Privacy Policy
How we handle — and, just as importantly, how we refuse to handle — your data. Privacy here is not an afterthought bolted on at the end. It is part of the architecture: the Lab is built to know enough to be useful to you, and deliberately not built to know everything about you.
Introduction & Our Commitment
Welcome to the Bunkros Identity Lab ("Bunkros," "we," "us," "our"). Our mission is to provide a secure and affirming space for self-discovery, and that mission only works if you can trust what happens to the things you share here. This policy explains, in plain language, what information we collect, why we collect it, how long we keep it, how we protect it, and the rights you have over it.
This Privacy Policy is written in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and relevant Dutch data protection law. It applies to everything you do in the Lab, and it sits alongside our User Agreement and Manifesto as part of how we operate.
We collect as little as we can, we use it to make the Lab genuinely yours, we keep it only as long as we need it, and we never sell it. The rest of this page is the detail behind that promise.
Data Controller Information
The entity responsible for deciding how and why your personal data is processed (the "Data Controller") is Bunkros. If you ever want to reach a human about your data, these are the right addresses:
- Entity: Bunkros
- Privacy inquiries: privacy@bunkros.net
- General contact: contact@bunkros.net
We read what comes in to these inboxes, and we treat privacy requests as a priority rather than a formality.
What Personal Data We Collect
We have designed the platform to collect the minimum amount of data necessary to provide our services. We don't gather data "just in case." Here is what we process, why, and the legal basis for each category:
| Data category | Types of data | Purpose | Legal basis |
|---|---|---|---|
| Account information | Email address, encrypted password, account creation date | Create and manage your secure account, authenticate logins | Art. 6(1)(b) — Contract |
| Test & interaction data | Questionnaire answers, AI interactions, identity-related inputs | Generate personalized insights and connect them to the content library | Art. 9(2)(a) — Explicit consent (special category) |
| User-generated content | Journal entries, reflections, essays, profile info | Document your journey and build your personal narrative | Art. 6(1)(a) — Consent |
| Communication data | Your email address and the content of emails / support messages you send us | Respond to you, provide support, and keep a record of our correspondence | Art. 6(1)(f) — Legitimate interest |
| Technical data (anonymized) | Aggregated visitor counts and traffic patterns — no IP addresses or device IDs stored | Monitor server health and prevent abuse | Art. 6(1)(f) — Legitimate interest |
Information about sexual orientation, sexual life, and health is treated with the highest level of protection under the GDPR. We will not process this kind of data without your explicit, freely-given consent, and you can withdraw that consent at any time without losing access to the parts of the Lab that don't depend on it.
Automated Decision-Making and Profiling
The Bunkros AI uses your inputs to perform a limited form of profiling. It is important to be precise about what that does and does not mean.
What it does
- Analyzes patterns in what you choose to share to draw connections;
- Suggests relevant content — glossary entries, archetypes, articles, reflective prompts;
- Helps you build and revisit a personal identity map over time.
What it does not do
- Make automated decisions that produce legal or similarly significant effects on you;
- Provide medical diagnoses or clinical assessments;
- Render fixed or final judgments about who you are.
The AI's outputs are reflective prompts to aid your own exploration, not authoritative conclusions. You always remain the author of your own identity; the tool just holds up the mirror.
Personalize, Not Hyper-Personalize
This is the principle that shapes every other choice in this policy. Our goal is to personalize your experience so the Lab is relevant, useful, and yours. Our equally firm goal is to never cross into hyper-personalization — the kind of surveillance-grade profiling that turns a person into a target.
What personalization means here
- We use what you choose to share to surface fitting content, remember where you left off, and adapt the experience to your stated interests;
- We aim to reflect you back to yourself more clearly — a mirror that helps you focus, not a feed engineered to hold your attention;
- Personalization is built on data you knowingly give us, and you can see, change, export, or delete the data behind it at any time.
The line we will not cross
- We do not build a permanent, ever-growing psychological dossier on you;
- We do not track you across other websites or buy third-party data to "enrich" your profile;
- We do not sell, rent, or share your profile with advertisers or data brokers;
- We do not use manipulative micro-targeting or persuasion techniques to change your behavior, upsell you, or maximize "engagement";
- We do not infer sensitive traits you didn't choose to share in order to target you.
Hyper-personalization optimizes for the platform; honest personalization optimizes for the person. A tool should help you understand yourself — not quietly assemble a model of you that works against your own interests. If you ever want less personalization, you can minimize it and still use the Lab.
Data Sharing and Third-Party Processors
We are committed to not selling, renting, or leasing your personal data to anyone for marketing purposes — ever. We only share data with a small set of trusted service providers who help us run the Lab and who are contractually bound to protect it:
- Infrastructure & hosting: secure servers, located within the EEA where possible;
- Security services: protection against DDoS attacks and malicious bots;
- Essential functional services: components such as font libraries and core platform functionality.
We have Data Processing Agreements (DPAs) in place with each of these processors to ensure GDPR-level protection, and we share only the data each one genuinely needs to do its job.
Data Retention
We practice data minimization: we keep your data only as long as we have a clear reason to, and then we delete it. Concretely:
- Account & test data: retained while your account is active, and permanently deleted within 30 days of you deleting your account;
- User-generated content: retained while your account is active, or until you delete it yourself;
- Communication data (emails & messages you send us): the emails and support messages we receive are kept as a record of our correspondence for up to 24 months from our last exchange, after which they are deleted — unless we are required to keep them longer to meet a legal obligation or to establish, exercise, or defend a legal claim;
- Anonymized technical data: may be retained indefinitely, because it can no longer identify you.
If you would like correspondence deleted sooner than the periods above, you can ask us and we will honor the request wherever we are not legally required to retain it.
Your Rights Under GDPR
The data is yours, and the law gives you real control over it. As a user in the EU you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — correct data that is inaccurate or incomplete;
- Erasure — request deletion of your data (the "right to be forgotten");
- Restriction — limit how we use your data;
- Portability — receive your data in a structured, machine-readable format;
- Objection — object to processing based on our legitimate interests;
- Withdraw consent — withdraw consent for special-category data at any time.
To exercise any of these rights, email privacy@bunkros.net. We will respond within one month, and we won't charge you or make you justify the request beyond confirming it's really you.
Data Security
We implement appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access:
- Encryption: passwords are cryptographically hashed, and data is encrypted in transit (SSL/TLS) and at rest;
- Access control: access to personal data is strictly limited to authorized personnel who need it;
- Anonymization: we anonymize wherever possible, especially in analytics;
- Regular review: we keep our security practices under ongoing review.
No method of transmission or storage is ever 100% secure. We do our part, and we ask you to do yours by keeping your password confidential and unique, and by telling us promptly if you suspect your account has been compromised.
Children's Privacy
The Bunkros Identity Lab is intended for adults only. Our services are not directed at anyone under the age of 18, and we do not knowingly collect personal data from minors.
If we become aware that we have collected data from someone under 18, we will take immediate steps to delete that information and close the associated account. If you believe a minor has provided us with data, please contact us so we can act on it quickly.
International Data Transfers
Our primary operations are within the European Economic Area (EEA). Where we use a data processor located outside the EEA, we make sure the transfer is protected by appropriate safeguards, including:
- The European Commission's Standard Contractual Clauses (SCCs); and
- Adequacy decisions, where one applies to the destination country.
Changes to This Policy
As the Lab evolves, this policy may need to change too — to reflect new features, new processors, or new legal requirements. When that happens, we will:
- Post the updated policy on this page with a new "Last Updated" date; and
- Notify registered members by email when the changes are significant.
We will never quietly weaken your protections without telling you.
Contact & Complaints
If you have any questions, concerns, or requests about this policy or your data, reach us at privacy@bunkros.net.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, that is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority): autoriteitpersoonsgegevens.nl.