POLEMIC/POLWELL Privacy Notice
(Time–Version)
This privacy notice describes how your personal data will be used in the research study as a participating individual. You have also been provided with a document called “Information Sheet”, which explains in more detail how the study is carried out, what is being studied in this research study, specifies exactly what data is collected and for what purpose, and the purpose of processing personal data.
The current version of this Privacy Notice is always available at study website — to be confirmed. We may update this notice during or after the study — for example, if research data is later shared with other universities or research organisations as part of further research projects. Any updated version will be published at that same address, and we will notify you by email of any significant change. You can check that address at any time to see the version that currently applies to your data. Where a change materially affects how your data is used or shared, and the law requires it, we will ask for your consent again before the new processing begins.
The data streams, purpose, and retention are fixed in the research plan, Information Sheet, privacy notice, and consent form. Any change requires an Ethical Review Board amendment.
The data will not be used for product development or any commercial purpose, and will not be shared with third parties for such purposes; any use beyond what is described in the Information Sheet or privacy notice would require an Ethical Review Board amendment and, where required, re-contacting participants for consent.
1. What personal data is processed in the research study
This research study examines how our social media use is related to our mental health and well-being. By studying the association between individuals’ social media exposure and their mental health and well-being, we will gain crucial insights into how social media is impacting individuals in our socio-technical society. For this research purpose, we combine passive sensing data collected from the mobile phone with surveys on mental health and well-being. Aalto University is responsible for this study. This research is funded by the Research Council of Finland.
We collect data about the participant using the (i) contact information and survey on the study website, (ii) mobile phone activity data from the Aware mobile app, and (iii) third-party data donated by the user. Each category listed below is collected for a specific, defined role in answering one or more of the study’s research questions (RQ1 — association between online content consumption and mental health; RQ2 — temporal/causal direction of that association; RQ3 — which sociodemographic groups are more vulnerable), or for the pilot’s methodological feasibility goal. In addition, the AWARE screen-text and screenshot streams are technically restricted to four social media applications (Bluesky, YouTube, Instagram, TikTok); no screen text or screenshots are collected from any other app on the device (including messaging, email, banking, browsers, and any other application) or when the apps are inactive.
1.1 Information collected through the study website
You will be invited to register on the study website. You will be asked to provide contact information (email address) to create an account to join the study. You will be asked to review the consent forms and information sheet on the study website before proceeding with the study.
- Email address (account registration): surveys delivery, gift-card distribution, withdrawal/data-subject requests
- Name and Personal identity codes: tax-authority reporting for remuneration (see Section 8)
- Consent forms
- Questionnaire responses and response times: mental-health & well-being outcomes (RQ1, RQ2), political alignment (RQ1, RQ3), personality (RQ3), sociodemographic covariates (RQ3), self-reported media use (RQ1), and methodology feedback (feasibility)
- Social media account names: linkage between donated third-party data and the participant’s pseudonymous study ID
1.2 Phone usage collected with the Aware app
The study website will guide you through the installation of the Aware app. The application will send us sensor readings, activity data, and your application’s usage.
- Text appearing on screen: restricted to four social media applications — Bluesky, YouTube, Instagram, TikTok. Primary measure of exposure to polarising online content: the content the participant actually reads on these four social media platforms (RQ1, RQ2). Screen text from any other app on the device (messaging, email, banking, browsers, etc.) is not collected.
- Screenshots: restricted to the same four social media applications. Validation only: used by Aalto Science-IT to verify that the screen-text extraction pipeline is working correctly within the four in-scope apps; not analysed as research data and destroyed after validation. Screenshots are never captured outside these four apps.
- Phone sensor readings: location, acceleration, battery and screen status, and timezone. Screen on/off status, battery level, and timezone provide the temporal scaffolding required to align the passively collected signals with questionnaire responses across time zones and participants’ waking hours (RQ2). Coarse location and accelerometry capture behavioural and lifestyle factors — mobility, physical activity, and daily routine — that are known to covary with mental-health and well-being states and that therefore serve as relevant contextual variables and confounders in our analyses (RQ2, RQ3).
- Call and SMS metadata (counts/timestamps; no content): social-activity behavioural indicator. Social contact frequency is a recognised correlate of depression and is used as a control variable (RQ2).
- Applications, usages, and installations: exposure context and behavioural indicator of changing engagement; also a feasibility metric (RQ1, RQ2, feasibility)
- Device information (device model, manufacturer, Android version, and other technical device parameters reported by the operating system): needed to assess whether the multimodal data-collection methodology works reliably across the device population of Aalto students. Your device will be assigned a device label that is linked only to the pseudonymous code, never to any direct identifier.
1.3 Donated third-party data
Additionally, you will be invited to provide us access to data stored by third-party services, restricted to the same four social media platforms from which on-screen text is captured (TikTok, YouTube, Bluesky, Instagram). These donated exports are collected in addition to, and not as a duplicate of, the on-screen text, because they provide information the passive screen-text stream cannot: the participant’s earlier activity history (may contain a longer exposure baseline, including before the study); the specific videos actually watched on the audiovisual platforms (YouTube, TikTok), which on-screen text (limited to titles, captions, and visible comments) cannot fully reconstruct; explicit engagement actions (likes, comments, favourites, follows, and searches) that distinguish content the participant actively chose to engage with from content that merely scrolled past; and a complete, structured record that we also use to validate the accuracy of the data collected passively from the phone, both the on-screen text and the validation screenshots, by comparing it against what the participant actually watched and engaged with. Donation is optional, and participants who do not donate still contribute to the on-screen-text stream.
- TikTok activity (browsing, search, liked, comments, favourites, hashtags): short-form video exposure with high polarising-content prevalence in the student demographic (RQ1, RQ2)
- YouTube (video, action and search history): direct measure of polarising-content exposure on a major video platform; cannot be reconstructed from on-screen text alone (RQ1, RQ2)
- Bluesky handle (RQ1, RQ2): captures engagement with polarising content on an emerging platform with a rapidly growing, politically active user base that is not representable from on-screen behaviour alone
- Instagram activity (posts, likes, comments, search/viewing history): image/short-video content exposure on one of the four in-scope platforms (RQ1, RQ2)
Findings and notes made by researchers will be similarly stored.
Special categories of personal data (sensitive personal data)
In addition, the following special categories of personal data are processed:
- Political opinions
- Data concerning health
| From the participant | Study website and online surveys |
| From a data register | Not applicable |
| Other | Passive sensing data collected with the Aware app and digital data donation (optional) |
The research methods are described to you in more detail in the “Information Sheet” document.
2. Processing of necessary personal data and removal of direct identifiers from the data
The research study only processes personal data that is necessary for the purpose and execution of the study. Your data may contain identifying information that cannot be fully avoided. Researchers and data handlers will not attempt to extract or identify you from this data. Any identifying information we require, such as account usernames, is requested from you directly.
A randomly generated participant ID is used instead of your email, and each participant’s device is assigned a device label that is linked only to the participant’s pseudonymous code, never to any direct identifier. Your direct identifiers (name, the email address you used to register, personal identity code for remuneration, and other personal identifiers you provide) are stored separately by the Aalto Science-IT team, who hold the key that links them to a pseudonymous participant code.
The researchers analysing the data work only with this pseudonymous code and never have access to the key. Location (GPS) data collected via AWARE is aggregated by Aalto Science-IT before the research team receives it; raw location traces are not accessible to the researchers.
Screen text is captured only from a small set of pre-approved applications: the four social-media platforms central to the research questions — Bluesky, YouTube, Instagram, and TikTok. Text from all other apps on your phone (banking, messaging, email, browsers, password fields, and so on) is not collected at all. What is captured is encrypted in transit (TLS) and at rest on Aalto’s secure servers. We will make efforts to remove personally identifiable information from screen text data (such as automatically removing email addresses and the social media handle you provided to us), but we cannot guarantee its complete removal. However, the researcher has no incentive for re-identifying participants, and no process will be made that could lead to re-identification. Because free-form text cannot be redacted perfectly, the residual data is treated as if it may still contain incidental personal information; access is restricted to named project researchers on Aalto systems, and the data does not leave the pseudonymised Science-IT pipeline. Screenshots are used only for internal validation of the data pipeline and are either destroyed after validation or, alternatively, only pre-approved and low-risk screenshots will be retained for validation; they are not used as research data.
Your data may still contain identifying information that cannot be fully removed (for example, names appearing inside captured screen text). The research team will not attempt to extract or identify you from this data. The identity of the individual research participant will not be disclosed in a scientific publication or other research results to be published.
4. Legal basis for the processing of personal data
- The legal basis is scientific research, a task in the public interest
5. Sharing personal data
Research data containing your personal data is shared with the following parties:
Independent controllers: Research data, which consists of your personal data, may be transferred to a third party, such as a scientific publication, for the peer-review process or for other purposes, which is mandatory for scientific publishing or validation of the research results.
Research data containing personal data is retained for use in further scientific research in the same scientific discipline or in other disciplines that support this research study. Research data may also be transferred to other universities or research organisations as part of further research projects.
6. International data transfers
During the execution and analysis phase of research, research data containing personal data will not be transferred to non-EU/EEA countries or international organisations. However, as part of the scientific publishing process, it might be necessary to transfer the data outside the EU/EEA for publishers or peer reviewers for verification of research results, as such parties may be located outside the EU/EEA area. However, it is exceptional that the scientific publication process would require transferring data regarded as personal data.
7. Storage and protection of personal data
Information processed in IT systems: Your personal data is processed and preserved in secure IT systems, which are approved by Aalto University and suitable for personal data. Access to all computers and IT systems is protected by username and a strong personal password. Access to IT systems containing personal data is technically restricted in a manner that only researchers participating in the study and persons necessary for the implementation of the study have access to your personal data.
Data received from external services is encrypted at rest and in transit.
The research data is archived: fully anonymous data, such as statistical data, may be published as open data after the study concludes. Any archived data will not contain information that can be linked back to individual participants.
8. Retention and deletion of personal data
Deletion during and after the study
The personal data required for tax reporting (participant name and personal identity code) are collected when registering the account on the study website, stored separately from the research data on a restricted Aalto system, and access is restricted to authorised personnel responsible for processing participant payments and fulfilling legal tax-reporting obligations. The participant’s name and personal identity code are destroyed once tax reporting has been completed (no later than two weeks after all gift-card payments).
Research data containing personal data is retained for use in further scientific research in the same scientific discipline or in other disciplines that support this research study. It is deleted five (5) years after the last publication in which this research data has been used and exploited. This covers your pseudonymised questionnaire responses, the AWARE smartphone data collected for you (screen text from the four pre-approved social-media apps together with sensor and metadata streams), and any data you voluntarily donate from accounts.
Directly identifying contact data (your email address, severing the link between the participant and pseudonymous identifier) and the pseudonymisation key are held separately by the Aalto Science-IT team. They are retained for as long as pseudonymised research data still exists, so that a withdrawal or deletion request can always be carried out. The key is destroyed once both your contact information and all research data have been deleted.
You can withdraw from the study, or ask us to delete your data, at any time — without giving a reason and without any negative consequences. You can do so on the study website or by emailing the research team at data admin project email and include the email address you used to register, so that your pseudonymous record can be located; deletion is carried out by the Aalto Science-IT team, who hold the pseudonymisation key. Data already used in analyses may remain in those analyses, but no new data is collected from you after withdrawal, and your direct identifiers and your entry in the pseudonymisation key are destroyed as part of the deletion.
9. Rights of the research participant
According to the General Data Protection Regulation (GDPR), a data subject has the right to:
- receive information on the processing of their personal data
- access the personal data collected and processed
- request rectification of inaccurate personal data
- request that the processing of personal data be restricted
- object to the processing of personal data
- request erasure of personal data if the conditions of Article 17(1) of the Data Protection Regulation are met and processing is no longer necessary for archiving purposes in the public interest or for scientific research or statistical purposes in accordance with Article 89(1)
If the research purpose does not require, or no longer requires, the identification of the data subject, the controller shall not be obliged to obtain further information so that the data or the data subject may be identified only for purposes to enable the data subject to exercise his/her rights. If the controller is unable to link the data to a particular data subject, the data subject does not have the right to access or correct the personal data, object to the processing, or delete the personal data. However, if the data subject provides additional information that allows their identification from the research data, the rights will not be restricted.
10. Contact details of the controller
The controller of this research study is Aalto University Foundation sr., operating as Aalto University.
Project email address: data_collection_project_name@aalto.fi
In this data request service, you can request the exercise of your rights under GDPR from Aalto University as the controller: https://datarequest.aalto.fi/en-US/.
If a participant of the research study feels that his or her personal data has been processed in violation of data protection legislation, the participant has the right to lodge a complaint with the supervisory authority, the Data Protection Ombudsman’s Office (read more: www.tietosuoja.fi).