Privacy policy
Last updated: October 2026. This policy describes the site's actual data flows.
1. How answers are handled
Free-test answers are saved on your device in browser localStorage. The free test requires no login. Email verification is used to purchase or restore a paid report.
Answers are also saved on our server only when you begin a purchase (see the storage details below). Answers from the free test alone are not saved in customer report storage.
2. Answers in your URL (important)
After completing the test, your result URL has this format:
/r?a=2226262262…
a= contains your individual answers. Questions 1–60 are encoded as a sequence of digits from 1 to 7, so the individual answers can be reconstructed. Trailing unanswered questions are omitted to keep the URL shorter.
- When you open the page: Your browser sends this URL to our server so it can return the result-page framework. Answers are not saved at that point; calculations take place in your browser. However, the URL may appear in ordinary web-server access logs.
- 「Copy link」:copies a share URL for your basic result, not your private report URL. A recipient can therefore see your individual answers.
- Share (image): The image contains only your type and dimension scores; it does not contain individual answers. The URL is not included. Choose this option if you want to keep your answers private.
- Browsing history: Because the URL contains answers, they may remain in browser history and on recipients' devices. Keep this in mind when using a shared device.
3. Information sent to payment providers
When you purchase a detailed report, we send PayPal the following information:
- Your encoded answers, to associate the purchase with the correct result
- A randomly generated purchase ID and product information
Card numbers and other payment details do not pass through this site. You enter them directly with the payment provider, and we do not retain them. The provider's privacy policy applies to its handling of that information.
4. Email login and report storage
We store your verified email, purchase entitlement, order associations and saved answers, types and dates. After purchase, each retest while signed in creates a separate report record. Private reports can only be viewed by someone signed in with that email.
We use Upstash Redis for storage, Resend for verification and purchase emails, and PayPal for payments. Each provider receives the data needed to perform its service.
Verification codes are stored as hashes and expire after 10 minutes, with up to five incorrect attempts. Login sessions use an HttpOnly cookie and expire after 30 days. Email and IP hashes used for rate limiting expire after one hour. Signing out invalidates that device's session.
Orders and history
When you begin a purchase, our server stores order records in order and customer storage. These contain the following fields:
| Order ID and purchase ID | To match payments and confirm purchased access |
|---|---|
| Encoded answers | To let you reopen a purchased report after changing devices or losing the URL |
| Type code and payment status | To verify purchased access and handle support requests |
| Record timestamp | To manage retention periods |
Retention: Confirmed payment records are retained so customers can reopen their reports.Legacy unpaid order records are generally removed after about 90 days. Email-linked purchase records are kept as needed to restore payments and prevent duplicate purchases.
If you do not want encoded answers stored, contact us before purchasing. Free-test answers alone are not stored in customer report storage.
5. Data saved on your device
| Answers | localStorage (not saved on the server before starting a purchase) |
|---|---|
| Result history | localStorage (the latest 12 results, for comparison) |
| Copies of order and purchase IDs | localStorage (for restoring legacy purchases and checking payment status; access is verified on the server) |
| Login state | HttpOnly cookie (30 days; invalidated on sign-out) |
| Access logs | May be retained on the server for a period, including URLs, IP addresses and timestamps |
6. Analytics
We currently use no third-party analytics tools. Any introduction of them will be announced on this page in advance.
7. Disclosure to third parties
We do not disclose collected information to third parties except where required by law or needed for the payment, storage and email services described above.
8. Contact and data requests
For questions about this policy or requests to access, correct or delete your information, contact [email protected] . On request, we can also remove encoded answers from order records, after which the purchased report can no longer be reopened.