Lens

Legal

Privacy statement

Lens is a research repository, so protecting personal data is central to what we build — not an afterthought. This statement explains what we collect, why, and the choices and rights you have.

Last updated: 27 July 2026

Who we are

“Lens” (“we”, “us”) is the UX research repository available at lensresearch.app. Lens is operated by Erik Niemeijer, based in the Netherlands, who is the data controller for the purposes described below. For any privacy question or to exercise your rights, contact us at [email protected].

Where Lens is self-hosted by your organisation on its own infrastructure, that organisation — not us — controls the hosting and this statement describes the software’s behaviour rather than a service we operate for you.

Cookies and browser storage

This website uses no tracking cookies and no third-party analytics.We don’t run Google Analytics, advertising pixels, or session-recording tools, and we set no cookies for marketing or profiling. There is nothing here to “consent” to, which is why you won’t see a cookie banner.

What we do use is strictly functional, first-party browser storage:

Fonts are self-hosted from our own domain, so simply visiting the site sends no data to Google or other font providers. None of the above is used to track you across sites.

Information we collect

When you visit the website. Our hosting provider (Hetzner) keeps short-lived, security-related server logs (such as IP address and request details) to protect the service against abuse. These are not used to build a profile of you.

When you request access. The “Request access” form collects the details you provide — typically your name, work email, and any message — so we can respond to your enquiry and follow up.

When you use the app. We process:

Your data and our role

For personal data contained in the research content your team uploads (for example, interviewees and participants), your organisation is the data controller and Lens acts as a data processor on your behalf, under a data processing agreement. For your account information and interactions with our website, Lens is the controller.

How we use data and our legal bases

AI features

AI features are optional and use a key you provide. When you invoke one, the relevant text is sent — through our server — to the AI provider your workspace has configured (for example Anthropic, OpenAI, xAI, or Google), which processes it under its own terms solely to generate a response. We do not use your research data to train AI models.

You can enable PII redactionin Settings, which removes emails and phone numbers from text before it is sent to the AI provider. If you don’t configure AI, no data is sent to any AI provider.

Sharing and sub-processors

We don’t sell your data. We share it only with service providers that help us run Lens, under appropriate agreements:

A current list of sub-processors is available on request at [email protected].

Where your data is held

Our cloud service and its primary database are hosted in the European Union. Where a provider (such as an AI provider you configure) is outside the EEA, any transfer is covered by an appropriate safeguard such as the European Commission’s Standard Contractual Clauses. Lens can also be self-hosted, in which case your organisation controls where data resides.

How long we keep it

We keep account data for as long as your workspace is active and delete it within 90 days of account closure, unless we must retain it longer for legal reasons. Research content is retained under your organisation’s own settings and our agreement with them. Access-request submissions are kept only as long as needed to handle your enquiry.

Security

We use encryption in transit and at rest, tenant isolation between workspaces, role-based access, and encrypted storage for sensitive secrets such as AI keys. No system is perfectly secure, but we work to protect your data and to limit access to those who need it.

Your rights

Under the GDPR you can ask us to:

Email [email protected] to exercise any of these. If your request concerns research content held on behalf of a customer, we will direct it to that customer as the controller. You also have the right to lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Children

Lens is a workplace tool and is not directed at children. We do not knowingly collect personal data from children under 16.

Changes to this statement

We may update this statement as the service evolves. We’ll change the “last updated” date above and, for material changes, provide a more prominent notice.

Contact

Questions about this statement or your data? Email [email protected].