Legal
Privacy statement
Lens is a research repository, so protecting personal data is central to what we build — not an afterthought. This statement explains what we collect, why, and the choices and rights you have.
Last updated: 27 July 2026
Who we are
“Lens” (“we”, “us”) is the UX research repository available at lensresearch.app. Lens is operated by Erik Niemeijer, based in the Netherlands, who is the data controller for the purposes described below. For any privacy question or to exercise your rights, contact us at [email protected].
Where Lens is self-hosted by your organisation on its own infrastructure, that organisation — not us — controls the hosting and this statement describes the software’s behaviour rather than a service we operate for you.
Cookies and browser storage
This website uses no tracking cookies and no third-party analytics.We don’t run Google Analytics, advertising pixels, or session-recording tools, and we set no cookies for marketing or profiling. There is nothing here to “consent” to, which is why you won’t see a cookie banner.
What we do use is strictly functional, first-party browser storage:
- Theme preference — remembers light or dark mode on your device.
- Application state — once you sign in, your session and interface preferences are stored locally so the app works and remembers your view. This exists only after you choose to log in.
Fonts are self-hosted from our own domain, so simply visiting the site sends no data to Google or other font providers. None of the above is used to track you across sites.
Information we collect
When you visit the website. Our hosting provider (Hetzner) keeps short-lived, security-related server logs (such as IP address and request details) to protect the service against abuse. These are not used to build a profile of you.
When you request access. The “Request access” form collects the details you provide — typically your name, work email, and any message — so we can respond to your enquiry and follow up.
When you use the app. We process:
- Account data — name, email, role, and workspace membership needed to authenticate you and run the service.
- Research content — the projects, interviews, notes, insights, and participant records you and your team create. This content can itself contain personal data about research participants.
Your data and our role
For personal data contained in the research content your team uploads (for example, interviewees and participants), your organisation is the data controller and Lens acts as a data processor on your behalf, under a data processing agreement. For your account information and interactions with our website, Lens is the controller.
How we use data and our legal bases
- To provide the service — performance of our contract with account holders.
- To respond to access requests and enquiries — our legitimate interest in answering you, or steps taken at your request before a contract.
- To keep the service secure and reliable — our legitimate interest in preventing abuse and protecting data.
- To send you optional updates — only where you have consented, and you can withdraw at any time.
- To meet legal obligations — where the law requires it.
AI features
AI features are optional and use a key you provide. When you invoke one, the relevant text is sent — through our server — to the AI provider your workspace has configured (for example Anthropic, OpenAI, xAI, or Google), which processes it under its own terms solely to generate a response. We do not use your research data to train AI models.
You can enable PII redactionin Settings, which removes emails and phone numbers from text before it is sent to the AI provider. If you don’t configure AI, no data is sent to any AI provider.
Sharing and sub-processors
We don’t sell your data. We share it only with service providers that help us run Lens, under appropriate agreements:
- Supabase — database, authentication, and file storage, hosted in the European Union.
- Hetzner Online GmbH — application server infrastructure, in EU data centres.
- Figma — only for tests that embed a Figma prototype, and only from the participant’s own browser when they start it: Figma then sees their IP address and may set cookies. Participants are told this before they take part.
- Your configured AI provider — only when you use AI features, and only for the text involved.
- Email delivery — to send transactional and access-related messages, where applicable.
A current list of sub-processors is available on request at [email protected].
Where your data is held
Our cloud service and its primary database are hosted in the European Union. Where a provider (such as an AI provider you configure) is outside the EEA, any transfer is covered by an appropriate safeguard such as the European Commission’s Standard Contractual Clauses. Lens can also be self-hosted, in which case your organisation controls where data resides.
How long we keep it
We keep account data for as long as your workspace is active and delete it within 90 days of account closure, unless we must retain it longer for legal reasons. Research content is retained under your organisation’s own settings and our agreement with them. Access-request submissions are kept only as long as needed to handle your enquiry.
Security
We use encryption in transit and at rest, tenant isolation between workspaces, role-based access, and encrypted storage for sensitive secrets such as AI keys. No system is perfectly secure, but we work to protect your data and to limit access to those who need it.
Your rights
Under the GDPR you can ask us to:
- access the personal data we hold about you;
- correct inaccurate data or complete incomplete data;
- erase your data, or restrict or object to its processing;
- receive your data in a portable format; and
- withdraw consent where processing relies on it.
Email [email protected] to exercise any of these. If your request concerns research content held on behalf of a customer, we will direct it to that customer as the controller. You also have the right to lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
Children
Lens is a workplace tool and is not directed at children. We do not knowingly collect personal data from children under 16.
Changes to this statement
We may update this statement as the service evolves. We’ll change the “last updated” date above and, for material changes, provide a more prominent notice.
Contact
Questions about this statement or your data? Email [email protected].