1. Who is responsible
Fatherhood AS, Norwegian organisation number 998 472 768 MVA, is responsible for the story, result, access and product-support data described here. Contact: support@howvikingareyou.com.
Stripe or Link is separately responsible for payment, fraud, tax, receipt and transaction-support processing covered by the notices shown in Checkout.
2. Information you provide
You provide the choices you make in the story, a selected character presentation and a name or nickname before revealing the result. The name is used to personalise your private Viking profile, personal books and PDF. It is not added to public shares by default.
If you contact support, we process the information in that correspondence. Do not include a private result or saga token in a support message.
3. Story choices and result data
Incomplete journey state, including your choices, is stored in your browser so you can continue the experience. It remains there until you reset the journey, start over or clear browser storage.
Session storage also holds a short-lived signed journey-attempt proof and bounded attribution labels such as device class, traffic source and paywall variant. These values support completion integrity and consistent first-party measurement during the current browser session.
When you complete the story, the service stores your completed choices, locale, scoring output, archetypes, supporting evidence and resolved Viking Portrait and Saga plan in Supabase. No single choice is used as a standalone personality verdict.
4. Result IDs and private links
The service creates random result and profile IDs. Private links also contain a separate access token in the URL fragment. The database stores a cryptographic digest of that token, not the raw token itself.
Anyone with the complete private link can open the content. The token is exchanged for an essential, secure session cookie that normally lasts 30 minutes. Checkout-state cookies can last up to two hours.
5. Name and email
The name or nickname you enter after the quiz is stored as one editable value linked to the completed result. It is separate from the immutable score and Saga snapshot, and the same value is used in the free result, premium library, personal books and future PDF downloads. We do not derive or replace it from your email address or Stripe details.
After a completed quiz, you may optionally ask us to email a private link to your free result. A requested result email is not treated as marketing consent. The address is normalised, encrypted at rest and linked to that specific result.
Separately, you may actively choose personalised Viking insights and occasional offers. That optional choice is recorded with its wording, source and time, can be withdrawn through the unsubscribe link in every marketing email, and is not required to receive the result.
Stripe collects an email address in Checkout. After Stripe confirms a paid purchase, the application normalises and encrypts that address before storing it with the specific purchase and report. A separate one-way keyed digest supports secure lookup without exposing the address. Stripe retains payment-contact information under its own privacy notice.
The purchase email is used for payment, receipts, delivery of the purchased report, customer support and secure report recovery. Providing it for a purchase is not consent to marketing.
6. Purchase and transaction data
We process checkout and purchase references, amount, currency, tax and payment state, Stripe customer, session, payment or charge references, refund and dispute status, billing country and limited regional eligibility information, legal-consent evidence and purchase-confirmation snapshots.
We do not receive or store your full card number or card security code.
7. Technical, device and log data
Vercel and the application process ordinary request, security and error information such as timestamps, requested routes, response status, device class, browser or network information and IP-derived location signals used for security and checkout-market selection.
8. Cookies and analytics
The optional analytics flow is first-party. After you allow analytics, the browser sends allowlisted events such as homepage views, journey completion, result views and premium interactions to our own endpoint. The endpoint writes bounded operational logs and may retain the validated events in our restricted Supabase analytics store.
With analytics consent, we issue a random, signed, product-bound analytics-session cookie. It is HttpOnly, expires after 24 hours, cannot open a result or report and is not joined to activity on another HowX product. The browser preference itself records only the necessary, analytics and marketing choices and their update time; it contains no visitor identifier.
Analytics can include bounded labels such as device class, referrer host, traffic class, locale, variant, currency, paywall placement and a coarse presentation or archetype category. Marketing parameters and provider campaign, ad-set or ad IDs are retained only after the marketing choice. Analytics does not include your name, email, character image, raw choices, full result or profile ID, private access token, full referrer URL, IP address, user-agent string or generated Saga text.
Choosing necessary only leaves the story, result and checkout available without creating an analytics session. Essential cookies are still used for secure journey, result, premium and checkout access. They are not advertising cookies. You can reopen Privacy choices and withdraw an optional choice; the browser then stops sending optional events and expires its analytics-session cookie.
9. Why we use information
We use information to run and resume the story, calculate and preserve your result, personalise your private result, books and PDF, provide and recover private access, deliver purchased reports, process and reconcile purchases and refunds, create public shares you request, respond to support, protect the service, diagnose failures, understand the conversion journey and improve the product.
10. Legal bases
Where EEA or UK data-protection law applies, processing needed to provide the requested story and purchased content is based on performance of a contract. Accounting, tax, refund and compliance records are processed to meet legal obligations.
Limited security and error information needed to operate and protect the service is processed for our legitimate interests, balanced against the limited data involved. The optional first-party analytics session and marketing measurement described above are activated from your recorded choice. This technical implementation and wording must still be reviewed for the markets in which the service is promoted.
11. Payments and Stripe
Stripe processes payment methods, fraud checks, payment authentication, receipts, tax and refunds. For eligible international purchases, Stripe or Link may operate Managed Payments as merchant of record. Review the Stripe or Link privacy information presented in Checkout for their processing.
12. Hosting, database and service providers
Supabase provides the production database and passwordless authentication used to verify an email address and connect purchased reports to that verified user. Vercel hosts the application and provides network and runtime logging. Stripe and Link provide payment and related transaction services.
Resend sends operational emails for purchased-report delivery, secure report recovery and free-result links you request. It also sends the two optional follow-up messages only after explicit marketing consent. Email addresses, access links and one-time tokens are not sent to analytics.
13. AI and text providers
The active result and premium Saga are assembled through deterministic scoring and structured editorial templates. Your choices, name, email and private report data are not sent to OpenAI or another generative-AI provider at runtime and are not used for model training.
15. Optional premium feedback
If you choose to review a purchased Saga, we store your accuracy and value ratings, the section you found most useful and an optional comment of up to 300 characters with the associated result and profile records. Feedback is used to improve the product and does not change your Saga.
Do not include private or sensitive information in the optional comment.
16. International data transfers
Our providers may process information in countries outside your own. Where required, transfers rely on an applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism together with relevant safeguards.
17. Retention
Result, Saga and report-access data is retained while the private service is provided or until deletion, revocation or another operational reason requires a change. Purchase, refund, tax and accounting evidence is retained for the periods required by law. Raw analytics sessions and events follow a configurable purge schedule documented in our operations controls; campaign aggregates that no longer identify a session may be kept longer. Security and support information is kept only as long as reasonably necessary for its purpose and applicable obligations.
A free-result email address without marketing consent is removed or anonymised after the result delivery, retry and abuse-protection period, normally within 30 days. An address with active marketing consent is kept while that consent remains active; after unsubscribe, active sending stops and only limited consent and suppression evidence is retained where necessary.
No single fixed retention period applies to every category. A private token can be revoked without erasing transaction evidence that must be retained.
18. Security
We use encryption for stored purchase email addresses, access controls, secure and HttpOnly session cookies, capability digests, verified passwordless sign-in, server-side payment verification and restricted database operations to protect the service. No system is perfectly secure, so protect private links and contact us if you believe one has been exposed.
19. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or receive a copy of personal information, object to certain processing, withdraw consent where consent applies, or complain to a regulator.
Send a request to support@howvikingareyou.com. We may need information sufficient to locate and verify the relevant record. Some transaction evidence must be retained, and the current service may require a technically supported process to remove embedded result details; we will explain the outcome and any lawful limitation rather than promise deletion we cannot complete.
20. EEA, UK and regional information
EEA and UK users may complain to their local supervisory authority; in Norway this is Datatilsynet. United States residents may have additional access, correction, deletion, copy or appeal rights under applicable state law. Mandatory local rights remain available.
We do not sell personal information or use it for cross-site targeted advertising. The Saga does not make an automated decision with legal or similarly significant effect.
21. Children
The service and paid product are not directed to children. A purchaser must be at least 18 or have valid parent or guardian authorisation. If you believe a child has provided personal information without appropriate permission, contact us.
22. Marketing, sale and model training
We do not sell personal information or use story data for cross-site advertising. Neither a purchase email nor a requested result email is treated as marketing consent. We send the optional two-message follow-up only after a separate, voluntary choice; every such message includes a no-login unsubscribe link that stops future brand marketing. We do not use your choices, name, email or Saga to train generative models.
23. Contact and changes
Privacy questions and requests can be sent to support@howvikingareyou.com. We may update this policy when the service, providers or law changes. The latest update date appears at the top of this page.