Concentric

Legal

Privacy

Last updated 27 August 2026

The short version

We do not ask for your name, your email, or anything else that identifies you. We are not promising to keep your identity safe — we are declining to hold it, which is a stronger guarantee, because it does not depend on us keeping a promise or on never being breached. The link you get at the end is the only handle that exists for your answers, and we do not keep a copy of it: if you lose it, your answers are beyond your reach and beyond ours.

1.What we collect

Required, because the instrument cannot work without them:

  • An alias. Whatever you type. Never verified, never unique, not used to identify you, and not an account name.
  • Your age in years. Percentiles are meaningless without an age-matched reference group. Stored in years; released only in bands.
  • Sex assigned at birth, and gender identity. Collected separately and for different reasons — see section 3.
  • Country. From a dropdown, so that we can caveat norms that do not apply to you.
  • Your answers, with how long each took and how many times you changed it. Latency and revisions drive the data-quality checks that keep careless responding out of the published statistics.

Optional, each with its research reason stated at the point we ask: region, urban or rural, education, relationship status, household composition, broad occupation, primary language, ethnicity, religiosity, political orientation.

Separately consented and clearly skippable: self-reported neurodivergence or diagnosis, and a short block about your early social environment. Both are special-category data under GDPR, both are directly relevant to whether closeness-conditional expression has developmental origins, and both have their own consent checkbox and their own exclusion switch in the export pipeline. Neither is ever required to finish or to see results.

2.What we deliberately do not collect

  • No name, no account, no password.
  • No email, unless you choose to supply one for a magic link — in which case it is stored separately from your responses and is never part of any release.
  • No stored IP address. Your IP is used at the moment you submit to derive a coarse region as a data-quality cross-check, and is then discarded. There is no IP column to withhold, subpoena or leak.
  • No third-party analytics, no tracking pixels, no cross-site cookies.
  • No advertising data. Adverts never appear on the assessment or your results.

3.Why we ask about sex and gender separately

This is a real methodological problem and we would rather explain it than hide it.

The reference sample every percentile on this site is computed against recorded a single binary sex variable. Matching you to it therefore requires a comparable variable. But sex assigned at birth and gender identity are different things, and the second is the one that is interesting as research.

So we collect both, separately, using the two-step method; we let you choose which reference group you are compared against; and we state the limitation on your results page — the reference sample is coarser than you are. Gender modality is derived from the two answers rather than asked, and gender identity is available as a variable in its own right instead of being used as a proxy for something else.

4.How published statistics are stopped from identifying you

Aggregate figures are published openly on /explore and /data. Aggregates look anonymous and often are not, so four rules are applied before anything is written — not at display time, and never left to the browser.

  1. Minimum group size. Nothing describing fewer than 25 people is published.
  2. Complementary suppression. If we published a total and hid only one group inside it, subtraction would recover the hidden group exactly. So a second group is hidden too — and because that can expose a group somewhere else, the process repeats until nothing more is exposed.
  3. A cap on combined filters. At most 3 at once, whatever the group size. Somebody who knows six things about you can find you in a group of four hundred.
  4. Defences against comparing releases over time. This is the one usually left out, and it defeats the other three on its own: anyone who knows roughly when you responded could compare last night’s figures with tonight’s and recover you exactly. So we publish weekly rather than nightly, round every count to the nearest 5, refresh a group only once it has gained at least 10 new people, and never publish a minimum, a maximum or an exact count.

The implementation is src/lib/privacy/kanon.ts and it has a test for each attack. If you find a way through it, please tell us.

5.Consent, and asking us to remove your answers

Consent is granular, versioned, and stored with a hash of the exact text you agreed to, so a later change to our wording cannot retroactively alter what you consented to. You are asked at the start and confirmed again at the end, once you have seen what the instrument actually involves. Full detail on /consent.

We cannot look you up. There is no name, no email and no account, so nothing here connects a set of answers to a person. The link you were given at the end is the only handle that exists, and we hold no copy of it. That is the design working as intended, and it has a consequence worth knowing before you start: if you lose the link, nobody — including us — can find your answers again.

If you still have the link, send it to privacy@trovvy.com and we will remove that record. There is no self-service delete button, nothing on this site deletes anything on a schedule, and we cannot action a request that does not carry the link, because without it we have no way to tell which rows are yours. Under GDPR Article 11 a controller who is not in a position to identify a data subject is not obliged to act on a rights request unless the subject supplies the information that makes identification possible. Your link is that information.

Anything already included in a published aggregate or an open-data release cannot be retracted from files other people have downloaded. That is why consent to be included in releases is a separate checkbox from consent to take part at all, and why the release checkbox is the one the consent page tells you to treat as permanent.

6.Where the data lives

On a server we operate, in a database shared with other projects we run but logically separate from them. Backups follow that server’s schedule. We do not sell data, do not share it with advertisers, and have no commercial arrangement with anyone that involves it.

The one thing we do share is the open dataset, deliberately and only with consent, under CC0. That is the point of the project.

7.GDPR, and everyone else

We apply GDPR practices to everybody, everywhere, rather than geo-blocking or applying them only to people who can invoke them. Most of what it requires — data minimisation, explicit consent, purpose limitation — is what we wanted regardless. The lawful basis for processing is your consent.

What we hold is pseudonymous, not anonymous, and we would rather say so than claim otherwise. A results link resolves to one person’s answers, so those answers are attributable to an individual by anyone holding that link. Data is not anonymous merely because we do not know whose it is. Claiming otherwise would be the more flattering description and the less true one, and this is a project that publishes its own falsification conditions.

What follows from that is Article 11 rather than an exemption. We are not in a position to identify you, so a request about “your data” can only be actioned if you supply the link that makes identification possible — and we are not required to acquire more information about you in order to be able to act on such requests. That is a feature rather than an obstruction: the alternative is holding something that could find you, which is the thing we declined to hold.

We do not profile you, make automated decisions about you, sell anything, or share anything with advertisers. The only data that leaves here is the open dataset, with consent, under CC0.

8.Age

18 and over only. We do not knowingly collect data from anyone younger. If you believe a minor has submitted responses, send the link to those results to privacy@trovvy.com and we will remove them. As above, we have no way to find them without it.

Questions: privacy@trovvy.com, or see /about. Related: terms · consent.