Privacy
UtilityLab has no accounts, no cookies and no analytics. Your studies stay in your browser. The only time study data leaves your computer is when you choose to push a survey to your own LimeSurvey server.
Last updated 7 October 2026
What stays in your browser
UtilityLab saves your work in your browser’s local storage, on your device only. It is not sent to us, and we cannot see it. This covers:
- your studies, their earlier designs and the list of studies;
- small settings, such as your theme choice and which notices you have dismissed;
- the LimeSurvey address, username and survey ID you last used, to save retyping. Your LimeSurvey password is never stored.
This data stays until you delete it. Clearing your browser’s data for this site removes it, and Safari may remove it after seven days without a visit. To keep a copy, or to move a study to another computer, download it as a project file (Studies → Download). Project files leave out your LimeSurvey username.
What reaches a server
Loading the site. UtilityLab is hosted by Vercel. Like any website host, Vercel processes standard request information, such as your IP address, browser and the page requested, to deliver the site and protect it from abuse. See Vercel’s privacy policy (opens in a new tab). UtilityLab itself adds no analytics, tracking or cookies, and its fonts are served from this site, not from Google.
Pushing to LimeSurvey (only if you use it). When you press Push or Test connection, your browser sends your LimeSurvey address, username, password and survey ID, and the study’s choice tasks, to a server function run by Vercel in Frankfurt, Germany (EU). The function passes them to your LimeSurvey server, returns the result to you, and then forgets them: UtilityLab does not store or log them. To limit abuse, it keeps your network address in the server’s memory for about ten minutes, and never writes it anywhere. If you would rather nothing leave your browser, download the LimeSurvey file (LSS) and import it yourself.
Feedback. The Feedback form does not send anything itself: it opens GitHub in a new tab with your text filled in, so GitHub receives that text, and the app version and browser if you leave them ticked, when its page loads. Nothing is published until you submit it there, under GitHub’s privacy statement (opens in a new tab).
Images you link. If you add an image address to an alternative, attribute or level, your browser loads the image from that site, which can then see your IP address. The same happens for respondents when an exported survey shows the image. Host images on your survey platform if that matters for your study.
Exports and your respondents
Qualtrics, LimeSurvey and Sawtooth files are created in your browser. Once you import them, that platform’s terms apply. UtilityLab never sees your respondents or their answers: they are collected by your survey platform under your study’s own data protection arrangements.
Your rights
Apart from the hosting provider’s request logs, UtilityLab holds no personal data about you, so there is nothing for us to access, correct or delete. Your browser data is under your control: you can delete studies in the app or clear the site’s data in your browser at any time.
UtilityLab is open source, so all of the above can be checked in the source code (opens in a new tab). Questions can be raised as a GitHub issue (opens in a new tab), or privately with the maintainer, Ioannis Tsouros (opens in a new tab).
Changes
If this page changes, the date at the top changes too, and every earlier version is kept in the project’s history on GitHub. See also the terms and disclaimer.