Privacy
Last updated 8 September 2026.
Your answers never leave your device
The test is scored in your browser. Your 36 individual answers stay on the device you took the test on. Your derived scores can leave it when you allow anonymous score collection, request an email summary, download your paid report, or agree to a partner comparison, as described below.
That is not a policy we could change quietly. It is how the product is built, and the methodology page shows the scoring it runs.
The rest of this page is what we do hold, why, for how long, and how to get it out.
Who is responsible for it
Jakes Creates Ltd, trading as illustro, is the data controller. The company is registered in England and Wales (company no. 16971656) with its registered office at 3rd Floor, 86-90 Paul Street, London EC2A 4NE.
Write to support@illustro.tech about anything on this page. There is one address and it is answered by a person.
What we hold
Your answers and your result
What: your 36 answers, your five trait scores, your type, and an unguessable link to them. All of it in your own browser's storage.
Why: to show you your result and let you come back to it.
Processing: the test and local result run in your browser. Optional sharing and the services you request are described separately below.
How long: we promise at least three days on that device, and nothing we run removes it after that.
How to remove it: clear this site's data in your browser.
Anonymous trait scores
What: five trait sums, your type, whether it was your first attempt at the test, and the time it arrived. There is no address, no name, no IP address and no link to your result on the row, and the table has no column any of those could go in.
Why: so percentiles can eventually be reported against real takers as well as against the published research sample.
Lawful basis: your consent to analytics. Nothing is sent if you did not allow it.
How long: these rows are counts. They stay part of the counts.
How to remove it: we cannot find your row, because nothing on it points at you. That is the point of storing it this way, and it is also the honest limit of it.
Purchases
What: which result was unlocked, which price arm it was in, the currency, the amount, whether a partner comparison was added, the Stripe payment reference, and whether it was refunded. No name, no email address, no billing address, and no card detail.
Why: to unlock the report you bought, and to keep our own record of the sale.
Lawful basis: performing the contract you made with us, and our own legal obligation to keep records of what we sell.
How long: while it is the row that unlocks your report, and after that as the record of a sale.
How to remove it: ask us and we will delete our row. Stripe's own record of the payment stays with Stripe, which is required to keep it, and that is outside what we can erase.
Your email address
We store your address only when you ask us for an email. Other records, including purchase references and private result links, may also relate to you even where they do not contain your name.
What: the address as you typed it, the moment you asked for your summary, whether you ticked the marketing box and when, which screen you were on when you did, a random token that unsubscribes you, and the link to the result your summary points at.
Why: to send the summary you asked for, and, only if you ticked the box, the two emails after it.
Lawful basis: the summary rests on the request you made when you typed your address in. The two emails after it rest on your consent, which is a separate, unticked box that does nothing unless you tick it.
How long: until you ask us to delete the row. Unsubscribing stops the email sequence and retains a suppression record so we do not restart it accidentally. Nothing expires on its own.
How to remove it: the unsubscribe link in the footer of any email is one click, needs no sign-in, and is honoured immediately. To have the row deleted, write to support@illustro.tech.
One trade-off is worth stating rather than burying. That row holds the link to your result, because a permanent link is the whole point of the summary email. While the row exists, your address and one result sit in the same place. Deleting the row is what takes that apart.
When you request a summary, your browser sends your type, five trait scores and percentiles to our server to render that email. We send the summary through Resend without saving those scores beside your address in our database. The email contains a private recovery link with a copy of those result values in its URL fragment. This lets another device restore your result; browsers do not include the fragment in the HTTP request to our site. Anyone you forward the email or complete link to can read the summary and may access the report if it is unlocked. Keep it private. Removing our subscriber row does not remove a copy already in your inbox.
Downloading a paid PDF sends the result values to our server to generate the document after checking purchase access. The generated response is not cached. Your original 36 answers are not needed for that request.
Partner comparisons
What: for each of the two people, five trait percentiles and a type name, and the moment each of them agreed to share. No name, no address, no answers, and nothing that says who either person is.
Why: a comparison needs both sets of numbers in one place, and the two people are never on the same device.
Lawful basis: consent, given separately by each side. The buyer's half is written when they create the invite. The other half is written only when the person they invited presses the button on a page that says exactly what will be shared.
How long: until it is deleted.
How to remove it: the buyer can remove the person they invited, which erases that person's half. Either of you can write to us to have the whole thing deleted. It is one row holding both halves, so deleting it deletes both: there is no way to remove one person's numbers and leave the other's readable.
Analytics
What: which pages are opened and which steps of the test are reached. No address and no name. Where a page's address carries a token, the token is replaced with the name of the thing before the event leaves your browser, so a comparison page is reported as /compare/:pairToken and never as the link itself.
Why: to see where people give up, so the parts that lose them can be fixed.
Lawful basis: your consent.
How long: for as long as our analytics provider keeps it.
How to remove it: refuse when you are asked. To change your mind later, clear this site's data in your browser and answer again, or write to us.
The same consent, and no separate one, also starts Meta's advertising measurement, so we can tell which of our ads led to a visit or a purchase. Meta sees the address of the page you are on, but never a page that carries a private link, because those events are held back before they leave your browser. It sees which step of the buying flow you reached, and the amount and currency of a purchase. It never sees your answers, your result, your name or your email address. If you refuse analytics, none of this runs and the _fbp cookie it would set is never written.
Cookies, and what sits in your browser
Nothing is loaded for analytics, and no analytics cookie is set, until you allow it. Neither our product analytics nor Meta's advertising measurement is fetched at all before that point, so refusing is not a cookie you have to trust us about: there is nothing there to set one. Once you allow it, Meta sets a _fbp cookie in your browser to measure our advertising, and that is the only advertising cookie the site uses.
What we do keep in your browser, in its local storage rather than in cookies, is your test session and result, your answer to the analytics question, and whether you have an invite open. Those sit on your device and are not sent to us.
When a payment form is on screen it is Stripe's, loaded from Stripe, and Stripe sets what it needs to run and protect it.
Who else sees anything
| Provider | What they do | What they see |
|---|---|---|
| Supabase | Our database, hosted in London (eu-west-2) | The anonymous score rows, the purchase rows, the subscriber rows, and the comparison rows |
| PostHog | Product analytics, on their EU cloud | Analytics events, after you allow them. No address, and no tokens in page addresses |
| Meta | Advertising measurement, after you allow analytics | The address of the page you are on, but never a page carrying a private link, the standard buying-flow events, and the amount and currency of a purchase. It sets a _fbp cookie. No name, no email address, no result |
| Stripe | Takes the payment | Your card details, which go to Stripe and never to us, and whatever else you give Stripe at checkout |
| Resend | Sends our email | Your address and the contents of the email we sent you, in their send log |
| Vercel | Hosts the site | Every request, including the address of the page requested |
Two of those are worth spelling out.
Resend's send log holds the body of what was sent. Your summary email prints your type and your five percentiles, so for anybody who was sent one, that log holds an address and a trait profile together for as long as Resend's retention runs. When somebody asks to be erased, purging that log is part of the request we make of Resend.
Vercel records the address of every request it serves. A comparison link has its token in the address, so those links reach the host's request log. Nothing we write puts a token in a log line and no query of ours can take one out of theirs. If you ask us to delete a comparison, the row goes and the link stops working immediately, but the address of a page you visited may sit in the host's log until their retention window passes.
Where the data sits
Our database is in London. Product analytics run on our provider's EU cloud. Meta, Stripe, Resend and Vercel are companies based in the United States, and processing by them is not limited to the UK.
What we do not hold
- No name, unless you put one in an email to us.
- No IP address, in any record of ours.
- No test answers, and no copy of anyone's answers.
- No card number, expiry or security code. Those go to Stripe and never touch our servers.
- No analytics profile against an address.
- No trait score sitting beside a person, with one exception: while your subscriber row and a comparison row both exist, they share a link to the same result. That is the single place the two could be put together, it only exists for people who used a comparison, and deleting the rows is what takes it apart.
Your rights
Under UK GDPR you can ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, or hand it to somebody else. You can object to processing, and where we rely on consent you can withdraw it at any time without giving a reason.
Ask at support@illustro.tech. We have a month to answer and we will not use all of it if we do not need to. If you used a partner comparison, say so, because that is the one thing an address alone will not find.
If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You can do that without coming to us first, though we would rather have the chance to put it right.
Children
Our tests are for people aged 13 and over.
Changes to this policy
We update it when the product changes, and the date at the top says when. If a change matters to somebody already on our list, we say so in an email rather than quietly editing the page.