Online polarizing content consumption and mental well-being Privacy Notice
A
Aalto University

POLEMIC/POLWELL Privacy Notice

(TimeVersion)

This privacy notice describes how your personal data will be used in the research study as a participating individual. You have also been provided with a document called “Information Sheet”, which explains in more detail how the study is carried out, what is being studied in this research study, specifies exactly what data is collected and for what purpose, and the purpose of processing personal data.

The current version of this Privacy Notice is always available at study website — to be confirmed. We may update this notice during or after the study — for example, if research data is later shared with other universities or research organisations as part of further research projects. Any updated version will be published at that same address, and we will notify you by email of any significant change. You can check that address at any time to see the version that currently applies to your data. Where a change materially affects how your data is used or shared, and the law requires it, we will ask for your consent again before the new processing begins.

The data streams, purpose, and retention are fixed in the research plan, Information Sheet, privacy notice, and consent form. Any change requires an Ethical Review Board amendment.

The data will not be used for product development or any commercial purpose, and will not be shared with third parties for such purposes; any use beyond what is described in the Information Sheet or privacy notice would require an Ethical Review Board amendment and, where required, re-contacting participants for consent.

1. What personal data is processed in the research study

This research study examines how our social media use is related to our mental health and well-being. By studying the association between individuals’ social media exposure and their mental health and well-being, we will gain crucial insights into how social media is impacting individuals in our socio-technical society. For this research purpose, we combine passive sensing data collected from the mobile phone with surveys on mental health and well-being. Aalto University is responsible for this study. This research is funded by the Research Council of Finland.

We collect data about the participant using the (i) contact information and survey on the study website, (ii) mobile phone activity data from the Aware mobile app, and (iii) third-party data donated by the user. Each category listed below is collected for a specific, defined role in answering one or more of the study’s research questions (RQ1 — association between online content consumption and mental health; RQ2 — temporal/causal direction of that association; RQ3 — which sociodemographic groups are more vulnerable), or for the pilot’s methodological feasibility goal. In addition, the AWARE screen-text and screenshot streams are technically restricted to four social media applications (Bluesky, YouTube, Instagram, TikTok); no screen text or screenshots are collected from any other app on the device (including messaging, email, banking, browsers, and any other application) or when the apps are inactive.

1.1 Information collected through the study website

You will be invited to register on the study website. You will be asked to provide contact information (email address) to create an account to join the study. You will be asked to review the consent forms and information sheet on the study website before proceeding with the study.

1.2 Phone usage collected with the Aware app

The study website will guide you through the installation of the Aware app. The application will send us sensor readings, activity data, and your application’s usage.

1.3 Donated third-party data

Additionally, you will be invited to provide us access to data stored by third-party services, restricted to the same four social media platforms from which on-screen text is captured (TikTok, YouTube, Bluesky, Instagram). These donated exports are collected in addition to, and not as a duplicate of, the on-screen text, because they provide information the passive screen-text stream cannot: the participant’s earlier activity history (may contain a longer exposure baseline, including before the study); the specific videos actually watched on the audiovisual platforms (YouTube, TikTok), which on-screen text (limited to titles, captions, and visible comments) cannot fully reconstruct; explicit engagement actions (likes, comments, favourites, follows, and searches) that distinguish content the participant actively chose to engage with from content that merely scrolled past; and a complete, structured record that we also use to validate the accuracy of the data collected passively from the phone, both the on-screen text and the validation screenshots, by comparing it against what the participant actually watched and engaged with. Donation is optional, and participants who do not donate still contribute to the on-screen-text stream.

Findings and notes made by researchers will be similarly stored.

Special categories of personal data (sensitive personal data)

In addition, the following special categories of personal data are processed:

From the participantStudy website and online surveys
From a data registerNot applicable
OtherPassive sensing data collected with the Aware app and digital data donation (optional)

The research methods are described to you in more detail in the “Information Sheet” document.

2. Processing of necessary personal data and removal of direct identifiers from the data

The research study only processes personal data that is necessary for the purpose and execution of the study. Your data may contain identifying information that cannot be fully avoided. Researchers and data handlers will not attempt to extract or identify you from this data. Any identifying information we require, such as account usernames, is requested from you directly.

A randomly generated participant ID is used instead of your email, and each participant’s device is assigned a device label that is linked only to the participant’s pseudonymous code, never to any direct identifier. Your direct identifiers (name, the email address you used to register, personal identity code for remuneration, and other personal identifiers you provide) are stored separately by the Aalto Science-IT team, who hold the key that links them to a pseudonymous participant code.

The researchers analysing the data work only with this pseudonymous code and never have access to the key. Location (GPS) data collected via AWARE is aggregated by Aalto Science-IT before the research team receives it; raw location traces are not accessible to the researchers.

Screen text is captured only from a small set of pre-approved applications: the four social-media platforms central to the research questions — Bluesky, YouTube, Instagram, and TikTok. Text from all other apps on your phone (banking, messaging, email, browsers, password fields, and so on) is not collected at all. What is captured is encrypted in transit (TLS) and at rest on Aalto’s secure servers. We will make efforts to remove personally identifiable information from screen text data (such as automatically removing email addresses and the social media handle you provided to us), but we cannot guarantee its complete removal. However, the researcher has no incentive for re-identifying participants, and no process will be made that could lead to re-identification. Because free-form text cannot be redacted perfectly, the residual data is treated as if it may still contain incidental personal information; access is restricted to named project researchers on Aalto systems, and the data does not leave the pseudonymised Science-IT pipeline. Screenshots are used only for internal validation of the data pipeline and are either destroyed after validation or, alternatively, only pre-approved and low-risk screenshots will be retained for validation; they are not used as research data.

Your data may still contain identifying information that cannot be fully removed (for example, names appearing inside captured screen text). The research team will not attempt to extract or identify you from this data. The identity of the individual research participant will not be disclosed in a scientific publication or other research results to be published.

4. Legal basis for the processing of personal data

5. Sharing personal data

Research data containing your personal data is shared with the following parties:

Independent controllers: Research data, which consists of your personal data, may be transferred to a third party, such as a scientific publication, for the peer-review process or for other purposes, which is mandatory for scientific publishing or validation of the research results.

Research data containing personal data is retained for use in further scientific research in the same scientific discipline or in other disciplines that support this research study. Research data may also be transferred to other universities or research organisations as part of further research projects.

6. International data transfers

During the execution and analysis phase of research, research data containing personal data will not be transferred to non-EU/EEA countries or international organisations. However, as part of the scientific publishing process, it might be necessary to transfer the data outside the EU/EEA for publishers or peer reviewers for verification of research results, as such parties may be located outside the EU/EEA area. However, it is exceptional that the scientific publication process would require transferring data regarded as personal data.

7. Storage and protection of personal data

Information processed in IT systems: Your personal data is processed and preserved in secure IT systems, which are approved by Aalto University and suitable for personal data. Access to all computers and IT systems is protected by username and a strong personal password. Access to IT systems containing personal data is technically restricted in a manner that only researchers participating in the study and persons necessary for the implementation of the study have access to your personal data.

Data received from external services is encrypted at rest and in transit.

The research data is archived: fully anonymous data, such as statistical data, may be published as open data after the study concludes. Any archived data will not contain information that can be linked back to individual participants.

8. Retention and deletion of personal data

Deletion during and after the study

The personal data required for tax reporting (participant name and personal identity code) are collected when registering the account on the study website, stored separately from the research data on a restricted Aalto system, and access is restricted to authorised personnel responsible for processing participant payments and fulfilling legal tax-reporting obligations. The participant’s name and personal identity code are destroyed once tax reporting has been completed (no later than two weeks after all gift-card payments).

Research data containing personal data is retained for use in further scientific research in the same scientific discipline or in other disciplines that support this research study. It is deleted five (5) years after the last publication in which this research data has been used and exploited. This covers your pseudonymised questionnaire responses, the AWARE smartphone data collected for you (screen text from the four pre-approved social-media apps together with sensor and metadata streams), and any data you voluntarily donate from accounts.

Directly identifying contact data (your email address, severing the link between the participant and pseudonymous identifier) and the pseudonymisation key are held separately by the Aalto Science-IT team. They are retained for as long as pseudonymised research data still exists, so that a withdrawal or deletion request can always be carried out. The key is destroyed once both your contact information and all research data have been deleted.

You can withdraw from the study, or ask us to delete your data, at any time — without giving a reason and without any negative consequences. You can do so on the study website or by emailing the research team at data admin project email and include the email address you used to register, so that your pseudonymous record can be located; deletion is carried out by the Aalto Science-IT team, who hold the pseudonymisation key. Data already used in analyses may remain in those analyses, but no new data is collected from you after withdrawal, and your direct identifiers and your entry in the pseudonymisation key are destroyed as part of the deletion.

9. Rights of the research participant

According to the General Data Protection Regulation (GDPR), a data subject has the right to:

If the research purpose does not require, or no longer requires, the identification of the data subject, the controller shall not be obliged to obtain further information so that the data or the data subject may be identified only for purposes to enable the data subject to exercise his/her rights. If the controller is unable to link the data to a particular data subject, the data subject does not have the right to access or correct the personal data, object to the processing, or delete the personal data. However, if the data subject provides additional information that allows their identification from the research data, the rights will not be restricted.

10. Contact details of the controller

The controller of this research study is Aalto University Foundation sr., operating as Aalto University.

Person in charge of the research study Questions regarding the conduct of the research study may be addressed to the person in charge of the study: Talayeh Aledavood / Juhi Kulshrestha.
Project email address: data_collection_project_name@aalto.fi
Data Protection Officer If the research participant has questions or requests related to data protection or the processing of personal data, the research participant should contact the Data Protection Officer of Aalto University: tel. +358 9 47001 (exchange), dpo@aalto.fi.

In this data request service, you can request the exercise of your rights under GDPR from Aalto University as the controller: https://datarequest.aalto.fi/en-US/.

If a participant of the research study feels that his or her personal data has been processed in violation of data protection legislation, the participant has the right to lodge a complaint with the supervisory authority, the Data Protection Ombudsman’s Office (read more: www.tietosuoja.fi).