Privacy Policy
Effective date: September 6, 2026
1. Introduction
Welcome to JungOcean (jungocean.com). We value your privacy. This policy outlines how we handle data collected at every step of using our Jungian Typology & Big Five assessment — the free test, your results, an optional emailed copy, the paid Deep Dive and AI Blueprint reports, the Alchemical Sandbox chat, and the update email you can opt into.
As of 6 September 2026, JungOcean is not available to visitors in the European Economic Area: we're a small Australian business and can't yet meet the EU's requirements for handling data from there, so we've switched the site off for EEA visitors rather than get it wrong. The UK and Switzerland are unaffected.
2. What We Collect, Step by Step
- Free assessment: your answers are scored in your browser to compute your Big Five (OCEAN) traits and Jungian type. Nothing about your answers is sent to our servers just to see your free results.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR) to calculate and render your profile.
- Your results (paid purchases): if you buy a report, we store your scores and Jungian type in our database so you can come back and restore them without redoing the test. See Section 6 for how long. Your free assessment results are never stored on our server this way — they stay saved directly in the browser you took the assessment in.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR).
- Optional emailed copy of your free results: on the free results screen, you can enter your email to get a one-time confirmation email confirming your profile is ready — it doesn't include a link back to your results, your scores, or your type, and we don't cache your scores on our server for this; your free results stay in your browser. If you also tick the separate newsletter checkbox there, we create a subscriber record with your email and Jungian type (never your OCEAN scores) so we can send you occasional update emails — kept for 90 days after the last email we send you, and deleted right away if you unsubscribe. Leaving that box unchecked means we don't create this record at all.Legal Basis: Legitimate Interest (Art. 6(1)(f) GDPR) for sending the one-time confirmation email; Explicit Consent (Art. 6(1)(a) GDPR) for update emails and the subscriber record that supports them.
- Email addresses: when you provide your email to receive a copy of your free results or to unlock a paid report, we collect your email address. This is used to email your report and, only if you explicitly opt in, to send occasional update emails.Legal Basis: Performance of Contract for results delivery; Explicit Consent (Art. 6(1)(a) GDPR) for update emails.
- Paid Deep Dive report: payments are processed directly and securely by Stripe. We do not store or have access to your credit card details. Since 6 September 2026, purchases store your scores and type only in our own database (see Section 4); Stripe holds the payment record and a checkout reference. Purchases made before that date are moved to our database and cleared from Stripe the first time they're opened, or by our one-off migration.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR).
- AI Blueprint report: if you buy this add-on, your OCEAN scores and Jungian type are sent to the Google Gemini API to generate the report text. Your name or email are never included in that request.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR).
- Alchemical Sandbox chat: if you use the AI Blueprint's follow-up chat, the messages you send are sent to the Gemini API to generate a reply, the same way the report itself is generated.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR).
- Update emails (drip): if you opt in, we store your email address and send a short series of follow-up emails. You can unsubscribe from any of them at any time.Legal Basis: Explicit Consent (Art. 6(1)(a) GDPR).
- Device and Usage Data, four independent categories: Our cookie banner lets you choose four things separately, not just accept-or-decline. Necessary is always on: it remembers your choice and, if you buy, your checkout session. Basic counting is on by default for an undecided visitor: a random ID stored only in your browser's
sessionStorage, gone the moment you close the tab, counting which steps of a visit happen with no cookie at all. Analytics across visits is off by default: turning it on upgrades that same ID to a persistent cookie so we can tell a return visit from a new one. Session replay is off by default: turning it on records how you move through the pages so we can fix confusing screens, with everything you type, your answers, and your results masked in your browser before anything leaves it. See “Your Choices” below for the full breakdown and how to change any of this at any time.Legal Basis: Legitimate Interest / the first-party audience-measurement exemption (Art. 6(1)(f) GDPR) for basic counting, with an opt-out available any time via “Reject all” or the Basic counting switch; Explicit Consent (Art. 6(1)(a) GDPR) for analytics across visits and session replay. Server-side crash diagnostics run separately under Legitimate Interest. - Purchase Recovery Records: If you request purchase recovery, we look up your transactions in Stripe and send a temporary recovery token containing your Stripe session identifier via Resend.Legal Basis: Contractual Necessity (Art. 6(1)(b) GDPR) to restore your purchased access.
3. Cookies & Advertising
Before you make a choice on the cookie banner, we don't set any cookie at all. The session ID described in Section 2 lives only in sessionStorage, tied to that one browser tab, and is gone as soon as you close it. Turning on “Analytics across visits” is what sets a real, persistent cookie (via PostHog) so return visits are recognized. Rejecting everything sets one small cookie recording that choice, and nothing else. PostHog also keeps its own small record of your accept/decline/opt-in choice in your browser's localStorage, separate from the cookie above; the Privacy choices control below can clear both together.
JungOcean is currently 100% ad-free. We do not display advertisements, and no advertising cookies or device identifiers are set on this site.
If we introduce advertising in the future, it will be consent-gated: ad cookies and personalization will only load after you explicitly opt in through our cookie banner, and this policy will be updated first to disclose the vendors involved and how to opt out.
If you wish to change your cookie choices or withdraw consent for analytics on this site, you can reopen your choices at any time — the same Privacy choices control also appears at the bottom of every page:
3a. Your Choices
The cookie banner (and the Privacy choices control above) lets you turn four things on or off separately:
- Necessary — always on, can't be switched off. Remembers this choice, and your checkout session if you buy. Nothing else.
- Basic counting — on by default. A random ID kept in this tab only, gone when you close it. Counts which steps of the visit happen. No cookie.
- Analytics across visits — off by default. The same ID kept between visits (browser storage and a cookie), so we can tell a return visit from a new one.
- Session replay — off by default. A recording of how you move through the pages, so we can fix confusing screens. What you type, your answers, and your results are masked before it ever leaves your browser.
You can change any of these at any time from the cookie banner or the Privacy choices control above — there's no need to wait for a reset. A full reset clears everything and puts you back to the not-yet-decided state.
4. Third-Party Services We Use
We share data with or utilize the following third-party processors to run the site:
- Stripe: Payment transaction gateway. No financial details touch our servers. Since 6 September 2026, purchases store your OCEAN scores and Jungian type only in our own database (Upstash, below); Stripe holds the payment record and a checkout reference. Purchases made before that date are moved to our database and cleared from Stripe the first time they're opened, or by our one-off migration.
- Resend: Transactional and marketing email provider. We share your email address and results report with Resend to deliver your analysis documents.
- Google Gemini API (paid tier): For generating the Jungian Analytical AI Blueprint report and the Alchemical Sandbox chat. We send assessment scores (OCEAN metrics and Jungian cognitive type profile), and your sandbox messages if you use it, to Gemini to generate text. No personally identifiable details (like your name or email) are sent to the AI API. This processing may happen on Google's infrastructure anywhere in the world, including the US. Google keeps this data for up to 55 days for abuse monitoring — during which authorised Google personnel may review it — before deleting it.
- PostHog (US-hosted): For analytics, server-side crash diagnostics, and, only if you turn it on, session replay. Before you make a choice, PostHog only sees the session-scoped ID and event set described in Section 2 — no cookie, no cross-visit tracking. Turning on “Analytics across visits” sets a persistent cookie; turning on “Session replay” starts a masked recording of that session only. We've configured PostHog to discard your IP address and delete precise location data before it's stored. Separately, our production server also reports its own crashes to PostHog using an anonymous, fixed identifier, never a visitor identity. We don't use it for advertising or cross-site tracking. If you're visiting from the European Economic Area, the UK, or Switzerland, our cookie banner tells you plainly that our servers and analytics are US-hosted before you decide.
- Vercel (US-hosted): Hosts the site and runs the server that terminates analytics requests before they reach PostHog.
- Upstash (database and caching): stores your assessment results, generated AI report text, and — if you sign up for update emails — your subscriber record. Each of these expires automatically (see Section 6, Data Retention) rather than being kept indefinitely. We use it so you can come back and restore your results without starting over.
Where a provider above is based in the US, we rely on their own current certification under the EU-US Data Privacy Framework (and its UK Extension, where applicable) as the legal basis for sending data there, backed by standard contractual clauses where a provider isn't DPF-certified.
5. Do Not Track
We don't currently change what we track based on your browser's Do Not Track signal — your choice in the cookie banner is what actually controls measurement on this site.
6. Data Retention & User Rights
How long we keep things depends on what it is:
- If you bought a report, we keep your OCEAN scores and Jungian type in our own database for 12 months so you can restore them, and delete them sooner on request. Since 6 September 2026, purchases store your scores and type only in our own database; Stripe holds the payment record and a checkout reference. Purchases made before that date are moved to our database and cleared from Stripe the first time they're opened, or by our one-off migration.
- Your generated AI Blueprint report text is kept for 30 days, whether or not you bought it — reopening it after that regenerates a fresh version rather than restoring the old one.
- If you request the optional emailed copy of your free results without buying a report, we don't cache your scores on our server at all — we only send the one-time confirmation email described in Section 2; your free results stay in your browser. If you also tick the newsletter checkbox there, see the next bullet for how long we keep the subscriber record it creates (it includes your Jungian type, never your scores).
- If you sign up for update emails, we keep your subscriber record for 90 days after your last activity, and delete it right away if you unsubscribe.
- Once you unsubscribe or ask us not to email you again, we keep a record of that choice indefinitely — the whole point of keeping it is to make sure we honour it.
- Stripe's own record of your payment follows Stripe's own independent retention obligations, not ours.
If you are a resident of the European Union (GDPR), United Kingdom, or California (CCPA), you have the right to request access to, rectification of, restriction of, or deletion of your personal data, to object to marketing at any time, and to withdraw any consent you've given.
You may withdraw your consent or request permanent deletion of your test records and email history by emailing us at support@jungocean.com. You also have the right to lodge a complaint with your local Data Protection Authority (DPA) if you believe our data processing practices violate applicable law.
If you have a complaint about how we handle your data, email support@jungocean.com — we read and personally respond to every message sent there.
We never sell your personal data, your scores, or your type to anyone, for any price.
If we make a material change to this policy, we'll post the updated version here with a new effective date — this page is always the current version.
A note on our own numbers: when we talk about “visitors” measured before you accept the cookie banner, that count reflects browser sessions, not distinct people. Opening a new tab, or coming back tomorrow, looks like a new visitor to us, even if it's you again. Once you accept and get a persistent ID, we can tell returning visits apart properly.