Skip to main content

Anonymity and data handling in surveys

This page describes what Pomelo actually stores when students answer surveys, and what is visible to whom. It complements How we work with GDPR.

Students never sign in​

Students taking part in a survey use a code per occasion. Pomelo creates no login for them: no password, no profile, no session beyond the moment of answering.

The participant is given a temporary identity that exists only during the survey occasion and is not saved afterwards.

No personal data about students is stored at all. The school sets up classes with a name and a number of students — not individual students.

If the school is connected via Skolon​

Class lists are then retrieved automatically from Skolon. The students are counted to give the class its size and year group, and no data about individual students is stored. Student accounts created by earlier versions of the service are deleted automatically at every synchronisation.

Only staff accounts are created via Skolon. Students do not sign in, and a response is stored without any link to a person.

Responses cannot be linked to a student​

A response from a student who signed in with a code is stored without a sender. There is no link between the response and a person, either in the interface or in the database.

The consequence runs all the way through:

  • The teacher sees how many have answered, never who.
  • No one can later find out what an individual student answered — not the teacher, not the school's administrator, not us.
  • For the same reason, an individual response cannot be removed afterwards. There is nothing to point at.

This applies to the pulse survey, the check-in survey and the exit ticket survey — and it applies whether or not the school is connected via Skolon.

Answers from one sitting belong together​

A response is stored with no sender. Pomelo still has to know which answers came in at the same sitting, so that a survey can be reported broken down by how the pupils answered one of its own questions (see Questions about the pupil).

Every response is therefore marked with a key that is generated at random per sitting. It is created when the pupil enters the code and is never stored as an account. The key does not identify a person, it exists in no other register, and a pupil answering the next survey is given a new one.

Protection against duplicate responses​

To stop the same student answering twice on the same device, a marker is stored locally in the browser recording that the occasion is complete. The marker contains no information about the person, only which survey occasion it concerns.

It stays in the student's browser and is never sent to us. A student who switches device can therefore answer again — the protection is a safeguard against mistakes, not a hard block.

The class's results​

The teacher sees the class's responses as summaries: distributions, averages and counts. The basis is the whole class, never individual rows.

A result is never shown for fewer than two respondents. If only one student has answered there is no summary to show — an average of a single response is that response. In a class where the teacher knows who was present, it could identify who answered.

The floor applies everywhere the class's responses are presented: the pulse survey, the check-in, the exit ticket survey and the detailed statistics. It cannot be bypassed — not even by closing the survey early, which otherwise lets the teacher proceed without everyone having answered.

Recommendations are not results. Which strength Pomelo suggests the class train is a pedagogical proposal from the service, not an account of what the students answered, and is therefore always shown. What the teacher does not get to see is the summary of the responses: distributions, averages and counts per question.

The floor therefore does not stop the teaching. The teacher can move on, choose a strength and let the class train even when only one student has answered — how far a class project is taken is the teacher's decision. What is held back is insight into the responses, until at least two students have answered.

Questions about the pupil​

A survey may contain a question about the pupil themselves, whose answer the other answers can be grouped by. The teacher can then see how different groups in the class answered, rather than only the class's combined figures. Today there is exactly one such question, and it asks about gender.

The question is answered like every other question in the survey. The answer options are Boy, Girl, Other and Prefer not to say, and each one forms a group of its own — no pupil falls outside the grouping.

A group's answers are shown only if at least five pupils answered within that group. The groups that reach it are shown; the rest are withheld individually. A withheld group appears with its name and nothing else — how those pupils answered the survey's other questions is not reported.

Nor is the number in a withheld group reported, and a group no pupil chose is withheld the same way. That is what makes "nobody chose this" and "four chose this" look identical.

That threshold is higher than the two respondents that apply to the class's results generally. A group is built from a subset of the class and is therefore always smaller than it, and in a class where the teacher knows the pupils, a small group says a great deal about the individuals in it. In a class of ordinary size, not every group will reach five.

Answers to such a question never count towards the class's strengths, towards the recommendation of what the class should train on, or towards the comparisons with other schools.

Comparisons between schools​

A class's results can be compared with other schools at four levels: the school, the municipality, the country and globally. The comparisons are built from de-identified, aggregated figures.

An average is never shown for fewer than ten responses. Where the basis is below ten, the value is shown as hidden together with the count instead. This prevents a small group from being worked backwards to individual students.

That is a higher bar than the one for a class's own results (two respondents), and deliberately so: a comparison sets several schools' data against each other, and the smaller a compared group is, the more it says about the individuals in it.

Groups marked as administrative — staff groups, teaching teams — are not included in the comparisons at all.

The comparisons are recalculated every night and never run directly against other schools' raw responses.

Staff have accounts​

Teachers and administrators have real accounts with a name and an email address. What is stored about them is the account data, which groups they belong to, and when they last signed in.

When a staff account is deleted it is anonymised: the name and email address are overwritten and the person can no longer sign in. Class projects and surveys the person created remain, without pointing to a named individual.

Reviews shared between schools​

Teachers' ratings and comments on exercises are deliberately visible to teachers at other schools. They are shown with first name and initial, school and municipality.

This is the only personal data in Pomelo that is deliberately shared outside the school itself, and it always comes from a teacher — never from a student. Students' star ratings count towards the average but are not listed.

Where the data is held​

Pomelo runs on servers in Sweden, with a Swedish provider. See How we work with GDPR for how we work with personal data more broadly.