Skip to main content
Data masking detects personal data in open text responses and replaces it automatically before responses are translated, classified or exported. It is available as an add-on for your account and is set up once, for all surveys, by an admin.

Two areas are called “Data masking”

Honestly has two areas with this name, and they do different things:
  • Automatic masking lives in your account settings, under Access & privacy → Data masking. It scans every incoming open text response and masks the categories you chose, for the whole account. This is the switch described below.
  • Manual masking is a separate page, Data masking under Settings in the side menu. It lets an admin read through open text answers, mask individual passages by hand and take existing masks back.
Neither area links to the other — you reach each one from the menu. They also work independently: manual masking does not need automatic masking to be switched on. Both are visible only to admins and both require the Data masking add-on.

What data masking does

When it is switched on, every open text response that comes in is scanned for personal data. Anything it finds is replaced with a neutral placeholder — a name becomes a name token, an email becomes an email token — before the response is translated, classified or included in an export. Everyone sees the masked response, and only the masked version is translated, classified, exported and displayed. The original text is stored separately when masking runs. It is never shown beside the masked response, and the only way back to it is an admin removing a single mask by hand on the Data masking page, described below.

Which data is masked

You choose which categories are masked. At least one has to be selected:
  • First name, last name
  • Email address
  • Phone number
  • Postal address
  • Unique IDs / customer numbers
The setting applies to your whole account, not to a single survey. Every survey in the account uses the same masking configuration.

Where to find it

Go to your account settings and open Access & privacy → Data masking. Only admins can see and change it. Switch on Automatically mask personal data, tick the categories you want, and click Save changes. To detect the personal data, the response text is sent to Microsoft (Azure OpenAI). For that reason you have to allow Microsoft as a sub-processor for your account first. Until that consent is given, the masking setting stays locked and cannot be switched on. You grant it in the Subprocessors tab in your account settings.

Masking is not retroactive

Only responses that come in while masking is active are masked. Switching it on later does not change responses that were already collected — those keep their original text. For a survey’s open responses to be masked, the setting has to be active before those responses are submitted.

Mask single passages by hand

Automatic masking only covers the categories you switched on, and only responses that come in while it is active. To mask something it missed — or a passage in an older answer — use the Data masking page under Settings in the side menu. It is a separate page from the account setting above, and the two do not link to each other; you open each from the menu. The page lists your account’s open text answers, not only the ones automatic masking touched, and it works whether or not automatic masking is switched on. Use the survey filter to narrow the list to a single survey, and the Question filter to narrow it further to one question of that survey. The To review and Reviewed tabs each carry the number of answers in them, and Answers per Page sets how many you work through at a time: 10, 20, 50, 100 or 250. The survey, the question and the page size you picked are still set the next time you open the page. To mask a passage:
  1. Select the text you want to hide in an answer.
  2. Under Mask as what?, pick the category that fits — Name, Email, Phone, Address, ID / number or Other.
  3. Click Apply. The passage is replaced with a neutral placeholder for its category.
If the same passage appears in other answers, choose Mask other matches. The preview lists every answer that contains it, with the passage highlighted and a checkbox on each one, so you can untick the answers that should keep their wording before you apply. Because a person does the masking here, no Microsoft consent is needed for it. Each row in the list has a checkbox of its own. Tick the answers you are through with, or tick the whole page from the bar above or below the list, and click Mark as Reviewed to move them to the Reviewed tab in one step. The same bar on the Reviewed tab sends a selection back with Mark as “To Review”. A selection covers the page you are looking at, not the whole survey. A mask can be taken back: click the × on it (Remove mask) and the original wording returns in its place. This works for masks you set by hand and for passages the automatic detection masked, which is how you correct a false positive, a product name read as a person’s name for instance. Removing a mask affects that one passage in that one answer and nothing else. Like automatic masking, this page is visible only to admins and requires the Data masking add-on.

Data masking and anonymity are separate

The two controls do different things and work independently:
  • The anonymity threshold decides whether a response is shown at all.
  • Data masking removes personal details from inside a response that is shown.
A response can be visible because the anonymity threshold is met and still have its personal data masked. For how the anonymity thresholds work, see Open-text anonymity.