A clear account of what happens to your answers
16Kinks asks about deeply personal preferences. Every field therefore needs a stated purpose, a defined lifetime and a boundary from identity and third-party analytics.
The complete report is free during the public beta. You can take the test without an account, and we do not use advertising pixels or third-party audience analytics.
Anonymous testing does not create a saved result
An unchecked, explicit-consent gate comes before every question. After you agree, your browser holds the working answer set for the current session and sends it to our server to calculate the report. A separate optional research box lets us retain exact options and structured interaction events for up to 12 months under a random attempt ID that is not linked to your account, email, payment data, raw IP or full User-Agent.
Some features cannot work without temporary or user-requested storage. Each one has a defined purpose and lifetime.
What we may keep
- Your email and expiring authentication records when you ask for a sign-in link.
- A 30-minute draft containing your email and answers while a cross-device sign-in completes.
- Answers, scores and report snapshots only for results you deliberately save to an account.
- If you separately opt in, exact test choices, answer timing and changes, questions entering or leaving the visible area, page navigation, foreground/background state and completion or exit events for questionnaire research lasting up to 12 months.
- A hashed share token for up to 30 days; creating a replacement or revoking it deletes the previous token.
- Match choices and hashed participant tokens for up to 7 days, then the whole session is deleted.
- Short-lived request identifiers in abuse-prevention systems and request metadata in operational logs.
What the current beta does not collect
- Passwords
- Card or payment details
- Photos, video or contacts
- Precise GPS location
- Session recordings, keystrokes or unrestricted interaction payloads
- Advertising profiles or cross-site tracking data
How we reduce exposure
No system can promise zero risk. These controls reduce both what exists and what an incident could expose.
HTTPS in transit
Requests are encrypted between your browser, Cloudflare and our application services.
Server-trusted scoring
The server validates and recalculates answers instead of trusting scores supplied by the browser.
Purpose-separated research
Research answers use a random attempt ID in dedicated tables with no account, email, payment, raw-IP or full-User-Agent fields, and are never sent to GA, Sentry or application logs.
Hashed secrets
Share links and Match participant tokens are stored as one-way hashes, not as their raw secret values.
No third-party audience analytics
The public beta does not load Google Analytics, ad networks or social tracking pixels.
Automatic expiry
Scheduled cleanup removes expired drafts, shares, Match sessions, auth tokens and questionnaire-research rows after 12 months.
Your controls
Saved account data remains under your control. Identity-separated research expires automatically and can be deleted while its random attempt ID remains in the browser session.
Withdraw from an active tool
The test clears browser answers and research attempts remembered in that browser session; Match lets each participant delete their own stored answers.
Export your account data
Download your profile, saved results and any legacy purchase audit rows as JSON.
Delete individual results
Removing a saved result also removes its active share link.
Delete your account
Account settings remove the account and its associated pending drafts, unused sign-in tokens, results, sessions, shares and legacy purchase rows.
Revoke a share immediately
Revocation deletes the active token row; the public URL then stops working.
Your answers are not the business model
We do not sell personal data or use it for advertising. If that model ever changes, this policy and the product consent flow must change before the data practice does.
— The 16Kinks team
Questions or a privacy request? Email support@16kinks.com
The complete policy
The formal section below lists purposes, retention periods, service providers and your available rights.
Last updated: July 22, 2026
Scope and contact
This policy explains how 16Kinks handles data on this website. Because answers can reveal intimate sexual preferences, we treat them as sensitive data. Collection is purpose-limited and structured: the service, questionnaire research, account, payment-history and security datasets are kept separate. Questions or rights requests can be sent to support@16kinks.com.
Test, report preview and optional questionnaire research
Before any question is shown, you must actively tick a separate, unchecked box that explicitly consents to processing sexual-preference answers to provide the test. The working answer set is held in your browser's session storage and sent to our server to validate, score and assemble the report you requested. The preview endpoint itself does not insert those choices into the database. Session storage normally lasts for the browser-tab session and is also cleared by supported retake and withdrawal controls.
A second, separately unchecked research box is optional. If you select it, our first-party research stream stores a random attempt ID; test, item, telemetry and consent-notice versions; consent time; locale; normalized internal referral category/path; coarse device, viewport and pointer classes; start/completion times; page durations; each question's entries into and exits from the visible area and answer timing; exact selected options and their change sequence; page navigation; foreground/background events; and completion or exit. This lets us study hesitation, confusing questions, answer distributions, revision patterns and drop-off. The research tables have no user ID, email, result ID, payment identifier, raw IP address or full User-Agent, and answers are not sent to Google Analytics, Sentry or application logs. Raw attempt, answer and event rows are deleted after 12 months. The in-test withdrawal control deletes attempt IDs remembered in the current browser session sooner.
Accounts, drafts and saved results
- Magic-link sign-in: we use your email address and expiring authentication tokens to send and complete sign-in. We do not store a password.
- Result draft: if you ask to save a result while signed out, we temporarily store the normalized email, complete answers and result metadata for up to 30 minutes so the same result can be claimed after cross-device sign-in. A successful claim consumes the draft.
- Saved result: when you deliberately save, we store the complete answer snapshot, server-recomputed scores, result and consent-notice versions, creation time and localized report snapshots under your account. These remain until you delete that result or the account.
- Legacy purchase rows: payments are disabled and the current beta collects no new payment data. An account created under an earlier version may still contain amount, currency, status and provider reference identifiers for historical support and audit. We never stored full card numbers.
Sharing, Match and email
- Saved-result sharing: only your explicit share action creates a public URL; saving a result or receiving its confirmation email does not. The public URL contains a random token; the database stores only its SHA-256 hash. A link expires after the configured period (30 days by default). Replacing or revoking it deletes the active row, and scheduled cleanup removes expired rows.
- Match: before swiping, each participant must actively tick a separate explicit-consent box. A Match session stores both participants' yes/maybe/no choices, the consent-notice version, a random session code, and one-way hashes of participant tokens. Raw participant tokens stay in each browser's local storage; a participant's reusable copy of their own choices is limited to that tab's session storage. A session expires after 7 days and scheduled cleanup deletes it and all answers. The in-product delete control removes a participant's answers earlier.
- Transactional email: when you request a sign-in or result confirmation, Resend receives the destination address and message necessary to deliver it. A result confirmation links to your authenticated saved-result page, not a public share. The public beta does not offer arbitrary-address Match email delivery or maintain a lead or marketing database.
Request security and operational data
Cloudflare necessarily processes request information such as IP address, headers, URL, timing and security signals to deliver and protect the site. Upstash stores short-lived rate-limit keys derived from an IP address, account id or keyed email hash. Application logs record structured operational events and deliberately exclude raw answer choices, full email addresses, request bodies and secret tokens. Infrastructure providers may retain limited request metadata under their security and operational settings.
Cookies and browser storage
- An essential cookie remembers that the 18+ age gate was acknowledged.
- Authentication cookies keep a signed-in session working and expire according to the session configuration.
- Session storage holds an in-progress test and fresh result on the device.
- Session storage also holds current consent receipts, random research attempt IDs needed for in-session deletion and, during Match, a reusable copy of that participant's own choices for this tab session.
- Local storage holds a raw Match participant token on that participant's device.
- The public beta does not load Google Analytics, advertising networks or social tracking pixels, and does not set an analytics-consent cookie.
Why we process data
We ask for explicit consent before processing sexual-preference answers for the test or Match. A separate explicit choice covers storing identity-separated answers and interaction events to evaluate and improve questionnaire quality; declining that research choice does not prevent the test from working. Account and email data support authentication and requested messages; limited technical data secures, debugs and operates the service. You may withdraw from the active test and erase research attempts remembered in that browser session, delete your Match participant row, delete saved results, or delete your account using the product controls. Withdrawal does not make earlier lawful processing unlawful.
Service providers and international processing
- Cloudflare — DNS, CDN, Workers hosting, security and request logs.
- Neon — managed PostgreSQL database for application records.
- Upstash — Redis-backed rate limiting and abuse prevention.
- Resend — delivery of requested transactional emails.
These providers act for us to supply their specific function and may process data in countries other than yours. We do not sell personal data, provide it to data brokers, or use it for targeted advertising.
Retention summary
- Unsaved preview answers: no database record; browser-session lifetime on the device.
- Result drafts: up to 30 minutes, or earlier same-email account deletion.
- Optional questionnaire-research attempts, exact options and structured interaction events: 12 months, or earlier in-session withdrawal.
- Match sessions and answers: 7 days.
- Share tokens: configured expiry, 30 days by default, or earlier revocation/replacement.
- Verification tokens and login sessions: until their own expiry or earlier account deletion.
- Saved results and account profile: until individual-result or account deletion.
- Operational and security metadata: only as configured for diagnosis and abuse prevention.
Your choices and rights
The test offers a withdrawal-and-clear control for browser answers and research attempt IDs remembered in the current session; Match participants can delete their own stored answers with their secret browser token. Because questionnaire-research attempts are deliberately not linked to an account or email, they do not appear in an account export and may no longer be identifiable after the browser session ends. Account controls let you export your profile, saved results and legacy purchase records; delete individual results; revoke shares; and delete the account together with pending same-email drafts and unused sign-in tokens. Depending on where you live, you may also have rights to access, correct, erase, restrict or object to processing, receive a portable copy, and complain to a privacy regulator. Contact support@16kinks.com if the in-product controls do not cover your request.
Security, age and changes
We use encrypted transport, access controls, one-way token hashes, server-side validation, rate limits and finite retention. No internet service can guarantee absolute security. The site is for adults aged 18 or the higher age of majority where they live; we do not knowingly collect data from minors.
We may update this policy as the service changes. Materially broader data uses require an updated notice and, where required, a new consent before that use begins.