Data, privacy and security
What Quizably stores, how IP addresses are hashed, cookies, rate limits, who can access data, what uninstalling deletes, and how consent works.
This page describes what the free Quizably plugin collects and stores on your own WordPress site. It is general information, not legal advice. Check the rules that apply to you, such as GDPR, with a qualified advisor.
All data stays in your WordPress database. Quizably does not send data to outside services on its own. The only outgoing requests are webhooks you configure and any media links you add.
What is stored
Quizably creates its own database tables, using your WordPress table prefix. In general terms they hold:
- Quizzes, questions, answers and results (your content).
- Submissions, one per visit to a quiz.
- Leads, created when a visitor submits your form.
- Plugin settings and your question bank.
Submissions
Each submission stores:
| Item | Notes |
|---|---|
| Answers | Chosen options and typed text, per question, including time spent. |
| Score, result and breakdown | Set when the quiz is completed. |
| IP hash | A hashed form of the visitor’s IP address. The real address is never stored. |
| User agent | The browser’s identification text, up to 255 characters. |
| UTM values | utm_source, utm_medium, utm_campaign, utm_term and utm_content from the page address, if present. |
| Start and finish times | In UTC. |
| Lead link | Connects the submission to a lead if the visitor submitted the form. |
A submission is created when the quiz loads, so visitors who never start a quiz still leave a small record. Unfinished submissions are not cleaned up automatically.
Leads
A lead stores the email, name, consent checkbox result (yes or no), the double opt-in status when the quiz uses it, and the time created. Email is always collected. Name is optional. The same email for the same quiz updates one lead record instead of creating a second one. The same email on a different quiz is a separate lead.
IP addresses
Quizably never writes a plain IP address to the database. It stores a salted SHA-256 hash, cut to the first 16 characters. The salt is your site’s own WordPress salt.
The hash is used for rate limiting and is stored on each submission. It is not used to block repeat votes or repeat submissions, so a poll counts every completed run.
If your site sits behind a proxy or CDN, all visitors may appear to come from one address. That affects the hash and the rate limits below.
Cookies and browser storage
- Quizably sets no cookies.
- It uses a
sessionStorageentry,quizably_quiz_seed. It holds a random number that keeps question and answer order stable when randomization is on. It disappears when the visitor closes the tab. - It saves quiz progress so a visitor can resume after a reload. This is one
localStorageentry per quiz, namedquizably_progress_<quiz uuid>(sessionStorageis used iflocalStorageis blocked). It holds the question position, the chosen options and ratings, the shuffle seed and whether the form was done. It lasts 7 days and is cleared when the quiz is completed, on Start over, or when the quiz changes. Names, emails, consent and typed text answers are never stored there. - Popups and slide-ins that open automatically remember that they did, in
quizably_seen_popup_<uuid>orquizably_seen_slidein_<uuid>(sessionStorageforonce="session",localStorageforonce="day"). It holds a timestamp only.
Rate limits
To reduce abuse, the public quiz requests are limited to 60 requests per minute and 300 per hour for each hashed IP address. Beyond that, visitors see “Too many attempts. Please slow down.”
A quiz of about ten questions uses roughly 13 requests, so around 20 completions per hour from one address. Visitors behind a shared address, such as a school, office or mobile network, share this allowance. The limit is not a captcha, and there is no other spam protection on the quiz forms.
Who can access the data
Only users with the Administrator role can open the Quiz Builder menu and use the admin screens, the leads list and the exports. Editors and Authors cannot.
Visitors can read the public parts of a published quiz, meaning its questions, answer labels and result text. They cannot read leads or other visitors’ answers.
Consent checkbox
Each quiz has its own consent text on the Form tab, under Consent, in the GDPR consent text field.
- If the field is empty, no checkbox appears on the form.
- If you write text, a checkbox with that text appears and visitors must tick it to submit.
- The result is stored on the lead as yes or no. It appears in the lead detail panel as GDPR consent and in the leads CSV as
consent_gdpr. - New quizzes start with the text from Settings, Privacy, Default consent text, when you set one and the quiz has a form.
For a confirmed email address, turn on Double opt-in on the Form tab. The lead stays Pending until the visitor clicks the link in the email. See Double opt-in.
The plugin does not add a privacy policy link for you. Put any link you need inside the consent text.
Deleting a lead
On the Leads screen, select the delete icon (Delete lead) and confirm. This removes the lead record only. The linked submission stays, including the answers, IP hash, user agent and UTM values. There is no bulk delete.
Deleting a whole quiz from All Quizzes and confirming removes its questions, results, submissions and leads together.
Privacy export and erase tools
Quizably does not connect to the WordPress personal data export and erase tools under Tools. If a person asks for their data, you have to find it yourself. Search the Leads screen by email, then open the lead detail to see their answers, or export the leads CSV, which has one column per question. Keep in mind that answers from visitors who never gave an email cannot be tied to a person.
Retention
There is no retention setting and no automatic deletion. Leads and submissions stay until you delete them.
Uninstalling the plugin
Deactivating Quizably keeps all your data. Deleting the plugin from the Plugins screen also keeps it. Quizzes, questions, results, submissions, leads, settings and integration settings stay in the database, so deleting and re-uploading the plugin never loses your work.
To erase everything when the plugin is deleted, for example for a GDPR erasure, add this line to wp-config.php before you delete the plugin:
define( 'QUIZABLY_REMOVE_ALL_DATA', true );
With that constant set, deleting the plugin drops every Quizably table and removes every option that starts with quizably_, including the double opt-in signing secret. This cannot be undone.
Before you erase data this way:
- Export each quiz from All Quizzes with Export. This saves a JSON file with questions, answers and results.
- Export leads from Leads with Export CSV.
- Export analytics from each quiz’s Settings tab with Export CSV if you need them.
- Take a database backup.
Exports of quizzes do not include leads or submissions. The leads CSV includes the quiz, result, score, double opt-in status, UTM tags, custom fields and each question’s answer.
Security notes
- Keep WordPress and your admin accounts secure. Anyone with an Administrator login can see all leads.
- In the leads CSV, a cell that starts with
=,+,-or@gets a leading apostrophe so a spreadsheet does not run it as a formula. - Webhook payloads contain personal data. Use HTTPS and keep the URL private. See Webhooks.
Related
Last updated October 4, 2026.