ThinkTraits · Last updated: September 4, 2026
Privacy Policy
A ThinkTraits account is optional. Tests, games, and curated experiences remain available without a name, email address, or sign-in. Data handling varies by feature; the notice beside an input or optional action is the most specific explanation.
Data kept on your device
Theme and language preferences, unfinished runs, game progress, and completed private results may be kept on your device. Private result addresses contain only opaque random IDs, never answers, scores, names, birth data, prompts, or result text. Removing app or browser site data removes local records.
Browser sync, backups, shared device profiles, browser history, the clipboard, an operating-system share sheet, or a destination app may retain device-controlled data or a URL you choose to copy or share.
Optional accounts
When hosted account services are available and you choose them, they use Better Auth and a PostgreSQL database hosted by Railway. ThinkTraits receives your email address and, for password sign-in, your password over encrypted HTTPS; only a password hash is stored. Resend delivers email codes, and Google processes Google sign-in. A verified Google identity and matching verified email identity are linked only through the reviewed account flow.
When profile saving is available and enabled, validated result data needed to reopen a result may be stored in your private account. You can stop future saving, delete individual or all account results, sign out, or permanently delete the account and its private data. Signing in does not silently upload earlier device results.
Public-by-link results
When public sharing is available, Save and share creates a separate minimized bearer-link copy only after an explicit action. Anyone holding that unguessable link can open the public copy, which expires within 90 days. Deleting a device or account copy does not revoke an independently created public copy.
Public previews use a deny-by-default projection and never include raw answers, names, birth data, questions, dream narratives, photos, prompts, or private account identifiers.
AI and other optional online features
When an AI action is available, it shows a feature-specific disclosure and asks for consent before bounded data is sent through ThinkTraits to Ollama. The exact projection differs by feature and excludes data the action does not need. Do not submit secrets or another person’s information without permission. Ollama’s policy may change, and ThinkTraits cannot enforce a provider’s practices.
Astrology place search sends only the search words and reviewed English service locale to Open-Meteo; entering coordinates manually avoids that lookup. Email delivery and social sign-in involve Resend or Google only when you choose those account actions.
Hosting, security, and telemetry
Hosted releases use Railway for the public website and Flutter Web Gateway. The Gateway proxies browser API calls to the Railway-hosted data service; native apps call that service directly. Hosting and network providers may process technical connection data such as network address, time, user agent, requested path, and response status under their own terms.
Production browser builds use Cloudflare Web Analytics on public pages to measure aggregate page views and performance. The beacon uses no cookies, browser storage, fingerprinting, custom events, or persistent visitor ID. It is not served on direct requests for account, private-result, or bearer-share pages, and App SPA tracking is disabled. Native apps and non-production builds do not load it. Answers and sensitive inputs are never sent. Cloudflare processes public page URLs, referrers, browser/operating-system and country categories, and performance data; it says it does not collect or use visitors’ personal data. Unsampled beacon data is kept for seven days and later aggregated.
Your choices and contact
Use local activities without an account, skip sharing and optional online actions, enter coordinates manually, remove device data, control account preferences, or delete account records. For a privacy question or an early-removal request for a public result link, contact admin@thinktraits.com and include only the account email or exact result link needed to identify the record.