the footer; opting out turns analytics off and
clears the _ga and _ga_* cookies.
Ad conversion measurement. If you arrive from one of our ad campaigns, your email address is passed to Google's advertising tag running in your own browser, which hashes it (SHA-256) before anything is sent to Google, so Google Ads can match your signup to that ad click. We never send your email in plain text, and this is used only to measure whether our campaigns are working, never to personalize ads or build a cross-site profile of you (Google Signals and other ad-personalization features stay off; see §5). Outside the UK/EEA this is on by default and you can opt out at any time. Inside the UK/EEA it is off unless you choose "Accept all" in the cookie banner — never the default there. The legal basis is our legitimate interests in measuring our own campaigns where it runs by default, and your consent (GDPR/UK GDPR Art. 6(1)(a)) where the banner applies. You can change your choice at any time using Cookie preferences.
4. Why we process it, and our legal bases (GDPR Art. 6)
- To provide the service (run analyses, store your projects, authenticate you): performance of a contract.
- Security, abuse-prevention, rate-limiting, debugging: legitimate interests.
- AI-assisted wording of your report prose (Anthropic Claude): after our deterministic statistics engine computes your results, the draft Results text is sent to our AI sub-processor — Anthropic's Claude API (see §5) — to improve its readability. The AI never computes a number — every statistic, p-value, and confidence interval is calculated by our own deterministic engine, and the polished text is checked against the original values before it reaches you; if this step fails or is unavailable, you simply receive the unpolished text. What our AI sub-processor receives is the draft report prose — which includes your variable names, category labels, and computed results — never your uploaded dataset itself. Because datasets must be de-identified (§1), this text should contain no personal data. This step is on by default, but optional: an "AI Polish" toggle in the Analyze flow lets you turn it off for that analysis, in which case your report is produced entirely by our deterministic engine with no AI sub-processor involved. Legal bases: performance of our contract and our legitimate interests in producing publication-quality output; whether or not you use the toggle, you may also object at any time by emailing info@statsplease.com.
- Billing: performance of a contract / legal obligation.
- Product communications / marketing (if any): consent, withdrawable anytime.
- Analytics cookies (Google Analytics 4, see §3): consent (GDPR/UK GDPR Art. 6(1)(a) / PECR) where a cookie banner applies; legitimate interests elsewhere. Opt-out available anytime via Cookie preferences.
- Ad conversion measurement (Google Ads, see §3): legitimate interests (Art. 6(1)(f)) where it runs on by default (outside the UK/EEA); consent (Art. 6(1)(a) / PECR) inside the UK/EEA, a separate "Accept all" choice and never the default there. Opt-out/withdrawal anytime via Cookie preferences.
- First-party product-usage events (see §2): legitimate interests in understanding and improving the product. These events are first-party, non-identifying, and not consent-based; you can object to this processing at any time by emailing info@statsplease.com.
5. Sub-processors and third parties
What we never do with your data. Your uploaded datasets never leave StatsPlease's own infrastructure and are never shared with any third party. The only third party that sees any part of your results is our AI-polish sub-processor — Anthropic's Claude API — which receives the draft report text solely for the wording step described in §4, and only when AI Polish is on (§4); never for analytics, advertising, or model training. Neither Google Analytics nor Google Ads — analytics and advertising-measurement services — ever sees your datasets or results. We do not sell your personal data, and we do not show ads to you or build an advertising profile of you. The only third-party analytics is Google Analytics; it is on by default outside the UK/EEA and opt-in via the cookie banner inside, and it sees general site-usage data (such as pages viewed and approximate location from your IP), never your datasets or results. Separately, ad conversion measurement (§3; on by default outside the UK/EEA, opt-in via "Accept all" inside) uses your hashed email only to tell us whether an ad campaign led to your signup; we keep Google Signals and ad-personalization features turned off, so this is never used to advertise to you or to build a cross-site or cross-product profile. Our own first-party product-usage events stay in our database and are not shared with any third party for analytics. The providers listed below process data only to help us run StatsPlease, as described.
| Provider | Purpose |
|---|---|
| Supabase | Authentication + database (your email, account, subscription record). |
| Modal | Cloud compute + storage (runs analyses; stores your projects/uploads). |
| Anthropic | AI text-polish of your report prose (see §4). Receives the draft report text (variable names, category labels, computed results) — never your uploaded dataset. Under Anthropic's Commercial Terms, our content is not used to train Anthropic's models. Transfers to the US are covered by Anthropic's EU-US Data Privacy Framework certification and the UK Addendum incorporated in its Data Processing Addendum. |
| Paddle | Payments + Merchant of Record (checkout, tax, refunds). We never see card data. |
| Resend | Transactional email: analysis notifications and account/security notices; receives your email address. Notification emails follow your email preferences; security notices are always sent. |
| Google (Google Analytics / Google Ads) | Website and app analytics (on by default outside the UK/EEA; opt-in via the cookie banner inside — see §3), to understand and improve how the product is used. Separately, ad conversion measurement (also §3; on by default outside the UK/EEA, opt-in via "Accept all" inside) passes your hashed email so Google can measure whether an ad campaign led to your signup. Neither ever receives your datasets or your results. |
| Sentry | Error monitoring. Events are scrubbed before they leave our servers to strip uploaded filenames, column names, long numeric IDs, request bodies and query strings. |
| Cloudflare | Content-delivery network in front of the app. |
Some of these providers process data on servers outside your country, including in the United States. Where that happens, the transfer relies on appropriate safeguards such as the Standard Contractual Clauses (or the UK IDTA), or an adequacy-based certification such as the EU-US Data Privacy Framework, and only the information needed to run the service is sent, never your raw datasets or anything that identifies an individual.
6. Retention
- During open access, every account has Author-level access. While StatsPlease is free during open access, all accounts retain their work: your analysis results and projects are saved between sessions, and nothing you create is cleared on sign out. A project is kept while you use it and is removed after 12 months of inactivity (measured from your last activity on that project), or whenever you delete the project or your account. (When paid tiers begin, a Researcher (free) account will not keep saved projects between sessions; no account is on that footing today.)
- Uploaded files. The original file you upload is automatically deleted within 7 days. Your analysis results are stored separately as part of your saved project, so deleting the raw file does not remove your work.
- Product-usage events (see §2) are kept for up to 12 months from the event date, then deleted or irreversibly aggregated; they are removed immediately when you delete your account.
- Account data is retained while your account is active. When you delete your account from your account settings, your profile and stored data are permanently removed.
7. Your rights
Depending on where you live, you have rights to access, correct, delete, export (portability), restrict or object to processing, and to withdraw consent at any time. EU/UK residents have these under GDPR/UK-GDPR; California residents have rights under the CCPA/CPRA (to know, delete, correct, and to opt out of "sale"/"sharing"; we do not sell or share personal data). You stay in control of your data: you can delete individual projects in-app and permanently delete your account and all of its data yourself from your account settings, with no need to contact us. To exercise any other right, email info@statsplease.com. EU/UK residents may lodge a complaint with their supervisory authority.
8. Security
We use authentication, access controls, encryption in transit, per-user data scoping, and PII-scrubbing on diagnostics. No system is perfectly secure; the single best protection for participant privacy is not uploading identifiable data (see §1).
9. Children
StatsPlease is not directed to children and is for users 18 or older. We do not knowingly collect data from anyone under 18.
10. Contact
StatsPlease Limited, company number 17276823, registered office 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, info@statsplease.com.