Privacy Policy

Last updated: April 22, 2026

This Privacy Policy describes how Persona ("we," "us," "our") collects, uses, shares, and protects your personal information when you use startpersona.com and associated services (the "Service").

Plain-language summary. We collect what's needed to run the quiz, build your reading, power the AI coach, and bill your subscription. We don't sell your data. We use a small list of named processors (Stripe, Anthropic, Microsoft Clarity, Meta, Resend, Railway). You have full rights to access, export, or delete everything. Full details below.
Contents
  1. Who we are
  2. What we collect
  3. How we use it
  4. Legal bases (EEA / UK / Switzerland)
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. Security
  9. Your rights
  10. California privacy (CCPA/CPRA)
  11. Children
  12. Cookies
  13. Data-breach notifications
  14. Changes to this policy
  15. Contact & DPO

1. Who we are

Persona operates the Service. Our registered contact for privacy inquiries is privacy@startpersona.com. If you are an EU/UK resident, you may also contact our designated representative at the same address with the subject line "EU Representative" or "UK Representative" as applicable.

2. What we collect

CategoryExamplesSource
Account dataEmail address, password hash, name, date account was created, subscription statusYou (signup, profile setup) + Stripe (subscription state)
Quiz & assessment dataLikert answers (1-5), forced-choice picks, computed scores, derived archetypeYou (answering the quiz)
App usageMood entries, habit completions, 100-day challenge progress, AI chat turns, saved readings, connections, invitesYou (using the app)
Device & technicalBrowser type, OS, IP address, timezone offset, referrer URL, pages visited, timestampsAutomatic (server logs + browser)
PaymentLast 4 digits and brand of card, expiry (not full card numbers), billing country, invoice historyStripe — we never see or store full card numbers
Cookies & similarSession ID, quiz-progress storage, Clarity anonymous session IDs, Meta Pixel event IDsBrowser (see Cookie Policy)
CommunicationsSupport tickets, contact-form messages, feedbackYou (when you email or use the contact form)

What we don't collect

We don't ask for — and don't want — government IDs, social-security numbers, driver's-license numbers, full card numbers, medical records, biometric identifiers, precise GPS location, or content from third-party services you haven't explicitly connected.

3. How we use it

We do not use your quiz answers or personal data to train third-party AI models. The data you submit to AI features (chat, reading) is sent to Anthropic's API for processing; by their API terms Anthropic does not use API-submitted data to train their models.

If you're in the EEA, UK, or Switzerland, we process your data on one or more of these legal bases under the GDPR / UK GDPR:

5. Who we share it with

We use a short list of named processors. Each is contractually bound to act only on our instructions and keep your data secure:

ProcessorPurposeLocation
StripePayment processing, subscription billing, fraud preventionUSA (EU-US DPF certified)
AnthropicAI model inference for chat, reading, mood analysis, habit suggestionsUSA (SCCs)
Microsoft ClarityAnonymous session recordings and heatmaps — we use these in aggregate for UX improvementUSA / Azure (SCCs)
Meta (Facebook)Conversion tracking for advertising; only non-sensitive event data is sentUSA (SCCs)
ResendTransactional email delivery (receipts, password resets)USA (SCCs)
RailwayCloud hosting for our servers and databasesUSA

We do not sell personal information to third parties. We do not share your individual quiz answers, chat history, or psychological scores with advertisers. Aggregated, anonymised patterns may appear in public posts or research, but never in a way that identifies you.

We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation or valid law-enforcement request, (b) protect our rights or property, (c) protect users' safety, or (d) detect and address fraud or security issues.

6. International transfers

Our infrastructure is based in the United States. If you are in the EEA, UK, or Switzerland, your data is transferred to the US and potentially to our processors' regions. We rely on:

7. How long we keep it

DataRetention
Account & quiz dataWhile your account is active, plus 12 months after cancellation (so you can return without re-taking). Deleted sooner on request.
Subscription & billing records7 years from the invoice date — required for tax and accounting law.
AI chat & mood entriesWhile your account is active. Wiped on account deletion.
Support tickets24 months.
Server logs (anonymised after 30 days)90 days in identified form, indefinitely in aggregate.
Clarity session recordings30 days (Microsoft's default).

8. Security

We apply industry-standard safeguards including:

No system is perfectly secure. If you spot a vulnerability, please email security@startpersona.com and we'll acknowledge within 48 hours.

9. Your rights

Regardless of where you live, you have the following rights over your data:

To exercise any of these rights, email privacy@startpersona.com. We respond within 30 days.

10. California privacy (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

To exercise any CCPA/CPRA right: privacy@startpersona.com with subject line "California Privacy Request." We verify identity via the account email before responding.

11. Children

Persona is for adults. We do not knowingly collect data from anyone under 18. If a minor has created an account or provided information, a parent or guardian can contact privacy@startpersona.com and we will delete it promptly.

12. Cookies

We use strictly-necessary cookies to run the app, plus optional analytics cookies from Microsoft Clarity and the Meta Pixel. You can block these at the browser level without breaking core functionality. See the Cookie Policy for the full list, purposes, and how to opt out.

13. Data-breach notifications

If we suffer a personal-data breach that creates a risk to your rights and freedoms, we will:

14. Changes to this policy

We may update this policy over time. Material changes are announced via an updated "Last updated" date and, where required, a direct email notification. Your continued use of the Service after changes take effect constitutes acceptance.

15. Contact & Data Protection Officer