Privacy Policy
Last updated: August 2026
1. Controller
The controller responsible for the processing of personal data on the TESTUNO platform ("we", "us") is:
Steve Thomas Schütz, trading as JDMTarmac.
Contact for data protection matters: jdm.prjct [at] gmail.com
The full provider identification, including the postal address used for service of documents, is set out in our legal notice.
2. Legal bases (Art. 6 GDPR)
We process personal data on the following legal bases:
- Art. 6 (1) (b) GDPR — performance of a contract or pre-contractual steps: account creation, running a test, storing your results in your account, generating and delivering a purchased personalized test report, and processing your payment.
- Art. 6 (1) (f) GDPR — legitimate interests: operating and securing the platform, preventing abuse, and pseudonymised norm calibration to keep scoring and percentiles accurate (Section 7).
- Art. 6 (1) (c) GDPR — legal obligations, in particular statutory retention of payment and accounting records.
- Art. 6 (1) (a) GDPR — consent: optional analytics (Section 11) and the optional TESTUNO Mind Brief newsletter (Section 13). You can withdraw consent at any time.
3. Categories of personal data
We follow data minimisation. The categories we process are:
- Account data — email address, password (stored only as a salted hash by the platform), display name and account role. Created only if you register; TESTUNO can be used anonymously.
- Test and assessment data — described in detail in Section 4.
- Purchase data — product purchased, amount, currency, payment status and the payment provider's transaction identifier (Section 14).
- Personalized report data — the generated report content and the result snapshot it was based on (Section 8).
- Norm calibration records — pseudonymised records used to build reference distributions (Section 7).
- Optional analytics events — only with your consent (Section 11).
- Communication data — your email address and newsletter consent state, if you subscribe to the Mind Brief (Section 13).
4. Test and assessment data — what is actually stored
TESTUNO offers around 180 tests: reaction and speed benchmarks, memory and attention tasks, reasoning and IQ assessments, personality, relationship, career and self-assessment questionnaires, language and knowledge quizzes, and entertainment tests. All of them are scored and stored through the same pipeline, so the following applies to every test unless stated otherwise.
When you finish a test, we store one result record containing:
- the test key (which test you took) and the time of completion;
- the primary score, its unit and its display label — for example a median reaction time in milliseconds, an estimated IQ value, a words-per-minute figure or a questionnaire index;
- subscores and dimension scores where the test has them — for example the five Big Five factors, the seven IQ domains, EQ dimensions or a career interest profile;
- the result band or classification (for example an archetype, attachment style, CEFR level or descriptive band);
- a quality flag derived from the attempt (used to exclude invalid attempts from norms);
- the device class and input class (for example "mobile-touch" or "desktop-mouse") and the locale of the test;
- whether the attempt was a personal best;
- either your account ID (if you were logged in) or a random local session ID generated in your browser (if you were not).
What we do not store: we do not store your individual answers, your selected answer options, per-item response times or raw per-trial data on our servers. Timing and item-level responses are processed in your browser to calculate the score, and are then discarded — with one exception: if you purchase a personalized report for a questionnaire-based or language test, the answers of that attempt are transmitted for report generation and stored as part of that report's snapshot (Section 8).
We also do not store your IP address as part of a test result, and we do not ask for or store your date of birth, age or age band. Percentiles are calculated at display time from reference distributions and are not part of the stored result record.
Anonymous use: if you are not logged in, your personal bests and a local history of up to 60 entries (test name, score, label) are stored only in your own browser under the keys `testuno.personalBests` and `testuno.history`. Clearing your browser storage deletes them; we cannot access or restore them.
5. Account-linked test history
If you are logged in when you complete a test, the result record described in Section 4 is stored with your account ID so that your results persist across devices, so your test history and domain tracks can be shown on your profile, and so your Human Benchmark Score can be calculated from your anchor results. This is processing necessary to provide the account features you signed up for (Art. 6 (1) (b) GDPR).
Access is restricted at the database level: result records can only be read, changed or deleted by the account that created them (and by platform administrators for support and abuse handling).
Account-linked results are kept for as long as your account exists, because your profile and Benchmark Score are built from them. There is currently no self-service button to delete an individual result or your whole account inside the app. You can ask us to delete individual results, your entire test history, generated reports, or your whole account at the contact address in Section 21, and we will do so without undue delay and at the latest within one month.
When your account is deleted, the associated results, personalized reports and profile records are deleted from the live database. Because our platform provider keeps operational backups, residual copies may persist in those backups for a limited period after deletion and are removed as the backups expire — deletion is therefore not necessarily instantaneous across all systems. Pseudonymised norm calibration records (Section 7) are not deleted automatically with your account; you may object to them or request their deletion separately.
6. Public profile (optional)
If you choose a handle and publish a profile, the handle, display name, Human Benchmark Score, band, block and radar values, your top results and your completed-test count become publicly accessible at a URL of the form /u/your-handle. This is optional and based on your decision to publish (Art. 6 (1) (a), (b) GDPR). Your email address and your individual answers are never part of a public profile. Ask us at any time to unpublish or delete it.
7. Norm calibration data (NormObservation) — pseudonymised, not anonymous
When a test is completed, we additionally store one calibration record so we can build the reference distributions used for percentiles and bands. It contains only: the test key, the metric key, the score, the locale, the device class, the input class, a quality flag, and a contribution hash used to limit duplicate contributions from the same source.
No email address, name, IP address or individual answers are stored in these records. However, we want to be precise about their status: the contribution hash is derived deterministically from your account ID (or your local anonymous session ID) plus the test key. Because that calculation can be repeated, these records are pseudonymised personal data, not anonymous data — they can in principle be linked back to an account by us. We therefore do not claim they are irreversibly anonymised.
The legal basis is our legitimate interest in maintaining and improving measurement accuracy (Art. 6 (1) (f) GDPR). They are retained for as long as they are needed for calibration, which is not currently time-limited, because removing older observations would degrade the reference distributions. You can object to this processing at any time under Art. 21 GDPR (Section 19), and we will remove your contributions unless we can demonstrate compelling legitimate grounds.
8. Personalized test reports and AI-generated content
For a number of tests you can buy a personalized test report — for example the Personalized IQ Report, the Big Five Personality Report, the Attachment Style Report, the Career Match Report, the Emotional Intelligence Report, the Cognitive Ability Profile Report, or a language-level report. All of them work the same way, described here.
Your scores are not produced by AI. Every number in the report — the overall score, band, dimension values, estimated IQ, confidence interval and percentiles — is calculated deterministically by TESTUNO's own scoring logic from the attempt you just completed. AI is used only to write the narrative interpretation around those fixed numbers, and is instructed never to recalculate or contradict them.
What is transmitted to the AI model. To generate the report, we send a structured prompt through the Base44 platform's AI integration containing: the report product and its section list, the primary score/label and its unit, the band or classification, the dimension or domain values, and — for the IQ report — the estimated IQ, its confidence interval, percentile and classification. For questionnaire-based and language tests, the individual answers of that attempt (item key and chosen value) are also transmitted, because those reports explain how your answer patterns produced your scores and which item types you struggled with. Your locale is transmitted so the report is written in your language.
What is not transmitted: we do not send your email address, your name or display name, your account ID, your payment data, or any results or history from other tests. The AI model receives only the data of the specific attempt the report is about.
The generated report is then stored in your account together with the result snapshot it was based on, a PDF version is created and stored in private file storage, and a link is emailed to you. Reports are readable only by the account that owns them (and by platform administrators for support). Ask us at any time to delete a report.
Research articles: for our editorial research-news and science sections, publicly available abstracts and metadata are fetched server-side from PubMed, arXiv and Semantic Scholar and sent to the same AI integration to draft articles. No user personal data is involved in that pipeline, and no personal data is sent to those three services.
AI-generated text is informational only, may contain inaccuracies, and does not constitute professional advice or a medical or psychological diagnosis.
9. Automated scoring, profiling and automated decisions
We want to distinguish four things clearly:
- Automated scoring. Your responses are evaluated automatically by fixed, deterministic scoring rules (answer keys, timing measurements, dimension averages). No human reviews each attempt.
- Profiling. Where a test automatically evaluates or infers aspects such as cognitive performance, memory or attention performance, preferences, behavioural tendencies or personality dimensions, and where those results relate to an identified account, this may constitute profiling within the meaning of Art. 4 (4) GDPR.
- AI-assisted narrative generation. For purchased reports, an AI model writes an interpretation of scores that were already calculated (Section 8). It does not evaluate you independently and does not produce any score.
- Automated decision-making under Art. 22 GDPR. Test results, scores, profiles and reports are provided for information, self-discovery, education and — for entertainment-class tests — amusement. We do not use them to make decisions about employment, lending, insurance, formal education placement, medical treatment, government benefits or administrative matters, and they produce no legal or similarly significant effects for you. On that basis we do not consider our processing to fall under Art. 22 (1) GDPR. We also do not claim that every AI-generated report is automatically such a decision.
If you believe a report or result about you is inaccurate, or you have questions about how it was produced, you can contact us at the address in Section 21 and a human will look at it. This is a support commitment we offer voluntarily; it is not presented as a statutory right to human intervention under Art. 22 (3) GDPR, which applies only to decisions with legal or similarly significant effects.
10. Special categories of personal data (Art. 9 GDPR)
TESTUNO is not designed to collect special categories of personal data. No test asks for health, medical or psychiatric information, ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation, and none of these is used as a scoring dimension.
We have reviewed the test library individually rather than assuming a blanket answer. Some tests are health-adjacent: they measure performance on attention, memory or cognitive tasks, or ask about mood, emotional patterns, emotional availability or life satisfaction. These are designed and scored as performance measures or self-reported tendencies, not as health findings, and the platform is instructed never to present them as clinical or diagnostic. Nevertheless, self-reported answers on such topics can in some circumstances indirectly indicate something about a person's mental well-being, so we treat this group as sensitive in practice: reports for these tests are subject to additional non-diagnostic constraints, and the data is never used for advertising or shared for any purpose beyond producing your own result and report.
We do not assume that a personality or cognitive test is automatically Art. 9 data. Where the correct classification and legal basis for an individual health-adjacent test cannot be settled from the implementation alone, that test is flagged in our internal audit for legal review rather than being assigned a legal basis we cannot justify. If we conclude that a specific test does process special-category data, we will ask for your separate, explicit consent before that data is stored with your account or used to generate an AI report — as its own, clearly worded step, never bundled into general acceptance of the Terms.
Please do not enter health, medical or other sensitive details in free-text fields such as feedback messages.
11. Cookies, analytics and advertising
We use two categories of browser storage and scripts:
Your choice is stored in your browser under the key "testuno.consent". You can change or withdraw it at any time via the "Cookie settings" link in the footer, which re-opens the consent banner; withdrawing revokes the consent signals immediately and the tag is no longer loaded on subsequent page loads.
When analytics is active, Google Analytics is configured with IP anonymisation. The IP address is still transmitted to Google's infrastructure before being truncated — we do not claim that no transmission takes place, only that GA4 does not retain the full IP address.
Advertising: TESTUNO currently displays no advertising. No Google AdSense, ad tag or advertising cookie is loaded, and all advertising consent signals are set to denied. If we introduce advertising in future, we will update this policy, add a separate advertising consent category (and, where required for Google advertising in the EEA/UK, a certified consent-management platform) before any ad script is loaded.
Assessment data is never used for advertising. Your IQ or cognitive scores, personality and relationship results, health-adjacent results, individual answers and report contents are kept logically separate from any advertising function and are not used to build advertising audiences or to select personalized ads. This remains true if advertising is introduced.
- Necessary (always active) — session and authentication tokens set by the platform, your consent choice, and your local test history and personal bests. Payment functionality (Stripe) loads only when you actually start a checkout. Without these the service cannot work; they are not used for tracking or profiling across sites.
- Analytics (opt-in only) — Google Analytics 4. The Google tag is not loaded until you consent: the page ships only with a consent-mode configuration in which analytics and advertising storage are denied, and the Google script is injected only after you actively opt in. If you decline, no request is made to Google Analytics at all. Our first-party product-event logging via the Base44 platform (events such as "test completed" with the test key, locale and device class — never your answers) is also switched off unless you consent.
12. Third-party tools — data types collected
The following overview lists every third-party tool involved in running TESTUNO, the data each one receives, why, and whether it depends on your consent. It is deliberately structured so it can be read at a glance and used for app-store privacy disclosures.
| Tool | Data received | Purpose | Legal basis / condition |
|---|---|---|---|
| Google Analytics 4 (Google Ireland Ltd.) | Device identifiers and cookie IDs, IP address (transmitted before truncation, not retained in full), page views and usage events, approximate region, browser and device information. | Aggregate audience and usage measurement. | Consent, Art. 6 (1) (a) GDPR — opt-in only; the tag is not loaded unless you consent (Section 11). |
| Stripe (Stripe Payments Europe, Ltd.) | Payment method and card details, billing and tax details you enter on Stripe's hosted checkout, purchase amount, currency and transaction identifier, IP address of the checkout. | Processing your purchase, fraud prevention, receipts. | Contract, Art. 6 (1) (b) GDPR — loaded only when you start a checkout. Not conditional on analytics consent (Section 14). |
| Base44 (hosting, database, backend functions, private file storage, email, AI integration) | Account data (email address, password hash, display name, role), result records (test key, scores, band, quality flag, device class, input class, locale), purchase and entitlement records, generated reports and their PDFs, pseudonymised calibration records, newsletter consent state, server and security logs including IP address. | Operating the platform: hosting, storing your account and results, generating and delivering reports, sending emails. | Contract and legitimate interests, Art. 6 (1) (b) and (f) GDPR — necessary; processor acting on our instructions (Section 15). |
| Anthropic (AI model provider, reached via Base44's AI integration) | Report prompt content only: the report product and section list, the primary score, unit and label, band or classification, dimension and domain values, the estimated IQ with confidence interval and percentile where applicable, the individual answers of that one attempt for questionnaire and language reports, and your locale. No email address, name, account ID or payment data. | Writing the narrative interpretation around scores that TESTUNO already calculated. | Contract, Art. 6 (1) (b) GDPR — only when you purchase a personalized report (Section 8). |
| PubMed, arXiv, Semantic Scholar (server-side research APIs) | No personal data. Only our own search queries for publicly available abstracts and metadata. | Sourcing editorial research and science articles. | Legitimate interests, Art. 6 (1) (f) GDPR — no user data involved. |
Plain-English summary (app-store privacy disclosure). Contact info: we collect your email address, linked to your account, if you register or subscribe to the newsletter. Identifiers: we use an account ID or a random local session ID; analytics and cookie identifiers are collected only if you opt in. Usage data: test results, scores, device class and input class, and locale are collected pseudonymously; analytics events about page and feature use are consent-only. Diagnostics: basic server and security logs, including IP address, are processed by our hosting provider for operating and securing the service. Financial info: purchase history (product, amount, currency, status, transaction ID) is stored, while payment-method and card data are collected by Stripe and never stored by TESTUNO. Sensitive info: for purchased personalized reports, score snapshots and, for questionnaire and language tests, the answers of that one attempt are sent to the AI model provider — never your name, email address or payment data.
We do not collect precise location, health or medical records, browsing history outside our own service, your contacts or address book, or biometric data. We do not sell personal data, and assessment data is never used for advertising.
13. Email communication
Service emails. If you purchase a personalized report, we email it to the email address of your account, with a link to the report page and a time-limited download link to the PDF. This is part of delivering the product you bought (Art. 6 (1) (b) GDPR).
TESTUNO Mind Brief (optional). You can subscribe to our newsletter from your profile. We then store your account ID, your consent state, the wording you consented to, the time of consent, your locale and the sequence state needed to send the emails (Art. 6 (1) (a) GDPR). You can unsubscribe at any time from your profile; we keep the consent record after unsubscribing as evidence of consent, as GDPR requires. Emails are sent through the platform's email integration.
14. Payments (Stripe)
Purchases are processed by Stripe (Stripe Payments Europe, Ltd. and its affiliates), which acts as an independent payment service provider under its own privacy policy: https://stripe.com/privacy.
What Stripe processes: the checkout itself takes place on Stripe's own hosted page. Your card or payment-method details, and any billing details Stripe collects for the payment or for tax purposes, are entered directly with Stripe and are never seen or stored by us.
What we store: for each purchase we store your account ID, the product purchased, the amount, the currency, the payment status, and Stripe's session/transaction identifier (which we also use to prevent double fulfilment). We additionally store an entitlement record showing that your account is allowed to access the report you bought. We do not store card numbers, and we do not currently store billing addresses, invoices or tax records of our own alongside these records; where a receipt or invoice is issued, this is done through Stripe.
15. Processors and sub-processors
Base44 (hosting, database, backend functions, file storage, email and AI integration). TESTUNO runs on the Base44 platform, which processes personal data on our behalf as a processor under a data processing agreement (DPA) that is part of Base44's Terms of Service. This includes the application hosting, the database holding accounts, results, reports and calibration records, the server-side functions, private file storage for report PDFs, the email delivery integration and the AI integration used for reports and articles. We have archived the current DPA version for our records.
AI model providers (via Base44). Base44's AI integration routes requests to third-party model providers. Base44 lists OpenAI and Anthropic (both United States) as sub-processors for LLM API calls. TESTUNO's report generation explicitly requests the Claude Sonnet model, so personalized report prompts are processed by Anthropic as a sub-processor via Base44. The content transmitted is limited to what is described in Section 8; no email address, name, account ID or payment data is sent.
Other Base44 sub-processors. Base44's sub-processor list additionally includes MongoDB, Render, Google Cloud Platform (GCP), SendGrid, Supabase and Datadog, which provide infrastructure services (database hosting, application hosting, email delivery, monitoring) to Base44 as part of operating the platform. These providers process personal data only on Base44's instructions as our processor's sub-processors.
Stripe (payments). See Section 14.
Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) processes usage data for Google Analytics 4, and only if you have consented. Privacy policy: https://policies.google.com/privacy.
Research APIs (server-side, no personal data). PubMed, arXiv and Semantic Scholar are queried from our backend to fetch publicly available abstracts and metadata for editorial articles. No user personal data is transmitted to them.
16. International data transfers
Some of the services above are operated by companies based outside the European Economic Area, or may process data outside it:
- Google (analytics, opt-in only): our contracting entity is Google Ireland Ltd. in the EU; data may nevertheless be processed in the United States. Google Ireland's terms rely on the EU Standard Contractual Clauses, and Google LLC is certified under the EU-US Data Privacy Framework. This transfer only happens if you consent to analytics.
- Stripe (payments): our contracting entity is Stripe Payments Europe, Ltd. in Ireland; Stripe's group companies, including in the United States, may be involved in processing. Stripe states that it uses the EU Standard Contractual Clauses and that Stripe, Inc. is certified under the EU-US Data Privacy Framework.
- Base44 (platform hosting) and AI model providers: Base44 stores data in the United States by default; EU/UK storage has been available since April 2026 for Elite and Enterprise plans. This is not automatically incompatible with the GDPR. Base44's DPA names the EU Standard Contractual Clauses, the EU-US Data Privacy Framework and other recognised transfer mechanisms as the basis for transfers to the United States. AI model providers OpenAI and Anthropic are also based in the United States and process report prompts under their own usage policies.
Where a safeguard is named above, it reflects the provider's published position and the terms of the applicable DPA.
17. Retention
We keep personal data only as long as necessary for the purposes described above:
- Local anonymous data (personal bests, local history, consent choice, pending-purchase context) — stays in your browser until you clear it or, for the pending-purchase context, until the purchase completes. We cannot delete it for you.
- Anonymous result records stored with a local session ID rather than an account — retained as part of the result data set; they contain no identifiers that let us contact you, and can be deleted on request if you can identify them.
- Account-linked results, test history and profile — for as long as your account exists, then deleted on account deletion; residual copies may persist briefly in the platform's operational backups (Section 5).
- Personalized reports and their PDFs — kept in your account so you can access what you paid for, and deleted with your account or earlier on request.
- Purchase, entitlement and accounting records — retained for the applicable statutory retention periods under German tax and commercial law, which may differ depending on the type of record. These records are kept even if you delete your account, and then deleted once the applicable period expires.
- Norm calibration records — kept as pseudonymised calibration data for as long as needed for measurement accuracy, with no fixed end date (Section 7); removable on objection.
- Newsletter consent records — kept after unsubscribing as evidence of consent, then deleted.
- Optional analytics data — retained according to the retention configured in Google Analytics; only exists if you consented.
18. Children
Account creation requires you to be at least 16 years old (Art. 8 GDPR as implemented in Germany); anonymous use of the public tests is intended for ages 13 and over. We do not verify age: registration does not ask for a date of birth, and we do not collect or store any age or age-band information from any user. This means we cannot detect a younger user, and we do not want to claim a level of protection we do not deliver.
We do not knowingly maintain accounts for children below the age threshold. If you are a parent or guardian and believe a child has created an account or provided personal data, contact us and we will delete the account and its data.
19. Security
Personal data is transmitted over encrypted connections (HTTPS/TLS). Passwords are handled by the platform's authentication service and stored only as hashes — we never see them. Access to results, reports, purchases and profiles is restricted per record at the database level, so one account cannot read another account's data, and privileged server-side operations run only in backend functions rather than in your browser.
Correct answer keys for ability and knowledge tests are kept out of the client where the test design requires it, and scoring for those tests does not depend on data the browser could tamper with in a way that would corrupt other users' data.
Your individual test answers are not stored on our servers at all, except as part of a personalized report you purchased (Section 4 and Section 8). We do not sell test data or personality data, and we do not use test answers, results or report contents for advertising targeting.
No online service can guarantee absolute security, but we review these measures as the platform develops.
20. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15) — confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16) — correction of inaccurate data.
- Erasure (Art. 17) — deletion of your data, subject to statutory retention obligations for accounting records.
- Restriction (Art. 18) of processing.
- Data portability (Art. 20) — your account data, results and reports in a machine-readable form.
- Objection (Art. 21) — you may object, on grounds relating to your particular situation, to processing based on legitimate interests, including norm calibration.
- Withdrawal of consent (Art. 7 (3)) — for analytics and for the newsletter, at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint to a supervisory authority (Art. 77) — see Section 21.
In the app you can: change or unpublish your profile handle, subscribe to and unsubscribe from the newsletter, change or withdraw your analytics consent, clear your local anonymous data through your browser, and permanently delete all your personal data (results, sessions, responses, reports, profile, email preferences, purchases, entitlements, meditation completions, shares and feedback) via the Delete Account function in your profile. Access and portability requests are handled by us on request — write to the address in Section 21 and we will act without undue delay, at the latest within one month. Note: the User login record itself (email) is platform-managed; deleting your data removes all personal content, and you can request full login-record removal by contacting us.
21. Contact and supervisory authority
To exercise your rights or ask any data protection question, contact us at jdm.prjct [at] gmail.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for the operator is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz — Hintere Bleiche 34, 55116 Mainz, Germany (postal: Postfach 30 40, 55020 Mainz). Telephone: +49 6131 8920-0. Email: poststelle@datenschutz.rlp.de. Website: datenschutz.rlp.de.
You may also complain to the supervisory authority of your own habitual residence or place of work.
