Privacy Policy

Last updated 17 September 2026

This policy explains what AskOne stores, why, for how long, and what you can ask us to do about it. It is written to be checked: everything below describes what the software actually does.

Who is responsible

HURYN Sp. z o.o.
ul. Hoża 29, 00-521 Warszawa, Poland
KRS 0000893173 · NIP 7011027727 · REGON 388627882

HURYN Sp. z o.o. is the controller for the data described here. We have not appointed a Data Protection Officer; we are not required to.

The two kinds of person AskOne knows about

Administrators and moderators sign in and run rooms. Participants do not: they open a link on a phone, ask and vote, and never create an account. We hold very different things about each.

If you are a participant

We do not know who you are, and we have no way to find out. When you open a room that is accepting participation, your browser is given one cookie containing a random number. Nothing about you is written to our database at that moment. The first time you ask, vote, answer a survey or set a name, we store the SHA-256 hash of that number — never the number itself — as the only handle we have on you.

We do not store your email address, your name, your IP address, or any identifier from your device. The hash cannot be reversed, so it connects you to no person and to nothing you do outside AskOne — not for us, and not for anyone who obtained a copy of our database.

It is, though, the same hash in every room you act in on that phone: one cookie covers the whole of AskOne. That is deliberate — it is what lets a ban reach every room owned by the workspace that issued it, instead of being shrugged off by opening the next room. It also means the rooms you have acted in can be linked to one another by anyone reading the database directly — though a room you only read leaves no record of you at all. Clear the cookie and you are a new participant everywhere.

Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in running a question queue that works — one vote per person, one survey answer per phone, questions that stay attached to whoever asked them, and moderation that can be enforced. This is the minimum that makes the feature possible.

If you are an administrator or a moderator

Your account — email address, name, password or social login, and your organization memberships — is held by Clerk, our authentication provider. Our own database stores only your Clerk user or organization identifier, so that rooms can belong to somebody. We read your name and email from Clerk when a page needs to show them; we never copy them into our database.

When an administrator or a moderator bans a participant, we record who did it, as their Clerk identifier, together with the ban.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — you asked us to run rooms for you.

Cookies

AskOne uses essential cookies only. There is no cookie banner because there is nothing to consent to: we set no advertising, profiling or cross-site tracking cookies at all.

Analytics

We use Microsoft Clarity to see how the screens are used — where people hesitate, what they never find. It is configured to run without cookies: the Clarity project has cookie storage switched off and the page tells Clarity that both analytics and advertising storage are denied before it collects anything. In that mode Clarity assigns an identifier per page view and cannot follow you between visits or across sites.

Clarity records how pages are used, not what you typed: text you enter is masked before it leaves your browser. If Clarity is not configured on the deployment you are using, no analytics script loads at all.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving the product, weighed against a cookieless configuration that does not track individuals.

Who else processes it

Each is a processor acting on our instructions under a data processing agreement. Where any of them processes data outside the European Economic Area, that transfer relies on the European Commission’s Standard Contractual Clauses.

How long we keep it

Being straight with you about deletion: the 30-day date is recorded against every closed room, and deleting a workspace deletes everything under it immediately. The scheduled job that sweeps expired rooms is not running yet. In the meantime we delete on request, promptly, and you should ask — see below.

Your rights

Under the GDPR you may ask us to:

There is no charge, and we answer within one month. Write to us at the address above.

A limit worth knowing about, if you are a participant. We identify you only by a hash of a cookie we cannot read back. If you still have the cookie, tell us which room and when, and we can find your rows. If you have cleared it, we genuinely cannot — there is nothing linking those rows to you, which is the same property that protects you the rest of the time.

You also have the right to complain to a supervisory authority. Ours is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl.

Security

Only our server talks to the database; no key that could read it is ever sent to a browser. Row-level security is switched on for every table with no policies at all, so a leaked public key reads nothing. Participant cookies are signed, and only their hashes are stored. Every change to a room is checked against the workspace that owns it, on the server, on every request.

Children

AskOne is not directed at children under 16. Participants are never asked for personal details, so a child joining a room shares no more than an adult does: a question, a vote, a survey answer, and a name only if they type one.

Changes

If this policy changes we update the date at the top. Material changes affecting administrators and moderators are notified by email through Clerk.

Terms of Use · Pricing · Home