Collect what the research needs—and understand what it reveals

Citizen science data can include accounts, precise locations, timestamps, images, device information and sensitive local knowledge. Responsible design starts before the consent screen.

Security and privacy are defaults in Pocket Science delivery, not optional extras. They are designed into accounts, permissions, collection, storage, exports, hosting and maintenance from the beginning.

Participant-facing research often combines data that seems harmless in isolation. A photograph, precise coordinate and timestamp may reveal a home, workplace, protected species, vulnerable site or individual routine. The technical design must reflect the actual context.

Data minimisation is architectural

Before choosing fields and permissions, establish why each element is needed, who can access it, how long it must be retained and what can be made public. Collecting everything “for later” creates scientific ambiguity as well as privacy risk.

  • Purpose and lawful basis
    Align collection and processing with the project’s approved governance.
  • Participant choice
    Make consent and optional public sharing distinguishable where required.
  • Location protection
    Consider rounding, delay, aggregation or access control for sensitive places.
  • Media review
    Address faces, identifiers, embedded metadata and inappropriate content.
  • Access and retention
    Define research, operational and public roles plus deletion processes.
  • Security
    Authentication, authorization, encryption, logging, updates and incident ownership.

The interface is not the governance

An app can implement consent choices and access controls, but the project owner remains responsible for legal, ethical and research decisions. Pocket Science works with those qualified owners to translate approved requirements into the system.

Worldwide projects need explicit scope

Pocket Science works internationally. Applicable law, institutional review, participant age, data location and partner responsibilities must be established for the actual deployment. European GDPR experience is useful, but it is not presented as a universal legal answer.

Design this into your project

These decisions are most effective when made with the research method and participant workflow—not added after the app has been built. Tell Pocket Science about the goal, participants and constraints.