WhichAmI

Privacy Policy

Privacy Policy

whichami.com is owned and operated by Vikas Dulgunde, a London-based software engineer who builds and maintains the site (referred to here as "we" or "us"). This policy explains what we collect, why, and what you can do about it. It is written in plain English. If anything is unclear, email privacy@whichami.com.

Last updated: 2026-06-19

What We Collect

Quiz Takes (Anonymous by Default)

When you take a quiz, we log the quiz ID, the answers, the result generated, and a duration figure. Takes are anonymous by default. We do not attach them to a name, email, or persistent user account. There are no user accounts on the site.

Anonymous Take Token

To let you resume a quiz where you left off and to dedupe abusive submissions, your browser generates a random opaque token. It lives in your browser's localStorage, not in a cookie. It contains no personal information and is never combined with PII on our servers. Clearing your browser data removes it.

Country Code

Our edge layer (Cloudflare in front of our origin server) passes a country code derived from your IP address. We store the country code only, never the IP itself. We use it to tailor language, currency, and a small set of region-specific suggestions.

Email (Opt-In Only)

If you choose to join the newsletter through an email gate or footer form, we collect your email address through Kit (formerly ConvertKit) using double opt-in. You receive a confirmation email and only become a subscriber after clicking the link. We do not buy lists and we do not subscribe you automatically.

Analytics

We use Google Analytics 4 to understand, in aggregate, which quizzes and pages people enjoy. It is loaded only if you grant the analytics consent category in the cookie banner, and it sets its own cookies and sends data to Google. If you decline analytics, Google Analytics is never loaded and sets no cookies. We also send a few custom events (quiz start, quiz complete, share) carrying only the quiz slug, result code, and share platform. No user identifier is attached, no raw answers, nothing that could re-identify you.

We also use Microsoft Clarity to see how the site is actually used, through heatmaps and anonymized session replays of on-page interactions like clicks, scrolls, and navigation. Clarity masks text and form inputs by default, so what you type is not captured. Like Google Analytics, it loads only if you grant the analytics consent category, sets its own cookies, and sends data to Microsoft. Decline analytics and Clarity is never loaded.

Error Tracking

We run Sentry Community Edition, self-hosted on our own server to capture runtime errors so we can fix bugs. IP addresses are redacted at the edge before reaching Sentry. We do not capture quiz answers or email addresses in error reports.

Local Storage Generally

Your browser stores quiz progress (current question, answers so far) locally so you can resume. This data stays on your device. We do not read it from our servers.

Cookies

We set no analytics cookies unless you grant the analytics category, in which case Google Analytics sets its own cookies to measure traffic. Decline it and no analytics cookie is set. Essential cookies may be set for basic site function such as security checks by Cloudflare.

We show a cookie consent banner on your first visit with separate, off-by-default toggles for analytics and advertising. We default to denying non-essential storage until you choose (Google Consent Mode v2), and you can change your choice any time from the "Privacy choices" link in the footer. The footer also carries a "Do Not Sell or Share My Personal Information" link for visitors in regions that require one (EU, UK, California, and others).

When advertising is enabled and you have granted the advertising category, Google AdSense sets advertising cookies under its own policies to serve and measure ads. If you do not grant the advertising category, the AdSense library is not loaded and those cookies are not set. You can also control ad personalization directly through your Google Ad Settings.

How We Use What We Collect

  • To run and improve the quizzes.
  • To send the newsletter, only if you opted in.
  • To understand traffic patterns in aggregate.
  • To diagnose errors and keep the site stable.
  • To meet legal obligations.

We do not sell personal data. We do not share quiz answers with third parties in a way that could identify you.

Third Parties

  • Cloudflare (CDN, WAF, edge DDoS protection): see cloudflare.com/privacypolicy
  • Kit / ConvertKit (newsletter, opt-in only): see kit.com/privacy
  • Resend (transactional email such as newsletter confirmation and account messages): see resend.com/legal/privacy-policy
  • Google Analytics 4 (analytics): measures aggregate traffic, loaded only after you grant the analytics consent category, sets cookies and transfers data to Google in the United States, see policies.google.com/privacy
  • Microsoft Clarity (analytics, heatmaps and session replay): records anonymized on-page interactions with text and inputs masked by default, loaded only after you grant the analytics consent category, sets cookies and transfers data to Microsoft in the United States, see privacy.microsoft.com
  • Sentry CE (error tracking): self-hosted on our origin server, no third-party transfer
  • Google AdSense (advertising): serves and measures display ads, loaded only after you grant the advertising consent category, see policies.google.com/privacy

We do not currently use affiliate networks. If we add affiliate links in future, the relevant network may set its own outbound-click tracking, no quiz data would be shared, and we will list each network here before any such links go live.

Your Rights

If you live in the European Union, the United Kingdom, or California, you have the following rights:

  • Access: request a copy of any personal data we hold about you.
  • Erasure: request deletion of personal data we hold about you.
  • Portability: request export of your data in a machine-readable format.
  • Object / withdraw consent: every Kit email contains a one-click unsubscribe. You can also email us at any time.

To exercise the first three, email privacy@whichami.com with the subject "Privacy Request". We respond within 30 days.

California (CCPA / CPRA): the footer carries a "Do Not Sell or Share My Personal Information" link per CPRA requirements, which opens your privacy choices so you can decline the advertising category. When you decline, personalized advertising cookies are not set.

Data Retention

  • Quiz take logs: 365 days. After that, individual rows are deleted and only aggregate counts remain.
  • Newsletter subscribers: retained until you unsubscribe, or after 24 months of inactivity (no opens, no clicks), whichever comes first.
  • Anonymous take token: stored indefinitely in your browser's localStorage. Clearing site data removes it. We never tie it to PII server-side.
  • Error logs: 90 days, then purged.

Children

WhichAmI is not directed at children. Under US COPPA we do not knowingly collect data from anyone under 13. Under EU GDPR the threshold for parental consent is 16. We do not knowingly collect data from minors below either threshold. If you believe a child has submitted information, email us and we will delete it.

International Transfers

The site and all our databases are hosted in Germany (EU) on a Contabo VPS. We picked an EU host so that EU and UK visitor data does not leave the European Economic Area at our layer.

Kit (ConvertKit) is based in the United States. When you subscribe to the newsletter, your email is transferred to the US under Standard Contractual Clauses as approved by the European Commission. Google Analytics and Microsoft Clarity (only if you grant the analytics category) and the other US-based providers we may use for advertising or payments operate under the same SCC framework.

Changes to This Policy

We will post any material changes on this page and update the date at the top. Major changes (such as the launch of AdSense or a new third-party processor) will be announced through a banner on the homepage for at least 14 days.

Contact

Privacy questions and data requests: privacy@whichami.com