Privacy Policy
Last updated: August 3, 2026
Mivora is an independently operated personality-preference assessment and digital-report service for education and self-reflection. It is not a psychological or medical diagnostic service. This Policy explains how Mivora (“we,” “us,” or “our”) handles information when you use mivora.cc (the “Service”).
1. Who controls your information
Mivora, operated by an independent individual, is responsible for information processed through the Service. Contact us at support@mivora.cc. The Merchant of Record is separately responsible for the payment and tax information it collects through its hosted checkout.
2. Information we process
Assessment and result information
We process your answers, four continuous-axis scores, four-letter preference combination, assessment model and item-bank versions, language, and limited quality indicators. The free assessment is calculated in your browser. Its draft, answers, and result are stored in browser sessionStorageand are not written to our production database merely because you complete or view the free result.
If you start paid-report checkout, the answers are sent to our server to validate and calculate the result associated with the purchase. Our current database stores the calculated axes, preference combination, model and item-bank versions, language, and quality indicators; it does not store your item-by-item answer values.
Purchase and report information
We may process an anonymous visitor identifier, internal assessment and order identifiers, the Merchant of Record’s order identifier, product, amount, currency, payment or refund status, timestamps, checkout email address, generated report, report status, and a hashed, expiring report-access token. Mivora does not receive or store full payment-card numbers, security codes, or bank credentials.
AI-assisted reflection
To generate a paid report, we send your calculated axes, preference combination, language, and generation instructions to DeepSeek. If you voluntarily submit a situation, we also send that text to DeepSeek to generate a response. We do not intentionally include your email address, payment details, or item-by-item answers in the AI prompt. Please do not submit medical records, government identifiers, passwords, payment credentials, or another person’s private information.
Technical, support, and product-event information
Our hosting and security providers may process ordinary network and diagnostic information such as IP address, browser, device, requested route, response status, and request time. We may keep privacy-limited product events, AI request counts and timing, internal operational identifiers, and a one-way network hash for security, rate limiting, and abuse prevention. If you contact us, we process the email, message, and attachments you choose to send.
Optional product-research feedback
If you answer a short product-research prompt, we process the selected reason or rating, optional comment, language, anonymous visitor identifier, limited campaign parameters, and, when verified for the same browser, an internal order identifier. Please do not include names, contact details, medical or trauma information, payment details, or another person's private information. Automated tools may classify and summarize de-identified or filtered feedback, but feedback does not change your result or make a significant decision about you.
3. How and why we use information
We use information to:
- calculate and display the free result;
- create checkout, verify payment, generate, deliver, and restore a purchased report;
- provide AI-assisted reflection when you request it;
- send transactional messages and answer support or privacy requests;
- secure the Service, prevent abuse and fraud, diagnose errors, and maintain availability;
- understand aggregate product performance and improve the user experience; and
- meet accounting, tax, refund, dispute, legal, and compliance obligations.
We do not sell personal information. We do not use assessment answers or AI-situation text for targeted advertising or provide them to data brokers or advertising networks.
4. Legal bases in the EEA and UK
Where the GDPR or UK GDPR applies, we rely on contract to provide features and purchases you request; legitimate interests to operate, secure, troubleshoot, and improve the Service; consent for optional analytics where required; and legal obligation for applicable business records. You may withdraw consent at any time without affecting earlier lawful processing.
Assessment answers are needed to calculate a result. Checkout information is needed to purchase a report. The AI-situation field is optional. Mivora does not use automated processing to make legal or similarly significant decisions about you.
5. Browser storage and analytics choices
Essential storage
sessionStorage keeps an in-progress assessment and free result in your browser for the session. It may also keep allow-listed UTM campaign labels so voluntary feedback can be compared across acquisition channels; these labels must not contain names or contact details. When server-side assessment saving, feedback submission, or checkout begins, Mivora sets an essentialopc_visitor cookie containing a random identifier. It does not contain answers or an email address. The cookie is HttpOnly, SameSite=Lax, usesSecure in production, and expires after 12 months unless deleted earlier.
Optional analytics
Google Analytics and PostHog load only after you choose “Accept analytics.” Google advertising signals and ad personalization are disabled. PostHog automatic capture, user profiles, page capture, persistent identifiers, and session recording are disabled. We send only manual, allow-listed product events and do not send preference combinations, order or assessment IDs, answers, report content, AI-situation text, access tokens, email addresses, or payment details. Mivora does not use Microsoft Clarity or another session-replay tool in the current release.
Choose “Privacy settings” in the site footer to change your selection. If your browser sends Global Privacy Control or an enabled Do Not Track signal, optional analytics remain off for that browser.
6. Payments and the Merchant of Record
The production integration uses Dodo Payments as Merchant of Record. Its hosted checkout may collect billing contact, payment, country or region, tax, and fraud-prevention information under its own Privacy Policy. It sends Mivora limited transaction information needed to fulfill or revoke a purchase, send a report link, provide support, and keep required records. If the checkout identifies a different Merchant of Record, that provider’s privacy notice governs its payment processing.
7. Providers and disclosures
We use providers only as needed to operate the Service:
- Vercel — hosting and application delivery;
- Supabase — server-side database;
- Dodo Payments — Merchant of Record, hosted checkout, tax, fraud prevention, receipts, refunds, and payment disputes;
- DeepSeek — AI report and reflection generation;
- Resend — transactional email;
- Google Analytics and PostHog — optional analytics after consent; and
- professional advisers or public authorities where reasonably necessary or legally required.
Providers may process information in countries with different privacy laws. Where applicable law requires a transfer safeguard, we use an appropriate recognized mechanism available through the provider, such as an adequacy decision or standard contractual clauses.
8. Retention and security
We keep information only as long as reasonably needed for service delivery, security, support, accounting, tax, refunds, disputes, legal compliance, and legal claims. BrowsersessionStorage is generally cleared when the relevant browser session ends. The essential visitor cookie expires after 12 months, and a report recovery token is configured to expire after 12 months. Purchased report content is retained while reasonably needed to provide the purchased access, subject to refunds, deletion requests, and applicable recordkeeping duties. Product-research comments are normally retained for no more than 12 months, unless anonymized earlier or a shorter period is appropriate. Operational records may be kept longer where required for an active transaction, dispute, security investigation, or legal obligation. We delete, anonymize, or isolate information when it is no longer needed.
Safeguards include encrypted HTTPS transport, server-side database access, row-level security with no public database policies, hashed report tokens, signed payment webhooks, rate limiting, and restricted application logging. No online service can guarantee absolute security. Keep report links private and contact us if you believe one has been compromised.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive portable information, withdraw consent, and complain to a privacy authority. California residents may also have applicable rights to know, correct, delete, opt out of sale or sharing, and receive equal service. Mivora does not sell personal information or share it for cross-context behavioral advertising.
Email support@mivora.cc with the subject “Privacy Request.” Include enough information to locate the relevant record, such as the checkout email and approximate purchase date, but do not send card details, passwords, identity documents, or assessment text unless we specifically and lawfully request verification. We may retain records where an exception or legal obligation applies, and will not discriminate against you for exercising a right.
10. Age requirement
The Service is intended only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us and we will review and delete it where required.
11. Changes and contact
We may update this Policy when the Service, providers, practices, or law changes. We will publish a new “Last updated” date and provide additional notice or seek consent when required for a material change.
Privacy questions and requests: support@mivora.cc