Privacy
Confidentiality is a design constraint, not a policy page.
Participants tell this instrument things they have not told their board, their co-founder or their partner. The architecture is built on that assumption.
01
What we collect
- Account details: your email address, name and any preferred name you provide.
- Assessment data: your responses, response timings and revision counts. Timing is used only as a data-quality signal.
- Programme data: reality audit check-ins, decision ledger entries, experiments, interview transcripts and observer submissions.
- Derived data: construct scores, evidence claims and confidence values produced by our scoring engine.
02
What we never do
- We do not sell your data, and we do not share it with advertisers or data brokers.
- We do not use your individual responses to train external models.
- We do not disclose who invited an observer to that observer, or the observer's raw answers to anyone but you in aggregated form.
- We do not publish, share or export your report on your behalf.
03
How your data is protected
- All traffic is encrypted in transit; all records are encrypted at rest.
- Row-level security means every record is bound to your account. Even our own application code cannot read another participant's file without an explicit, audited staff role.
- Staff access is limited to safety review and support, is role-gated, and every privileged read or change is written to an immutable audit log.
04
Safety review
- Interview messages and reality audit entries pass an automated screen for language indicating crisis or acute distress.
- A match raises an internal flag for a trained reviewer. This exists to protect participants, not to police them.
- Personality Lab is a personal-development and decision-support platform. It is not a medical, psychological or psychiatric service, and it is not a substitute for emergency care.
05
Your controls
- Export: download a complete JSON archive of everything held against your account at any time, from Settings.
- Erase: permanently delete your responses, scores, claims, interviews, audits, decisions, experiments, observer records and notifications. This action is irreversible and is not recoverable from backups after 30 days.
- Revoke: cancel any pending observer invitation before it is completed.
06
Retention
- Active accounts retain their evidence file so that rescoring and longitudinal comparison remain possible.
- Deleted data is removed from live systems immediately and purged from encrypted backups within 30 days.
- Anonymous, non-identifiable aggregate statistics used for instrument calibration may be retained indefinitely.
Questions about your data can be raised from inside your workspace at any time. This notice is reviewed whenever the instrument changes what it collects.