SAM
(Social Analysis of Meaning)

SAM Privacy Notice

How the SAM app handles account, billing, support, research, and AI-analysis data. Last updated 7 September 2026.

Back to signupTerms

1. Who we are

The SAM app is operated by BigQualDataLabs Ltd. SAM means Social Analysis of Meaning, a qualitative research platform for uploaded, imported, or sample research materials.

For privacy questions, support, and rights requests, contact support@bigqualdatalabs.com.

2. What the SAM app collects

Account data: email address, display name, sign-in events, workspace memberships, invitations, access roles, and account status.

Billing data: subscription status, plan, payer contact, invoice references, and Stripe customer or subscription identifiers. The SAM app does not store full payment-card details.

Research data: files, text, metadata, analysis outputs, coding decisions, reports, exports, and workspace settings that users choose to upload, generate, or save.

Public source data: where a workspace user chooses SAM Collect, SAM may retrieve public or official source text and metadata from configured sources, including scholarly records, government and parliamentary records, research-funding records, clinical trial registry records, public social posts, public YouTube video text, transcripts or subtitles, and public YouTube comments.

Depending on the selected source, public source data may include public names, handles, channel names, author or investigator names, organisations, dates, source URLs, identifiers such as DOIs, grant references, NCT IDs or video IDs, public engagement counts, and public media or thumbnail references.

Support and operations data: support tickets, support-widget messages, safe technical logs, browser/session metadata, and security or troubleshooting events.

3. Why the SAM app uses data

The SAM app uses account, workspace, and billing data to provide the service, manage access, process subscriptions, support users, and keep the platform secure.

The SAM app uses research data only to provide the analysis, coding, reporting, export, and workspace features requested by the user or workspace.

The SAM app keeps operational logs proportionate and does not intentionally log raw uploaded research content in normal application logs.

4. Research data and user responsibility

Users must only upload data they are entitled to process in the SAM app. This includes having the necessary consent, ethics approval, lawful basis, licence, institutional permission, or other authority for the material.

The public SAM app route is intended for public, sample, de-identified, low-risk, or explicitly approved pilot material. It is not a Safe Haven, NHS clinical system, or guaranteed controlled-data environment.

Do not upload identifiable patient or clinical data, highly sensitive special-category data, children's data, legal case data, or other controlled data unless BigQualDataLabs Ltd has agreed and enabled a separate controlled-data route in writing.

Where a workspace user chooses a YouTube Collect source, SAM may retrieve public YouTube-sourced text and metadata for the supplied public URL. This may include video titles, descriptions, available transcripts or subtitles, channel names, public comments, public usernames or channel identifiers, timestamps, source URLs, public engagement counts and thumbnail or source references. SAM does not collect YouTube passwords, private messages or non-public account data. Google's Privacy Policy applies to YouTube's own handling of user data: https://policies.google.com/privacy.

5. Privacy Shield

SAM's Privacy Shield helps detect and redact common identifiers, metadata, handles, URLs, and selected location or identity fields.

Shield is a review aid. It reduces exposure, but it does not guarantee anonymisation or remove the user's responsibility to review outputs before treating data as de-identified.

A future local Shield tool may allow users to redact material before upload, but the shipped Shield tools in the SAM app should still be treated as an assistive safeguard rather than a compliance guarantee.

6. AI analysis providers

The SAM app may send relevant text or metadata to configured AI providers when a user starts an AI-assisted analysis, summary, coding, or related workflow.

The SAM app does not silently turn the public SAM app into a controlled-data route. Controlled, patient, clinical, or highly sensitive material requires a separate provider-routing and data-processing arrangement before use.

Where BigQualDataLabs Ltd later offers a managed EU or institution-managed route, its model, region, retention, logging, monitoring, and fallback behaviour should be documented separately.

7. Service providers

The SAM app currently relies on specialist service providers for hosting, database/authentication, payment processing, transactional email, support messages, and AI analysis.

Examples may include Railway, Vercel, Supabase, Stripe, Resend, Microsoft 365, Bright Data for selected public source collection, and configured AI providers. The exact provider route can vary by environment and agreed customer setup.

Payment details are handled by Stripe-hosted checkout and portal pages. Email sign-in, invites, and selected transactional messages may be sent through Resend or configured authentication email services.

8. Retention and deletion

Account and workspace records are kept while an account or workspace is active, and for a reasonable period afterwards where needed for security, support, billing, audit, or legal reasons.

Billing and invoice records may be retained for accounting and legal obligations. Support messages may be retained to resolve issues and maintain a support history.

Research data should be deleted when it is no longer needed by the workspace, subject to backups, audit needs, and any specific written agreement.

9. Your rights

Depending on the circumstances, users may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data held about them.

Where the SAM app processes research participant data on behalf of a researcher or institution, rights requests may need to be handled by the relevant research controller or institution.

UK users can also contact the Information Commissioner's Office if they are unhappy with how a privacy concern is handled.

10. Changes

This privacy notice may be updated as the SAM app's launch services, support tooling, controlled-data routes, or provider arrangements change.

Material changes should be reflected on this page and, where appropriate, communicated to affected users or workspace owners.

Institutional and controlled-data arrangements

The SAM app is currently set up for shipped samples, public or synthetic material, and clearly de-identified low-risk research. For institutional, controlled-data, Safe Haven, NHS, or bespoke enterprise arrangements, contact Support before using that material in the SAM app. These routes need a separate data-processing agreement and assurance pack.

Contact Support about Data Governance + Shield