Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains how we collect, use, store and protect your personal data when you use the ScaleForm platform. By using the platform, you accept the practices described in this policy.
1. Who We Are
ScaleForm is a web-based digital scale and survey platform built for researchers and academics. It lets you create Likert and similar scales and questionnaires, collect participant responses, measure the completion time of each response, run automated data-quality and suspicious-response checks, and export your data in CSV, Excel or SPSS format.
The platform is operated from Türkiye. ScaleForm is the data controller under this policy. For any questions or requests, you can contact us at cahitgs@gmail.com.
2. Data We Collect
Depending on how you use the platform, we process the following categories of data:
- Account data: The email address and name you provide at sign-up, and optionally your institution.
- Form content: The scale and survey definitions you create, including questions, answer options and configuration settings.
- Participant responses: Answers submitted to your forms; optional demographic information where collected (age, gender, education level, etc.); the completion time and timestamps of each response; and automatically generated data-quality and suspicious-response flags.
- Technical data: Session and authentication information required for the service to operate securely.
By enabling the anonymous response option on your forms, you can collect participant data without identifying the individual. As the researcher creating the form, you largely decide which data is collected.
3. How We Use Data
- To create your account and provide the service to you.
- To host your scales and surveys, and to collect and store responses.
- To provide analytical features such as response-time measurement, data-quality checks and suspicious-response detection.
- To let you export your data in CSV, Excel and SPSS formats.
- To maintain the security, integrity and operability of the platform.
- To communicate with you about important service-related matters.
4. Legal Bases
When processing your personal data, we rely on the following legal bases (under Article 6 of the GDPR):
- Performance of a contract: To manage your account and provide the service.
- Legitimate interest: To keep the platform secure, prevent abuse and improve the service.
- Explicit consent: For optional demographic data provided by participants when responding. You can withdraw consent at any time.
- Legal obligation: To comply with legal requirements that apply to us.
5. Data Processors and Infrastructure
To deliver the service, we use the following trusted infrastructure providers as data processors:
- Supabase: Database hosting and authentication.
- Vercel: Hosting and serving the application.
- Paddle: Payment processing (see below).
These providers process your data only to provide services to us and in accordance with our instructions. We do not sell your data to third parties.
6. Payment Data
For paid plans (the Researcher plan at $7/month; monthly, no commitment, cancel anytime), payments are processed by Paddle.com acting as the Merchant of Record. This means Paddle issues the invoice, collects and remits global taxes (VAT/sales tax), and handles refunds.
ScaleForm does not store or directly process your credit card details. The processing of your payment information is governed by Paddle's own privacy policy. Only limited information, such as subscription status, is shared with us.
7. Cookies
We use only functional cookies and local storage. We do not use advertising or tracking cookies.
- Language preference: The
scaleform_langcookie remembers your chosen interface language. - Session: Secure session cookies used to authenticate you when you are signed in.
- Theme: Your appearance preference (light/dark) is stored in your browser's localStorage.
8. Data Retention and Deletion
Participant response data is under the researcher's control and is retained for as long as your account is active. You can delete a form or its responses at any time; deleted data is permanently removed.
When you choose to close your account, your account and all associated data (including form definitions and participant responses) are deleted. Except for limited records that must be retained for legal obligations (for example, billing records held by Paddle), your data is deleted within a reasonable period.
9. Your Rights
Under the GDPR and Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK), you have the following rights:
- Access: To access the personal data we process about you.
- Rectification: To request correction of inaccurate or incomplete data.
- Erasure: To request deletion of your data (the "right to be forgotten").
- Portability: To receive or transfer your data in a structured, commonly used format.
- Objection: To object to certain processing activities and to withdraw consent you have given.
To exercise these rights, you can use the relevant tools in your dashboard or reach us at cahitgs@gmail.com. Users in Türkiye also have the right to apply to the Personal Data Protection Authority (KVKK) to exercise their rights and submit complaints.
10. International Data Transfers
The infrastructure providers we use (Supabase, Vercel, Paddle) may process your data on servers outside Türkiye. In such cases, we work with providers that include appropriate safeguards (such as standard contractual clauses) to ensure your data is transferred with the level of protection required by the GDPR and KVKK.
11. Children
ScaleForm is not directed at individuals under the age of 18, and we do not knowingly collect personal data from them. Researchers are themselves responsible for obtaining any required legal permissions (including parental consent) where minors participate in their studies.
12. Security
We apply industry-standard measures to protect your data. Data is encrypted in transit using SSL/TLS. At the database level, Row Level Security (RLS) policies ensure that each user can access only their own data. While no system can guarantee absolute security, we maintain reasonable technical and organizational measures to protect your data.
13. Contact
For questions about this Privacy Policy or the processing of your personal data, you can contact us at cahitgs@gmail.com. We may update this policy from time to time; for significant changes, we will revise the "Last updated" date on this page.