Privacy Policy
Last updated: 15 August 2026
This policy explains what data the Archetype Personality Test app and website collect, how it is used, and your rights. The data controller is Archetype Personality, reachable at privacy@findyourarchetype.com.
1. What we collect
The app and website collect only what is needed to deliver your personality profile and to understand and improve the app:
- Assessment answers — your responses to the personality questionnaire
- Personality results — your archetype, scores, and match weights derived from your answers
- Demographics — age group and gender, if you choose to provide them (optional and skippable)
- Goals — if you choose to share them
- How you heard about us — after the test we ask one optional question: "Where did you hear about us?". If you choose to answer, we record the option you picked (for example "TikTok" or "A friend or family member"). The question is skippable, and your answer goes only to our analytics providers (below) — linked to your account identifier when you are signed in, or to a randomly generated, pseudonymous device/browser analytics identifier otherwise. We use it to understand which channels bring people to Archetype. It is never stored with your personality results.
- Account information — name (optional), email address and password, if you create an account. You can also sign in with Apple. On your first authorization, we request your full name and email; Apple may provide the name and either your real verified email address or a private relay address that forwards to it. If Apple provides a name while you create an account, we may store it as your display name. Apple may continue to include the email address in later sign-ins, but does not provide the name again.
- Internal quality flags — technical metadata used to assess result reliability
- Crash & diagnostic data — when the native app or this website crashes or hits an error, we collect a crash/error report so we can find and fix the problem. Reports may include the error type, stack trace, screen or page in use, app or site version, and device model and operating-system or browser diagnostics; native reports may also include app-start and navigation performance data, while website Sentry reporting is limited to error reports. These reports exclude your account identity and assessment content, but include a randomly generated, pseudonymous install identifier in the native app or browser identifier on the website so we can count affected installations or browsers. In the native app, the identifier is scoped to the current installation and remains stable across sign-out. After a successful account deletion, the app attempts to clear it with the other local app data. If local storage cleanup fails, the identifier may remain on that device until you delete and reinstall the app or clear the app's data. After the persisted identifier is cleared and the app is launched again, a different identifier is generated. On the website, the identifier is stored in browser local storage for the
www.findyourarchetype.com origin and remains stable for that browser and origin until local site data is cleared; a later visit then generates a different identifier. Neither identifier is an account identifier, and neither is joined to your name, email, Supabase user identifier, assessment answers, scores, or archetype.
- Usage & product analytics — how you move through the app (screens viewed, steps taken, where you stop), your archetype and trait score bands, the age group, gender and goals you chose to provide, your locale, app version, a stable account identifier, and an approximate location (country, region and city) that our analytics providers derive from your IP address. This helps us understand and improve the experience. We also capture tap/interaction and screen-view data — your questionnaire text, the answers you select, your numeric scores, and your login details are never sent. When you are signed in, these are linked to your account identifier; without an account they are tied to a randomly generated, pseudonymous device/browser analytics identifier.
- Security & anti-abuse data — when you choose to create a compare-with-a-friend link, Cloudflare Turnstile processes browser and network security signals, including your IP address, browser user-agent, page origin, site key, and a short-lived one-time challenge token, to distinguish people from bots. Our compare service sends the token and source address to Cloudflare for verification. Our application code does not write either value to application storage or application-generated logs; Supabase and Cloudflare may process standard request metadata under their service terms. We store only a secret-keyed, truncated pseudonym for a temporary rate-limit counter. We do not send your assessment answers, scores, name, email, or account identifier to Turnstile.
- Compare links (website only) — if you choose to create a "compare with a friend" link on our website, we store a coarse summary of your result — your archetype name and your High / Medium / Low band for each of the five traits — under a random, unguessable link, so the friend you send it to can compare their result with yours. This never includes your assessment answers or your numeric scores, and it is not linked to your name, email, or account. You choose whether to create such a link.
We do not collect precise (GPS-level) location, contacts, browsing history, or anything beyond what is listed above — the approximate location described above is coarse (city level at most), derived from your IP address by our analytics providers, and is never used to track you across other apps or companies. We never send your individual questionnaire answers, the personality question text, your email, or your name to our analytics providers.
2. How your data is stored
Without an account: your assessment answers and results are stored locally on your device or in your browser only. Product-analytics events (above) are still collected under a randomly generated, pseudonymous device/browser analytics identifier — they carry no account identifier, no email, and no name. Deleting the app or clearing the website's local data removes your local assessment data permanently. The one exception is a compare link you deliberately create on the website (see section 1): the coarse archetype + trait-band summary it contains is stored on our server so your friend can open it — never your answers or scores — and is checked daily and deleted within 24 hours after it reaches 90 days old (see section 5).
With an account: your data is synced to a secure cloud database (Supabase, hosted on AWS infrastructure) so you can access your results across devices. Your data is protected by row-level security — only you can read your own records.
3. How we use your data
- To calculate and display your personality archetype and results
- To sync your results across your devices if you have an account
- To understand which channels bring people to Archetype — using your answer to the optional "Where did you hear about us?" question, if you gave one
- To respond to support or data access requests
We do not sell your data, use it for advertising, or share it with third parties for marketing purposes.
Legal basis (GDPR Article 6). We process your data on the basis of your consent — which you give by choosing to take the assessment and, optionally, create an account — and to perform our contract with you, namely delivering and syncing the personality results you requested. Usage analytics and crash/diagnostic data are processed on the basis of our legitimate interest in understanding and improving the app and keeping it reliable. Turnstile security signals and the temporary compare rate-limit counter are processed on the basis of our legitimate interest in preventing automated abuse. You can withdraw consent at any time by deleting your account or the app.
4. Third-party services
- Supabase — cloud database and authentication provider. Processes data on our behalf under a data processing agreement. Infrastructure is hosted on AWS (EU region where available).
- Apple — if you use Sign in with Apple, Apple handles authentication. On your first authorization, we request your full name and email. Apple may provide the name and either your real verified email address or a private relay address that forwards to it; later sign-ins do not provide the name again.
- Resend — email-delivery processor used through Supabase Auth to send password-recovery and account-security messages. It processes the recipient email address, authentication email content, and technical delivery metadata needed to deliver those messages. Link and open tracking are disabled.
- Cloudflare Turnstile — security and bot-prevention service used when a website visitor creates a compare link. It processes browser and network security signals and a one-time token to distinguish people from bots. We do not send assessment answers, scores, names, email addresses, or account identifiers. See Cloudflare's Turnstile Privacy Addendum.
- PostHog — product-analytics processor, used to understand how the app is used and to improve it. Processes data on our behalf under a data processing agreement, hosted in the EU (eu.posthog.com). No advertising, no data sale, no cross-app tracking. Sensitive content (your answers, scores, and login details) is never sent.
- Mixpanel — product-analytics processor, used alongside PostHog while we evaluate which analytics tool best helps us understand and improve the app. It receives the same usage events and account/trait data as PostHog. Processes data on our behalf under a data processing agreement, hosted in the EU (api-eu.mixpanel.com). No advertising, no data sale, no cross-app tracking. The same sensitive content (your individual answers, the personality question text, your email, and your name) is never sent.
- Sentry — crash, error, and native performance-diagnostics processor (Functional Software, Inc. dba Sentry), used to detect and fix bugs and keep the app and this website stable; website reporting is errors-only. Processes data on our behalf under a data processing agreement, hosted in the EU data region (de.sentry.io). Reports exclude account identity and assessment content, but include device or browser diagnostics and the randomly generated, pseudonymous install or browser identifier described in section 1. The native identifier is stable across sign-out; after successful account deletion, the app attempts to clear its persisted value, subject to the local-storage failure and manual clearing fallback described in sections 1 and 5. The website identifier follows that browser origin's local-storage lifecycle. Neither identifier is joined to a Supabase user identifier, name, or email. No advertising, no data sale, no cross-app tracking.
5. Data retention
Your data is retained for as long as your account is active. If you delete your account, your account and synced data are removed from Supabase, and our production deletion pipeline also requests deletion of the data linked to your account identifier from PostHog and Mixpanel. The pipeline counts a provider request as accepted only after validating the provider's response, but provider-side processing is asynchronous and may continue after the app confirms your account deletion. A provider request failure does not delay or prevent the Supabase deletion; emailing privacy@findyourarchetype.com is the manual fallback for completing provider-side deletion. After Supabase confirms deletion, the app attempts to clear its local app data. If local cleanup fails, some data may remain on that device or browser even though the account is gone. In the native app, delete and reinstall the app or clear its app data; on the website, clear site data for the www.findyourarchetype.com origin. Local-only data (no account) is removed when you delete the app or, on the website, clear that origin's site data. Compare-with-a-friend links (website) hold only a coarse, accountless archetype and trait-band summary; they are checked daily and deleted within 24 hours after reaching 90 days old, and you can have one deleted sooner at any time by emailing privacy@findyourarchetype.com. Temporary compare rate-limit counters contain only a truncated, secret-keyed pseudonym; they expire after 48 hours and are removed by the next hourly cleanup, within about 49 hours at most.
6. Your rights
If you are in the EU or EEA, you have the following rights under the GDPR:
- Access (Article 15) — request a copy of the data we hold about you
- Portability (Article 20) — receive your data in a structured, machine-readable format
- Erasure (Article 17) — request deletion of your account and all associated data
- Rectification (Article 16) — request correction of inaccurate data
- Restriction (Article 18) — request that we limit processing of your data
- Objection (Article 21) — object to processing based on legitimate interests
To exercise any of these rights, email privacy@findyourarchetype.com. We will respond within 30 days. For account deletion, you can also delete your account directly from within the app.
You also have the right to lodge a complaint with your local data protection authority.
7. Data export and access requests
We do not currently offer an in-app data export button. To request a copy of your data, email privacy@findyourarchetype.com with the subject line "Data export request" and the email address associated with your account. We will deliver your data in JSON format within 30 days.
8. Security
Your data is encrypted in transit (HTTPS/TLS). Account credentials are managed by Supabase Auth and never stored in plain text. If you use Sign in with Apple, your credentials are handled entirely by Apple.
9. Children
The app is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the app evolves. The date at the top of this page reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or requests:
Archetype Personality
privacy@findyourarchetype.com