Obsera
How your data is kept.
Short version: your observations are kept apart from your name, only you can read your notes, and nothing leaves the Observatory except figures about groups of ten or more.
Two separate places
Your account, your membership and your payments live in one database. Your observations live in a different one, under a random participant id that never sits next to your name or your email. The two are held apart on purpose.
The one thing that can pair them is a small, locked function that runs when you sign in. It looks up your participant id, hands the app a short-lived pass for it, and writes a line in a log every time it does. No person, dashboard or export can do that pairing.
What we ask for
An age band, where you are in your cycle or menopause, and whether you use HRT. All as bands, none as exact figures.
You can also add six measurements if you want to: height, weight, waist, your average sleep, your resting heart rate and the steps in a typical day. Every one of them is optional and a blank is a perfectly good answer. You enter them yourself — Obsera takes nothing from a phone, a watch or any other app — and, unlike the bands, they are kept exactly as you type them. They sit beside your own patterns as context: no reading, state or suggested experiment is calculated from them. They are part of your export, they can be cleared at any time from your account, and they are erased with everything else.
We never ask for your occupation or your address inside Obsera. Dates are kept to the day for you, to the week in your own timeline, and to the month in anything that leaves. The one exception is the hour of a Capacity Check, explained below.
Your Capacity Checks
A Capacity Check is five short tasks: reaction, attention, sequence memory, rule switching, and placing objects to recall later. Before it we ask how sharp you feel, 0 to 10, and four quick questions about the last night and the last two hours: how long you slept, caffeine, alcohol, and whether exercise came just before. All of that is kept, under your participant id, because time of day, sleep and coffee change how anyone does on these tasks and the check is only readable beside them.
We keep the raw log of every task: each thing shown, whether and how fast you responded, and whether it was right. We also keep which device you used (a phone, a tablet or a computer, nothing more specific), the calendar day, and the hour of the day. The hour is the one place Obsera keeps anything finer than the day, and it is kept for this reason alone.
Your scores are not compared with anyone else’s. Your first check is your own 100; later checks are read against it. When you are offered a short intervention, a walk, a breathing pattern, a few minutes outside, we keep which one, how sharp you felt before and after, and the state you were in at the time. That before-and-after record is what lets Obsera notice what appears to help you. None of it is a test result, and it does not diagnose anything.
Capacity Checks and intervention responses are part of your export and are erased with everything else. If you are taking part through your employer, your employer never sees your checks: only figures about groups above a minimum size, ranking interventions and never people.
If you join through your employer
Your employer gives you a code. The code lets you in without a membership; it does not tell Obsera who you are, and it is not stored beside your observations. Everything above is the same for you: your record sits under a random participant id, apart from your name.
What your employer receives is a report about the group, and only where the group is big enough. Every figure in it is about at least ten people, or it is left out and the report says so. The report says how many people took part, how the group’s Capacity Index moved, which short interventions appeared to help the group most, and under which conditions, short sleep, say, or the time of day, the group felt less sharp. It never contains your name, your id, your checks, your responses, your notes or your reason for joining, and it cannot be taken apart to find one person. A copy of every report handed over is kept, exactly as it was handed over.
A facilitator can see whether and when you last took part, so they can check in with you if you go quiet. They cannot see what you recorded. If you said yes to contributing to aggregated learning, a named researcher may receive your rows under your participant id and the month, never the day, the hour or a note. If you said no, no researcher receives them.
When your cohort ends, nothing is taken from you: your account, your observations, your export and your erase button all stay yours.
Your field notes
Field notes are free text, so they are the most personal thing here. Each note is encrypted on your device before it is sent, and the observation project stores only the ciphertext; the key is held by the sign-in service, apart from the observations, and handed to your device when you sign in. Notes are never counted in any figure and never shared for research. They are part of your own export, and erased with everything else. Anonymised quotes are off unless you switch them on; while they are off, no one at the Observatory can read a note.
Three choices, yours to change
- Use Obsera. Needed for the app to work at all.
- Contribute to aggregated learning. Optional and separate from your membership. If you say yes, your observations can be counted in group figures. If you say no, they never are.
- Allow anonymised quotes. Off unless you switch it on. Reviewed by a person before any use.
Change any of them from your account at any time. Every record remembers which version of these choices it was made under.
What leaves
Only aggregates: figures about groups of ten or more people, with small cells hidden and averages rounded. When research partners receive data, they receive participant ids and months, never notes and never the pairing. In their hands it is anonymous.
Export and erase
From your account you can download everything recorded here, or erase it. Erasing removes your observations and the pairing. Where contribution was switched on, figures already published stay published, because they were never about you alone.
Where and who
Everything is stored in London. River Arts Observatory Ltd is the data controller. The full privacy notice explains the lawful basis, retention and your rights under UK data protection law.
Obsera supports self-observation and pattern awareness. It does not diagnose, treat or monitor medical conditions and is not a substitute for professional healthcare.