What is an Institutional Review Board?

Institutional Review Board (IRB) Information

Read Our Privacy Policy Here

Privacy Policy

• Please visit https://app.expiwell.com/privacy for the full ExpiWell Privacy Policy.

ExpiWell Data Security and Privacy information

• ExpiWell uses the industry's best standards to protect customer data and data collected for research.
• Our servers are protected by high-end firewall systems, and scans are performed regularly to ensure that any vulnerabilities are quickly found and patched.
• ExpiWell uses Transport Layer Security (TLS) encryption, or HTTPS, for all transmitted data. All stored data is encrypted at rest using a standard Amazon EBS encryption protocol.
• Our services are hosted by Amazon Web Services (AWS), which is a well-known and trusted data center that meets the requirements of security-sensitive organizations while providing data privacy.
As further discussed in the web link: https://aws.amazon.com/compliance/data-privacy-faq/ "AWS's alignment with ISO 27018 has been validated by an independent third-party assessor. ISO 27018 is the first International code of practice that focuses on the protection of personal data in the cloud. It is based on ISO information security standard 27002 and provides implementation guidance on ISO 27002 controls applicable to Personally Identifiable Information (PII) processed by public cloud service providers. This demonstrates to customers that AWS has a system of controls in place that specifically address the privacy protection of their content."
• ExpiWell subscribers control their users and their data. Therefore, it is important for subscribers to practice sound security practices by using strong account passwords, not storing passwords in easily accessible places, and restricting access to their accounts to authorized persons who can access data.
• ExpiWell researchers control their users and their own participant data. Researchers may request any of their data to be deleted, and it will immediately be removed from ExpiWell's databases. To make a deletion request, Researchers must select the item they wish to delete and confirm they would like to send their request. ExpiWell performs daily backups, and thus, the deleted data will be retained for a set period of time. After this retention period (8 days), the Data will be automatically removed from ExpiWell's servers. 

Personally Identifiable Information (PII) and Passive info

• ExpiWell collects sensitive information and follows industry standards to protect this data (see above). Information that may be collected include: first name, last name, date of birth, ethnicity, gender, country, and state.
• This information collected is for the purpose of building a Participant's ExpiWell profile and is not shared with Researchers at any time.
• Submission data may also include sensitive information but will not include profile information, and both are protected under our Data Protection practices.
• ExpiWell currently collects only two forms of passive information.
One form of passive information includes location or GPS (long., lat., and time zone) data. If Researchers enable data location collection, Takers must first consent to allow passive GPS information to be collected. ExpiWell requests access for Participants' phone microphone, camera (photo and video), storage, and GPS (long., lat., and time zone). We do not store any device identifiers or any other passive information that would link back to the user on the app side.

The second form of passive information includes anonymous passive app usage data for the purpose of detecting mobile issues and performance metrics.

Data Protection and Retention

ExpiWell servers are protected by high-end firewall systems, and scans are performed regularly to ensure that any vulnerabilities are quickly found and patched. ExpiWell uses Transport Layer Security (TLS) encryption, or HTTPS, for all transmitted data. Our services are hosted by Amazon Web Services (AWS), which is a well-known and trusted data center that meets the requirements of security-sensitive organizations while providing data privacy.

ExpiWell Researchers control their users and their own data. Researchers may request any of their data to be deleted, and it will immediately be removed from ExpiWell's databases. To make a deletion request, Researchers must select the item they wish to delete and confirm they would like to send their request. ExpiWell performs daily backups, and thus the deleted data will be retained for a set period of time. After this retention period (8 days), the Data will be automatically removed from ExpiWell's servers. It is important for Researchers and their users to practice sound security practices by using strong account passwords and not storing passwords in easily accessible places. It is also important that they are restricting access to their accounts to authorized persons who can access data.

ExpiWell Data Privacy and Security: IRB application

  1. ExpiWell takes data security and privacy seriously, adhering to rigorous standards to protect participant information. With third-party verification, the software complies with both the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR), ensuring that all personal and health-related data is securely managed and protected. ExpiWell employs robust security measures, including data encryption, secure servers, and strict access controls, to safeguard against unauthorized access and data breaches. Data is anonymized and de-identified whenever possible to further protect participant privacy. Additionally, ExpiWell ensures that all data is collected, stored, and processed in accordance with applicable legal and ethical standards, guaranteeing that participant rights are upheld throughout the research process. Through ExpiWell's Privacy Policy and Terms and Conditions, participants are informed about how their data will be used, and consent is obtained before data collection begins, ensuring transparency and compliance with regulatory requirements.  
    • Related Articles

    • Project Review for EMA and ESM

      Review the Settings of Your EMA and ESM Project The project review page is the final step before launching your ecological momentary assessment (EMA) and experience sampling method (ESM) project. On this page, you will be able to review the settings ...
    • General Information about EMA and ESM Notifications

      What You Need to Know About EMA and ESM Notifications Information about Push Notifications The ExpiWell app uses Google's Firebase Cloud Messaging push notifications to send surveys, reminders, and message notifications to participants. Push survey ...
    • FAQ

      12 FAQ about the ExpiWell Platform These are some commonly asked questions by researchers seeking to do experience sampling or ecological momentary assessment on the ExpiWell platform. 1) I've created an account but can't log in as it says my account ...
    • Free Basic Version

      Discover the benefits of our Basic Free Version on ExpiWell In ExpiWell, you can conduct your Ecological Momentary Assessment, or Experience Sampling Method for FREE. VIDEO TUTORIAL Get Started After signing up for a FREE Basic account on ExpiWell, ...
    • Creating a Project in ExpiWell: Step-by-Step Guide

      Welcome to ExpiWell! This guide will walk you through the process of creating a project on our platform. It's easy! Main Dashboard After logging in, you'll land on your main dashboard. To create a new project, click on either the '+New' or 'Create ...