Test attempts
Test answers and calculated results are processed on the server. Completed attempts may be stored so results can be shown in an account, associated with an anonymous browser visitor, and used for aggregate site analytics.
When a completed attempt is stored, TypologyOnline also records an approximate location inferred by Cloudflare from the internet connection used at completion. The attempt-linked record contains a country code and, when available, a region and city. It does not contain the raw IP address, coordinates, postcode, metro code, timezone, Cloudflare request identifier or a new device fingerprint. This inferred network location is kept separate from any country you choose to report yourself, may be inaccurate when a VPN, mobile network or shared gateway is used, and is used only to understand geographic coverage and assess aggregate sample quality.
After a completed result, you may optionally select a fixed feedback category and leave a private plain-text comment of no more than 800 characters. At least a category or comment is required before anything is saved. The feedback is linked to that completed attempt so only one current record can exist per attempt; it can be updated or removed from the same result page. Comment text is encrypted in the database, is never published, and is not sent to site analytics or application logs.
The feedback record contains the attempt reference, public assessment identifier, frozen definition version, selected category, encrypted comment, comment length, and timestamps. It does not add an email address, username, IP address, browser user-agent string, analytics identifier, or separate fingerprint. Authorised administrators can read the comment alongside limited assessment/version metadata but not through a public page. Feedback expires no more than 730 days after its last update. Administrators may remove spam or unusable feedback sooner; its text and category are erased immediately, while an empty attempt-linked marker can remain within the normal retention period to prevent resubmission from that attempt.
HEXACO Personality Test
The assessment asks for explicit completed-response storage consent before it starts. Until completion, responses, random question order, timing totals, and the current position remain in this browser so progress can be resumed. No item responses are sent to the server before the final submission.
On completion, all 96 raw responses are stored with stable private item IDs, their random delivery order, response timings and revision counts, response-quality indicators, calculated raw scale scores, and the frozen assessment, scoring, and norm version identifiers. The record is linked either to your signed-in account or to a random pseudonymous browser visitor. It may be used for saved results, reproducible scoring, and future aggregate assessment analysis.
Response-quality warnings never change scores. Free result responses do not include the private scoring directions, item-to-facet key, norms, facet percentiles, or domain percentiles. The reference layer is returned only after a server-side premium-entitlement check.
Enneagram Personality Test
The assessment keeps progress, a random browser participant ID, previous-attempt links, results, and optional feedback in your browser until you clear them. JSON and CSV files are created only when you choose to export them.
Every completed attempt also stores its stable core, quality-check, contrast-check, and adaptive-comparison item IDs; raw response values; delivery and left/right presentation order where applicable; response timings and revisions; scoring versions; nine core scores; and provisional three-centre pattern. This ordinary attempt record is separate from optional consented calibration events, allowing the result to be reproduced and future scoring methods to be evaluated against the original responses.
If you actively select research consent, the completed question IDs and order, responses, broad optional research categories, response timings, quality flags, calculated evidence, previous self-type, and any later fit feedback are sent to TypologyOnline for assessment calibration and research. Names, email addresses, precise birth dates, account details, advertising identifiers, IP addresses, and browser user-agent strings are not added to the calibration record.
Jungian Personality Type Test research assessment
As with the other assessments, a completed Jungian attempt stores its 48 stable item IDs and raw 1–5 responses, random delivery order, randomised A/B presentation orientation, response timings, calculated scale positions, assessment and scoring versions, and non-scoring response-pattern indicators. This preserves the evidence needed to reproduce the result, show saved account history, inspect aggregate item performance, and evaluate later scoring versions.
If you actively select anonymous-research consent, the same versioned response record and any optional structured accuracy and context feedback may additionally be sent to the separate Jungian research collection. Declining that optional consent does not prevent completion, ordinary attempt storage, or local JSON and CSV export.
The research record does not include your username, email, account ID, IP address, precise location, advertising identifiers, browser user-agent string, or free text. The random session UUID is transformed with a secret server-side keyed hash before the encrypted event is stored. Scores are independently recomputed on the server. Every paired comparison has equal scoring weight, and the resulting scale positions are not population percentiles or probabilities.
Accepted events are retained for up to 3650 days, subject to documented periodic review and earlier deletion where required. To request deletion, retain the session UUID in your JSON export and provide it through the contact page. Collection does not automatically change live scoring; any model change requires offline analysis, holdout evaluation, review, and an explicit new version.
Pseudonymous linkage and scoring checks
Random browser participant and attempt identifiers are transformed using a secret server-side keyed hash before storage. This allows retest records to be linked without retaining the original browser identifiers. Submitted client scores are retained for auditing, while the primary rational core score is independently recomputed on the server before analysis. Contrast checks, adaptive comparisons, previous-type information, and feedback remain separate from that primary score.
Purpose, consent and retention
The purpose of collection is to inspect data quality, question performance, structure, stability, and possible future calibration. The basis for this optional research collection is your explicit consent. Declining consent does not prevent you from completing the assessment or exporting your own record.
Accepted research events are retained in restricted, encrypted application storage for up to 730 days, unless they must be removed sooner. Access is limited to authorised server administrators using private command-line tools. Raw accepted events remain separate from processed analysis exports.
Research deletion and future versions
You can clear browser copies from the assessment. To request deletion of a submitted research record, use the contact page and provide the participant or attempt ID shown in your JSON export; the operator can transform that identifier and remove matching records without storing it in readable form.
Collected responses do not automatically alter this assessment or anybody else's result. Any scoring change must be analysed, evaluated on held-out data, reviewed, and released under a new explicit version. This assessment is not clinically validated for diagnosis, employment, selection, or treatment decisions.
Accounts
Accounts are optional. If you create one, saved test history and article bookmarks can be attached to it. An article bookmark stores the article identifier and the time it was saved so it can appear in your account. Passwords are protected using Laravel’s standard password hashing and are never stored as readable text.
If you rate an article, TypologyOnline stores the article identifier, your 1–5 helpfulness rating, any optional reason selected from the fixed list, and timestamps. A signed-in rating can be attached to your account. For a guest, a random value is placed in an encrypted, Secure, HTTP-only first-party cookie only after feedback is submitted; the database stores a one-way derived key so that browser can change or remove its current rating. Article feedback does not contain free text, assessment data, an IP address, a browser user-agent string or an analytics identifier. The private administrator view shows aggregates rather than reader identities, and ratings expire no more than 730 days after their last update.
For account security, responsible-use enforcement and payment-dispute handling, TypologyOnline may store the current account status and reason, status dates, an append-only history of status decisions, an operator or case reference, and a limited encrypted private decision note. Where Stripe billing is used, the site may also store Stripe dispute, customer, charge and payment-intent identifiers, dispute status and reason, amount and currency, and relevant evidence-due and event dates. Raw Stripe webhook payloads, submitted dispute evidence and complete payment-card details are not stored in this account-restriction record.
If premium billing is enabled, TypologyOnline may record the plan and price requested, the version identifiers of the purchase policies acknowledged before Checkout, relevant Stripe Checkout/subscription/invoice/payment identifiers and timestamps, entitlement changes, and the first time a premium report is generated, accessed, or downloaded. This limited delivery record does not contain assessment answers or scores, IP addresses, browser user-agent strings, device fingerprints, or complete card details.
Operational account information is available only through restricted administrative access. The routine administrator console shows account and completion metadata needed to operate the service and private assessment comments submitted specifically for the team, but does not display raw assessment responses, scores, result payloads, demographics, OAuth provider identifiers, or encrypted private restriction notes. Access to individual account and dispute summaries is recorded in an append-only administrator audit history.
An open payment dispute may pause premium access and new purchases while leaving free account features available. A serious security or responsible-use restriction may prevent account sign-in. Contact TypologyOnline through the contact page if you believe an account restriction is mistaken or want it reviewed.
If you choose Google sign-in, your browser is sent to Google so Google can authenticate you. TypologyOnline receives and stores Google's stable account identifier and your verified email address, and uses the name Google returns when creating a new account. Google access and refresh tokens are not stored. An existing password account is never joined to Google solely because the email addresses match; you must first sign in normally and explicitly connect Google from your account.
Optional demographics
Demographic questions are optional. When provided, each field is stored with version history so original responses can be distinguished from later updates in aggregate analysis.
Analytics, search insights and cookies
Essential first-party cookies may be used for security, account access, saved results, privacy preferences, and normal site behaviour. If you submit an article rating while signed out, the optional article-feedback cookie keeps that feedback editable and removable from the same browser.
Cloudflare Web Analytics provides privacy-focused, aggregate traffic and performance measurements such as visits, page views, paths, referrers, approximate country, device type, browser, operating system and page-load timing. It does not use cookies, local storage or an advertising identifier for these measurements.
These aggregate Cloudflare measurements include visitors from the European Union.
TypologyOnline also uses Umami Cloud in its European data region for cookie-free audience, navigation and performance measurement. The tracker records page paths carrying at most strictly validated UTM campaign labels, query-free referrers, page titles, language, screen size, browser, operating system, device category, approximate location and Core Web Vitals. Umami groups activity into anonymous sessions using a one-way value derived from the request IP address, browser user-agent and this site's public Umami identifier; TypologyOnline does not add a distinct user ID or connect the session to an account.
The Umami tracker strips arbitrary URL query strings, query-bearing referrers and fragments, preserves only strictly validated UTM campaign labels, respects the browser's Do Not Track setting, and does not set an analytics cookie. TypologyOnline sends only five custom journey event types: assessment start; anonymous progress at 25%, 50% and 75%; assessment completion; a post-result next-step selection carrying only the public assessment identifier and one fixed action category; and account creation with the method recorded as email or Google. It does not configure session replay, heatmaps, distinct IDs or identity fields, and does not send test answers, scores, type results, search phrases, form values, names, usernames, email addresses, account IDs, visitor IDs or attempt IDs.
TypologyOnline uses Google Analytics 4 in advanced consent mode. The Google measurement tag loads with analytics storage and all advertising consent states denied. Before analytics-cookie consent, it sends limited cookieless measurements to Google without setting a GA4 analytics cookie or using a GA4 browser identifier. If you allow analytics cookies, GA4 can use first-party analytics cookies and a pseudonymous browser identifier for fuller journey measurement.
TypologyOnline sends a query-free page path plus tightly restricted events when an assessment starts, reaches a fixed progress milestone, completes, offers a selected post-result route, or creates an account. Assessment journey events contain only the public assessment identifier and, where relevant, a fixed milestone or next-step category. GA4 Enhanced Measurement is also enabled for page views, scroll depth, safe outbound-link clicks, form starts and submissions, public embedded-video engagement, and public file downloads. These automatic events may include the relevant public link, form, video or file metadata, but must never include values entered into a form. Although GA4's site-search measurement control is enabled, the Google tag is not loaded on site-search URLs or any page carrying an unapproved query value, so search phrases remain excluded. Only URLs containing no query or strictly validated UTM campaign labels are eligible for measurement.
TypologyOnline does not send GA4 test answers, scores, type results, names, usernames, email addresses, search phrases, account IDs, TypologyOnline visitor or attempt IDs, IP-derived identifiers, advertising identifiers or user-level properties. Google Signals, advertising storage and advertising-personalisation signals remain disabled.
You have not allowed Google Analytics cookies in this browser. Limited cookieless measurement is active by default.
TypologyOnline records a small set of first-party assessment milestones: a test was started, a completed attempt was stored, the full result was displayed, an anonymous result was later attached to an account, or another assessment was started after viewing a result in the same browser tab. These counts help measure completion and improve the assessment journey; they are session events rather than unique-person or audience figures, and they cannot explain why somebody left.
Lifecycle records contain a one-way random journey key, fixed event type, assessment identifier, optional source assessment identifier, version and timestamps. They do not contain an account ID, visitor ID, test-attempt ID, username, email address, IP address or hash, user-agent value or hash, advertising identifier, device fingerprint, answers, scores, demographics, page URL, referrer or free text. A short-lived encrypted follow-on token can be held in the current tab's session storage and is removed after the next successful assessment start.
Duplicate milestones are rejected, automated write volume is capped outside the primary database, and raw lifecycle events expire after no more than 395 days. Lifecycle measurement does not alter assessment scoring or replace the completed-attempt record.
The optional first-party search-insight system is currently disabled, so search terms and search-result clicks are not stored for site analysis.