Gnosora
Legal

Privacy Policy

Last updated: August 10, 2026.

1. Who we are and what this covers

This policy describes how Gnosora (“we”, “us”) handles personal data across gnosora.com and related services. We keep the principle simple: we collect the minimum needed to run the product, we do not sell personal data, and we do not show ads. Questions and requests: support@gnosora.com.

2. Data you give us

If you take a test without signing in, your answers stay in your browser and are not stored on our servers as personal data. When you create an account and save a result, we store: your account identity (name/email, managed by Clerk), your test answers and computed score profiles, AI readings generated for you, share links you create, and your subscription status.

If you join the Premium waitlist, we store the email you submit — only to let you know when Premium launches. Ask us to remove it at any time. If you write to support, we keep the correspondence for as long as needed to resolve your request.

3. Data collected automatically

Like any web service, our hosting infrastructure (Vercel) processes technical request data — IP address, browser type, timestamps — transiently, for delivering pages and for security. Our error monitoring records exceptions with technical context so we can fix failures. Product analytics is cookieless: it sets no analytics cookies and stores no identifier on your device, so anonymous visits are not linked across sessions; once you sign in, product events (for example “test completed”) are associated with your account id — never with your answers or the text of your readings. We use no advertising pixels and no cross-site tracking.

4. Why we process it (legal bases)

To provide the service (performance of a contract): accounts, saved results, readings, subscriptions, sharing. Legitimate interests: keeping the service secure, monitoring errors, and understanding aggregate product usage — in ways that do not override your rights. Consent: the waitlist email (withdraw anytime by asking us to delete it). Legal obligations: payment and tax records kept by our payment provider.

5. Processors we rely on

A deliberately small set, each processing your data only to provide the service under contractual data-protection obligations: Clerk — authentication; Supabase — database hosting; Stripe — payments as merchant of record (we never see, collect, or store your card details); Anthropic — generation of AI readings under our instructions; PostHog — cookieless product analytics and error monitoring; Vercel — web hosting and cookieless aggregate web analytics.

6. AI readings

Personal readings are generated from your computed scores (not your raw browsing or identity) by Anthropic models under our instructions; per Anthropic’s API terms, data submitted this way is not used to train their models. Generated readings are stored against your account so you can re-read them without regeneration. The service makes no automated decisions about you that produce legal or similarly significant effects — readings are informational self-development content.

7. Sharing and disclosure

Results are private by default. If you create a share link, a frozen snapshot of that score profile (never your AI reading, never your name unless you share it yourself) becomes visible to anyone with the link, until you revoke it from your account. Beyond the processors above, we disclose personal data only if required by law or to protect the service and its users from fraud or abuse.

8. Cookies and local storage

We set only strictly necessary cookies (sign-in, and payment sessions on Stripe’s pages), use local storage for a few on-device preferences, and run analytics without cookies. Details — including every stored key — are in our Cookie Policy.

9. Where data is processed

Our infrastructure and processors operate primarily in the United States and the European Economic Area. Where personal data is transferred internationally, our processors rely on recognized safeguards such as Standard Contractual Clauses or participation in the EU–U.S. Data Privacy Framework, together with technical measures like encryption in transit and at rest.

10. Security

Data is encrypted in transit and at rest by our providers; database access is restricted by row-level security so each account can read only its own records, and administrative credentials follow least-privilege practice. No system is entirely impervious to risk — if we learn of a breach affecting your data, we will assess, contain, and notify as required by law.

11. Retention and deletion

We keep your saved results and readings while your account exists. You can request deletion of your account and associated data at any time by contacting support@gnosora.com; we will delete data we control and instruct our processors accordingly, subject to legal retention obligations (for example, Stripe’s payment records). Waitlist emails are kept until Premium launches and the announcement is sent, or until you ask us to delete yours.

12. Your rights

Depending on where you live (including GDPR and US state privacy law jurisdictions), you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Contact us at support@gnosora.com — we aim to respond within 30 days and may need to verify your identity first. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your supervisory authority.

13. Children

Gnosora is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

14. Changes and contact

We may update this policy; material changes will be reflected on this page with a new “last updated” date. Continued use of the service after changes take effect means the updated policy applies. Questions: support@gnosora.com.