An anonymous survey is one where nobody, including you as the administrator, can tell which answers came from which person. Switch on Anonymized responses and LimeSurvey never writes the link between a participant and their response to the database.
Anonymous and "open to anyone" are two different settings. You can invite a named list of people, send each a personal access code, chase the ones who haven't answered, and still not be able to see who said what. That combination is what most research ethics boards ask for, and it is the setup this article describes.
Open Settings (the gear in the left toolbar) > Participant settings and turn on Anonymized responses (1).
With it on, LimeSurvey stores responses with no reference to the access code that was used. Nobody, not even an administrator, can link response data and participant data.
Do this before you activate the survey. Response-recording settings are fixed at activation, and the only way to change them afterwards is to deactivate, which archives the responses you already have. Decide once, up front.
Anonymized responses covers the access code. Everything else is a separate switch, in Settings > Notifications & data:
| Setting | Set to | Why |
|---|---|---|
| Save IP address | Off | An IP address is personal data in the EU and often identifies a household or a workplace |
| Anonymize IP address | On, if you need IPs at all | Masks part of the address: a middle ground when you want rough geography |
| Save referrer URL | Off | Reveals which page the participant came from, such as a course or an intranet link |
| Date stamp | Off | A precise submission time can be matched against door logs, lecture times or your own sent-mail |
| Save timings | Off | Per-page timings are a behavioral fingerprint, and rarely needed |
These five lock the moment you activate the survey. On an active survey they appear greyed out. Everything on the Publication & access panel stays editable.
Note what switching on Anonymized responses does to timestamps: submission and token completion dates are set to 1980-01-01 00:00. That is deliberate: it removes the ordering information that could otherwise line responses up against your invitation list. It also means you cannot reconstruct when anything was answered, so if you genuinely need response dates for your analysis, decide that now, not later.
On the Share tab, the access-mode dropdown gives two options:
With access codes, LimeSurvey records against each participant only whether they have completed, never what they answered. That is what lets you send a reminder to the right people without breaking anonymity.
This is where anonymity is usually lost, and no setting protects you from it.
If participants need to interrupt and come back, Participant may save and resume later (in Notifications & data) asks them to set a name and password. Tell them to use a pseudonym and a new password, not their real name, not their work login, and not the email option, since an email address stored for resuming defeats the anonymity you just configured.
An anonymity promise is only worth what your settings do. LimeSurvey has a Privacy policy panel in Settings: use it to state plainly: what is collected, what is not (no IP addresses, no timestamps, no link to the invitation), who sees the results, and how long data is kept. If you use access codes, explain why you can still send reminders without knowing who answered, because participants reasonably assume the opposite.
Don't. Export responses and participant lists separately, and don't join them in a spreadsheet: that recreates the link you removed.
No. Confidential means you can identify people but promise not to. Anonymous means you cannot. Use the right word in your invitation.
Before you invite anyone, submit a test response and open the responses table. If you see an access code, an IP address or a real submission time next to it, something is still switched on.