How we handle your data
We do not see your answers. We do not ask for your email. We do not track you across the web. This page explains how we keep your information yours.
What this means for you
Your profile is locked with a password or passkey
You can protect each profile with a strong password or a phishing-resistant passkey. Passwords are hashed with bcrypt, not stored in plain text, so we cannot read them.
You choose who sees your profile
Share links expire when you decide. You stay in charge of who can open your profile and for how long.
Tracking is off by default
We do not run ads, use analytics, or follow you around the web unless you opt in. Google Analytics is an external service that only runs if you enable it. Your information stays with you.
We cannot link your profile to you
We do not ask for accounts or email addresses. Your profile is reached through a random, unguessable link. We cannot tie it back to you, and neither can anyone else.
We watch for misuse
We keep an eye out for suspicious behaviour and put limits in place to cut down on spam, bots, and unwanted access attempts.
Your data is encrypted in transit
Everything sent between your device and our servers uses HTTPS. That makes it much harder for anyone to intercept your information on the way.
The technical side
If you want the detail, here is what happens under the surface:
Passwords and passkeys
- • bcrypt with 12 salt rounds
- • Old hashes are automatically upgraded when you log in
- • Passkeys (WebAuthn) for passwordless login
Sessions
- • httpOnly, SameSite=Strict and HTTPS-only cookie flags
- • One-time-use CSRF tokens
- • Short-lived, auto-expiring sessions
Rate limits
- • Sliding-window algorithm (Redis)
- • Per-endpoint limits
- • Cloudflare Turnstile bot protection
Input checks
- • Schema-based validation (Zod)
- • XSS prevention and sanitization
- • Strongly typed data handling
Browser protections
- • HSTS (2-year, preload)
- • Clickjacking and MIME-sniffing protection
- • Restrictive Permissions-Policy
Infrastructure
- • Managed PostgreSQL (encrypted in transit and at rest)
- • Ephemeral Redis for sessions and tokens
- • Railway managed hosting behind TLS
Common web vulnerabilities
We keep on top of common web vulnerabilities such as SQL injection, broken authentication, XSS, and CSRF. Crash reports go through our own tunnel, so your IP address or profile data is not shared with third-party error trackers.
What we collect and what we do not
What we collect
- • Your questionnaire responses, only what you choose to submit
- • IP addresses for rate limiting, used only to stop abuse
What we do not collect
- • Personal identification documents
- • Browsing history or cross-site tracking
- • Email addresses, unless you contact us
- • Financial information
What you can do
- • Delete your profile at any time. It is removed straight away.
- • Export your data in JSON format
- • Walk away without an account, so there is nothing to leave behind
Questions?
If something is not clear, or you think you have spotted a problem, let us know.
Get in touchLast updated: September 2026