Themescape by Charlotte Price
Privacy and data handling

Your data stays on your computer

Why Themescape reads your coded data without ever storing it, and what that means for your participants and your ethics approval.

The principle

Built for sensitive material

Themescape is made for qualitative researchers who hold sensitive material: interview transcripts, coded quotes, and the words of real participants who were promised confidentiality. The design of the tool follows directly from that responsibility. Your coded data stays on your own computer at every step, and Themescape is built so that it could not send it elsewhere even if asked to.

The promise

Your data is read on your machine, held only in your browser's memory for as long as the page is open, and is never uploaded, stored, or transmitted to anyone.

The model

Import and export, not upload and save

Most online tools work on an upload-and-save model. You send your file to a company's servers, it is stored in an account somewhere, and you log back in later to find it waiting for you. That convenience carries a cost. Once data has left your machine, you are trusting an external party to hold it safely, to honour their own retention policies, and to remain secure. For most spreadsheets this is an acceptable trade. For coded qualitative data, where a single quote can identify a participant, it is not a trade many researchers can responsibly make, and it is rarely one an ethics committee will have approved.

Themescape deliberately works the other way, on an import-and-export model. There is no account, no login, and no server-side storage. You bring a file to the viewer, the viewer reads it in front of you, and when you are finished you simply close the page. Nothing is kept because there is nowhere for it to be kept. This is not a setting you need to switch on or a policy you have to trust. It is a property of how the tool is made.

In plain terms. Upload-and-save means your data lives on someone else's computer. Import-and-export means your data only ever lives on yours. Themescape uses the second model by design.
What happens

Opening a file, step by step

When you drag a CSV into the viewer, or choose one through the file picker, your web browser reads that file directly from your own disk using the standard file-reading tools built into every modern browser. The contents are turned into an interactive display entirely within the browser tab on your machine. At no point does the file travel across the internet.

You choose a file

You drop a CSV onto the viewer or select it through the browser's own file picker. The file stays exactly where it is on your disk.

Your browser reads it in memory

The page reads the file locally and builds the themes, quotes, and filters in the working memory of the tab. This all happens on your computer.

You explore the display

You move between the grouped model view and the card wall, filter by participant, and switch between refined and verbatim quotes, all without any data leaving the machine.

You close the page, and it is gone

Refreshing or closing the tab clears everything held in memory. A Start over control does the same on demand. Nothing is written to an account, a cookie, or a server.

Because the display exists only while the page is open, Themescape keeps no history of what you loaded, no record of your themes, and no copy of your quotes. Each session begins empty and ends empty.
Working, not just viewing

Work mode, and how progress is saved

Themescape is not only for looking at a finished analysis. Work mode lets you develop it. You can edit the working definitions that sit behind your themes, adjust the descriptions of each branch, and shape how the structure reads, all inside the viewer and all on your own machine. This makes the tool a place to think, not merely a place to present.

The way progress is saved follows the same principle as everything else. Because nothing is stored online, the edits you make live only in the browser's memory while the page is open. To keep them, you export, which writes an updated file back to your own computer. You then reopen that file whenever you want to carry on. The rhythm is deliberate and consistent: import a file, work on it, export to save. There is no autosave to a server and no account quietly holding a copy, because there is no server and no account. Your saved progress is a file you own, in a place you chose, and nowhere else.

! Export before you closeChanges made in work mode are held in memory only. Export to write them back to your machine before refreshing or closing the page, or they will be discarded. This is the same safeguard that keeps your data off the internet: nothing is retained anywhere you did not put it yourself.
A fair question

Served from the web, but still local to you

Themescape is a single web page, and it is delivered to you the same way any web page is, from a host such as Netlify or a website. It is reasonable to wonder whether that undermines the privacy promise. It does not, and the distinction is worth understanding clearly, because it is the point an ethics reviewer is most likely to probe.

The host does one thing only. It sends you the page, in the same way a library hands you a blank notebook. Once the page has loaded, it runs entirely inside your browser on your own machine. When you then open a CSV, that file is read by your computer and is never sent back to the host. The people who serve the page never receive your data and have no means of requesting it. The transaction is one directional: the page comes to you, and your data never goes back.

i The distinction that mattersThe host serves the tool. It does not receive your data. Loading the Themescape page transmits nothing about your participants, because your file is only ever opened after the page is already running on your own computer.
The exception

Live Google Sheets mode, and its firm boundary

Themescape offers an optional live mode that reads directly from a published Google Sheet, so that a shared, non-sensitive dataset can be displayed without exporting files each time. This is the single route by which data reaches the viewer from somewhere other than your own disk, and it is entirely opt-in. It is never on unless you deliberately choose it.

This mode is intended only for data you are content to have published, such as a teaching example, a synthetic dataset, or a public-facing summary. It should never be used with confidential participant material. Connecting a live sheet requires that sheet to be published, and published data is, by definition, no longer private. The safe and default path for any real participant data is always the local file route described above.

! Please noteUse the local file route for anything confidential. Reserve the live Google Sheets connection for data that is already public or entirely synthetic. If in doubt, keep your data on your own machine and use the drop zone.
For your approval

What this means for your ethics application

If you are describing Themescape in an ethics application, a data management plan, or a conversation with your supervisor, the position is straightforward to state. The tool involves no third-party data processor, no cloud storage of participant material, and no transfer of data off your device. Coded quotes are read locally by your browser and are discarded the moment the page is closed. In the language of most institutional frameworks, this means there is no additional data sharing, no new storage location to account for, and no external party gaining access to identifiable information.

You retain full custody of your data throughout. Themescape does not change where your files are stored, who can reach them, or how long you keep them; those remain governed by your existing approved arrangements. All the tool adds is a way of viewing material you already hold, on the machine where you already hold it. Provided you use the local file route rather than the live sheet connection, no new data-protection obligations arise from using it.

A note on verbatim quotes. Themescape never edits the words of a participant. The verbatim quote is preserved exactly as recorded, and any tidying for presentation is kept in a separate refined field that you control. The record of what was actually said is never altered by the tool.
In short

The whole position, briefly

Themescape works on an import-and-export model rather than an upload-and-save one. Your data is read on your own computer, held only in memory while you use it, and never sent anywhere. The same holds when you develop your analysis in work mode: you edit your theme definitions and branch descriptions locally, and you export to save your progress to a file you own. The web host serves the page and receives nothing in return. A live Google Sheets mode exists for public or synthetic data alone, and confidential material always stays with you on the local file route. The result is a tool you can bring to sensitive work with confidence, and describe to an ethics committee without caveat.