Privacy Policy

How assessment browser storage, Umami analytics, Google AdSense, community posts, email, retention, and user controls work.

Last Updated: September 6, 2026

1

1. Scope and Current Review Status

This policy describes the data paths visible in the current Narcissist Test website code: the NPI-16 assessment, browser storage, site analytics, Google advertising, the read-only community archive, and email contact.

This is an operational disclosure, not a claim of certification or universal legal compliance. Independent legal review and verification of production account settings remain pending.

Last updated: September 6, 2026

2

2. Assessment Data Stored in Your Browser

The NPI-16 feature stores assessment data in your browser's localStorage so that progress can resume and the latest result can be shown.

Progress record: item choices already made, current item number, instrument and scoring versions, and start/update timestamps. Invalid or expired progress is removed; valid unfinished progress expires after 24 hours.

Result record: all 16 selected options, raw score, score range, answered-item count, instrument and scoring versions, and completion time. It remains until you delete it, retake the assessment, or clear this site's browser data.

Migration notice: a small local value records whether a one-time notice about removal of incompatible old assessment data has been shown.

The current assessment code does not submit answers or scores to the community API or include them in its own analytics events. Result share cards are generated inside the browser and never include item-level answers; the raw score is included only after the user selects that option. Browser extensions, device backups, shared browser profiles, hosting infrastructure, the operating-system share target, or third-party scripts have separate capabilities outside that narrow statement.

Last updated: September 6, 2026

3

3. Umami Analytics

On the production domains, the site loads an Umami analytics script from umami.tsrenjian.com with website identifier 5dd8f836-51a6-4480-9975-08062cdb5fbe on every page. The site does not provide its own opt-out for this page analytics and does not disable it in response to Do Not Track or Global Privacy Control signals. Browser extensions, content blockers, network controls, or script failures can still prevent a request from reaching Umami.

The script is restricted to the two production domains and excludes URL search parameters and fragments. The site's before-send filter blocks payloads containing question identifiers, answers, selected options, scores, result bands, assessment localStorage keys, free text, or email addresses.

The application sends a fixed set of name-only interaction events for the assessment funnel: first answer, completion, changing reflection prompts, opening the answer review, choosing a next-step path, opening a social sharing page, and successful system-share, download, or copy actions. These events do not identify the selected social platform and do not include the selected question, answer, raw score, whether the score was included on a share card, which next-step path was chosen, or any free text. An event can indicate that a person used a feature on the NPI-16 page even though it does not contain their response data.

Depending on the deployed Umami configuration and network infrastructure, requests may include the normalized page path, referrer origin/path, browser/device information, and network information such as an IP address. The repository does not prove the production server's retention period, IP handling, log retention, backup policy, or whether always-on analytics is appropriate in every jurisdiction. Those operator settings and the applicable legal basis require separate verification.

Last updated: September 6, 2026

4

4. Google AdSense and Advertising Data

The site loads Google AdSense using publisher identifier ca-pub-1778677071690115. Google and other advertising vendors may receive the page URL, IP address, browser or device information, advertising identifiers, and interaction data. They may place or read cookies or use other local storage where permitted.

Third-party vendors, including Google, use cookies to serve ads based on visits to this and other websites. Google's advertising cookies allow Google and its partners to serve personalized ads when permitted. If personalization is unavailable or declined, ads may still be contextual or limited, and information may still be processed for delivery, measurement, fraud prevention, and security.

You can review Google's explanation at How Google uses information from sites or apps that use its services and control personalization through Google Ads Settings.

Before the Google loader is installed, the site initializes Consent Mode with ad_storage, ad_user_data, ad_personalization, and analytics_storage denied. The loader is added only on the two production hostnames and only once per document.

For users in the EEA, United Kingdom, and Switzerland, personalized ads require a Google-certified CMP integrated with the IAB Transparency and Consent Framework. This site does not present Umami analytics as an advertising CMP. The Google Privacy & messaging configuration, site targeting, consent-mode integration, vendor list, and live message behavior are account-level settings that the owner must verify.

Last updated: September 6, 2026

5

5. Read-Only Community Archive

The community is currently a read-only archive. New submissions and anonymous likes are disabled. Previously approved posts may remain public with their title, content, display name, timestamps, and generated slug; pending and rejected records are not returned by public endpoints.

The posting endpoint no longer reads forwarding headers, creates posts, or stores an IP-derived value. A database migration removes the legacy reversible IP field; that migration must be backed up and applied during the controlled production release. The application no longer reads or writes the former likedPosts browser key.

Archived posts are personal accounts, not confidential communications or clinical advice. Email [email protected] with the post URL to request review or removal.

Last updated: September 6, 2026

6

6. Contact, Hosting, and Security Logs

If you email [email protected], the email provider may process your address, message, attachments, and delivery metadata. Use email for corrections, privacy questions, or technical support—not for emergency or clinical care.

Hosting, database, email, security, and content-delivery providers may process ordinary request information needed to operate and protect the service, including IP address, timestamps, requested URLs, headers, and error logs. Exact production providers, regions, and retention periods require an operator inventory and are not inferred from the source code.

Last updated: September 6, 2026

7

7. Sharing and Retention

Information may be processed by service providers used for hosting, databases, email, analytics, advertising, security, and legal compliance. We do not claim that no third party receives data: Umami, Google AdSense, infrastructure providers, and any service used to send email have separate data paths.

Browser assessment progress is limited to 24 hours by the application. The latest result remains in localStorage until removed by you or replaced by the application. Archived community post retention currently follows the database record. Third-party and infrastructure retention is governed by their settings and policies and must be verified separately.

Last updated: September 6, 2026

8

8. Your Choices and Controls

You can:

  • use Delete saved result on the result page;
  • retake the assessment, which replaces the current result;
  • clear this site's localStorage, cookies, and other site data in your browser;
  • use browser, device, extension, or network controls to restrict third-party scripts and cookies;
  • use Google Ads Settings to control Google ad personalization;
  • change or withdraw advertising choices through Google's certified privacy message when it is presented;
  • email [email protected] about a community post or privacy question.
  • Blocking storage or scripts may prevent progress recovery, analytics, ads, or parts of the community archive from working.

    Last updated: September 6, 2026

    9

    9. Children, Policy Changes, and Contact

    This service is a general-audience educational site and is not designed to provide care to children. Do not send a child's sensitive information by email.

    Material policy changes will update the date shown on this page. This revision records always-on production-domain Umami page analytics with sensitive-payload filtering and name-only assessment interaction events, default-denied Google Consent Mode, the separate certified-CMP requirement, browser-local result sharing, the read-only community archive, assessment localStorage, and pending legal/account verification.

    Questions or removal requests: [email protected]. We do not publish a guaranteed response time.

    Last updated: September 6, 2026

    Questions or corrections?

    Contact the site about this privacy policy, an accessibility issue, or a factual correction. Email is not a clinical or emergency service.

    Document status

    This document describes the current service but does not constitute legal advice. Independent legal review remains pending, and the NPI-16 result does not replace professional mental health care.