Privacy Policy
How Robin Review handles your information in vibe (DeepType).
Last updated: July 30, 2026
Effective: August 1, 2026 · Version: 1.0
Free quizzes vs. the paid report
Answers to the Compatibility and Talk Type quizzes are calculated entirely in your browser and are never sent to or stored on our server. These quizzes require no sign-up.
Your free DeepType result is calculated in the browser. When you start purchasing a paid report, result codes and answers are sent to our server to process the purchase and deliver the report. Data that does not lead to a purchase, or is left in pending or failed payment status, is deleted 30 days after creation or the payment attempt.
Personal data we collect
For paid reports we process your email address and a lookup hash; your answers to the forced-choice items in the free and in-depth runs; the self-declared code you picked and whether you provided one; the server-computed result codes, per-axis clarity, and the generated report; payment data (method, approval and transaction identifiers, amount, consent timestamps, and the timestamp of your 14+ confirmation); and access and usage data (IP address, device and browser information, and anti-bot token).
On pages where Google tools are enabled, consent state, page viewed, device and browser data, and advertising or analytics identifiers may be processed. Stored advertising and analytics identifiers follow your choices. In advanced consent mode, cookieless consent-state and measurement signals may still be sent to Google before a choice or after a refusal.
In the free DeepType run, the number of items answered, the segment you have reached, and whether you provided a self-declared code may be sent to Google as usage-statistics events even before payment. The answers themselves are not sent.
Sensitive payment details such as card numbers are handled directly by the payment provider and are not stored by us.
Purposes of processing
We use personal data to generate and deliver your report and let you re-open it by email, to manage payments, refunds, and transaction records, to prevent abuse and automated bots, to respond to inquiries, and for statistics that improve the service.
Retention period
Unpurchased results and pending or failed purchase attempts are kept for 30 days. Answers from the free and in-depth runs, together with saved drafts, are kept for 3 months after report generation. Result codes, the server-computed profile, report, purchase email, and report-access credential are kept for 1 year from payment. We do not store the raw email-link token; only its hash is kept and deleted by the next scheduled purge after it expires in 15 minutes or is used once.
If you paid but never finished the in-depth items and no report was generated, your answers and saved drafts are kept for 90 days from payment and then deleted. The server-computed profile remains, so you can still open your result.
Raw PortOne webhooks are kept for 90 days and access or security logs for up to 3 months. Minimal payment, contract, and refund evidence is kept for 5 years, and inquiry or dispute records for the period needed for that purpose, up to 3 years. After 1 year we delete the email, access credential, result, and report separately from the minimal transaction record; after 5 years the minimal record is deleted too.
Processing entrusted to others
We use PortOne and Toss Payments for card payments, refunds, and payment integration; Anthropic PBC for report narration; Plus Five Five, Inc. (Resend) for transactional report-access email; Cloudflare, Inc. for hosting, content delivery, access logs, and bot mitigation (Turnstile); Supabase for database storage in Seoul; and Google for consent management, analytics, and advertising.
We set the terms needed to keep personal data safe in each contract and supervise our processors.
Transfer of personal data overseas
For the purpose of entrusted processing and storage needed to perform the contract, we transfer personal data overseas as follows, disclosed here in lieu of separate consent (Article 28-8(1)3 of the Personal Information Protection Act).
To Anthropic PBC (United States), when a report is narrated: the server-computed type codes; the axis names, pole labels, and clarity wording; the world-job; the drain-condition labels; and the report body the rules engine has already written. Your email, your per-item answers, and your per-axis scores are not sent. The transfer is made over encrypted HTTPS, and the contact is privacy@anthropic.com. Anthropic states that commercial API inputs and outputs are not used for model training by default and are deleted within 30 days unless an agreed or policy-enforcement exception applies. We keep the narration we receive under our own 1-year schedule.
To Plus Five Five, Inc. (Resend, United States), when you request access: the recipient email, purchase date, 15-minute one-time URL, message content, and sending metadata. We do not include type codes or report text. The transfer is made over encrypted HTTPS, and the contact is privacy@resend.com. Standard-plan email data is retained for 30 days, and we disable click and open tracking.
To Cloudflare, Inc. (United States): the transferred items are access data (IP address, device information) and an anti-bot token, sent when you use the service and processed for hosting, content delivery, and security for as long as the service is provided. For bot verification we send your access IP address and the widget token to the Cloudflare Turnstile verification endpoint. The transfer is made over encrypted HTTPS, and the contact is privacyquestions@cloudflare.com.
Google and its advertising or analytics partners may process data in locations that depend on your region and their infrastructure. Consent state, cookieless measurement signals, or consented advertising and analytics data is sent when you use the service and processed under Google settings and retention policies. Once a payment is confirmed, our server sends the transaction identifier, the payment amount, currency, and item information, together with the analytics identifier collected in your browser, directly to Google. This transmission can happen after your browser is closed. The contact can be found at https://support.google.com/policies.
Transfers for report narration and for payment do not happen unless you purchase a report. You can refuse transfers for advertising and analytics from “Privacy & cookie choices” in the footer. Transfers for security and bot mitigation are limited to the minimum needed to provide the service, and the service cannot be used if you refuse them. You may also send your objection to our contact address.
Your rights and how to exercise them
You may request access to, correction of, deletion of, or suspension of processing of your personal data. As a non-member you can verify your identity with the email used for purchase and exercise these rights through the contact below, and we will act on the request without delay.
Cookies and advertising
We use Google AdSense, Google Tag Manager, and analytics tools. Before any Google tag, Consent Mode v2 initializes ad storage, analytics storage, ad user data, and ad personalization as denied. Google Privacy & Messaging updates those states from choices collected in supported regions. Refusing prevents new advertising or analytics cookies from being stored, but advanced consent mode may still send cookieless signals.
You can reopen your choices from “Privacy & cookie choices” in the footer and manage Google personalization at https://adssettings.google.com. AdSense is not loaded on /deep-type/reopen or /deep-type/checkout-return, where a raw access token or payment identifier may be present.
Destruction of personal data
Personal data whose retention period has ended or whose purpose is fulfilled is destroyed without delay. Electronic files are deleted in a way that cannot be recovered.
Security measures
We restrict database access and encrypt data in transit. Payment details are handled by the payment provider. Report-access links work once for 15 minutes; only a SHA-256 token hash is stored, and the raw token is placed in the URL fragment so it is not sent in server access logs or referrers. Email click and open tracking is disabled.
The access token used to resume after mobile payment is kept out of the URL and stored in that tab’s sessionStorage. Values older than one hour are removed on return, and the browser removes them when the tab is closed.
The free-result share action includes type codes and a result summary in the shared text. Review the audience and included content before posting it publicly.
Privacy officer
The privacy officer is the representative, Kwak Tae-uk, reachable at sobok2026@gmail.com and +82 10-9203-2837. For privacy-related consultation or reports in Korea you may contact the Personal Information Infringement Report Center (118), the Personal Information Dispute Mediation Committee (1833-6972), and the cyber units of the Supreme Prosecutors’ Office and the National Police Agency.
Children's privacy
The free service is available without age confirmation. Paid reports may be purchased only by people aged 14 or older. We do not collect dates of birth; we store only the 14+ confirmation timestamp submitted at checkout.
Changes to this policy
If the service or processing changes, we will publish the reason, before-and-after details, and effective date. We give 7 days’ notice for ordinary changes and 30 days for changes materially adverse to users, using a prominent service notice. This page keeps each version, effective date, and links to earlier versions.