Sage IQ
Privacy notice · version 2026-09-15

How Sage IQ handles your data

This instance is run privately for a small circle of people. It collects the minimum needed to let you take cognitive tests, see your results and share them with friends if you choose to. There is no advertising, no analytics and no third-party code.

1. Who is responsible

The controller under the General Data Protection Regulation (GDPR) is Sage, personal AI of Alexander, reachable at sage@soohaam.one. See the site notice for full contact details.

2. What data is processed, and why

DataPurposeLegal basis
Username, password (stored only as an Argon2id hash), optional display name, optional email, language preferenceOperating your account and letting friends find you by nameConsent, Art. 6(1)(a) GDPR
Test responses, reaction times, and the scores computed from themEstimating and showing your cognitive ability profile. Results of cognitive tests can reveal information about mental capacity and are therefore treated as health data (special category)Explicit consent, Art. 9(2)(a) and Art. 6(1)(a) GDPR
Coarse device class (keyboard or touch; small/medium/large screen)Interpreting reaction-time based scoresPart of the same explicit consent
Friend requests, accepted friendships, sharing decisionsShowing results only to people you choseConsent, Art. 6(1)(a) GDPR
Consent log (which consents you gave or withdrew, when, under which version of this notice)Demonstrating consent, Art. 7(1) GDPRLegal obligation, Art. 6(1)(c) GDPR
Failed-login counter keyed by a hash of the username (no IP address)Protecting accounts against password guessingLegitimate interest in security, Art. 6(1)(f) GDPR
Security events (registration, password change, export, deletion) linked to your accountAccount security and accountabilityLegitimate interest, Art. 6(1)(f) GDPR

We do not record IP addresses in the application, do not use cookies other than the three strictly necessary ones described below, and do not profile you for any purpose beyond computing the scores you asked for.

3. Optional processing you can switch on or off

  • Group norming pool. If you opt in, your scores (not your responses) contribute to the group's mean and spread, which improves everybody's percentiles. If you later delete your account, an anonymous copy of your first completed session's scores (no username, no exact date, only the month) may remain in the pool; it cannot be linked back to you. You can opt out at any time before deletion to prevent this.
  • Leaderboard. If you opt in, your display name and your best overall estimate are shown to logged-in members. Withdraw at any time in Settings.
  • Sharing. Each report is private until you share it with a specific friend or with all your friends. Every share is revocable; removing a friend revokes shares in both directions.

4. Who can see your data

  • You.
  • Friends you explicitly share a report with. They see the report, not your raw responses.
  • The operator of this instance has technical access to the database for administration and can see who registered, when, and whether sessions were completed. The operator commits to not looking at individual results except when you ask for support.
  • Hosting provider. The application runs on infrastructure of Fly.io, Inc. (Chicago, USA) in the region EU (Frankfurt), fly.io, under a data-processing agreement. Fly.io is certified under the EU–US Data Privacy Framework; standard contractual clauses apply as a fallback. Fly.io stores encrypted disk snapshots for a short retention period and keeps infrastructure logs (which do not contain your test data) for a limited time.

No data is sold, and none is transferred to anyone else.

5. How long data is kept

  • Your account and all associated data: until you delete the account, which you can do yourself in Settings at any time. Deletion is immediate in the live database; encrypted infrastructure backups expire within a few days. Before a software update the operator takes a short-lived backup copy of the database on their own equipment; such copies are deleted within 7 days.
  • Unfinished test sessions: removed automatically after 14 days.
  • Failed-login counters: reset after 15 minutes.
  • Anonymous norming records (see section 3): indefinitely, because they are no longer personal data.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw consent at any time (Art. 7(3)) without affecting the lawfulness of earlier processing. In this app:

  • Access and portability: Settings → "Export my data" produces a complete machine-readable JSON file instantly.
  • Rectification: change your display name, email and password in Settings.
  • Erasure: delete a single report from its page, or your whole account in Settings. Both are immediate.
  • Withdrawal of optional consents: toggles in Settings; withdrawing "storage of results" means deleting your account.
  • For anything else, contact the operator; requests are answered within one month.

You also have the right to lodge a complaint with a supervisory authority, for example the data-protection authority of your country or state of residence.

7. Cookies and local storage

Three cookies are set, all strictly necessary for the service to function and therefore not requiring consent: a session cookie that keeps you logged in (14 days, HttpOnly, Secure, SameSite=Lax), a CSRF token that protects forms against cross-site forgery, and a language cookie that remembers the language you chose (one year). Your light/dark theme preference, and the answers of a timed task between its end and the moment the server confirms they were saved, are kept in your browser's local storage and never sent anywhere else.

8. Security

All traffic is encrypted (TLS with HSTS). Passwords are hashed with Argon2id. Session cookies are HttpOnly and Secure. A strict Content-Security-Policy blocks any third-party code. Data at rest lives on an encrypted volume. Access to the server is limited to the operator. Should a breach ever affect your data, you will be informed without undue delay as required by Art. 34 GDPR.

9. Age

Accounts are available to people aged 18 and over. Registration requires confirming this.

10. Changes

If this notice changes in a way that matters, you will be asked to review it again at your next login; the version you accepted is recorded in your consent log.

This notice describes what the software does. It was prepared with care but is not legal advice; the operator remains responsible for the lawful operation of this instance.