An anonymous survey is one where nobody — including you as the administrator — can tell which answers came from which person. LimeSurvey does this properly: switch on Anonymized responses and the link between a participant and their response is never written to the database in the first place.
The single most important thing to know: anonymous and "open to anyone" are two different settings. You can invite a named list of people, send each a personal access code, chase the ones who haven't answered — and still not be able to see who said what. That combination is what most research ethics boards actually ask for, and it is the setup this article describes.
Open Settings (the gear in the left icon rail) → Participant settings and turn on Anonymized responses.
With it on, LimeSurvey stores responses with no reference to the access code that was used. The manual is unambiguous: there will be no way to connect answers and participants — even the admin will not be able to link response data and participant data.
Do this before you activate the survey. Response-recording settings are fixed at activation, and the only way to change them afterwards is to deactivate — which archives the responses you already have. Decide once, up front.
Anonymised responses covers the access code. Everything else is a separate switch, in Settings → Notifications & data:
| Setting | Set to | Why |
|---|---|---|
| Save IP address | Off | An IP address is personal data in the EU and often identifies a household or a workplace |
| Anonymize IP address | On, if you need IPs at all | Masks part of the address — a middle ground when you want rough geography |
| Save referrer URL | Off | Reveals which page — which course, which intranet link — the participant came from |
| Date stamp | Off | A precise submission time can be matched against door logs, lecture times or your own sent-mail |
| Save timings | Off | Per-page timings are a behavioural fingerprint, and rarely needed |
These five lock the moment you activate the survey. On an active survey they appear greyed out. Everything on the Publication & access panel stays editable.
Note what switching on Anonymized responses does to timestamps: submission and token completion dates are set to 1980-01-01 00:00. That is deliberate — it removes the ordering information that could otherwise line responses up against your invitation list. It also means you cannot reconstruct when anything was answered, so if you genuinely need response dates for your analysis, decide that now, not later.
On the Share tab, the access-mode dropdown gives two options:
With access codes, LimeSurvey records against each participant only whether they have completed — never what they answered. That is what lets you send a reminder to the right people without breaking anonymity.
This is where anonymity is usually lost, and no setting protects you from it.
If participants need to interrupt and come back, Participant may save and resume later (in Notifications & data) asks them to set a name and password. Tell them to use a pseudonym and a new password — not their real name, not their work login, and not the email option, since an email address stored for resuming defeats the anonymity you just configured.
An anonymity promise is only worth what your settings do. LimeSurvey has a Privacy policy panel in Settings — use it to state plainly: what is collected, what is not (no IP addresses, no timestamps, no link to the invitation), who sees the results, and how long data is kept. If you use access codes, explain why you can still send reminders without knowing who answered, because participants reasonably assume the opposite.
Participant settings reference: https://www.limesurvey.org/manual/Participant_settings