Skip to content
ECRtest

Privacy policy

An attachment style test touches on personal things: your relationships, your family, the people you’re close to. So we collect only what the site needs to work, and we explain every record we keep. You can take the test without signing up.

Updated October 5, 2026 · version 0.5

On this page
  1. 01Who’s responsible for your data
  2. 02What data we collect
  3. 03Why we use your data, and on what basis
  4. 04Cookies and browser storage
  5. 05Who we share data with
  6. 06How the AI report works
  7. 07How long we keep data
  8. 08Your rights
  9. 09How we protect your data
  10. 10Age
  11. 11Changes to this policy
  12. On this page

Who’s responsible for your data

The owner of ecrtest.com (ECRtest) is responsible for processing your data. In this policy, “we” and “us” mean the owner. The operator’s details are in the card at the bottom of this page.

If you have questions about your data, email support@ecrtest.com.

What data we collect

It depends on which parts of the site you use.

  • Taking the test. While you’re answering, your answers stay in your browser. When you click “Show my result,” the server receives all 72 answers (including the ones about your mother, father, and friend), plus the page language and how long you took. If you answered the questions about yourself, your age and relationship status are sent too. The test never asks for your name or email.
  • Your result. The server calculates your scores and saves a record: your answers, scores, style, answer-quality flags, your age and relationship status if you gave them, the language, and the date. There’s no name or email in it.
  • Your account, if you create one: your email, a password hash (we never store the password itself), language, sign-up date, and the results you’ve saved to it.
  • Technical data: your IP address and browser details, used to protect the site from bots and overload, plus server error logs.
  • Support emails: the address you write from and the conversation itself.

Your result link (the address with ?res=) contains all your answers in encoded form, plus a server signature. Anyone with the link can see your result. Treat it like a personal document and share it only with people you trust.

Why we use your data, and on what basis

  • Showing your result and saving it at a link: this is exactly what you ask for when you click “Show my result.”
  • Running your account: our contract with you under the terms of use.
  • Protecting the site from bots and abuse: our legitimate interest.
  • Compiling anonymized statistics (how many people take the test, how the styles are distributed) and, later on, our own norms for each language: our legitimate interest. These statistics contain no emails and no accounts.
  • Web analytics: to the extent described below, and for visitors from the EU only with their consent.

For visitors from Russia, we process data under Federal Law No. 152-FZ “On Personal Data.” By submitting your answers or creating an account, you consent to processing for the purposes listed above. For visitors from the EU, the legal bases are those in Article 6 of the GDPR: performance of a contract, legitimate interest, legal obligation, and consent.

Cookies and browser storage

The site sets only a few cookies of its own, and each one is needed for the site to work:

  • NEXT_LOCALE: remembers your language. Kept for up to 1 year.
  • next-auth.session-token (__Secure-next-auth.session-token over a secure connection): keeps you signed in for 30 days. Set only after you sign in.
  • next-auth.csrf-token and next-auth.callback-url: protect the sign-in form and remember where to send you after you sign in. Deleted when you close your browser.
  • ecr_bg: a technical bot-protection marker, deleted when you close your browser. Set only when enhanced bot protection is turned on.

Besides cookies, the site keeps a few entries in your browser itself (localStorage and sessionStorage). They’re never sent to the server on their own:

  • ecr:scheme: the theme you picked, day or night.
  • ecr:test-progress:ecr-r: a test you haven’t finished, so you can pick up where you left off. Kept for 7 days.
  • ecr:my-results and ecr:my-purchases: links to your results and purchased reports on this device, so a new attempt doesn’t wipe out earlier ones and a report opens without the email.
  • ecr:auth-email: the email you typed on the sign-in page, carried over if you switch to creating an account. Erased right after it’s used.

Visitor analytics (Yandex Metrica and Google Analytics) run only when they are turned on in the site settings. They set their own cookies (_ym_* for Metrica, _ga* for Google Analytics) to count visits. For visitors from the EU, the EEA, the UK, and Switzerland, they start only after you agree in the banner; for everyone else, they start right away. The site decides who sees the banner from your browser’s time zone, and everyone sees it on the versions of the site in EU languages (currently Italian and Portuguese). Your choice is stored in your browser (ecr:consent in localStorage), and you can change it with the “Analytics settings” link at the bottom of any page.

Metrica’s session recording (Webvisor) records what happens on the page: scrolling, clicks, and cursor movement. Result blocks, the full report, and anything you type into the email field are hidden from the recording. Page addresses are sent to the analytics tools without parameters, so the link to your result (?res=) and report access codes never reach them. Analytics events contain none of your answers, scores, or email.

You can delete these entries in your browser settings. If you do, your unfinished test and the list of results on that device will be gone, but the results themselves stay available at their links.

Who we share data with

We don’t sell data or hand it to advertisers. It goes only to services the site can’t run without:

  • the hosting provider and database the site runs on;
  • the email service that sends report access links and password reset emails;
  • language model providers, for the full report (details in the next section).

Some of these services operate outside Russia and the EU. Gumroad and the language model providers, for example, are based in the US. We send them only what a specific task requires.

We disclose data to government authorities only where the law explicitly requires it.

How the AI report works

The full report is written by a language model, working from a snapshot of your profile. The snapshot includes your scores and percentiles on both axes, your style and whether you’re in the borderline zone, your scores for each relationship (mother, father, partner, friend), the few statements you agreed with most strongly, answer-quality flags, the language, and your age and relationship status if you gave them.

Your email, name, account details, payment details, and result link are never sent to the model. Requests go to OpenAI, Anthropic, or Google, or through OpenRouter, depending on the site settings, and their servers may be outside your country. We use plans under which, according to the providers’ terms, request data isn’t used to train models.

The free result doesn’t use AI. Its texts were written by people in advance and are put together to match your profile.

How long we keep data

  • Unfinished test: in your browser, for up to 7 days.
  • Result: until you delete it. You can delete it on the result page using the management code, or along with your account. Once it’s deleted, the link stops working.
  • Account: until you delete it.
  • Security and server error logs: up to 90 days.
  • Support emails: up to 1 year after the last reply.

Your rights

You can ask what data we hold about you, get a copy of it, correct or delete it, withdraw your consent to analytics, and object to processing based on our legitimate interest.

  • Delete a result: use the “Delete the result” button on the result page (you’ll need the management code), or delete it from your account.
  • Delete your account: right from your account, instantly, with no need to email support. Your results and the reports bought for them are deleted along with it, and the links in your emails stop working. This can’t be undone.
  • Withdraw consent to analytics: use the “Analytics settings” link at the bottom of the page, or clear the site’s data in your browser settings.
  • Anything else: email support@ecrtest.com. Include your result link or account email, or we won’t be able to find the record: we don’t have your name or any other identifying details.

We reply within 10 business days. If you believe we’re violating your rights, you can file a complaint with Roskomnadzor (the Russian data protection authority) if you’re in Russia, or with the data protection authority in your EU country.

How we protect your data

The site runs over HTTPS only. Passwords are stored as hashes, and access keys for outside services are encrypted. The server signs every result link, so no one can forge a result by editing the address. Only a small number of people can access the admin panel, and everything they do there is logged.

No one can promise perfect security. If a breach affects your data, we’ll say so on the site and email you if we have your address.

Age

The test is meant for people 16 and older. If you’re under 16, please don’t take the test or create an account without a parent’s consent. If we learn we’ve received data from someone under 16 without that consent, we’ll delete it.

Changes to this policy

The date and version of this policy are shown at the top of the page. We’ll announce significant changes on the site in advance and email everyone who has an account.

Seller details

Seller and data controller
ALEKSANDR SOSNIN
Legal status
Individual entrepreneur
Support email
support@ecrtest.com