PII field masking
Mark any field as PII — it will not be captured at all. Applies to anonymous visitors too.
Privacy Controls
Administrators have full control over what data is captured, how long it's kept, and how it's deleted — at the field level, the user level, or across the entire account.
Data field controls
Admin onlyConsent tracking
User data deleted
u_3374 · all fields purged · logged
How it works
Privacy Controls gives administrators granular oversight over every piece of data encatch touches — from what is recorded in the first place to how long it is kept and who can act on it.
Administrators can inspect every field encatch collects and choose to mask it, exclude it entirely, or allow it through. Settings apply uniformly — including to anonymous visitors. No data should slip through because someone forgot to configure it.
User data field settings
Applies to all users, including anonymous visitors — no exceptions.
Accountability and identity
Audit actions, manage retention and exports, and protect the voice behind each response.
Every deletion, field change, retention update, and scheduled purge is written to an immutable audit log — recording who triggered it, what was affected, and when. Gives compliance teams the paper trail they need without any extra work.
Audit log
field_deleted
admin@acme.com · email
user_purged
admin@acme.com · u_3374
retention_updated
admin@acme.com · 90 → 30 days
scheduled_purge
system · 438 records
Immutable log — all admin actions on user data are recorded and timestamped.
Zero-data segmentation · Segmentation Engine
Pair the encatch Segmentation Engine's webhook mode with your CDP or identity system to run targeted feedback campaigns without ingesting any personal data. Your first-party data stays where it belongs — encatch only receives segment membership signals.
Full capabilities
Privacy Controls gives administrators the tools to honour user rights, meet compliance requirements, and keep sensitive data under tight control — at every level of the system.
Mark any field as PII — it will not be captured at all. Applies to anonymous visitors too.
Control what is recorded even for users with no identity — device context, session data, and more.
Manual feedback forms continue to work for visitors who decline cookies — no session tracking required.
Purge all data for a specific user in one action — responses, traits, and session records.
Remove a specific field from all responses across the entire account — surgical, audited, irreversible.
Set how long response data is kept. When the window expires, records are purged automatically.
Schedule daily exports to your own storage before the retention window closes. Your data, your archive.
Every admin action on user data — deletions, field changes, retention updates — is logged with actor and timestamp.
Application developers can signal consent status via SDK. encatch records when and how consent was provided.
Use CDPs for first-party segmentation and send only membership signals to encatch — zero PII crosses systems.
All privacy settings are gated to administrator roles — team members see only what they need to.
Deletion and masking actions take effect immediately — no queues, no overnight batch jobs.
AI neutralises writing style in free-text responses — protecting identity in small groups without losing a word of meaning.
Product journey
A little more detail
Common questions about data capture, retention, and deletion controls in encatch.
Exactly what data is captured, how long it's retained, and how it's deleted — at the field, user, or account level.
Yes — Privacy Controls include a cookie-less mode so feedback collection still works without tracking cookies.
Yes, PII and data-field controls let admins decide exactly which fields get recorded per form.
Your next step
Privacy Controls gives your team the tools to handle user data responsibly — from field-level masking to full account deletion — all audited and in your hands.