Participant data is stored on your hosted site (*.on.otree.org), on a DigitalOcean server in
Frankfurt, Germany, in a database dedicated to your site. All traffic uses HTTPS.
For this data, your institution is the controller and oTree Limited is the processor.
Participant data is not copied to otreehub.com, except for crash reports: if your experiment's code raises
an error, the site sends otreehub.com the error message, code location and page URL so the bug can be fixed.
Your oTree Hub account and the AI builder are covered by our privacy policy.
The AI builder
The AI builder only sees the researcher's chat messages and the project's code. It has no access to your
hosted site's database or to anything a participant entered.
What is stored about participants
The data your experiment collects.
The participant label, if your recruitment panel passes an ID in the start link.
IP addresses are not stored in the experiment database. The web server's access logs, which include
IP addresses, are deleted within 30 days.
Retention and deletion
Data stays on your site until you delete it. Deleting a site permanently deletes its database.
Backup copies are deleted within 30 days.
Subprocessor
DigitalOcean, LLC (server hosting, Frankfurt, Germany). oTree Limited is incorporated in Hong Kong, so our
DPA includes the EU Standard Contractual Clauses.
Text for your ethics application
You can paste and adapt this:
The experiment will be hosted on oTree Hub (on.otree.org), operated by oTree Limited. Participant data will be stored on a server in Frankfurt, Germany (EU), in a database dedicated to this study, and transmitted only over encrypted (HTTPS) connections. No participant data is processed by AI services. Participants will be identified only by a pseudonymous ID. IP addresses are not stored with the research data. oTree Limited acts as a data processor under a Data Processing Agreement with [institution]. After data collection, the data will be downloaded to [institution's storage] and deleted from the hosting server.