What is collected
Your answer (a rating from 1 to 5, or from 0 to 10 for the quarterly eNPS, which your organization can turn off), your OPTIONAL answer to the extra question of the week when your organization asks one (Rarely, Sometimes, Often or a 1 to 5 scale: attached to your weekly answer, detached and deleted with it, only read as a group result above the threshold, and never used to raise an alert), the survey week, your organization, and the segments your organization has defined to group results: your team, your reporting line (the chain of managers above you, whose scopes group your answer), and possibly other axes it created, such as a site or seniority band. There is no precise location or visible timestamp. There is only one free text, and it is OPTIONAL: the anonymous comment you can leave after a low answer (see “If your week went badly”). It is NOT LINKED to anything: not your account, not the time, not your team, not your rating; the database knows that you commented, never what. That is why it can't be given back to you or deleted at your request, and it does not appear in your data export. And content that identifies you identifies you, whatever Kwoji does. Each segment is frozen with your answer when you respond and never read again afterward. This guarantees that changing teams, managers, sites or seniority later can never reveal a past answer. Segments are only used to group results, always above the anonymity threshold.
What is never shown, to anyone
An individual answer. There is no “per person” screen: not for your manager, not for HR, not for the organization owner. During the week, your answer is linked to your account only to prevent duplicate responses, to include your own mood answers when you request your data (your answer to the question of the moment is not included yet), and, if your organization turns it on, to remind by email only the people who have not answered the open week (on Thursday, once per week; the “Stop receiving Pulse emails” link turns it off). Your organization never learns this: it does not know who receives that reminder. Seven days after a week closes, your answer is no longer linked to your account (see “Retention”). Until then, that link is never exposed: no screen, API or export requested by anyone else can reveal who answered what. For ratings, the database only returns averages computed from a minimum number of answers (the anonymity threshold, see below) and, for administrators only, the anonymous comments some people choose to leave, without an author identifier or associated group. Their text can, however, contain a name written by the person commenting. If your organization turns it on (it is off by default) and is on a paid plan, your manager can read in Insights, Pulse section, the average of their direct reports, or that of all their reports (direct and indirect), without their own answer, and in the same way that of each manager below them: it only shows once the week has closed and only if enough other people answered to reach the threshold, never split any other way (not by team, site or seniority), and never the number of answers while it is below that threshold. Your organization's administrators read, manager by manager, exactly the same groups, also without the manager's answer, and nothing more, apart from their participation (see “The anonymity threshold”). This rule is enforced in the database, not just in the interface. And if your organization is on the free plan, it reads nothing beyond the number of answers received: no average, no score, no breakdown by group. A count does not say what anyone answered.
The anonymity threshold
No result is shown below a minimum number of answers, the anonymity threshold: 5 answers by default. Your organization can set it to 4 or 3, never lower (the database rejects any threshold below 3), and only the account owner can change it. A lowered threshold only applies to the following weeks, never to answers already given: they stay protected by the threshold under which you gave them. A raised threshold applies right away to every week. Your organization's threshold is shown in the app: from your voting card, the “How is it protected?” link tells you the one that applies to the current week. The threshold applies to the organization as a whole and to any group (team, site, seniority or any other axis). A group that is too small never gets a figure of its own: it is grouped with others, and if that grouping still stays below the threshold, the smallest neighboring group is hidden too until the hidden groups reach the threshold. The same goes for the org chart: if a manager's reports, minus those of the managers below them, would leave fewer people than the threshold, the smallest of those groups is not shown. This prevents anyone from identifying an answer by cross-checking averages. A manager reads their reports without their own answer, and always across at least as many other people as the threshold. When two groups are almost the same people (a team and a manager's reports, for example), only one of the two is shown: otherwise, comparing the two averages would reveal the answers of a few people. This protection against comparing groups stays on whatever the threshold. It covers everything shown, to the administrators as to each manager, and the screen says which group is not shown, and why. Every average therefore covers at least as many people as the threshold, and no comparison between two groups can get below that. Finally, no result is shown while a week is still open: the organization sees “fewer than N answers” until the threshold of N answers is reached, then the number of answers, never the average move, and results only appear after the week closes on Friday at 6 pm. An average you can watch change answer by answer can be subtracted. In the Overview of Insights, administrators also read each group's average and participation over a period of 30, 90 or 180 days: the average of only the weeks in which the group's average was shown, and the average of its participation rates in those same weeks, without any number of answers. A week in which the group stays below the threshold does not count, and answers from several weeks are never pooled to reach the threshold. Managers' figures can only be read by going down the org chart, one level at a time. The signals of the “To handle” list, read by the administrators, in the same Overview, and by each manager for their own scope, only use these figures already on screen: a published average that falls below its usual values or to 2.5 out of 5 or less, a group lastingly below the average, or a usually published group that falls below the threshold, without ever saying how many, and, after an eNPS week, a published eNPS that is negative or sharply down. They reveal nothing about the answers that the screen does not already show; their strength (clear signal or signal to confirm) also takes into account the number of games played by the group, never by one person. On Friday after the week closes, the administrator designated to follow a team may receive by email the names of that team's strong signals, without any figure or comment.
Retention
Seven days after a week closes, your answer is no longer linked to your account: Kwoji only keeps the score and the groups you belonged to when you voted, and it stays in the averages. The exact time of your answer is erased at the same moment: only the hour remains. Those seven days only serve to fix a mistake if someone reports one. Your data export therefore only returns your answers that are still linked (the open week, and those closed less than seven days ago): it cannot return what is no longer linked to your account. Answers, and anonymous comments with them, are then kept for the whole duration of your organization's contract with Kwoji, until its owner deletes them, and at the latest 30 days after the contract ends. Follow-up actions on a signal (taken in hand, to review, not relevant), taken by administrators or by a manager on their own team's signals, with their date, their author and the average already shown at the time, are kept the same way and deleted with the history. In addition to those actions, the AI summary and the sentence putting an alert in context (see below), aggregated results of closed weeks may be kept in a technical cache, subject to the same anonymity rules, invalidated when data or rules change, and deleted with the Pulse history. Weekly averages and eNPS scores remain based on the answers still present, and the administrator chart, like a manager's, only shows the last 12 surveys. Answering earns no points and affects no leaderboard. If you delete your Kwoji account, your answers stay in the averages but are detached from you right away, without waiting for the seven days. That is what protects the others, and you the following week: if your answer vanished, every week would lose exactly one voice, and the difference between the averages would say what you had answered. Technical backups, kept for 30 days, then erase themselves.
If your week went badly
If your organization has named someone you can talk to (an HR contact, the works council, occupational health...), a low answer (1 or 2 on the week, 0 to 5 on the eNPS) shows “Want to talk about it?” on your card, with that person's name and a way to reach them. This offer only shows on your own screen, right after you vote, and disappears when you reload the page. Nothing about it is recorded or counted: not that it was shown, nor that you clicked. Showing it sends no request: the contact's name comes with the card before you even vote, whether your answer is high or low. And if you choose to reach out, you are the one writing, from your own mailbox or the link provided, in your own name: Kwoji sends nothing on your behalf. The same low answer also offers, below that invitation or in its place, to leave an anonymous comment of up to 500 characters, one per answer. Nothing is sent until you press “Send”, and your text is not kept anywhere on your device. Once sent, it is stored without your account, without the time, without your team and without your rating: the database only remembers that you commented this week, so that there is only one. It is read only by your organization's administrators (never by your manager), once the week has closed, mixed with the other comments in an order drawn at random each time they are read. If your organization has turned on the AI summary, it is also sent, with the week's other comments and exactly as you wrote it, to the model that writes that summary (see “The AI summary”): a name you write in it goes along with it. The anonymity threshold does not apply to comments: in a week where few people answered, a comment can be tied to one of them, which makes the warning all the more important. It goes into neither the printable report nor the exports. An administrator can remove a comment that names a colleague; you, on the other hand, can neither read it again nor have it deleted, since nothing links it to you anymore. So don't write anything that identifies you: a detail, a turn of phrase or a fact few people know can sometimes be enough to recognize someone.
The AI summary
Your organization can ask Kwoji for a written summary of each closed week: a few sentences and the main themes of the comments, to prepare a team meeting. It is optional and off by default: only the administrators of an organization on a paid plan can turn on the “AI features”, and the summary only runs if your organization uses Pulse. The summary is written by a Mistral AI model hosted by Scaleway, in France (Paris region), which receives only two things: the figures administrators already see on screen, never below the anonymity threshold, including those of managers' scopes with the manager's name, as the screen shows them; and the text of the week's anonymous comments, exactly as it was written and as administrators read it, names included: if you name someone in your comment, that name goes to the model too. According to its terms, Scaleway keeps none of this data and does not use it to train a model, except for a request that causes an error, which it may keep for up to two weeks for its own troubleshooting. The summary may comment on a team's or a manager's figures (“the people reporting to this manager are trending down”), but it never ties a comment or a theme to a team, a group or a manager, since no comment carries one: before it is saved, Kwoji automatically checks it, rejects it entirely if a sentence makes that link, and removes any sentence that carries a figure that is not on screen or copies more than five words from a comment. Kwoji keeps that summary, not what was sent to the model, as long as the answers, and deletes it if your organization turns the AI off or if a comment from the week is removed. Administrators read it over before using it. With the same setting, the same model can also write a sentence putting each alert of the “To handle” list in context, from the figures already published for that group only, and pick the suggested action from a fixed list: it receives no comment, and it never decides on an alert. That sentence and that action are kept like the summary, and also deleted if your organization turns the AI off. The same “AI features” setting also lets the mascot of the Galaxy (in the Overview of Insights) answer administrators' questions: it sends the same model, at Scaleway, the question exactly as written and the Galaxy's figures by group, including the published mood, never below the anonymity threshold, with managers' names in “X's team”; never an answer, never a comment. Kwoji keeps nothing of that exchange.