INITIALIZING BUNKROS IDENTITY LAB
LOC UNDERGROUND
SYS --:--:--
Legal & Trust

Privacy Policy

How we handle — and, just as importantly, how we refuse to handle — your data. Privacy here is not an afterthought bolted on at the end. It is part of the architecture: the Lab is built to know enough to be useful to you, and deliberately not built to know everything about you.

Last Updated: June 18, 2026
GDPR Compliant
01

Introduction & Our Commitment

Welcome to the Bunkros Identity Lab ("Bunkros," "we," "us," "our"). Our mission is to provide a secure and affirming space for self-discovery, and that mission only works if you can trust what happens to the things you share here. This policy explains, in plain language, what information we collect, why we collect it, how long we keep it, how we protect it, and the rights you have over it.

This Privacy Policy is written in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and relevant Dutch data protection law. It applies to everything you do in the Lab, and it sits alongside our User Agreement and Manifesto as part of how we operate.

In short

We collect as little as we can, we use it to make the Lab genuinely yours, we keep it only as long as we need it, and we never sell it. The rest of this page is the detail behind that promise.

02

Data Controller Information

The entity responsible for deciding how and why your personal data is processed (the "Data Controller") is Bunkros. If you ever want to reach a human about your data, these are the right addresses:

We read what comes in to these inboxes, and we treat privacy requests as a priority rather than a formality.

03

What Personal Data We Collect

We have designed the platform to collect the minimum amount of data necessary to provide our services. We don't gather data "just in case." Here is what we process, why, and the legal basis for each category:

Data categoryTypes of dataPurposeLegal basis
Account information Email address, encrypted password, account creation date Create and manage your secure account, authenticate logins Art. 6(1)(b) — Contract
Test & interaction data Questionnaire answers, AI interactions, identity-related inputs Generate personalized insights and connect them to the content library Art. 9(2)(a) — Explicit consent (special category)
User-generated content Journal entries, reflections, essays, profile info Document your journey and build your personal narrative Art. 6(1)(a) — Consent
Communication data Your email address and the content of emails / support messages you send us Respond to you, provide support, and keep a record of our correspondence Art. 6(1)(f) — Legitimate interest
Technical data (anonymized) Aggregated visitor counts and traffic patterns — no IP addresses or device IDs stored Monitor server health and prevent abuse Art. 6(1)(f) — Legitimate interest
Special category data

Information about sexual orientation, sexual life, and health is treated with the highest level of protection under the GDPR. We will not process this kind of data without your explicit, freely-given consent, and you can withdraw that consent at any time without losing access to the parts of the Lab that don't depend on it.

04

Automated Decision-Making and Profiling

The Bunkros AI uses your inputs to perform a limited form of profiling. It is important to be precise about what that does and does not mean.

What it does

  • Analyzes patterns in what you choose to share to draw connections;
  • Suggests relevant content — glossary entries, archetypes, articles, reflective prompts;
  • Helps you build and revisit a personal identity map over time.

What it does not do

  • Make automated decisions that produce legal or similarly significant effects on you;
  • Provide medical diagnoses or clinical assessments;
  • Render fixed or final judgments about who you are.
The point

The AI's outputs are reflective prompts to aid your own exploration, not authoritative conclusions. You always remain the author of your own identity; the tool just holds up the mirror.

05

Personalize, Not Hyper-Personalize

This is the principle that shapes every other choice in this policy. Our goal is to personalize your experience so the Lab is relevant, useful, and yours. Our equally firm goal is to never cross into hyper-personalization — the kind of surveillance-grade profiling that turns a person into a target.

What personalization means here

  • We use what you choose to share to surface fitting content, remember where you left off, and adapt the experience to your stated interests;
  • We aim to reflect you back to yourself more clearly — a mirror that helps you focus, not a feed engineered to hold your attention;
  • Personalization is built on data you knowingly give us, and you can see, change, export, or delete the data behind it at any time.

The line we will not cross

  • We do not build a permanent, ever-growing psychological dossier on you;
  • We do not track you across other websites or buy third-party data to "enrich" your profile;
  • We do not sell, rent, or share your profile with advertisers or data brokers;
  • We do not use manipulative micro-targeting or persuasion techniques to change your behavior, upsell you, or maximize "engagement";
  • We do not infer sensitive traits you didn't choose to share in order to target you.
Why the distinction matters

Hyper-personalization optimizes for the platform; honest personalization optimizes for the person. A tool should help you understand yourself — not quietly assemble a model of you that works against your own interests. If you ever want less personalization, you can minimize it and still use the Lab.

06

Data Sharing and Third-Party Processors

We are committed to not selling, renting, or leasing your personal data to anyone for marketing purposes — ever. We only share data with a small set of trusted service providers who help us run the Lab and who are contractually bound to protect it:

  • Infrastructure & hosting: secure servers, located within the EEA where possible;
  • Security services: protection against DDoS attacks and malicious bots;
  • Essential functional services: components such as font libraries and core platform functionality.

We have Data Processing Agreements (DPAs) in place with each of these processors to ensure GDPR-level protection, and we share only the data each one genuinely needs to do its job.

07

Data Retention

We practice data minimization: we keep your data only as long as we have a clear reason to, and then we delete it. Concretely:

  • Account & test data: retained while your account is active, and permanently deleted within 30 days of you deleting your account;
  • User-generated content: retained while your account is active, or until you delete it yourself;
  • Communication data (emails & messages you send us): the emails and support messages we receive are kept as a record of our correspondence for up to 24 months from our last exchange, after which they are deleted — unless we are required to keep them longer to meet a legal obligation or to establish, exercise, or defend a legal claim;
  • Anonymized technical data: may be retained indefinitely, because it can no longer identify you.

If you would like correspondence deleted sooner than the periods above, you can ask us and we will honor the request wherever we are not legally required to retain it.

08

Your Rights Under GDPR

The data is yours, and the law gives you real control over it. As a user in the EU you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — correct data that is inaccurate or incomplete;
  • Erasure — request deletion of your data (the "right to be forgotten");
  • Restriction — limit how we use your data;
  • Portability — receive your data in a structured, machine-readable format;
  • Objection — object to processing based on our legitimate interests;
  • Withdraw consent — withdraw consent for special-category data at any time.
How to use them

To exercise any of these rights, email privacy@bunkros.net. We will respond within one month, and we won't charge you or make you justify the request beyond confirming it's really you.

09

Data Security

We implement appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access:

  • Encryption: passwords are cryptographically hashed, and data is encrypted in transit (SSL/TLS) and at rest;
  • Access control: access to personal data is strictly limited to authorized personnel who need it;
  • Anonymization: we anonymize wherever possible, especially in analytics;
  • Regular review: we keep our security practices under ongoing review.
Honest caveat

No method of transmission or storage is ever 100% secure. We do our part, and we ask you to do yours by keeping your password confidential and unique, and by telling us promptly if you suspect your account has been compromised.

10

Children's Privacy

The Bunkros Identity Lab is intended for adults only. Our services are not directed at anyone under the age of 18, and we do not knowingly collect personal data from minors.

If we become aware that we have collected data from someone under 18, we will take immediate steps to delete that information and close the associated account. If you believe a minor has provided us with data, please contact us so we can act on it quickly.

11

International Data Transfers

Our primary operations are within the European Economic Area (EEA). Where we use a data processor located outside the EEA, we make sure the transfer is protected by appropriate safeguards, including:

  • The European Commission's Standard Contractual Clauses (SCCs); and
  • Adequacy decisions, where one applies to the destination country.
12

Changes to This Policy

As the Lab evolves, this policy may need to change too — to reflect new features, new processors, or new legal requirements. When that happens, we will:

  • Post the updated policy on this page with a new "Last Updated" date; and
  • Notify registered members by email when the changes are significant.

We will never quietly weaken your protections without telling you.

Contact & Complaints

If you have any questions, concerns, or requests about this policy or your data, reach us at privacy@bunkros.net.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, that is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority): autoriteitpersoonsgegevens.nl.