Privacy Policy

This policy explains what personal data UnlockPersonality processes when you take the free test, view your results, buy and restore the full report, sign in, or contact us. It also explains why we process it, who helps us, how long we keep it, and the rights you have under the laws of the EU, the UK, India, the United States, and other places.

Last updated October 7, 2026

In short

  • While you take the free test, your progress is saved in your own browser. When you finish, your answers are sent to our server so the test can be scored. We do not store or log those answers. We keep only the computed profile.
  • That profile (your type code, portrait, and trait percentages) is saved on our server under a random ID before you decide whether to pay, so the results page and checkout can work.
  • When you finish, we ask for your email address, or a Google sign-in, so we can save your result and send you a link to it.
  • If you buy the full report, we create a customer record with your email address (or reuse the one made when you saved your result) and link your profile to it. Dodo Payments runs the checkout as Merchant of Record. We never receive your full card number.
  • We use Google Analytics to measure how the Site is used. We do not run ads or sell your personal data or share it for targeted advertising, and we do not use it to train third-party AI models.
  • Your result is an automated score you asked for. It is not a medical or psychological diagnosis and we do not use it to make decisions with legal or similarly significant effects about you.
  • You can ask to access, correct, or delete your data, or raise a grievance, by emailing [email protected]. Section 15 explains how.

1. Who we are and how to contact us

1.1 The organisation responsible

UnlockPersonality is operated by CyberRudra Technologies (“we”, “us”, “our”), a business based in Maharashtra, India. For the personal data described in this policy, we are:

  • the “controller” under the EU General Data Protection Regulation (the “EU GDPR”) and the UK GDPR together with the UK Data Protection Act 2018 (the “UK GDPR”);
  • the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 and the rules made under it (together, the “DPDP Act”); and
  • the “business” or “controller” under the US state privacy laws described in Section 14.4.

Postal address: CyberRudra Technologies, 6, Keshav City, Vrundavan Nagar, Sindhi Meghe, Wardha, Maharashtra 442001, India.

Email for all privacy matters: [email protected]. You can also choose the privacy topic on our Contact Us page.

1.2 Grievance Officer

For the purposes of India’s Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, our Grievance Officer can be reached at [email protected] or at the postal address in Section 1.1. Please put “Grievance” in the subject line. Where the law requires it, we will acknowledge your grievance within 24 hours and resolve it within 15 days, or within any other period the applicable law sets. If you are a Data Principal under the DPDP Act and you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India (see Section 16.3).

1.3 Data protection officer and representatives

Given the size of our business and the nature of our processing, we have not appointed a data protection officer. The email address above reaches the people responsible for privacy and handles requests under the EU GDPR, the UK GDPR, the DPDP Act, and US state laws. If the law requires us to appoint a representative in the EU or UK, we will name them here.

1.4 How this policy relates to our Terms

The rules for using the Site and buying the full report are in our Terms & Conditions (the “Terms”). This policy explains how we handle personal data in connection with the Service. If the two documents appear to conflict on a privacy point, this policy applies.

2. Scope and who this policy applies to

This policy applies to anyone who visits the Site or uses the Service, wherever they are located, including people who only take the free test, people who buy the full report, people who restore or sign in to an existing purchase, and people who contact us.

It covers personal data we process online through the Site and offline when you email us. It does not cover:

  • the checkout pages hosted by Dodo Payments, which collect your card and billing details under Dodo Payments’ own privacy policy (see Section 9.1);
  • Google’s own processing when it runs reCAPTCHA or Google sign-in, which is governed by Google’s privacy policy;
  • websites, apps, or services operated by others that you reach through a link on the Site (see Section 20); and
  • information that is anonymous, meaning it cannot reasonably be linked to you.

Some sections apply only to people in particular places. Section 14 sets out rights by region, and Section 17 contains additional information for California residents. Where a law gives you more protection than this policy describes, that law applies.

3. Definitions

In this policy, the following terms have these meanings:

  • Site means the UnlockPersonality website and its pages, in every language we offer.
  • Service means the free personality test, the results page, the paid full report, and the related restore, sign-in, and support features.
  • Personal data means any information relating to an identified or identifiable person. It includes “personal information” under US state laws and “digital personal data” under the DPDP Act. We use the terms interchangeably.
  • Profile means the output of scoring your test: a 16-type code, a portrait or variant label, trait percentages, and related metrics.
  • Results Record means the record on our server that holds a Profile under a random public ID.
  • Customer Record means the record we create with your email address when you save a result, sign in with Google, or start a purchase. It notes which of these first created it.
  • Purchase Record means the record of a checkout attempt and its outcome (described in Section 4.4).
  • Entitlement means the record that gives your Customer Record access to the full report after a successful payment.
  • Report Snapshot means a copy of the Profile stored with your Entitlement so the purchased report can be shown and restored.
  • Browser Storage means cookies and similar site data kept on your device by your browser.
  • Service Provider means a company that processes personal data on our behalf or helps us deliver the Service, including a “processor” under the GDPR, a “Data Processor” under the DPDP Act, and a “service provider” or “contractor” under US state laws.
  • Data Principal means the person to whom personal data relates, as that term is used in the DPDP Act.

4. Information we collect

4.1 Sources

We collect personal data from three sources:

  • From you, when you finish the test, enter an email address, or send us a message.
  • Automatically, from your browser and device when you use the Site, through server and security logs and Browser Storage.
  • From Service Providers, namely Dodo Payments (payment status and identifiers) and, if you choose it, Google (basic account details for sign-in).

We do not buy personal data, and we do not collect it from data brokers, social networks, or advertising platforms. The rest of this section describes each step of the Service in the order you are likely to meet it.

4.2 Taking the free test

You do not need to give a name or email address while you answer the test. While you answer, your progress (the answers so far and your position in the test) is saved in your browser, so you can pause and continue on the same device. This copy stays on your device. We do not receive it while you are still answering.

4.3 Scoring and the Results Record

When you finish the test, your browser sends your answers to our server so they can be scored. The application uses them to compute your Profile and returns the Profile to your browser. The application does not store or log the individual answers contained in that scoring request.

We then save the Profile on our server in a Results Record identified by a random public ID. This happens before any payment, so the results page and the checkout can refer to your result. At this stage the Results Record contains:

  • the 16-type code and the portrait or variant label;
  • trait percentages and related metrics; and
  • the public ID and the time the record was created.

No name or email address is attached to a Results Record when it is created. On its own it does not tell us who you are, although it may still be personal data because it can be linked to your device through Browser Storage.

Your browser also keeps a copy of the result on your device so the results page can show it. Section 10 explains what is stored on your device and for how long.

4.3A Saving your result

Before the results page shows the checkout, we ask where to save your result. You can type an email address or continue with Google (see Section 4.5). When you save with an email address:

  • If the email address is new to us, we create a Customer Record for it, link the Results Record to it, note the time the result was saved, and sign you in on that browser. Because you have not yet proved that you control the address, this sign-in ends as soon as a purchase is made for that email address or someone signs in to it with a link, code, or Google.
  • If the email address already has a Customer Record, we do not sign you in and we do not link the result to that record. We only note the time the result was saved.
  • In both cases we send one email to that address with a private link to the result. Opening that link on a device that is not signed in to that email address asks you to sign in first.

If you are already signed in when you finish the test, we save the result to your Customer Record without asking again. The save form is protected by Google reCAPTCHA (see Section 4.6).

4.4 Buying the full report

The full report is a one-time purchase of US$19.99 (list price US$29.99). It is not a subscription. When you choose to buy it:

  • You enter an email address, which we fill in with the one you saved your result to. We create a Customer Record for it if one does not already exist.
  • We create a Purchase Record containing the payment provider (Dodo Payments), the checkout session ID, the payment ID, the status (pending, paid, failed, or refunded), the amount, the currency, and timestamps.
  • We send Dodo Payments your email address and our internal references (the purchase ID, customer ID, product, and Results Record ID) so it can process the order and tell us which purchase it relates to.

Dodo Payments hosts the checkout page and acts as Merchant of Record. It collects your card or wallet details, billing details, and country, and it may run fraud and risk checks. Accepted methods are Visa, Mastercard, and American Express, and Apple Pay or Google Pay may appear depending on your device and country. We do not receive or store your full card number, security code, or wallet credentials.

When Dodo Payments notifies our server that a payment has succeeded, we activate an Entitlement for your Customer Record, link the Results Record to it, and store a Report Snapshot (type code, portrait, and metrics). If the payment is later refunded or reversed through a chargeback, Dodo Payments notifies us and we switch the Entitlement off. We keep the Purchase Record as described in Section 12.

4.5 Restoring access and signing in

If you want to open a purchased report on another device, or after clearing your browser, you can use the restore or sign-in pages:

  • Restore. You enter your checkout email address and we email a one-time link that is valid for 45 minutes.
  • Email sign-in. You enter your email address and we email a link together with a short code, both valid for 45 minutes.

For both, we store only a cryptographic hash of the link token or code, together with its expiry time and the time it was used. We give the same on-screen response whether or not we find a matching purchase, so the forms do not reveal whether a given email address belongs to a customer.

When you sign in, or return to the Site from a successful checkout, we set a session cookie and store a hash of the session token on our server with its expiry time (up to 30 days). We may also set a cookie that remembers the email address used to unlock the report on that device. Section 10 gives the details.

Google sign-in. We offer “Continue with Google” as an alternative to typing an email address, when you save your result, sign in, or restore. If you choose it, Google shares with us your name, email address, profile picture URL, and Google account identifier. We use these only to find or create your Customer Record, save your result to it, and sign you in. We set two temporary cookies for the duration of the sign-in step. We do not receive your Google password, and Google’s handling of your account data is governed by the Google Privacy Policy.

4.6 Contacting us

If you use the contact form, we receive your name, email address, message, and the topic you select where the form offers one. The form sends your message to our support inbox by email through our email delivery provider, Resend. If you email us directly, we receive your email address, your message, and anything you attach.

The contact form, the save step at the end of the test, the sign-in and restore forms, and the checkout form when you are not signed in are protected by Google reCAPTCHA to block spam and automated abuse. When a page with one of these forms loads, a Google script runs in your browser and sends Google information such as your IP address, browser and device details, and signals about how you interact with the page. Google processes that information under its Privacy Policy and Terms of Service. reCAPTCHA is not loaded while you answer the test.

4.7 Technical and security data

The Site runs on a hosting server and is delivered through Cloudflare. As with any website, each request your browser makes reveals certain technical information. Our hosting provider and Cloudflare process IP addresses and request data to deliver pages, defend against attacks, and filter malicious traffic. Standard server and security logs may record:

  • your IP address;
  • your browser’s user agent (browser type and version, operating system);
  • the URL requested and the referring page; and
  • the date and time of the request and the response status.

We use this data to operate and secure the Site. We do not use it to build a profile of you or to follow you across other websites.

4.8 Information stored in your browser

Some information is kept only in Browser Storage on your device: test progress, a local copy of your result, a local record of your unlock status, the unlock email address, and small flags that control the interface. This information stays on your device until you clear it or it expires. Section 10 lists each item with its purpose and duration.

4.9 What you must provide

You can answer the test without giving contact details. To save your result and continue to the results page, you must give an email address or continue with Google, because that is how we keep your result and let you open it again. To buy, restore, or sign in, you must provide an email address, because that is how we identify your purchase and deliver access. To use the contact form, you must provide a name, email address, and message. If you choose not to provide this information, we cannot complete that step, but you can still use the free test.

5. How and why we use it

5.1 Purposes and legal bases (EU and UK)

Where the EU GDPR or UK GDPR applies, we must have a legal basis for each use of personal data. The list below shows each purpose, the data involved, and the basis we rely on.

  • Scoring the test and showing your results. Answers (processed transiently), Profile, Results Record, Browser Storage. Basis: performance of a contract, namely providing the free test under the Terms at your request (Article 6(1)(b)).
  • Keeping the Results Record before payment. Profile and public ID. Basis: steps taken at your request before entering into a contract (Article 6(1)(b)), and our legitimate interest in letting you return to your results and buy the full report without retaking the test (Article 6(1)(f)).
  • Saving your result to your email address. Email address, Customer Record, the link between it and the Results Record, session records, and the result-saved email. Basis: performance of a contract, namely keeping your result available at your request (Article 6(1)(b)).
  • Processing your purchase and delivering the full report. Email address, Customer Record, Purchase Record, Entitlement, Report Snapshot, and the references sent to Dodo Payments. Basis: performance of a contract (Article 6(1)(b)).
  • Restoring access, signing you in, and keeping you signed in. Email address, hashed tokens and codes, session records, cookies, and (if used) Google account details. Basis: performance of a contract (Article 6(1)(b)).
  • Sending transactional emails such as the link to your saved result, restore links, and sign-in codes. Email address. Basis: performance of a contract (Article 6(1)(b)).
  • Answering messages and support requests. Name, email address, message. Basis: our legitimate interest in responding to people who contact us (Article 6(1)(f)), or performance of a contract where the message concerns your purchase (Article 6(1)(b)).
  • Protecting our forms with reCAPTCHA. IP address, device and interaction signals. Basis: our legitimate interest in keeping the contact, save, sign-in, restore, and checkout forms free of spam and automated abuse (Article 6(1)(f)).
  • Keeping the Site secure and preventing fraud and abuse. Logs, IP addresses, request data, and payment status. Basis: our legitimate interest in protecting the Service, our customers, and ourselves (Article 6(1)(f)).
  • Handling refunds, chargebacks, and disputes. Purchase Record, Entitlement, correspondence. Basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in establishing, exercising, or defending legal claims (Article 6(1)(f)).
  • Keeping tax and accounting records. Purchase Record and Customer Record. Basis: compliance with a legal obligation (Article 6(1)(c)).
  • Responding to lawful requests and enforcing our Terms. The data relevant to the request. Basis: legal obligation (Article 6(1)(c)) or our legitimate interest in protecting our rights (Article 6(1)(f)).
  • Reorganisation or sale of the business. Customer, purchase, and entitlement data. Basis: our legitimate interest in being able to restructure or transfer the business while continuing to honour purchases (Article 6(1)(f)).

5.2 Legitimate interests

Where we rely on legitimate interests, we have weighed our interest against your rights and expectations. We consider that people who use a paid online service reasonably expect it to keep their result available, to stop fraud and spam, and to answer their messages. You have the right to object to processing based on legitimate interests (see Section 14.2). You can ask us for more information about how we carried out this balancing.

5.3 Consent

We do not rely on consent for the core Service, and we do not send marketing emails. If we ever introduce a feature that relies on consent, we will ask for it clearly at that point, and you will be able to withdraw it at any time without affecting processing that took place before withdrawal.

5.4 India (DPDP Act)

Where the DPDP Act applies, we process digital personal data either on the basis of your consent, which you give when you choose to submit data for the purpose described at that point, or for a legitimate use recognised by the Act. Legitimate uses include processing data you have voluntarily provided for a specified purpose where you have not indicated that you do not consent, and processing needed to comply with a law. This policy, together with the information shown at each step, is our notice to you. You may withdraw consent at any time by emailing us. Withdrawal does not affect processing done before it, but it may mean we can no longer keep your report restorable.

5.5 United States

For residents of US states with consumer privacy laws, we use personal information only for the business purposes described in Section 5.1, which include providing the Service you requested, security and fraud prevention, debugging, and legal compliance. We do not use it for targeted advertising, sale, or profiling that produces legal or similarly significant effects.

5.6 New purposes

If we want to use personal data for a purpose that is not compatible with the purposes above, we will update this policy and, where the law requires, tell you or ask for your consent first.

6. Personality results and sensitive data

The test consists of general statements about preferences and everyday behaviour. It does not ask about your health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric data, government identity numbers, financial account details, or precise location.

A Profile is an inference about personality preferences drawn from answers you chose to give. We do not treat it as “special category” data under Article 9 of the GDPR, because it does not reveal any of those categories and we do not use it to infer them. In particular, we do not use your result to infer anything about your physical or mental health, and the report is not a medical, psychological, or clinical assessment.

Please do not include sensitive information in a contact form message or email. If you do, we will use it only to deal with your message, and we may delete it if it is not needed.

Under California law, we do not collect or process sensitive personal information for the purpose of inferring characteristics about you (see Section 17).

7. Automated processing

Scoring the test is fully automated. Our software applies a fixed scoring method to your answers and produces the Profile you asked for. No person reviews your answers as part of this step.

This scoring is a form of profiling in the broad sense used by the GDPR, because it evaluates personal preferences. However, it does not produce a decision that has legal effects on you or that similarly significantly affects you, within the meaning of Article 22 of the GDPR and UK GDPR. We do not use the Profile to decide whether you can access any service, what price you pay, or anything about employment, credit, housing, insurance, education, or health care. We do not make any other automated decisions about people. Under US state laws, we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.

If you have questions about how your result was produced, you can contact us and we will explain the method in general terms.

8. What we do not do

  • We do not show advertising on the Site and do not work with ad networks.
  • We use Google Analytics (measurement ID G-CY58M7W0L6) to count visits and see which pages are used. We do not use advertising pixels, social media plugins that track you, or session recording tools.
  • We do not sell personal data, and we do not share it for cross-context behavioural advertising or targeted advertising.
  • We do not send marketing emails or newsletters.
  • We do not use your answers, Profile, or messages to train third-party artificial intelligence models, and we do not give them to anyone for that purpose.
  • We do not combine your data with information from data brokers or other outside sources to build a profile of you.
  • We do not offer the test for employment screening, and we do not make decisions with legal or similarly significant effects about you (see Section 7).

9. Who we share it with

We disclose personal data only to the recipients below, and only as much as each one needs.

9.1 Service Providers

  • Dodo Payments. Hosts the checkout and acts as Merchant of Record. We send it your email address and internal references, and it sends us payment status and identifiers. For the card, billing, tax, and fraud screening data it collects at checkout, Dodo Payments acts as an independent controller under its own privacy policy. It may also send you a receipt or invoice for your purchase.
  • Resend. An email delivery provider based in the United States. It sends the link to your saved result, restore links, and sign-in codes on our behalf, and delivers contact form messages to our inbox. It receives the recipient email address and the content of those emails.
  • Google (reCAPTCHA and sign-in). reCAPTCHA protects the contact, save, sign-in, restore, and checkout forms. It receives the technical and interaction data described in Section 4.6 and processes it under the Google Privacy Policy and Terms of Service. If you use Google sign-in, Google also handles that sign-in under the same policy.
  • Cloudflare. Delivers the Site through its global network and protects it against attacks. It processes IP addresses and request data for those purposes.
  • Our hosting provider. Runs the application and stores the databases that hold Results Records, Customer Records, Purchase Records, Entitlements, Report Snapshots, and session and token records.

Where a Service Provider acts as our processor, it may use personal data only on our instructions and must protect it under a written agreement.

9.2 Professional advisers

We may share information with lawyers, accountants, auditors, and insurers where needed for them to advise us or for us to meet our obligations. They are bound by professional or contractual duties of confidentiality.

9.3 Authorities and legal process

We may disclose information to courts, regulators, tax authorities, law enforcement, or other public bodies where we believe in good faith that the law requires it, or where it is necessary to establish, exercise, or defend legal claims, to investigate fraud or a security incident, or to protect the rights, property, or safety of any person. Where the law allows, we will try to tell you before disclosing your data in response to a request.

9.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganisation, or sale of all or part of our business, personal data needed to continue the Service and honour existing purchases may be transferred to the new owner or reviewed by a prospective buyer under confidentiality obligations. The recipient will be required to handle that data in line with this policy or a policy that gives you equivalent protection, and we will tell you where the law requires.

9.5 At your direction

If you ask us to share information with someone else, for example an authorised agent acting for you (see Section 15.3), we will do so after verifying the request.

10. Cookies and similar technologies

10.1 Our approach

We use cookies and browser storage to save your test, show your result, keep your purchase accessible, and sign you in. We also use Google Analytics, which sets its own measurement cookies so we can see how the Site is used. We do not use advertising cookies.

10.2 What we store on your device

  • Test progress. Your answers so far and your place in the test, so you can continue where you left off. Kept until you clear your browser data.
  • Your result. A local copy of your Profile, and the email address you saved it to, so the results page can show it. Kept until you clear your browser data.
  • Unlock status. Whether the full report is unlocked on this device and the email address used to unlock it, so the report can reopen without a new sign-in step. Kept for up to 180 days, or until you clear your browser data.
  • Sign-in. A session cookie that keeps you signed in after saving your result, checkout, restore, or sign-in. Our server stores only a hashed version of it. Kept for up to 30 days, or until you sign out.
  • Google sign-in. Two short-lived cookies that protect the sign-in step against forgery and return you to the right page. Kept for 10 minutes.
  • Page state. Temporary flags that stop the results page or the unlock prompt from repeating a step. Deleted when you close the tab.

These items are not used to track you across other websites, and none of them is shared with advertisers.

10.3 Third-party technologies

  • Google reCAPTCHA loads only on pages with a protected form: the contact, results, sign-in, and restore pages. Google may set or read its own cookies and use similar technologies to tell people from automated programs. We treat this as necessary to keep these forms secure. If you prefer not to load it on the contact page, you can email us directly instead of using the form.
  • Cloudflare may set strictly necessary security cookies where its protection features require them, for example to distinguish people from bots.
  • Dodo Payments may use cookies and similar technologies on its own checkout pages under its own policy.

10.4 Managing these items

You can delete cookies and site data at any time through your browser settings. If you clear site data before buying, your test progress and local result will be lost on that device. If you have bought the full report, you can still restore it using your checkout email address. If you block all cookies and storage, the test cannot save progress and sign-in will not work.

11. International transfers

We are based in India, and our Service Providers operate in several countries. Resend and Google are based in the United States, Cloudflare operates a global network, Dodo Payments processes payments internationally, and our hosting provider stores data in the country where its servers are located. As a result, your personal data may be transferred to and processed in India, the United States, and other countries whose data protection laws differ from those where you live.

Where the EU GDPR or UK GDPR applies to a transfer to a country that has not been recognised as providing adequate protection, we rely on appropriate safeguards, such as:

  • the European Commission’s Standard Contractual Clauses;
  • for UK data, the UK International Data Transfer Addendum to those clauses or the UK International Data Transfer Agreement;
  • where a US recipient is certified, the EU-US Data Privacy Framework and its UK Extension; and
  • in limited cases, a derogation permitted by law, such as where the transfer is necessary to perform the contract you asked us to enter into.

India is not currently the subject of an EU or UK adequacy decision, so the same safeguards apply to transfers to us where required. Under the DPDP Act, we may transfer personal data outside India except to any country or territory that the Government of India restricts by notification. You can ask us for more information about the safeguards that apply to your data.

12. How long we keep it

We keep personal data only for as long as we need it for the purposes in Section 5, including legal, tax, and accounting requirements. Our retention periods are:

  • Answers sent for scoring: not stored or logged by the application. They are used to compute the Profile and then discarded.
  • Results Records not linked to a customer: deleted or anonymised within 12 months of creation.
  • Customer Records with no purchase (created when you saved a result or signed in with Google), and the Results Records linked to them: deleted within 12 months of the last time you saved a result or signed in.
  • Customer Records, Purchase Records, Entitlements, Report Snapshots, and linked Results Records: kept while your access is active, and then for as long as needed for tax, accounting, chargeback, and legal purposes, generally up to 8 years after the purchase, in line with record-keeping rules under India’s Companies Act, 2013 and goods and services tax laws. If you ask us to delete your data, we will delete the data used to give you access (such as the Report Snapshot and sign-in records) where we are not required to keep it, and keep only the transaction records the law requires.
  • Restore link and sign-in code records: expire after 45 minutes and are purged periodically, within 90 days.
  • Session records: expire after 30 days and are purged within 90 days of expiry or of being revoked (for example, when you sign out).
  • Contact form messages and support emails: up to 24 months after the conversation ends, or longer if needed for an open dispute or legal claim.
  • Server and security logs: typically up to 30 days, unless we need them longer to investigate abuse, fraud, or a security incident.
  • Browser Storage: stays on your device until you clear it or, for cookies, until it expires (see Section 10). We cannot delete it for you.

Dodo Payments, Google, and our other Service Providers may keep data they collect as independent controllers for the periods set out in their own policies. When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you. If we delete your purchase data at your request, we will not be able to restore your report later.

13. Security

We use technical and organisational measures appropriate to the size of our business and the nature of the data, including:

  • encrypted connections (HTTPS) between your browser and the Site;
  • storing only hashes, not the tokens or codes themselves, for restore links, sign-in codes, and session tokens;
  • short expiry times for links, codes, and sessions;
  • random public IDs for Results Records that do not contain your name or email address;
  • access to production systems limited to the people who operate the Service;
  • no storage of card numbers, which are handled by Dodo Payments; and
  • network-level protection against attacks through Cloudflare.

No method of transmission or storage is completely secure, and we cannot guarantee the security of your data. Please keep your email account secure, because access to it allows someone to restore your report. On a shared device, anyone using the same browser profile may see the Results saved in browser storage, so clear your browser data when you are done.

If a personal data breach occurs, we will act promptly to contain it and will notify the relevant authorities and affected people where the law requires. That includes, for example, a supervisory authority under the GDPR, and the Data Protection Board of India and affected Data Principals under the DPDP Act, within the time limits those laws set.

14. Your rights

14.1 For everyone

Wherever you live, you can ask us what personal data we hold about you, ask us to correct it, and ask us to delete it. We will consider every request, even where a specific law does not give you that right, subject to our legal obligations. The rights below depend on where you live and on the law that applies to our processing. Section 15 explains how to make a request.

14.2 EU, EEA, and UK

If the EU GDPR or UK GDPR applies, you have the right to:

  • Access: receive confirmation of whether we process your personal data, a copy of it, and information about how we use it.
  • Rectification: have inaccurate data corrected and incomplete data completed.
  • Erasure: have your data deleted where, for example, it is no longer needed or you object and there is no overriding reason to keep it, subject to legal retention duties.
  • Restriction: ask us to limit how we use your data while a concern is resolved.
  • Portability: receive data you provided to us in a structured, commonly used, machine-readable format, and have it sent to another organisation where technically feasible, where processing is based on contract or consent and carried out by automated means.
  • Objection: object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. We will stop unless we have compelling legitimate grounds or need the data for legal claims.
  • Withdraw consent: where we rely on consent, withdraw it at any time without affecting earlier processing.
  • Automated decisions: not be subject to a decision based solely on automated processing that has legal or similarly significant effects. As explained in Section 7, we do not make such decisions.
  • Complain: lodge a complaint with a supervisory authority. In the UK, that is the Information Commissioner’s Office (make a complaint to the ICO). In the EU and EEA, it is the authority in the country where you live, work, or where the issue occurred (list of EU and EEA authorities).

We would appreciate the chance to address your concern first, but you do not have to contact us before complaining to a supervisory authority.

14.3 India (DPDP Act)

If the DPDP Act applies, and to the extent its relevant provisions are in force, you have the right to:

  • obtain a summary of the personal data we process about you and the processing activities, and the identities of other Data Fiduciaries and Data Processors with whom it has been shared, together with a description of the data shared;
  • have your personal data corrected, completed, or updated;
  • have your personal data erased, unless we must keep it to comply with a law;
  • withdraw consent where processing is based on consent, as easily as you gave it;
  • have a readily available means of grievance redressal through our Grievance Officer (Section 1.2);
  • nominate another person to exercise your rights in the event of your death or incapacity; and
  • complain to the Data Protection Board of India after first using our grievance process.

The DPDP Act also places duties on Data Principals, including not to register a false or frivolous grievance, not to impersonate another person, and to provide authentic information when asking for correction or updating.

14.4 United States

Residents of California and other states with comprehensive consumer privacy laws, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, have some or all of the following rights, subject to the conditions and exceptions in each law:

  • Know and access: confirm whether we process your personal information and obtain the categories and specific pieces we hold, the sources, the purposes, and the categories of recipients.
  • Portability: receive your data in a portable and, where feasible, readily usable format.
  • Delete: have personal information you provided or that we obtained about you deleted.
  • Correct: have inaccurate personal information corrected.
  • Opt out: opt out of the sale of personal information, sharing for cross-context behavioural advertising, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects. We do none of these, so there is nothing to opt out of, but you may still submit a request and we will record it.
  • Limit use of sensitive personal information: we do not use or disclose sensitive personal information for purposes that would give rise to this right.
  • List of third parties: in states such as Oregon and Minnesota, obtain a list of the specific third parties to which we have disclosed personal information. Section 9 already names them.
  • Non-discrimination: we will not deny you the Service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
  • Appeal: appeal our decision on your request (see Section 16.2).

You may use an authorised agent to make a request on your behalf (see Section 15.3).

14.5 Australia, Canada, and other countries

If you are in Australia, you may ask to access and correct your personal information under the Privacy Act 1988 and the Australian Privacy Principles, and you may complain to the Office of the Australian Information Commissioner if you are not satisfied with our response. If you are in Canada, you have rights of access and correction under the Personal Information Protection and Electronic Documents Act or applicable provincial law, and you may complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner. If you are in Switzerland or another country with its own data protection law, we will honour the rights that law gives you.

15. How to exercise your rights

15.1 Making a request

Email [email protected], ideally from the email address you used at checkout, and tell us which right you want to exercise and where you live. You can also use the privacy topic on our Contact Us page. Requests are free of charge, although where the law allows we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, and we will explain why.

15.2 Verifying your identity

To protect your data, we need to confirm that a request comes from you. We usually do this by matching the request to your checkout email address, for example by asking you to reply from that address or to confirm a one-time link we send to it. We do not hold your name, postal address, or other identifiers for most customers, so we will not ask for more than we need. We use information provided for verification only for that purpose.

Because Results Records that are not linked to a purchase contain no name or email address, we may not be able to verify that one belongs to you. If you can give us the public ID saved in your browser storage, we will do our best to help, and you can always delete the local copy yourself by clearing your browser data.

15.3 Authorised agents and nominees

An authorised agent may make a request for you under US state laws if they provide signed written permission or a valid power of attorney, and we may still ask you to verify your identity directly. Under the DPDP Act, a person you have nominated may exercise your rights on your death or incapacity, on providing reasonable proof. A parent or guardian may make a request on behalf of a child.

15.4 Response times

  • EU, EEA, and UK: within one month of receipt, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you within the first month.
  • US states: within 45 days, which we may extend once by up to 45 more days where reasonably necessary, with notice to you. For California, we will confirm receipt of a request to know, delete, or correct within 10 business days.
  • India: within the period set by the DPDP Act and its rules, and for grievances, as described in Section 1.2.
  • Elsewhere: within the time the applicable law requires, or otherwise within a reasonable time.

If we cannot fulfil a request in full, for example because we must keep certain records by law, we will tell you which part we cannot fulfil and why.

16. Appeals and complaints

16.1 Asking us to reconsider

If you disagree with our response to any request, reply to our email with the word “Appeal” in the subject line and explain why. Someone who did not make the original decision will review it where possible.

16.2 US state appeals

If you live in a US state that gives you a right to appeal, the process in Section 16.1 is your appeal. We will respond in writing within the period your state’s law sets, which is 45 days or 60 days depending on the state (in some states, extendable as the law allows), and we will explain the reasons for our decision. If we deny your appeal, you may contact the Attorney General of your state. For example, residents of Virginia, Colorado, Connecticut, Texas, and Oregon may submit a complaint to their state Attorney General, and California residents may also contact the California Privacy Protection Agency.

16.3 India

If you are not satisfied with how our Grievance Officer has handled your grievance, you may file a complaint with the Data Protection Board of India in the manner the DPDP Act and its rules provide.

16.4 EU, EEA, UK, and other regions

You may complain to the supervisory authority or regulator described in Section 14.2 or Section 14.5 at any time.

17. California Notice at Collection and CCPA disclosures

This section supplements the rest of this policy for California residents and serves as our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”). It reflects our practices in the 12 months before the “Last updated” date above.

17.1 Categories collected, sources, purposes, and recipients

  • Identifiers, such as email address, name (if you contact us or use Google sign-in), IP address, internal customer and Results Record IDs, and a Google account identifier (if you use Google sign-in). Sources: you, your device, and Google. Purposes: providing the Service, restore and sign-in, support, security, and legal compliance. Disclosed for business purposes to: Dodo Payments, Resend, Google, Cloudflare, and our hosting provider.
  • Personal information described in California Civil Code section 1798.80, namely name and email address. Sources: you. Purposes and recipients: as for identifiers.
  • Commercial information, such as the product purchased, amount, currency, payment status, refund or chargeback status, and timestamps. Sources: you and Dodo Payments. Purposes: processing your purchase, delivering and restoring the report, handling refunds and disputes, and tax and accounting records. Disclosed for business purposes to: Dodo Payments and our hosting provider.
  • Internet or other electronic network activity, such as browser and device details, URLs requested, timestamps, and reCAPTCHA interaction signals on protected forms. Sources: your device. Purposes: operating and securing the Site and preventing spam and fraud. Disclosed for business purposes to: Cloudflare, Google, and our hosting provider.
  • Inferences, namely your Profile (type code, portrait, trait percentages, and related metrics). Sources: computed by us from answers you submit. Purposes: showing your results and delivering and restoring the full report. Disclosed for business purposes to: our hosting provider, which stores it.

We do not collect precise geolocation, biometric information, or audio or video recordings. We do not collect sensitive personal information as defined by the CCPA for the purpose of inferring characteristics about you, and we do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit. We keep each category for the periods in Section 12.

17.2 No sale or sharing

We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.

17.3 Financial incentives

We do not offer financial incentives, discounts, or price or service differences in exchange for the collection, retention, or sale of personal information.

17.4 Shine the Light

California Civil Code section 1798.83 allows California residents to ask for information about disclosures of personal information to third parties for their own direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

17.5 Your California rights

Your rights under the CCPA are described in Section 14.4, how to exercise them in Section 15, and how to appeal in Section 16.2.

18. Do Not Track and Global Privacy Control

Do Not Track. Some browsers can send a “Do Not Track” signal. There is no agreed standard for how websites should respond to it. Because we do not track visitors across other websites or use tracking technologies, the signal does not change how the Site works.

Global Privacy Control. We honour the Global Privacy Control (GPC) signal, and other recognised universal opt-out mechanisms, as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for that browser. Because we do not sell or share personal information or use it for targeted advertising, you will not see a visible change, but we treat the signal as an opt-out under the laws that require it.

19. Children

The Site is intended for adults and is not directed at children under 16. Purchases must be made by a person who can enter into a binding contract, as described in the Terms & Conditions.

  • We do not knowingly collect personal information from children under 13, in line with the US Children’s Online Privacy Protection Act.
  • Under the DPDP Act, a child is anyone under 18. We do not knowingly process the personal data of anyone under 18 in India without the verifiable consent of a parent or lawful guardian, and we do not track, behaviourally monitor, or direct targeted advertising at children.
  • In the EU, EEA, and UK, we do not knowingly collect personal data from children below the age at which they can consent to online services in their country.

If you believe a child has provided personal data to us, please contact us. If we learn that we have collected personal data from a child in breach of these rules, we will delete it promptly.

21. Changes to this policy

We may update this policy to reflect changes in the Service, our Service Providers, or the law. When we do, we will change the “Last updated” date at the top of this page. If a change materially affects how we use personal data we already hold, we will give you prominent notice on the Site and, where we have your email address and the change requires it, by email. Where the law requires your consent to a change, we will ask for it. Earlier versions are available on request.

22. Contact

For questions about this policy, privacy requests, or grievances, contact:

CyberRudra Technologies
Attn: Privacy and Grievance Officer
6, Keshav City, Vrundavan Nagar, Sindhi Meghe
Wardha, Maharashtra 442001, India
[email protected]

You can also reach us through our Contact Us page.