Privacy Policy
The architecture is the policy.
Prismona is operated by Sensing Apparatus LLC. Personality data is sensitive, so we built the product so that we never hold it: the assessment, scoring, and reports run entirely in your browser. This page states exactly what that means — including the optional, opt-in exceptions (sections V and VI). Effective June 11, 2026; updated June 21, 2026 (accounts are now a self-generated key, not an email).
Personality quizzes earned a bad name for good reason. In 2018, Cambridge Analytica harvested roughly 87 million Facebook profiles through a personality quiz — reaching far past the ~270,000 people who actually took it by pulling their friends' data through the social graph — and built psychographic targeting on it. Prismona is built so that every one of those moves is impossible here:
- No social graph. There is no friend API, no contacts, no network. The most we ever see is a single self-contained code you chose to hand over.
- Never sold, never targeted. Your data is not an input to advertising, to any third party, or to anything you didn't trigger yourself.
- We don't know who you are. No email, no name, no login identity. An account, if you make one, is a self-generated recovery key — the same model privacy tools like Mullvad use. A database dump shows opaque one-way hashes, not people.
- It stays on your device. Your blueprint lives in this browser; our server is a calculator you send a code to, not a vault of profiles.
By default we store nothing about you. Server-side data exists only where you explicitly opt in: an anonymous norms contribution (trait scores plus coarse age/country, section V); a synced blueprint kept under a one-way hash of your recovery key, and nothing else (section VI); and an observed layer, which is off unless you switch it on — behavioral tags only, stored pseudonymously and auto-deleted after about 180 days (section V). We never store your answers, your name, an email (we don't ask for one), your contacts, your location, or any link between a code and a person.
What we never collect
Your answers, your facet blueprint, your dyad reports — the raw material of the assessment — are computed and stored only on your device. They are not transmitted to us or to anyone else, not stored on a server, not used for advertising, and not sold — ever. No account is required for anything. Trait scores follow the same rule with two narrow, explicit exceptions you control: the opt-in norms contribution (section V) and the opt-in account sync (section VI). Nothing leaves your browser unless you press the button.
Where your data lives
Completed blueprints are saved in your browser's local storage so your results survive a page reload. The same local storage holds everything else the product remembers: your retest history (compact per-assessment snapshots for the trajectory view), your interest-inventory result, the age range you optionally selected, and a flag noting whether you already contributed a given blueprint to our norms. All of it remains until you clear it — from the results page or by clearing your browser's site data — and it dies with the browser blueprint it lives in. If you use a shared or public computer, clear your results before leaving it.
Share codes, blueprint links, and exports
A share code carries six quantized trait scores, a date, and a checksum — twenty-one characters, no name, no identity, no individual answers. Codes are generated and decoded in the browser; comparing two codes never sends either one anywhere. A blueprint link (or manual link) is the same code carried in the URL after the # — a fragment, which browsers do not transmit in requests, so even our hosting provider's logs never see it. Sharing a code or link is your choice and your disclosure: anyone who holds it can view the domain-level report and run comparisons that include your trait blueprint. The copyable AI-context block works the same way — you copy it, nothing is sent by us — but once you paste it into a third-party assistant, that service's privacy terms govern what happens to it.
What our infrastructure sees
The site is static pages served from a hosting provider, plus a handful of narrow server endpoints: the opt-in norms contribution (section V), the optional sign-in and blueprint sync (section VI), and the MCP endpoint, which is stateless and stores nothing. Like virtually all web hosting, the provider records standard access logs (IP address, requested page, user agent, timestamp) for delivery and abuse prevention; these logs contain no assessment content, because assessment content is never sent — and blueprint links keep their payload in the URL fragment, which never reaches a server. Fonts are bundled with the site at build time, so no request is made to a font service. We run no advertising trackers and no analytics on answers or results.
Optional norms contribution
Our percentiles rest on provisional published norms, and improving them requires data — so the results page offers an explicit, optional contribution. If, and only if, you press Contribute anonymously, we receive exactly three things: the contents of your share code (six quantized trait scores, edition, date, and consistency index — the same payload you could text to a friend); the age range and continent you optionally selected before the assessment, as coarse selections only; and a two-letter country code derived from the network request at our edge, stored without the IP address it came from. We never ask your device for its location, never store precise location, and never attach names, identifiers, cookies, or user agents to a contribution. The purpose is stated and limited: re-estimating norms and comparing trait distributions across countries and age bands, in aggregate. Because contributions are anonymous by construction, we cannot link one back to you afterward — which also means we cannot selectively delete one; that is the trade the anonymity buys, and it is why the choice is yours each time.
A second optional inbound channel exists for collaboration field notes: an agent or person who holds your share code can report short observations about what worked and didn't while collaborating with you, which appear as a weekly digest on your own AI tab. Notes are stored pseudonymously against a hash of the code — no name, no IP, no identity — and are readable only by someone who holds the code. Sharing your code is what enables this; treat the code accordingly.
A related observed layer lets assistants you work with record short behavioral summaries (communication and work style — never message content, names, or private information, enforced by a server-side filter). It is off by default: nothing is stored until you switch it on from your blueprint's AI tab, and you can turn it off or clear it at any time. Like field notes, entries are keyed to a hash of your code, never your identity, and they age out automatically (about 180 days). They never move your measured trait scores.
Optional account and sync
You can use all of Prismona with no account. If you want to carry your blueprint between devices, you create an account — and an account is simply a recovery key you generate in your browser (a string like PRSM-ACCT-…). There is no email, no name, and no password; we ask for nothing about you. The server only ever sees a one-way hash of your key, so it cannot tell who you are and a database dump reveals no keys. The account stores exactly one thing — and only when you press Save this browser's blueprint — the blueprint bundle you chose to sync, kept under that hash. The session lives in a single httpOnly cookie. Nothing syncs automatically; you can delete the synced bundle from the account page at any time. The trade, by design, is the same one Mullvad makes: lose the key and the synced copy is unreachable — there is no reset. Your in-browser blueprint is unaffected.
Cookies
Prismona sets no cookies for visitors. The single exception is the httpOnly session cookie created if you choose to sign in (section VI) — it identifies your session and nothing else, and signing out removes it. Local storage is used solely to keep your own results on your own device, as described above; it is never read for tracking and never transmitted.
Children
Prismona is intended for adults. The instruments are normed on adult samples, and the service is not directed to children under 16. Because we collect nothing, there is nothing for us to delete — but the product is not designed or offered for minors.
Changes and contact
If the architecture ever changes, this policy changes first, visibly, with a new effective date, and any new collection will be opt-in — sections V and VI are the additions so far, each made under exactly that rule. Questions can be directed to Sensing Apparatus LLC. See the Method page for the scientific and ethical commitments that sit alongside this policy, and the Terms of Service for the rest of the agreement.