Myndspecie · sorted.quest — operated by ThinkWell Labs LLC
Effective date: July 12, 2026
This Privacy Policy explains what personal information we collect when you use Myndspecie at sorted.quest (the “Service”), why we collect it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have over it. Myndspecie is a self-knowledge instrument that renders a personal cognitive-pattern form (your “myndspecie”) and an optional written cognitive-orientation report. It is not a medical, clinical, psychological, or diagnostic tool. Please read this alongside our Terms of Service.
The Service is operated by ThinkWell Labs LLC (“we”, “us”, “our”), which is the data controller responsible for your personal information under the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable United States state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
You can reach us regarding privacy at b@twl.today.
We practice data minimization: we collect only what the instrument needs to function. Depending on how you use the Service, we process the following categories of information.
| Data | Why we collect it |
|---|---|
| First name | Mathematically seeds the geometry of your personal myndspecie through a phonetic decomposition. Not used to identify you and not stored alongside your trait scores unless you create an account. |
| Date of birth | Confirms age eligibility (adults 27 and older only). |
| Optional birth date, time & place | Provided only if you choose the optional astrology cross-analysis feature. Entirely optional; the core instrument works without it. |
| Assessment responses | Your answers to the instrument, used to compute your cognitive pattern and generate your myndspecie and report. |
| Derived neurotype / trait scores & myndspecie geometry | The results computed from your responses — the shape, the trait dimensions, and the report text. |
| Account email | Collected only if you create an account or sign in, to authenticate you and let you save and return to your data across devices. |
| Payment information | Handled entirely by Stripe. We never see or store your full card number. We receive only confirmation that a purchase succeeded and a record of your entitlement. |
| Technical data (IP address) | When your browser calls our report-generation service, our API worker logs your IP address transiently and briefly for the sole purpose of rate-limiting and abuse prevention. It is not used to build a profile of you. |
| Local storage / session storage | Your browser stores your in-progress session, preferences, and results locally on your device so you can pause and resume. See Section 9. |
We do not collect special-category (sensitive) data for clinical or diagnostic purposes; the instrument is for self-development only. We do not sell your personal information, we do not serve advertising, and we do not use third-party advertising or tracking cookies.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
We rely on a small number of trusted service providers to operate the Service. Each processes personal information only on our instructions and for the purpose stated below. We do not sell data to any of them.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Google Firebase / Google Cloud | Authentication and database (Firestore) for signed-in and guest accounts. | firebase.google.com/support/privacy |
| Stripe | Payment processing for one-time purchases. Handles all card data directly. | stripe.com/privacy |
| Cloudflare | Serverless API (Workers), key-value storage (Workers KV) for community sign-ups and purchase entitlements, and a fallback AI model for report text (Workers AI). | cloudflare.com/privacypolicy |
| 1min.ai | Primary large-language-model provider that generates your report text. Called server-side by our Cloudflare worker; your assessment-derived inputs are sent to produce the report. | 1min.ai/privacy-policy |
| Codeberg | Static hosting of the website (Codeberg Pages). | codeberg.org privacy policy |
We may update this list as our providers change; material changes will be reflected in this policy.
We and several of our sub-processors are based in, or store and process data in, the United States and potentially other countries outside your own. This means your personal information may be transferred internationally, including from the European Economic Area, the United Kingdom, or Switzerland to the United States.
Where such transfers occur, we rely on appropriate safeguards recognized under the GDPR and UK GDPR — principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with our providers’ certifications under applicable data-transfer frameworks. You may request more information about these safeguards using the contact details in Section 13.
You have the right to:
You have the right to:
You may use an authorized agent to submit requests on your behalf where the law permits.
You can exercise most rights immediately and yourself:
users document and its sessions, glyphs, and reports) and clears the Service’s data from this browser. To also delete your sign-in account record itself, or for any request we cannot complete automatically, contact us.We will respond to verifiable requests within the timeframes required by applicable law (generally one month under the GDPR/UK GDPR and 45 days under the CCPA/CPRA, each extendable where permitted). We may need to verify your identity before acting on a request.
We use only essential and functional storage. We do not use third-party advertising cookies, analytics cookies, or cross-site tracking technologies. The Service does not load Google Analytics or any comparable analytics or ad-tracking script.
To make the instrument work, we store small amounts of data in your browser’s localStorage and sessionStorage on your own device. These are used for:
These keys (all prefixed pm_) stay on your device, are not tracking identifiers, and can be cleared at any time via the “Manage my data” tool or your browser settings. Authentication uses functional storage from Google Firebase strictly to keep you signed in.
We take reasonable and appropriate measures to protect your information, including:
No method of transmission or storage is perfectly secure, but we work to protect your information and to review our safeguards over time.
The Service is for adults aged 27 and older only. It is not directed to children, and we do not knowingly collect personal information from anyone under this threshold. If you believe someone under the eligible age has provided us information, contact us and we will delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective date” above and, where changes are material, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.
For any privacy question, request, or complaint, contact the data controller: