Skip to content
VCS-Test

Privacy

Privacy

Last updated: May 28, 2026

The short version

What this policy says, in plain English.

  • We don't collect what we don't need.
  • Test results stay on your device by default. Nothing is sent to a server when you take the test.
  • We use PostHog for product analytics (event counts, no email) on the marketing site and — only after you opt in — on the test app. We use Microsoft Clarity for anonymized usability research on the marketing site only.
  • You can opt out of analytics any time, and we honor the browser's Do Not Track signal automatically.
  • We don't sell your data. Ever. There is no data broker pipeline.
  • Taking the test requires no personal information. Your result is computed in your browser.
  • If we ever charge for a paid tier, account info will be handled by Clerk and payments by Stripe — we will not store passwords or card numbers ourselves.
What we collect

The data that does get collected.

Marketing-site analytics events. When you visit the marketing site (this site, contrastscreen.com), PostHog records page views, clicks on "Take the test" buttons, FAQ expansions, and similar navigation signals. The events do not include your name, email, or any input you typed.

Marketing-site session recordings. Microsoft Clarity records cursor movement, clicks, and scrolling, with IP addresses masked. Text input on form fields is automatically scrubbed by Clarity. Recordings are used to understand which parts of the page confuse people, not to identify visitors.

Test-app analytics events (only after consent). On the test app at test.contrastscreen.com (currently also reachable at vcs-test-eight.vercel.app), we show a consent banner the first time you load the page. If you click "Yes," PostHog receives events such as test started, calibration complete, staircase complete, and test complete, with the resulting numbers (threshold contrast, log-CS, area under the curve). If you click "No," nothing is sent. If your browser has Do Not Track enabled, the banner does not appear and analytics stays off by default.

Email addresses (only if you give us one). If you sign up for newsletter updates or request a result by email (a feature that is not yet live), we store your email address to send you what you asked for. We do not subscribe you to anything else.

Account information (only if you create an account). If we launch a paid tier and you decide to use it, Clerk stores your email and password (Clerk handles password storage — we never see your password). Stripe stores your payment information directly; we receive only an indicator that the payment succeeded.

Standard server logs. Our hosting provider (Vercel) records request URLs, IP addresses, and user agents in short-term access logs for security, debugging, and uptime. We do not use these logs to identify individual visitors or to build advertising profiles.

What we don’t collect

The data that doesn’t get collected.

  • Your name, mailing address, or phone number.
  • Your precise location or any IP-based targeting profile.
  • Any medical-record data — we have no integration with electronic health records and no way to ingest them.
  • Biometric identifiers (no face scan, no fingerprint).
  • Browsing history outside of this site.
  • Cross-site advertising identifiers. We do not use third-party advertising cookies on this site.
  • Children's data (see Children's Privacy below).
Where your data goes

The third parties involved.

We rely on a small set of vendors. Some are live today; others are wired into the code but inert until we finish setting them up. We list both so nothing comes as a surprise.

VercelIn use todayTheir privacy policy →
Web hosting for the marketing site and the test app. Receives standard server access logs (IP, user agent, request URL) for security and uptime.
PostHogIn use todayTheir privacy policy →
Product analytics: page views, button clicks, test completions. No personal information attached. On the marketing site, runs by default and honors Do Not Track. On the test app, runs only after you click "Yes" on the consent banner.
Microsoft ClarityIn use todayTheir privacy policy →
Anonymized session recordings and heatmaps for usability research. IP-masked by default. Marketing site only — never loaded during the actual test, because the test must not be jankd by third-party scripts.
ResendFuture use onlyTheir privacy policy →
Transactional email (newsletter signups, future result-sharing emails). Only used if you provide an email address.
ClerkFuture use onlyTheir privacy policy →
Authentication for the future paid tier. Stores your email address and login credentials. Only used if you create an account.
StripeFuture use onlyTheir privacy policy →
Payment processing for the future paid tier. Receives your card details directly — we never see them. Only used if you make a purchase.
Cookies & local storage

What we put in your browser.

We do not use third-party advertising or cross-site tracking cookies. PostHog drops a single first-party cookie to give each visitor a stable, anonymous ID across page loads — this is what lets a "test started" event and a "test complete" event come from the same browser show up as a single funnel entry rather than two unrelated visits. The cookie carries no personal information.

We also store small bits of state in your browser’s localStorage (which is local to your device — we never read it from a server). The kinds of things stored:

  • Your analytics consent decision, so we don't re-prompt you on every visit.
  • First-touch and last-touch UTM parameters (where you came from), so we can tell if a particular blog post or ad is helping people find us.
  • Your test history — calibration values, completed thresholds, and result curves — so the results page can show you your previous runs.
  • Whether you've dismissed the privacy assurance banner.
  • If you choose to share a result, the share link metadata so you can find it again.

You can clear all of this by clearing your browser’s site data for our domains.

Your rights

What you can do.

Opt out of analytics. On the marketing site, you can opt out from the privacy modal in the footer; on the test app, use the "Manage analytics" link in the footer. Either action stops further capture immediately. We also honor your browser’s Do Not Track header without you having to do anything.

Delete locally stored data. Clear your browser site data for the marketing-site domain and for the test-app domain. That removes every value we described in the section above. There is no server-side copy to chase.

Request deletion of account data (when accounts exist). Once the paid tier launches and you have an account, you can request deletion through the account-settings page or by emailing us. We will remove the account and its associated history within 30 days, except where retention is required for a Stripe-related financial record.

For EEA / UK visitors (GDPR-style rights). You have rights of access, rectification, erasure, restriction, portability, and objection regarding your personal data, where applicable. Our lawful basis for processing analytics is your consent (opt-in on the test app; opt-out plus DNT honored on the marketing site); for account data, it is the contract you enter when you create an account. You can withdraw consent at any time. Email the contact below to exercise any of these rights.

For California visitors (CCPA / CPRA-style rights). You have the right to know what personal information we collect, to request its deletion, and to opt out of any "sale" or "sharing." We do not sell or share personal information for cross-context behavioral advertising. You can still ask us, in writing, to confirm and delete any data tied to your account.

Not a medical record

We’re a screening tool, not a clinic.

VCS-Test is a self-tracking and screening tool, not a medical device. It does not diagnose, treat, or cure any condition. Anything you do here is informational. Talk to a clinician about what your results might mean.

We are not a HIPAA-covered entity. Your test results are not part of a medical record we maintain; they live in your browser, under your control. If you choose to share a result with a clinician (for example, by emailing a PDF in a future version), that copy is governed by whatever privacy practices your clinician uses — not ours.

Children’s privacy

Not for kids under 13.

VCS-Test is not intended for users under 13. The contrast sensitivity task assumes an adult reading distance, adult attention span, and adult comprehension of the instructions. We do not knowingly collect any information from children. If you believe a child has provided personal information, contact us and we will delete it.

Changes to this policy

When this updates.

We’ll note material updates on this page with the date in the “Last updated” line at the top. For substantive changes that affect what we collect or who receives it, we’ll also call them out in our newsletter (if you’re subscribed) and in a banner on the site for at least 30 days.

Contact

How to reach us.

Questions about this policy, or a request to exercise the rights described above, can go to privacy@contrastscreen.com.