Legal
Privacy Policy
Last updated: June 19, 2026
Blueprint is not clinical. It is a self-insight tool inspired by public-record psychology research. Nothing on this site is medical advice, psychological diagnosis, or therapy. If you are in crisis, please contact a licensed professional or local emergency services.
Blueprint (“Blueprint”, “we”, “us”) is operated by tallminded llc. This Privacy Policy explains what personal information we collect when you use Blueprint, why we collect it, who we share it with, and the choices you have. Questions? Email info@tallminded.com.
Who is the data controller
tallminded llc is the data controller responsible for personal data processed through Blueprint, except where Paddle.com Inc. acts as Merchant of Record for payments (see “Payments” below).
Information we collect
Account information
- Email address and display name when you sign up.
- Sign-in identifiers (e.g. Google account ID if you use Google sign-in).
Assessment information
- Your answers to the Blueprint questionnaire and any free-text stories you write.
- Scores and personality profile derived from your answers.
- A short, randomly generated share code for each completed assessment.
- Optional information you choose to enter when taking the assessment: taker name, taker email, country, postal code, and birthday.
Technical information
- Request metadata processed by our hosting provider (IP address, browser user-agent, timestamps). This is used to operate the service and prevent abuse; we do not build advertising profiles from it.
Payment information
When you purchase a paid report, payment is processed by Paddle (Paddle.com Market Limited / Paddle.com Inc.), our Merchant of Record. Paddle collects your billing details, payment method, and tax-relevant location data directly. We receive only a confirmation that the purchase succeeded, the product purchased, the amount, the Paddle transaction ID, and (where you provided it) your email.
Why we use this information
- To create and operate your account.
- To compute and display your assessment results and reports.
- To let you share results via your share code.
- To process purchases and grant access to paid reports.
- To respond to support requests sent to info@tallminded.com.
- To keep the service secure and prevent abuse.
- To meet legal, accounting, and tax obligations.
Legal basis
Where required by law (e.g. EEA/UK), we rely on: contract for operating your account and delivering paid reports; legitimate interestsfor security and service improvement; consent for any optional information you provide; and legal obligation for tax and accounting records.
Who we share information with
- Lovable Cloud (Supabase / Cloudflare): hosting, database, authentication, and serverless compute. Acts as our processor.
- Paddle: Merchant of Record for payments, subscription management, tax compliance, and invoicing. Paddle acts as an independent controller for payment data.
- Lovable AI Gateway: used to generate narrative portions of paid reports. Your scores and the relevant assessment context are sent to the gateway to produce the report; the gateway does not train on your inputs.
- Professional advisers: legal, accounting, or tax advisers when needed.
- Authorities: when required by law, court order, or to protect rights and safety.
We do not sell your personal information.
Data retention
- Assessment results stay in your account until you ask us to delete them or close your account.
- Purchase records are retained for as long as required for tax and accounting purposes (typically 7 years), regardless of account deletion.
- Backups are rotated on a rolling basis and may retain data for up to 30 days after deletion.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, export, or object to our processing of your personal information, and to withdraw consent. To exercise any of these rights, email info@tallminded.com. We aim to respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Security
We use industry-standard technical and organisational measures, including TLS in transit, encrypted storage at rest provided by our hosting platform, role-based access controls, and row-level security on user data. No system is perfectly secure; please use a strong, unique password.
International transfers
Our hosting providers operate globally, which means your data may be processed in countries outside your own (including the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses with our processors.
Cookies
Blueprint uses only essential cookies and local storage required to keep you signed in and remember preferences. We do not currently use advertising or third-party analytics cookies.
Children
Blueprint is not directed at children under 16. Please do not use Blueprint or submit information if you are under 16.
Changes to this policy
We may update this policy from time to time. Material changes will be announced in-app or by email to the address associated with your account.
Contact
tallminded llc — info@tallminded.com
