Inclivio Logo

For researchers

Inclivio and your IRB application

What Inclivio collects from participants, how it protects that data, and what happens to it when your study ends. Use this page to answer your IRB's questions, and copy any of it into your protocol. Have a question we don't cover? Contact us or email support@inclivio.com.

Responses stay in your survey

Answers are stored in Qualtrics, REDCap, or your own platform, not in Inclivio.

Encrypted everywhere

Data are encrypted by TLS in transit and AES-256 at rest, on Google Cloud.

No data sold

Inclivio does not, and will never, sell, rent, or lease participant information.

Hosted in the US

Inclivio runs on Google Cloud on servers in the United States.

How Inclivio fits into your study

Inclivio schedules and delivers survey prompts, called pings, to your participants by text message, WhatsApp, email, or push notification through the Inclivio app for iOS and Android. Each ping contains a link. When a participant taps it, Inclivio records the click and sends the participant to your survey.

Your questionnaire lives in your own survey platform, such as Qualtrics or REDCap. Inclivio does not host questionnaires and does not receive or store survey answers. For most IRB applications, this means the data your study collects is governed by your survey platform. Inclivio holds only the contact and scheduling information needed to deliver pings.

Language for your protocol

You can adapt the paragraph below for the data security or study procedures section of your IRB application. Replace the bracketed text to match your study.

This study will use Inclivio (inclivio.com), an experience sampling platform, to send survey prompts to participants by [text message / WhatsApp / email / push notification through the Inclivio mobile app]. Each prompt contains a link to a survey hosted in [Qualtrics / REDCap / other]. Survey responses are collected and stored in [Qualtrics / REDCap / other] and are not stored by Inclivio. To deliver prompts, Inclivio stores each participant's name, email address, phone number, and time zone, along with a record of when each prompt was sent, opened, and completed. Inclivio does not collect location, sensor, or wearable data. Inclivio is hosted on Google Cloud in the United States, and all data is encrypted in transit (TLS) and at rest (AES-256). Only study team members who have been granted access to the study project in Inclivio can view participant information.

What Data Inclivio collects

Participants create an Inclivio account when they join a study. Inclivio stores the following information to deliver pings and to let you monitor participation.

InformationWhy Inclivio stores it
Name, email address, and phone numberTo create the participant's account and deliver pings. The phone number is verified by text message at sign-up.
Time zoneTo send pings at the right local time, including across daylight saving changes.
Ping activityWhen each ping was sent, opened, and completed, and when reminders went out, so you can monitor compliance.
Custom ID and custom survey parameters (optional)Identifiers and values you or your survey assign, passed into later survey links. Custom parameters are encrypted by Inclivio's servers before they are stored.
Device information (app users only)Device model, operating system, and notification permission, to deliver push notifications.
In-app messages (if you turn messaging on)Conversations between your study team and participants. Messages are encrypted on the sender's device before they are sent.

What reaches your survey

Inclivio adds parameters to each survey link so you can match responses to participants and pings without collecting identifiers in the survey itself:

  • participantid, a random ID Inclivio assigns to each participant
  • customid, your own ID for the participant, if you set one
  • projectid, scheduleid, and pingid
  • Ping timing: time sent, time zone, study day, and ping number
  • Any custom survey parameters you have set

Participant names, email addresses, and phone numbers are never added to survey links. Your survey data stays pseudonymous unless your survey asks for identifying information itself.

Learn how to set this up for Qualtrics or REDCap.

Anonymous projects

If your protocol requires that the study team never see who participants are, create the project as an anonymous project. Inclivio then never sends participant names, email addresses, or phone numbers to the study team, in the web app or through any export. You track participants by their Inclivio participant ID or by a custom ID you assign when you invite them.

Inclivio still stores participants' contact details, because it needs them to deliver pings. An anonymous project keeps those details from your study team. It does not stop Inclivio from storing them.

See Anonymous Projects in the Help Center.

How data is protected

Encryption

Every connection to Inclivio uses TLS. All stored data is encrypted at rest with AES-256 by Google Cloud. Custom survey parameters get an additional layer of encryption from Inclivio's servers before they are written to the database. All in-app communication is end-to-end encrypted, so Inclivio cannot read it.

Study team accounts

  • Users can turn on two-factor authentication for extra security.
  • Users are signed out automatically after 15 minutes of inactivity.
  • Sessions end after 12 hours, enforced on Inclivio's servers, in line with the NIST SP 800-63B reauthentication limit.

Access within your study

  • Each project has one owner, and only the owner can delete it.
  • The owner can share the project with collaborators as read-only or with full access. Only full-access collaborators can edit or remove participants.
  • Seeing participant messages and sending them are separate permissions, so you can limit who talks to participants.
  • Survey requests that change a participant's schedule, save custom parameters, or send email must include an API key unique to your project.

Audit logging

Inclivio logs sign-ins, failed sign-in attempts, sign-outs, data exports, and every request that reads or changes study data, with the user and time.

Message delivery

Text messages, WhatsApp messages, and emails pass through phone carriers and email providers, as any such message does. A ping contains your message text and a survey link, never survey content. For sensitive studies, consider push notifications through the Inclivio app, and write ping text that does not reveal the topic of your study to someone glancing at a participant's phone.

Service providers

Inclivio uses the following providers to run the service and deliver pings.

ProviderPurpose
Google Cloud and FirebaseHosting, database, sign-in, and push notifications
Apple Push Notification servicePush notifications on iOS
Twilio and VonageText message and WhatsApp pings
SendGridEmail pings and account emails
StripeResearcher billing only. No participant data is sent to Stripe.

Enrollment, consent, and withdrawal

Enrollment

You invite participants by email, or share a project-wide enrollment link and set the maximum number of participants who can join through it. Participants create an account with their name, email address, phone number, and a password. They can then receive pings by text, WhatsApp, or email, or install the Inclivio app for push notifications.

Informed consent

Inclivio does not collect informed consent for you. Obtain consent as your protocol describes, for example in a consent survey before you invite participants. Your consent form should tell participants which ping channels you will use, and that Inclivio stores their contact details to deliver pings.

Withdrawal

Participants can stop receiving text and WhatsApp pings at any time by replying STOP, and Inclivio notifies you by email when they do. They can turn off app notifications in their phone's settings. To withdraw from the study, participants contact the study team, and you remove them from the project.

Export, retention, and deletion

Export

You can export your participant list and each participant's ping activity as CSV files. Every export is recorded in Inclivio's audit log.

Retention

Two days after a ping is sent, Inclivio removes the participant's phone number and email address from its record, keeping only the timing and activity needed for your compliance reports. Inclivio does not automatically delete study data when a study ends. When data collection is finished, deactivate the project so that no further pings are sent.

Deletion

Removing a participant takes them off your project. Deleting a project removes its participants, schedules, invitations, and collaborator access. These actions do not delete participants' Inclivio accounts or the project's ping history. If your protocol requires all study data to be permanently deleted, email support@inclivio.com and we will delete it.

Questions from your IRB

If your IRB has a question this page does not answer, or your study involves protected health information under HIPAA, contact us before you enroll participants. We are happy to help with your application.

See also our Privacy Notice and Terms of Service.

Essential cookies are always on because the site can't work without them. Everything else is your choice.

Essential

Always on

Sign-in, security, payments, and remembering this cookie choice. The site can't work without these.

Cookies: inclivio_consent, __stripe_mid, __stripe_sid, _GRECAPTCHA

Analytics

Aggregated stats on which pages get used, so we know what to improve.

Cookies: _ga, _ga_*

Advertising

Lets us measure which ads bring researchers to Inclivio.

Cookies: __oppref, __obref