Privacy
Privacy
Last updated: September 3, 2026
What this policy says, in plain English.
- We don't collect what we don't need.
- Test results are saved to your account so you can compare tests over time, and a copy stays in the browser you tested on. We store the curve, the calibration values, and the timestamps — never your per-trial answers.
- We use PostHog for product analytics (event counts, no email) on both the marketing site and the test app. Analytics is on by default and uses a first-party cookie shared across our domains. We use Microsoft Clarity for anonymized usability research on the marketing site only.
- You can opt out of analytics any time from the footer of this site or of the test app — one choice covers both — and we honor the browser's Do Not Track signal automatically.
- We don't sell your data. Ever. There is no data broker pipeline.
- Taking the test needs an account, which means an email address to sign in with. That address, your results, and (if you buy unlimited) a record that you paid are all we hold about you.
- Sign-in is handled by Clerk and payments by Stripe — we do not store passwords or card numbers ourselves.
The data that does get collected.
Marketing-site analytics events. When you visit the marketing site (this site, contrastscreen.com), PostHog records page views, clicks on “Take the test” buttons, FAQ expansions, and similar navigation signals. The events do not include your name, email, or any input you typed. The footer of every page has the switch: “analytics: on · manage” turns PostHog and Microsoft Clarity off together, immediately.
Marketing-site session recordings. Microsoft Clarity records cursor movement, clicks, and scrolling, with IP addresses masked. Text input on form fields is automatically scrubbed by Clarity. Recordings are used to understand which parts of the page confuse people, not to identify visitors.
Your test results. Every completed test is saved to your account: the mode (quick or full), the threshold and log-CS value at each spatial frequency with the number of trials behind it, the AULCSF summary, the calibration values (pixel pitch, viewing distance, and display gamma, plus how each was measured), and timestamps. Not stored: your individual per-trial answers, the stimulus images, or anything about your device beyond those calibration numbers. Results live in a private store on Vercel (Vercel Blob) under your account id; nothing in it records IP addresses or user agents. A copy of each result also stays in the browser you tested on, so past results open offline. Deleting a result from the test app’s results list removes it from your account and from that browser. Results are otherwise kept until you delete them or the account. The account also keeps a count of tests taken, which is how the free first test works; deleting a result does not change it.
Test-app analytics events. On the test app at test.contrastscreen.com, PostHog receives events such as test started, calibration complete, staircase complete, and test complete, with the resulting numbers (threshold contrast, log-CS, area under the curve). Analytics is on by default; you can turn it off at any time with the “Manage analytics” link in the test app’s footer or the analytics control in this site’s footer (the two share one setting), and if your browser has Do Not Track enabled, analytics stays off automatically. Your per-trial answers never leave your device either way, and analytics is not how a result reaches your account — that is the results sync described above.
Email addresses (only if you give us one). “Email my results” goes to your account’s own address. If you sign up for notes by email (on this site or on the results screen), we store that address to send you what you asked for. If you share a result or your history with a provider, their address is used for that one email and not kept. List addresses are kept in our storage and, when one is connected, in our email provider’s contact list; every list email carries a one-click unsubscribe link, and you can ask us to delete the address entirely. We do not subscribe you to anything else.
Account information. Taking the test needs an account. Clerk stores your email and password (Clerk handles password storage — we never see your password); we file your stored results under the account id Clerk gives us. If you buy unlimited, Stripe stores your payment information directly; we receive only an indicator that the payment succeeded.
Standard server logs. Our hosting provider (Vercel) records request URLs, IP addresses, and user agents in short-term access logs for security, debugging, and uptime. We do not use these logs to identify individual visitors or to build advertising profiles.
The data that doesn’t get collected.
- Your name, mailing address, or phone number.
- Your precise location or any IP-based targeting profile.
- Any medical-record data — we have no integration with electronic health records and no way to ingest them.
- Biometric identifiers (no face scan, no fingerprint).
- Browsing history outside of this site.
- Cross-site advertising identifiers. We do not use third-party advertising cookies on this site.
- Children's data (see Children's Privacy below).
The third parties involved.
We rely on a small set of vendors, all in use today. Each one is listed here with what it receives, so nothing comes as a surprise.
- VercelIn use todayTheir privacy policy →
- Web hosting for the marketing site and the test app, and the private storage (Vercel Blob) that holds your account's test results. Receives standard server access logs (IP, user agent, request URL) for security and uptime.
- PostHogIn use todayTheir privacy policy →
- Product analytics: page views, button clicks, test completions. No personal information attached. Runs by default on both the marketing site and the test app, honors Do Not Track, and can be switched off at any time (the “analytics: on · manage” control in this site’s footer, or the “Manage analytics” link in the test app’s footer — the choice is shared between the two). Uses a first-party cookie shared across our own subdomains so both apps see the same anonymous visitor.
- Microsoft ClarityIn use todayTheir privacy policy →
- Anonymized session recordings and heatmaps for usability research. IP-masked by default. Marketing site only — never loaded during the actual test, because the test must not be jankd by third-party scripts.
- ResendIn use todayTheir privacy policy →
- Transactional email: result emails, provider shares, notes signups, and receipts. Only receives an address when you ask us to send something.
- ClerkIn use todayTheir privacy policy →
- Authentication. Every test needs an account, so Clerk stores your email address and login credentials; we keep only the account id it gives us, which is what your stored results are filed under.
- StripeIn use todayTheir privacy policy →
- Payment processing for unlimited. Receives your card details directly — we never see them. Only used if you make a purchase.
What we put in your browser.
We do not use third-party advertising or cross-site tracking cookies. PostHog drops a single first-party cookie to give each visitor a stable, anonymous ID across page loads — this is what lets a “test started” event and a “test complete” event come from the same browser show up as a single funnel entry rather than two unrelated visits. The cookie is scoped to our own domain and shared between the marketing site and the test app (both live under contrastscreen.com), so both apps see the same anonymous visitor. It carries no personal information. If you use the footer control to turn analytics off (or back on), a second small first-party cookie, vcs_analytics_consent, records that choice on the same domain so this site and the test app both respect it; it holds only the word “no” or “yes”.
We also store small bits of state in your browser’s localStorage (which is local to your device — we never read it from a server). The kinds of things stored:
- Your analytics opt-out choice, if you've made one, so it sticks across visits (the same choice is kept in the vcs_analytics_consent cookie so this site and the test app agree).
- First-touch and last-touch UTM parameters (where you came from), so we can tell if a particular blog post or ad is helping people find us.
- A copy of your test results — calibration values, thresholds, and result curves — so past results open offline and the test app's history list works without a round trip to your account.
- Your sign-in pass for the test app, so it knows which account to save results to.
- Whether you've dismissed the privacy assurance banner.
- If you choose to share a result, the share link metadata so you can find it again.
You can clear all of this by clearing your browser’s site data for our domains.
What you can do.
Opt out of analytics. Use the “analytics: on · manage” control in the footer of this site, or the “Manage analytics” link in the test app’s footer — either one switches PostHog and Microsoft Clarity off on both apps and stops further capture immediately. On both apps we also honor your browser’s Do Not Track header without you having to do anything.
Delete a result. Every result has a Delete button in the test app’s results list. That removes it from your account and from that browser. Clearing your browser’s site data for our domains removes the local copies, the analytics cookie, and the rest of the values described above — but not the results saved to your account.
Delete your account. Email us from the address on the account. We will remove the account and every result stored against it within 30 days, except where retention is required for a Stripe-related financial record.
For EEA / UK visitors (GDPR-style rights). You have rights of access, rectification, erasure, restriction, portability, and objection regarding your personal data, where applicable. Our lawful basis for processing analytics is legitimate interest in understanding aggregate product usage (analytics runs by default, with an opt-out on both apps and automatic respect for Do Not Track); for account data, it is the contract you enter when you create an account. You can object to the analytics processing at any time by using the opt-out. Email the contact below to exercise any of these rights.
For California visitors (CCPA / CPRA-style rights). You have the right to know what personal information we collect, to request its deletion, and to opt out of any “sale” or “sharing.” We do not sell or share personal information for cross-context behavioral advertising. You can still ask us, in writing, to confirm and delete any data tied to your account.
We’re a screening tool, not a clinic.
Contrast Screen is a self-tracking and screening tool, not a medical device. It does not diagnose, treat, or cure any condition. Anything you do here is informational. Talk to a clinician about what your results might mean.
We are not a HIPAA-covered entity. Your test results are not a medical record; they are stored against your account, and you can delete any of them at any time. If you share a result or your history with a clinician — by email, a PDF, or a read-only link — that copy is governed by whatever privacy practices your clinician uses, not ours.
Not for kids under 13.
Contrast Screen is not intended for users under 13. The contrast sensitivity task assumes an adult reading distance, adult attention span, and adult comprehension of the instructions. We do not knowingly collect any information from children. If you believe a child has provided personal information, contact us and we will delete it.
When this updates.
We’ll note material updates on this page with the date in the “Last updated” line at the top. For substantive changes that affect what we collect or who receives it, we’ll also call them out in our newsletter (if you’re subscribed) and in a banner on the site for at least 30 days.
How to reach us.
Questions about this policy, or a request to exercise the rights described above, can go to privacy@contrastscreen.com.