Privacy Policy
Effective: June 17, 2026
Last updated: June 17, 2026
DuoPersonica ("we", "us") is a dual-track personality test website offering an MBTI-style serious assessment and an SBTI-style scenario test, plus AI Coach discussions, deep-dive reports, invite rewards, and sharing features. We respect your privacy. This policy explains what we collect, how we use it, and what rights you have.
This policy covers duopersonica.com, duopersonica.uppervoid.top, and their sub-pages. The service is currently in beta; this policy may evolve as the product matures.
1. Information We Collect
Account information. When you sign in via Apple, Google, or email password, we store your email address, your display name (if provided), and an opaque user identifier from the OAuth provider. Email-password accounts store salted password hashes; we do not store plaintext passwords.
Test responses. Your full answers to the MBTI assessment (~50–120 items) and the SBTI scenario test (~24–75 items), along with the computed personality type and dimension scores, are stored in our database. Anonymous visitor responses are kept as sessions and auto-purged after 30 days. Signed-in users' responses are linked to the account so you can view them across devices.
AI Coach inputs. When you use the AI Coach, the scenario text you type (up to 500 characters), the category you select, and your MBTI + SBTI types are sent to a third-party AI provider (see Section 3). The AI's response is not persisted server-side beyond the request.
Compare-page tension queries. When you view the dual-track compare page, your MBTI × SBTI combination plus your language is used to generate an AI tension analysis. The result is cached for ~30 days keyed on (type combo + language); the cached text is generic and is not tied to any individual user.
Payment and entitlement records. When you buy or redeem a deep-dive report, subscription, or other benefit, we store order IDs, payment provider, product SKU, amount, currency, payment status, entitlement status, generated-report cache keys, and generation time. We do not store full card numbers or payment-account passwords.
Invite reward data. When you use invite links, we store referral codes, referrer and invitee account identifiers, conversion status, reward grant/reservation/consumption status, and anti-abuse quality results, rejection reasons, and answer-fingerprint hashes. Fingerprints are used to identify duplicate or abnormal responses; raw answers are not retained for that purpose long-term.
Technical data and first-party operations logs. When you access the site, our edge servers receive your IP address. We use IP addresses to (a) power anti-abuse counters, with the cache key SHA-256 hashed and truncated to 16 hex characters before writing to KV, usually expiring within 24 hours; (b) infer a coarse country code; and (c) write first-party operations logs for security review, source attribution, channel analysis, and support debugging. Operations logs may include page path, page title, referrer/referrer host, UTM parameters, referral code, login/signup/logout events, test start/submission, result views, sign-in entry opens, checkout entry clicks and their target/product identifiers, raw IP address, country code, Cloudflare colo, user agent, browser, operating system, device type, timezone, and screen size. Console access is limited to admins.
Anti-abuse signals. To deter scraping and stuffing, we record per-IP daily test counts, answer pacing, and consecutive-identical-option patterns. These signals are not tied to your identity and are used only for threshold detection.
Cookies and analytics. We use one HttpOnly, SameSite=Lax, Secure session cookie to maintain your sign-in. In addition to first-party operations logs, we use Google Analytics 4 and Cloudflare Web Analytics to measure page views, acquisition source, test starts/submits, checkout starts, and similar aggregate events. Events sent to third-party analytics services use safe dimensions only, such as locale, test type, result type, SKU, and page path. We do not send answers, emails, names, or report content to analytics.
2. How We Use Your Information
- Provide the core service. Store test results, enable cross-device access, generate comparisons, run the AI Coach.
- Process paid and invite benefits. Create orders, confirm entitlements, generate or retrieve deep-dive reports, and grant/reserve/consume invite rewards.
- Personalize AI output. Pass your computed personality type to the AI as context so its replies are relevant to your profile.
- Security, operations, and attribution. Record visits, sign-ins, browser, device, IP, country code, referrer, and UTM parameters to identify bots, debug account issues, and understand Google, Bing, direct, invite, and referral channel performance.
- Anti-abuse. Limit per-IP daily test count (default 5/day), detect anomalous answer patterns, deter bots.
- Improve the service. Analyze usage patterns such as test completion rates and source-level conversion, but we do not use test answers for advertising profiles.
- Legal compliance. Disclose information when required by law or to protect our or our users' rights.
3. Third-Party Services
DuoPersonica relies on the following third parties. Each has its own privacy obligations — please review their policies as well.
- Cloudflare (infrastructure): hosting, Workers compute, D1 database, KV cache, R2 object storage. Cloudflare processes your requests at edge nodes worldwide.
- Cloudflare Web Analytics / Google Analytics 4 (third-party aggregate usage analytics): used as supporting analytics alongside our first-party operations logs to understand acquisition sources, page views, test funnel events, and checkout entry points. We do not send test answers, emails, names, or report content to these analytics services.
- Apple Sign In / Google OAuth (sign-in): when you choose third-party sign-in, we receive your email and an opaque user identifier from the provider.
- Email service providers (transactional email): when we send sign-in, account, security, or support-related email, your email address is delivered via an email service provider.
- Payment processors (checkout): when you purchase paid benefits, payment processors handle checkout, payment confirmation, refunds, or subscription status. We store only the transaction records needed for orders and entitlements, not full payment credentials.
- DeepSeek (AI model): AI Coach replies and Compare-page tension analyses are currently powered by DeepSeek, which is hosted in mainland China. When you use AI features, your scenario text, personality types, and category are sent over HTTPS to DeepSeek's API. Important: if you are outside mainland China, using the AI features means your inputs cross borders and reach a Chinese AI provider. If you are not comfortable with that transfer, please do not use AI Coach.
4. International Data Transfer
DuoPersonica's infrastructure runs on Cloudflare's global edge network. Your requests may be routed to nodes outside your home region.
As noted in Section 3, the AI Coach involves a cross-border transfer to DeepSeek in mainland China. This matters in particular for users in the EU, UK, US, and other jurisdictions with strict data-localization or transfer rules. If you input sensitive information into AI features, please understand that information will reach a Chinese provider and be subject to local law there.
We are evaluating routing non-China users to Gemini or Claude in v1.1 to minimize unnecessary cross-border transfer.
5. Data Retention
- Account information. Retained until you delete your account. A deletion request immediately marks the account as deleted (you can no longer sign in) and starts a 30-day grace window; after 30 days a daily scheduled job (running at 04:00 UTC) hard-deletes your user row plus every linked record — test results, test sessions, sign-in sessions, and third-party identity links.
- Test results. Signed-in users' results are retained so you can revisit them; anonymous sessions purge after 30 days. Linked results are cascade-deleted alongside the user row when the account is hard-deleted.
- AI Coach inputs. Not persisted server-side beyond the API call.
- AI tension cache. Keyed on (MBTI type + SBTI type + language), cached ~30 days; the cached text is generic and contains no user identifier.
- Public share pages. When you generate a /r/[shortId] share link, the anonymous version is cached ~1 day for fast viewing.
- Order, report, and invite reward records. Retained while the account exists so we can provide entitlements, handle billing disputes, avoid duplicate charges, and prevent duplicate rewards. On account hard deletion, linked records are deleted or anonymized unless law or payment-platform rules require retention.
- First-party operations logs. Anonymous visit logs are retained for operational and security needs. Activity logs linked to an account are deleted when the account is hard-deleted.
- Anti-abuse counters. Daily counters keyed on hashed-IP auto-expire after 24 hours (KV TTL).
- Webhook records. Cleared after 90 days.
6. Your Rights
Wherever you are, you may:
- Access your account info and historical results — visit /my
- Correct your display name and other account fields
- Delete your account and all associated data — request from /my
- Export a copy of your data: while signed in, send a request to
POST /api/account/exportto immediately download a JSON file containing your account record, linked identities, every MBTI / SBTI result, raw test-session answers, AI-conversation metadata, and order and invite reward records. Limit: 1 export per user per day. For additional copies, email contact@duopersonica.com - Withdraw consent: simply stop using AI Coach to halt further cross-border transfers
To exercise any right, email contact@duopersonica.com. We will respond within 30 days as required by GDPR Article 12. If your request is complex, we may extend by up to 60 additional days with written notice to you.
If you are in the EU, you have additional GDPR rights (including the right to lodge a complaint with a supervisory authority). If you are in mainland China, you have rights under the Personal Information Protection Law (PIPL).
7. Data Subject Access Requests (DSAR)
GDPR, CCPA, PIPL, and most other jurisdictions grant users the right to obtain their data directly from a data controller. DuoPersonica offers two DSAR pathways:
- Self-serve (recommended): while signed in, send
POST /api/account/exportto download a complete JSON copy immediately. The endpoint is authenticated — unauthenticated requests receive a 401. Limit: 1 export per user per UTC day. - Email: write to contact@duopersonica.com with subject "DSAR Request" or "Data Subject Access Request" and state the action you wish to exercise (access / correction / deletion / objection / portability). We will respond within 30 days, with a permitted extension of up to 60 additional days for complex requests under GDPR Art. 12(3) — we will notify you in writing if we extend.
Identity verification. Email DSARs must be sent from the email address bound to your account, as a baseline identity check. We may additionally ask you to confirm the request from within the signed-in app to prevent impersonation.
No fee. DSAR responses are free of charge. Where a single user submits manifestly unfounded or excessive requests in a short window, we reserve the right to charge a reasonable fee or refuse, as permitted under GDPR Art. 12(5).
Right to complain. If you believe our DSAR response is inadequate, you have the right to complain to your jurisdiction's data-protection authority (e.g. an EU member-state DPA, the UK ICO, the Cyberspace Administration of China, or the California CPPA).
8. Children's Privacy
DuoPersonica is not directed to children under 13 (or 16 in the EU and other jurisdictions where that is the threshold). If we discover we have collected data from a child below the applicable age, we delete it. If you believe a minor has registered without guardian consent, please contact us.
9. Cookies and Local Storage
- Session cookie: HttpOnly + SameSite=Lax + Secure; carries a signed JWT for sign-in only.
- Language preference cookie: remembers your CN/EN choice; contains no personal info.
- Source-attribution cookie / sessionStorage: stores first landing path, referrer, UTM parameters, and referral code so login/signup events can be linked to their acquisition source. It does not contain test answers, email, name, or report content.
- Browser localStorage: stores your in-progress test draft (so a refresh doesn't lose it). Nothing is uploaded until you finish and submit.
- Analytics services: Google Analytics 4 and Cloudflare Web Analytics measure aggregate usage and funnel events. We do not use Facebook Pixel or advertising retargeting pixels.
10. Security
We follow industry-standard practices: enforced HTTPS, HttpOnly cookies, signed JWTs, API rate limits, and webhook signature verification. That said, no internet system is perfectly secure, and we cannot guarantee absolute security of data transmission or storage.
11. Changes to This Policy
We may update this policy. Material changes will be announced on the site or by email to registered users at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance.
12. Contact
For privacy questions, contact: contact@duopersonica.com
(Interim contact for beta; a formal legal contact will be published in a later release.)