What is never stored
No survey stores a respondent's name, email address or IP address against their answers. That is structural rather than a setting, and it is true of every survey on the platform.
The anonymity toggle controls something different: whether the dashboard refuses to show results for groups too small to stay anonymous.
The small-group floor
Filters make it easy to narrow a 120-person survey down to a slice of three people, with their open-text answers rendered underneath. At that size, colleagues can often tell who said what.
With anonymity on, results below the floor are suppressed — the chart grid, the open-text answers and the filtered export all withhold rather than render. The default floor is 5, or 3 for multi-rater and 360 surveys, and you can set your own.
It is applied after filters and after any excluded responses, so you cannot get under it by toggling “hide flagged responses” and watching the charts keep rendering.
The filter bar also stops printing exact match counts when a group is suppressed — “3 of 120 match” would itself be the disclosure.
Turning it on is always allowed, including on a survey that is already running. Turning it off once responses exist is refused, because a promise was already made to the people who answered.
If you need an identified version, duplicate the survey and run that separately.
Location plus tenure plus department is often enough to identify one person in a small company — and adding age, gender and postcode on top of that makes it near-certain. Collect the segments you will genuinely analyse, and no more.
This matters most on exactly the surveys where honesty matters most, like anything asking whether people feel safe raising concerns.