Your data, plainly.

What we collect, why, how long we keep it and the control you have over it. Your assessment answers are stored anonymously, we only know who you are if you tell us, and we never sell your data.

LAST UPDATED SEPTEMBER 2026 · SIGNAL LABS INC.


What we collect

Assessment responses (anonymous). When you take the Behaviour Code, we store your answers and your result without your name or email attached. We use this to generate your read, to improve and calibrate the instrument and for aggregated research. On its own it does not identify you.

Contact details (only if you give them). If you ask for your full read or join our research, we collect your email, and optionally your name, role and organisation. We use these to send what you asked for and relevant follow-up you can stop at any time.

Technical basics. Standard server logs (e.g. request metadata) for security and reliability. We do not run advertising trackers.

Why we use it

To deliver your read; to improve and calibrate the instrument; to conduct research; and to send only the communications you opted into. This includes using anonymized or aggregated assessment data to develop, train, validate and improve our models and the instrument behind the Service. When we use data for research or model improvement, we use it in a form that does not identify you.

Public information we analyse (the Decoder)

Separately from your personal data, parts of the Service analyse publicly available information about brands, organisations and public works, to build category and cultural reads. This analysis is transformative: we derive behavioural signals and structure, and we do not republish the source content. We do not construct profiles of private individuals from this material, and it is not connected to your assessment unless you ask us to.

Connected data: the “Lived” read (optional, off by default)

Some advanced reads (the Lived layer) can analyse real behavioural evidence, such as email or documents, to compare how a person or organisation actually behaves with how it describes itself. This is entirely optional and off by default. If you ever choose to connect a source:

  • We ask for explicit, per-source permission and the narrowest access needed (read-only).
  • We analyse the content to derive behavioural signals and store only those signals, we do not retain the raw emails or documents.
  • You can disconnect any source at any time, and we delete the derived data on request.
  • Connected content is never sold, shared or used to train third-party models.

This feature is not enabled today; the above describes how it will work when it is offered.

The Outside Read (what people who know you say)

You can send a link to people who know you, or take part in a Team Read with a room you belong to. Each of them answers a short set of choices about how you behave. Here is exactly what that involves.

If you are the one being read. We store each reader’s scored answers on your file, together with how they know you (colleague, client, friend and so on) and, if they chose to give one, a single word. We do not store a reader’s name, email or device, and we do not show you anyone’s individual answers: you see a pooled read only once at least three people are in, words and counts only from five. Your own Code is never changed by what readers say. Once a month we may record one number, the coherence between the readings, so you can see it move across seasons.

If you read someone else. We store only your scored answers on their file, marked by how you know them. Nothing we keep can identify you, to them or to us, and they never see who said what. Because there is nothing identifiable to delete, a reader’s answers are removed only when the person they describe deletes their readers or their read.

Your control. On your Identity page, under The Outside Read, you can delete every reader on your file in one stroke; the reader link, the seasons and any Team Read ledger go with them, and your Code stays. Deleting your read deletes all of it. For anything else, email privacy@signallabs.ca.

Reader links. A link stays open for thirty days and takes at most ten readers; you can make a fresh one after that. A Team Read link is personal to one member of the room and reaches nobody else’s results.

We do not sell your data

We do not sell, rent or trade your personal information, and we do not use it for third-party advertising. Full stop.

The conversation (the twenty-minute interview)

If you are in the Program or a member, you can hold a twenty-minute conversation with our interviewer, a language model that follows one fixed set of instructions and knows nothing about you. Here is exactly what that involves.

What we keep. The whole transcript, on your file, saved as you send each answer, with the time each answer took. We also keep the interviewer’s closing guess and your reply to it, and your first answer, which may appear as the quote line in your report.

What we do with it. The interviewer scores nothing. The transcript feeds the stories in your report, and it is read against a fixed rubric as one of your reads; it never changes your Code. To run the conversation, each answer is sent to our language-model provider (Anthropic) together with the transcript so far; it is not used to train their models.

Your control. On the conversation page you can delete the whole conversation in one stroke; the transcript, the closing guess and the quote go with it, and your read and your Code stay. Deleting your read deletes all of it. For anything else, email privacy@signallabs.ca.

Who processes it for us

We use a small set of reputable providers that process data on our behalf, under their own terms and safeguards:

  • Vercel: application hosting.
  • Supabase: our database (managed PostgreSQL).
  • Anthropic: the language model behind the reads we compose, the Agent and the conversation.
  • Resend: delivery of the read email you request.
  • ConvertKit (Kit): our email list and follow-up, if you opt in.

See our Trust & Security page for how the data is protected.

How long we keep it

Anonymized assessment data is retained to support ongoing research and improvement; because it no longer identifies you, it may be kept indefinitely in aggregate. Identifiable data (your email and anything you provided with it) is kept until you unsubscribe or ask us to delete it, and then removed within 30 days. Readers’ answers on your file (the Outside Read) stay until you delete them yourself or delete your read.

Your rights

You can ask us to access, correct or delete your personal data, and you can withdraw consent or unsubscribe at any time (every email includes an unsubscribe link). Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. To exercise any of these, email privacy@signallabs.ca.

Cookies

We use only what is needed to run the site (e.g. remembering your sound preference). We do not use advertising or cross-site tracking cookies.

Children

The Behaviour Code is intended for adults and is not directed to anyone under 16.

Changes & contact

This policy works alongside our Terms of Service. If it changes materially, we will update this page and the date above. Questions, or to exercise a right: privacy@signallabs.ca.

Signal Labs · The Personal Brand, Measured · File closed

◆ The thinking, in your inbox

One idea a week on reading people, and being read. No noise.