Back to sign in

Terms of Use

The terms under which researchers and authorised users may access, configure, and use the Carrier research platform.

1. About these Terms

These Terms of Use apply to researchers, study owners, administrators, collaborators, students, and other authorised users who create, configure, manage, test, analyse, or administer studies using Carrier.

Carrier is a research infrastructure platform for designing, running, and analysing online studies involving human–human interaction, human–AI interaction, AI-assisted messaging, simulated conversations, surveys, automated annotation, and related research workflows.

Carrier provides technical infrastructure. It does not replace researcher responsibility for study design, ethics approval, data protection compliance, participant management, analysis, reporting, or research governance.

By creating an account, accessing the researcher/admin area, creating a study, uploading study materials, configuring API keys, or otherwise using Carrier as a researcher, you agree to these Terms.

2. Acceptance of these Terms

You may be required to confirm acceptance of these Terms before using Carrier, for example by ticking a box stating:

“I have read and agree to the Carrier Researcher Terms of Use.”

The platform operator may record your acceptance of these Terms, including your name, email address, institution, account ID, date and time of acceptance, version of the Terms accepted, and related technical metadata where appropriate.

If you do not agree to these Terms, you must not use Carrier.

3. Authorised use

Carrier is intended for academic, educational, research, development, and testing purposes by authorised users.

You may use Carrier only if:

  1. you have been granted access by the platform operator or an authorised study owner;

  2. you use Carrier for legitimate research, teaching, development, testing, or related academic purposes;

  3. you comply with these Terms, applicable law, institutional policies, ethics requirements, data protection obligations, and third-party service terms;

  4. you have authority from your institution, supervisor, principal investigator, or project lead where such authority is required.

You must not use Carrier for unauthorised commercial activity, surveillance, profiling, behavioural manipulation, unlawful data collection, or any activity that creates unreasonable legal, ethical, security, operational, or reputational risk.

4. Researcher responsibilities

If you use Carrier to design, run, test, or analyse a study, you are responsible for ensuring that the study is properly designed, approved, documented, and managed.

You must ensure that:

  1. all required ethics approval, institutional approval, data protection approval, risk assessment approval, and, where relevant, safeguarding approval are obtained before participant data is collected;

  2. participants receive clear and accurate information about the study;

  3. participants are told what data will be collected, how it will be used, who will access it, how long it will be retained, and who to contact;

  4. any use of AI agents, LLMs, AI mediators, simulated participants, automated annotation, or AI-assisted analysis is appropriately disclosed, justified, and approved;

  5. personal data is collected only where necessary and proportionate;

  6. special category data is collected only where necessary, approved, legally justified, and protected with appropriate safeguards;

  7. participant consent, withdrawal, debriefing, payment, and completion procedures are correctly configured;

  8. screening logic, randomisation, quotas, redirects, timers, completion codes, survey links, and data export settings are tested before launch;

  9. exported data is stored, shared, analysed, archived, and deleted in line with applicable law, ethics approval, participant information, funder requirements, and institutional policy;

  10. any third-party tools used in the study are appropriate, approved, and disclosed where required.

Carrier is not responsible for errors caused by study misconfiguration, incorrect study logic, missing approvals, unsuitable prompts, incorrect participant information, researcher misuse, or failure to test a study adequately before launch.

5. Account security

You are responsible for keeping your Carrier account secure.

You must not:

  1. share your login details with another person;

  2. allow another person to use your account;

  3. use another person’s account;

  4. attempt to access studies, data, admin tools, API keys, or system areas for which you do not have permission;

  5. bypass authentication, authorisation, access controls, rate limits, or system safeguards;

  6. attempt to extract credentials, API keys, system prompts, secrets, or restricted configuration information.

You must promptly report any suspected unauthorised access, account compromise, data breach, accidental disclosure, API-key exposure, or security vulnerability to the platform administrator.

The platform operator may suspend, restrict, or remove access if there is suspected misuse, compromise, unauthorised access, breach of these Terms, or risk to participants, data, infrastructure, the platform, or the institution.

6. API keys and external AI providers

Carrier may allow researchers to connect external AI or LLM providers, including but not limited to OpenAI, Anthropic, or other model providers.

Where you provide, upload, store, configure, or use an API key through Carrier, you are responsible for that API key and for all usage, costs, limits, permissions, and risks associated with the relevant provider account.

You must ensure that:

  1. you have authority to use the API key for the intended study or research purpose;

  2. the API key is not shared with unauthorised users;

  3. the API key is not inserted into participant-facing pages, public prompts, public study materials, client-side code, shared documents, exported datasets, or insecure communication channels;

  4. the API key is configured with appropriate provider-side spend limits, usage limits, rate limits, model restrictions, project restrictions, and monitoring alerts;

  5. usage limits are set before launching any live study;

  6. usage is monitored during recruitment, testing, batch annotation, and automated agent deployment;

  7. the API key is rotated, disabled, or revoked immediately if there is suspected exposure, misuse, or compromise;

  8. the AI provider’s terms, privacy terms, data processing terms, and usage policies are compatible with your study;

  9. any data sent to the AI provider is permitted by the study’s ethics approval, participant information, consent materials, data protection arrangements, and institutional policy.

Carrier may provide technical mechanisms for storing or using API keys. However, you remain responsible for managing the provider account, monitoring usage, setting appropriate limits, and controlling provider-side costs.

To the fullest extent permitted by law, Carrier and its operator are not responsible for API-key leakage, misuse, unauthorised use, unexpected API charges, provider charges, provider account suspension, or loss of access where these arise from:

  1. researcher action or omission;

  2. study misconfiguration;

  3. insecure sharing of API keys;

  4. use of API keys outside Carrier;

  5. failure to set provider-side usage limits or spend caps;

  6. failure to monitor usage;

  7. failure to revoke or rotate a compromised key;

  8. excessive participant recruitment;

  9. automated retries, loops, or high-volume requests caused by study design;

  10. third-party provider outage, pricing change, policy change, model change, rate limit, or service restriction.

Nothing in these Terms excludes or limits liability where such exclusion or limitation would be unlawful.

Researchers should set conservative API usage limits before launching studies, especially when using automated agents, multi-participant studies, LLM-mediated conversations, high-volume recruitment, or batch annotation.

7. AI-generated content and AI-assisted interaction

Carrier may support studies involving AI-generated messages, AI mediators, simulated agents, automated prompts, AI-assisted annotation, or AI-supported analysis.

AI-generated content may be inaccurate, incomplete, biased, offensive, unsafe, misleading, or unsuitable for the intended purpose.

Researchers are responsible for:

  1. testing AI behaviour before launch;

  2. risk-assessing AI-generated content;

  3. monitoring AI outputs where appropriate;

  4. configuring prompts and safeguards appropriately;

  5. ensuring AI use is suitable for the participant group and study context;

  6. ensuring AI involvement is described accurately in participant-facing materials where required.

Carrier must not be used to provide medical, legal, financial, psychological, safety-critical, or emergency advice unless this has been specifically reviewed, approved, and legally authorised.

8. Participant protection

Researchers must take reasonable steps to protect participants from harm, distress, deception, privacy invasion, discrimination, manipulation, or other unreasonable risks.

You must ensure that:

  1. participant-facing materials are accurate, understandable, and consistent with the approved study protocol;

  2. sensitive topics are handled with appropriate warnings, safeguards, and support information;

  3. deception is used only where ethically approved and followed by appropriate debriefing;

  4. participants are not exposed to unnecessary personal data from other participants;

  5. moderation, escalation, or withdrawal procedures are in place where appropriate;

  6. studies involving children, young people, vulnerable groups, or sensitive topics have specific approval and safeguards;

  7. participants are not misled about whether they are interacting with a human, an AI system, a simulated agent, or a mediated conversation, except where this has been ethically approved.

Carrier may suspend, restrict, or remove a study if it appears to create unacceptable participant risk, data protection risk, governance risk, or reputational risk.

9. Data protection and confidentiality

Researchers are responsible for complying with applicable data protection law, institutional policy, ethics approval, and study-specific data management requirements.

You must:

  1. collect only the data required for the study;

  2. avoid collecting directly identifiable information unless necessary and approved;

  3. use pseudonymisation or anonymisation where appropriate;

  4. store exported data securely;

  5. restrict access to authorised collaborators only;

  6. avoid sharing participant data through insecure channels;

  7. comply with the retention periods stated in the ethics approval, participant information sheet, and data management plan;

  8. delete, archive, or anonymise data when required;

  9. report suspected data breaches immediately;

  10. ensure that data sent to third-party providers, including AI providers, is lawful, approved, and necessary.

You must treat participant data, study data, API keys, credentials, unpublished study materials, system prompts, and restricted platform information as confidential.

10. Controller and processor responsibilities

The data protection role of Carrier and its operator may vary depending on the study.

For some activities, the University of Bath may act as a controller, for example in relation to platform administration, account management, security, and operational logs.

For individual research studies, the controller may be the researcher’s institution, the principal investigator’s institution, or multiple institutions acting as joint controllers.

Where Carrier processes study data on behalf of another controller, Carrier may act as a processor or infrastructure provider under the relevant institutional arrangements.

Researchers are responsible for confirming the data protection role for their study and ensuring that this is accurately described in participant information sheets, privacy notices, ethics applications, and data management documentation.

11. Acceptable use

You must not use Carrier to:

  1. break the law or encourage unlawful activity;

  2. collect personal data without proper approval and participant information;

  3. collect special category data without appropriate legal and ethical justification;

  4. harass, abuse, threaten, exploit, deceive, or discriminate against any person or group;

  5. attempt to identify participants unless this is explicitly approved and necessary;

  6. upload malware, spyware, harmful code, or malicious scripts;

  7. probe, scan, overload, attack, reverse engineer, or disrupt Carrier systems;

  8. extract system prompts, credentials, API keys, secrets, or private configuration details;

  9. use prompt injection or similar methods to bypass safeguards, access controls, study rules, or system restrictions;

  10. use the platform for unauthorised surveillance, profiling, automated decision-making, or behavioural manipulation;

  11. infringe intellectual property rights, confidentiality obligations, third-party rights, or third-party service terms;

  12. impose unreasonable technical load on the platform or connected third-party services.

12. Study materials and intellectual property

Researchers are responsible for the study materials they upload, create, or configure in Carrier, including prompts, questionnaires, consent forms, images, text, experimental conditions, AI instructions, debriefing materials, and analysis settings.

You must ensure that you have the right to use all study materials uploaded to Carrier.

Unless otherwise agreed:

  1. researchers retain responsibility for their own study materials and research outputs;

  2. Carrier may store and process study materials and study data to provide the platform;

  3. Carrier may use operational metadata to maintain security, debug errors, improve reliability, and administer the service;

  4. Carrier does not claim ownership of researchers’ academic outputs.

Use of the Carrier software code may be governed by a separate open-source licence. Use of the hosted Carrier platform is governed by these Terms.

13. Testing before launch

Before launching a live study, researchers must test the study carefully.

This includes checking, where relevant:

  1. consent flow;

  2. screening logic;

  3. randomisation;

  4. group assignment;

  5. chatroom assignment;

  6. AI prompt behaviour;

  7. API usage and cost estimates;

  8. provider-side API limits and spend caps;

  9. quota logic;

  10. timers;

  11. redirect links;

  12. completion codes;

  13. data export format;

  14. withdrawal route;

  15. debriefing materials;

  16. browser and device compatibility;

  17. participant payment or reimbursement process.

Carrier is not responsible for data loss, poor-quality data, failed recruitment, participant underpayment, participant overpayment, incorrect allocation, excessive API costs, unusable study outputs, or failed studies resulting from inadequate testing or study misconfiguration, except where such exclusion would be unlawful.

14. Platform availability and changes

Carrier is provided on an “as is” and “as available” basis.

The platform may be updated, modified, suspended, restricted, or discontinued for maintenance, security, legal, funding, governance, or operational reasons.

We do not guarantee:

  1. uninterrupted availability;

  2. error-free operation;

  3. compatibility with all browsers, devices, or third-party systems;

  4. continuous access to third-party AI providers;

  5. permanent availability of any particular model, provider, function, feature, or study configuration;

  6. recovery of data not exported or backed up by the researcher.

Researchers should not rely on Carrier as the sole storage location for important research data and should export and back up data in accordance with their approved data management plan.

15. Third-party services

Carrier may integrate with third-party services, including AI providers, cloud hosting providers, database services, survey platforms, recruitment platforms, analytics tools, authentication services, and institutional IT systems.

Third-party services are governed by their own terms, policies, pricing, availability, security arrangements, and data processing terms.

Researchers are responsible for ensuring that third-party services used in their studies are appropriate, approved, and disclosed where required.

To the fullest extent permitted by law, Carrier is not responsible for third-party outages, provider charges, pricing changes, policy changes, rate limits, model changes, provider errors, data processing practices, service restrictions, or service discontinuation.

16. Suspension or removal of studies

The platform operator may suspend, restrict, or remove a study where there is reasonable concern about:

  1. lack of ethics approval;

  2. participant safety;

  3. unlawful or excessive data collection;

  4. data protection risk;

  5. security risk;

  6. API misuse or uncontrolled costs;

  7. harmful AI behaviour;

  8. breach of these Terms;

  9. breach of institutional policy;

  10. unacceptable operational load on the platform;

  11. reputational risk to the platform or institution.

Where appropriate, the platform operator will try to contact the study owner before taking action. However, urgent action may be taken without prior notice where necessary.

17. No warranty

Carrier is provided without warranties of any kind to the fullest extent permitted by law.

We do not warrant that Carrier will be uninterrupted, error-free, secure, suitable for a particular study, compatible with all systems, or capable of producing valid research results.

Researchers are responsible for independently validating their study design, study configuration, data quality, AI behaviour, analysis, and research conclusions.

18. Limitation of liability

Nothing in these Terms excludes or limits liability where such exclusion or limitation would be unlawful, including liability for death or personal injury caused by negligence, fraud, fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.

To the fullest extent permitted by law, Carrier and its operator are not liable for indirect, consequential, special, incidental, or punitive losses, including loss of data, loss of research opportunity, loss of publication opportunity, loss of funding, loss of goodwill, participant recruitment failure, API charges, third-party provider charges, or losses caused by researcher misconfiguration, researcher misuse, or unauthorised use of researcher-provided API keys.

Researchers remain responsible for their own studies, API provider accounts, participant management, data exports, analysis, publications, and compliance obligations.

19. Termination of access

You may stop using Carrier at any time.

The platform operator may suspend or terminate your access if:

  1. you breach these Terms;

  2. your account creates security, legal, ethical, operational, or reputational risk;

  3. your institutional authorisation ends;

  4. the relevant study ends;

  5. the platform is withdrawn, migrated, or replaced;

  6. your use of Carrier is inconsistent with the platform’s research, governance, or operational purpose.

After access ends, some data may be retained where required for research integrity, legal compliance, audit, security, backup, or institutional record-keeping.

20. Changes to these Terms

These Terms may be updated from time to time, and the latest version is always available on this page.

Where appropriate, users may be asked to accept the updated Terms before continuing to use Carrier.

Continued use of Carrier after updated Terms take effect means that you accept the updated Terms.

21. Governing law

These Terms are governed by the laws of England and Wales.

The courts of England and Wales will have jurisdiction, unless mandatory law provides otherwise.

22. Contact

For questions about these Terms, contact:

admin@carrierlab.org