How anonymity works
FDBK only works if the people you ask can afford to be honest. This page explains what happens to a response after someone writes it, what the person who asked can and cannot see, how the report gets written without anyone's words in it, and where the limits are.
Why it matters
The people around you carry a detailed picture of you. Most of them will never share it. Saying it out loud has a social cost, and the relationship is usually worth more to them than the observation, so the picture stays where it is.
Anonymity is what removes that cost. It is the reason someone will finally tell you the thing they have been sitting on for two years. Everything below exists to keep that trade honest: real cover for the person answering, and feedback worth reading for the person who asked.
What the person who asked can never see
- Individual responses. The person who created the form cannot read them through any part of the product. There is no screen in FDBK that shows them, and no setting that turns them on. This is enforced in the database itself, not just in the interface: their account has no read access to the responses table at all.
- How many people replied. No counts, no progress bar, no “a few people said.” The number is never shown in the app, in an email, or in the report. Their account cannot read the counters either, so the dashboard works from a handful of coarse states instead: collecting, nearly ready, ready.
- Which link came back. They can see which links they have copied and sent. They cannot see which ones were used. Their account has no read access to that column, so a link that has been answered and a link that has not are indistinguishable to them.
- How you described your relationship. That box is optional and free text. Before anything reaches the AI, your words are replaced with one broad category: friend, family, coworker, partner, or other. Only the category is ever used. What you actually typed is never shown to the person who asked and never reaches any stage of the writing process. It stays in our database, which is covered further down.
What is and isn't recorded when you open a link
The feedback page carries no analytics scripts, no advertising or social pixels, and no fingerprinting, and it sets no cookies while you read it, fill it in, or submit it. Nothing on that page tries to work out who you are. Being complete about it, three things do happen:
- We count that a page was opened. When a valid link is opened, our server adds one to a count kept against the form. It records no identity, no link code, and nothing about your device or browser, and the person who asked cannot see it. It exists so we can tell how many people who receive a link actually open it.
- Your IP address is used briefly, and not stored. Like any website, our servers see the address your request comes from. We hold it in memory for about a minute to stop someone flooding the form with junk. Our application never writes it to the database and never connects it to your answers.
- Saving your own form sets a cookie, on purpose. After you submit, we offer to save you a feedback form of your own. If you tap that button you are choosing to start your own account, and that step sets a cookie so your draft survives signing up. Answering someone else's form never does. If you close the page instead, nothing about you is kept.
How the report gets written
A report is written by three separate passes of an AI model, and the split between them is the whole point.
The first pass reads. It sees the responses and writes a set of observation notes: the themes that came up, what they suggest, the tensions underneath them. It is required to write those notes in its own plain language, and to organize them by theme rather than by who said what. Specific wording, invented images, jokes and stories are left behind at this step.
The second pass writes. It writes the report you actually read, and it is handed the notes and nothing else. It has no access to the responses at all. That distinction is worth being precise about: the writing stage is not merely instructed to avoid quoting anyone. It has nothing to quote from. We hold ourselves to that with an automated test that fails if anyone ever wires the responses into that stage.
The third pass checks. It compares the finished report against the original responses, hunting for anything traceable to one person: wording that survived, an image or anecdote someone invented, a hint at how many people said something, an observation pinned to a relationship. Alongside it, a plain mechanical scan looks for verbatim phrases carried across, and for email addresses, phone numbers, links and handles.
A report that fails either check is thrown out and written again from scratch. That happens routinely and is a normal part of how the system runs. It is not unlimited: after three attempts we stop, and the person who asked is told their report is delayed rather than being handed one that did not pass. We would rather deliver nothing than deliver something that points back at you.
The checking pass does read the original responses. It has to, because it is comparing them against the report to catch anything that slipped through. It never writes any part of what the person receives.
The rules the AI works under
- Aggregate language only. A report can say a pattern is there. It cannot say how many people mentioned it, or lean on “several” or “most” to imply a number.
- No attribution by relationship. Observations are never tied back to a coworker or a family member in any way that would narrow down who wrote them.
- Distinctive lines get dissolved. When someone answers with a phrase so specific and well-turned that its author would recognize it on sight, no amount of rewording makes it safe to keep. The rule is to fold the underlying point into a broader theme, or to let it go. This costs the report good material, deliberately.
- The coach follows the same rule. If someone subscribes to coaching on their report, the coach works from the published report and nothing else. It has not seen the responses either, and it will say so plainly if asked who said what.
The models doing this work are Claude models, run through Anthropic on our instructions. We have not built or trained a model of our own. What is ours is the pipeline above: which stage sees what, the rules each one works under, and what has to pass before anything is published.
Who at FDBK can see what
FDBK is small, and being straight about this is more useful than implying the data sits somewhere nobody can reach. Responses and the relationship text you type are stored in our database. No customer account can read them. The person who runs FDBK holds the administrative keys to that database, as the person running any service does, and can therefore reach them directly.
What we commit to is the practice around that: those keys are used to operate and repair the product, not to browse what people wrote, and we will not read responses to satisfy anyone's curiosity, including our own. Nothing in the product exposes them to anyone else, and we do not sell data or share it for advertising.
Two things we will not claim
That it is unbreakable. Nobody honest can say that about any system. What we can describe is what the product does, which is everything above: the person who asked has no path to individual responses, the stage that writes the report cannot see them, and nothing is published until it has been checked against them.
That the maths can be beaten. If someone sends a single link to a single person, that person is the only one who could have answered it, and no amount of careful writing changes that. The fewer people asked, the more a report narrows down. This is why reports need several responses before they are written at all, and why the writing gets more cautious the smaller the group. It is a real limit and we would rather you know it than discover it.
If something here does not sit right with you, you are under no obligation to answer a form, and you can close the page without anything being recorded. Questions are welcome at [email protected]. Our privacy policy covers what we store and for how long.