Question-bank, deck, and return-link counters.
The public 100-question resource can mark only a copy, print, native-share, or quiz-link-click occurrence. It never sends copied question text, a selected range, destination URL, or identifier. A private deck can mark only that its first explicit share action occurred; the event never contains its fragment, questions, answer key, score, or URL. Quick Read can separately mark that a return link was created and that its first explicit share action occurred; a successful copy counts as an action, while opening WhatsApp or another external channel counts only as intent—not message delivery.
Automatic X advertising measurement on eligible public pages.
Starting August 26, 2026, eligible production pages load the X base Pixel for event source reoq6 automatically, without a separate consent prompt. X can use the resulting site-visit and landing-page activity for campaign attribution, reporting, optimization, website-activity audiences, retargeting, and related audience modeling under X’s own terms and controls.
On an eligible public page, X may receive the public page URL, referrer or campaign context, X Click ID, X or browser cookie identifiers, and browser, device, and network information. ViewsMeet also keeps a valid twclid with its capture time in local storage for no more than 30 days so a later coarse conversion can be matched. The value is not written to the ViewsMeet funnel dataset.
The third-party X script is never injected on private challenge, score-relay, personality-challenge, Group Picks invitation, Studio, demo, non-production, capability-query, or private deck-fragment views. Those exclusions cover /c/*, /r/*, /personality/c/*, /group-experiment/c/*, /studio, #d1_*, and URLs carrying management, challenge, source-capability, response, token, or code parameters. Private codes, aliases, answers, predictions, scores, and deck fragments are not supplied to the X Pixel.
A separate first-party Conversion API bridge sends five coarse event classes: game started, challenge created, invite shared, response completed, and return challenge created. At the account owner’s direction, all five currently use the single X Event ID repfq and browser event tag tw-reoq6-repfq, so X reporting combines them into one conversion rather than distinguishing the funnel stages. Each request can contain the Event ID, a random deduplication ID, the stored X Click ID when available, and the request IP address plus user agent; it contains no answer, prediction, alias, score, private URL, email, or phone number. Global Privacy Control or browser Do Not Track causes restricted-data-use signaling where supported.
Daily play data.
A submission contains the pack ID, version, digest, five self choices, five panel predictions, and whether public contribution was selected. A server may return an opaque session ID and privacy-safe result metadata.
An optional allowlisted for label can frame the same daily round as a Quick Read for friends, best friends, partners, siblings, family, household members or roommates, a group chat, teammates, long-distance connections, coworkers, onboarding/new teams, classmates, or communities. It travels in creator and challenge URLs and changes interface and sharing copy only. It is not stored with answer sheets, never fills or infers a relationship label, and does not change the daily questions, scoring, challenge access, public opt-in, retention, or aggregate thresholds. Unknown labels are ignored rather than echoed.
Coworker and onboarding/new-team framing is voluntary entertainment only—not hiring, screening, performance evaluation, compatibility, or scientific assessment. Classmate framing is not grading or selection. Community framing is not membership verification.
ViewsMeet does not request a legal name, email address, contacts list, social graph, photo, or private account to play.
Know Me answer sheets stay inside the private challenge.
A creator’s 24 answers are stored with an expiring, unguessable challenge link plus the selected pack ID, version, and digest. For Remix, a concrete 12-hex-character random seed is part of that pack ID and reconstructs the exact reviewed set; it is not derived from an IP address, cookie, alias, answers, or browser profile. The stored challenge identity controls all later play. Each person submits 24 predictions, and every link holder receives the identical frozen questions. The service stores no second self-answer sheet for that person. After completing all predictions, they can reveal the creator’s issued answers and their own aggregate category scores. Other respondents do not receive that prediction sheet.
After a completed round, the response-token holder can explicitly create a score-to-beat relay lasting no more than seven days and never beyond the original challenge. The signed relay identifies only an opaque response record, one allowlisted audience framing label, and its expiry. The framing never sets or infers a relationship. On each open, the service checks that the response and challenge still exist and recomputes the exact prediction score. Its preview and landing reveal that score and the quiz creator’s already-shared alias and context, but never the respondent’s alias, predictions, answer sheet, response-control token, or another participant’s data. No relay table or additional answer record is created; deleting the source response or challenge invalidates the relay.
An optional allowlisted URL label can frame the same quiz for friends, best friends, partners, siblings, family, household members or roommates, a group chat, teammates, long-distance connections, coworkers, onboarding/new teams, classmates, or communities. It changes interface and sharing copy only; it is not stored in the challenge record, never fills or infers the separately selected relationship field, and does not change scoring, access, or public-cohort eligibility.
Coworker and onboarding/new-team editions are voluntary entertainment icebreakers—never hiring, screening, performance evaluation, compatibility, or scientific assessment. Classmate framing is never grading or selection. Community framing is not membership verification.
No Know Me pack is accepted by the public-cohort route, so these answers never create country nodes or public experiment ballots.
The personality snapshot is scored without storing its answer sheet.
The browser sends one complete 20-response Mini-IPIP sheet to the score endpoint. The Worker validates it, calculates five deterministic raw sums and means, returns those five results, and does not write the responses or scores to D1, Analytics Engine, a challenge, a public cohort, a model, or another ViewsMeet store. The request is still processed at Cloudflare’s edge and is subject to the operational security data described below.
An unfinished snapshot can keep its shuffled item order and bounded 1–5 responses in this browser’s local storage for up to seven days. It is removed after successful scoring or when you clear site storage. Sharing a result sends only generic invitation copy and the public /personality URL—never answers or trait values.
The human page’s score request creates one aggregate personality_completed event, and the browser can send one aggregate personality_started event. Neither event contains an answer, factor score, item order, result, alias, URL, or browser identifier. The stateless MCP scorer does not add that completion event.
New Test Lab scoring is server-stateless and solo-only.
The detailed IPIP-50, IPIP-IPC, and 36QB6 pages request a public instrument definition that omits its private scoring map and send one complete bounded vector to a same-origin scoring endpoint. The Worker validates the exact instrument ID, version, item IDs, response anchors, completeness, and shape; calculates only the published raw sums and means; returns them with the fixed disclosure; and writes neither the item vector nor scale results to D1, Analytics Engine, an account, a challenge, a public cohort, or an AI model.
To prevent a 32–50-item test from being lost on refresh, an unfinished assessment can keep its bounded item IDs, responses, current position, instrument version, and update time in this browser’s local storage for up to seven days. The draft is validated before resume and is removed when scoring succeeds, when “Start over” is chosen, when it expires, or when site storage is cleared. Results are never placed in the URL or local storage. The primary result share contains only generic test invitation text and an attributed public URL. A separate explicit “Copy my raw means” action can place the visible scale names, values, and public link in the browser clipboard so the person can choose where to paste them; ViewsMeet does not receive that clipboard content.
The Reaction Speed and Color Conflict tasks run their trial sequence and scoring entirely in the browser. Trial order, response choices, errors, and milliseconds remain in page memory and are discarded on reload. After any of the five new Lab modes completes, this browser can keep a maximum six-entry local history containing only the fixed test slug and UTC completion day. That history powers “pick up where you left off”; it contains no answers, results, times, accuracy, identity, or account data and is never uploaded. Only one fixed started, completed, or shared event name can be submitted for each Lab mode. No event contains the test answer sheet, trial vector, response time, accuracy, scale value, instrument item, result text, URL, alias, or identifier. These new event names are deliberately absent from the X Conversion API mapping.
The public Test Lab hub can also submit one of four fixed counters when the hub opens, any test is selected, its social-game bridge is selected, or a local recent-test link is selected. Those counters do not identify which history entry, test result, answer, route query, or person was involved. Eligible public Test Lab pages still load the automatic X base Pixel described above, so X can receive the public page URL and ordinary visit context. Test answers, scoring requests, raw means, reaction times, accuracy, and copied result text are never supplied to the Pixel or Conversion API by ViewsMeet.
Private perception links store five sums per role, never item vectors.
Creating this optional link sends the creator’s complete 20-item sheet once. The Worker scores it in memory and writes only five keyed raw sums, an optional normalized alias, an opaque management-capability hash, response count, and expiry metadata. The 20 responses are not written to challenge storage. Every invited browser or explicitly instructed MCP client similarly sends 20 predictions once; those are reduced to five keyed sums and discarded before storage.
A response row contains five predicted sums, an optional generated or chosen alias, a one-way participant-key hash, a one-way response-capability hash, a server-assigned web or mcp transport label, an optional fixed reaction, and timestamps. Creator management returns five factor-level pairs and gaps only. It never returns item IDs, responses, predictions, exact matches, distance, overall accuracy, rank, identity claims, or another deletion capability.
Perception challenges are private-by-sharing, excluded from public ballots, country data, Lab panels, AI, and the ledger. They expire no later than seven days after creation and are hard-deleted with their responses and safety reports; a creator or response capability can delete active data sooner. Cloudflare still processes the operational request data described below.
Full-profile rounds stay private.
The browser submits 21 listed choices to calculate a seven-axis result, then keeps the local answer vector needed to create an optional friend challenge. The score response contains only aggregate profile output. Full-profile choices are not accepted by the public cohort route, and friend comparison responses do not return either participant’s answer sheet.
Public contribution is off unless you choose it.
The “include my picks” control adds the five self choices to an aggregate cohort. A challenge alias is not attached to that public contribution. Results remain unpublished below configured privacy/sample thresholds.
For the public world view, ViewsMeet retains only the two-letter country code supplied by Cloudflare at the edge. It does not retain the raw address for the world view, request precise location, or publish country cells smaller than three responses.
When public opt-in is available, selecting it lazily loads a managed Cloudflare Turnstile widget and produces a one-use admission token. The widget is not loaded for private-only play. If an edition does not supply a Turnstile site key, the production interface disables public opt-in instead of claiming inclusion.
Public cohorts are not described as verified or representative populations. Do not submit sensitive information; questions are curated specifically to avoid soliciting it.
Anyone with a friend URL can use it.
A challenge stores the creator’s picks, optional alias, immutable pack reference, responses, safe reactions, and expiry. After someone completes the challenge, their per-question Knowledge and Match result can reveal the creator’s issued choices to them. No participant receives another respondent’s answer sheet.
Exact privacy-safe group tallies appear only after the link has five total people, including its creator. Challenge URLs are private-by-sharing, not encrypted messages. Do not post a link publicly if you want it to remain within a small group.
Control tokens, a play name, and unfinished drafts stay in this browser.
The browser stores opaque challenge-management and response-deletion tokens in local storage. They let the holder inspect privacy-safe management summaries or delete the associated challenge/response. A random browser key and per-challenge participant key help the service limit duplicate aggregate or friend submissions without creating an account. These values are not synchronized between devices by ViewsMeet.
If you enter a name or nickname, this browser remembers up to 32 characters and pre-fills it the next time a ViewsMeet name field appears. You can edit or erase the field before each submission. The remembered name is never sent by itself; it travels only when you submit a creation or response whose form visibly includes that alias.
If a 20-response personality snapshot or 21- or 24-choice round is unfinished, its bounded responses can be saved locally so a reload resumes the same item. Drafts are never sent to telemetry, expire from this browser after seven days, and are removed after a successful score or challenge response.
The underlying challenge can still expire normally, but this browser may no longer be able to resume a draft or delete it early.
The founding signal is not a payment profile.
If you choose “I’d give $5 once,” the browser submits one allowlisted aggregate support_intent event. The counter is not attached to an alias, answer sheet, result, challenge, public-country contribution, email address, or payment detail. ViewsMeet stores yes in local storage so the current browser remembers that it already signaled.
The aggregate count is not verified as unique people and the button does not create a pledge, checkout, donation, subscription, reservation, or mailing-list record. Clearing site storage removes the browser-side preference but cannot subtract a previously counted aggregate event.
Private labels and public topology use separate, side-specific choices.
A creator can optionally label themselves as a person or software. An invited participant can optionally choose one fixed relationship category and label themselves as a person or software. Those labels are stored beside that one challenge or response so its private creator board can draw a challenge-scoped connection star. The creator sees them alongside the alias and score already visible to that management capability.
The for value in a URL never fills, infers, or stores a relationship label. Blank labels remain unspecified. A web selection is self-declared; an mcp label establishes only transport—not a model, autonomous agent, identity, consciousness, or unique actor. Private labels do not follow anyone into another challenge or create a public person node.
The creator has a separate Atlas permission, off by default, for their person/software category. If they leave it off, the public creator side is stored as unspecified even though their chosen label can still appear on the private board. A participant has another separate checkbox, also off by default, for that participant’s relationship and actor categories. A participant cannot publish the creator’s private actor category; it appears publicly only when the creator separately allowed it.
An opted-in edge contains domain-separated opaque HMAC keys, a random challenge-lineage scope, only the permitted category labels, a UTC day, and expiry. It contains no alias, account, challenge or response ID, code, URL, answer, prediction, score, reaction, participant key, IP, country, model ID, or exact timestamp. It remains eligible for the fixed 30-day window and expires after 31 days. Deleting the response or challenge removes its unfrozen edge sooner.
A public cell opens only with at least 20 direct opted-in edge occurrences from at least 20 independent challenge lineages. Suppressed cells publish no hidden edge totals. Once-daily editions are frozen and hash-linked; later deletion removes live rows but cannot rewrite an already published historical aggregate. These are occurrences, not verified people, agents, identities, relationships, companies, regions, or representative samples.
Interaction counters are aggregate, not profiles.
The browser can submit one allowlisted event name when a mode starts, a challenge is created or successfully shared, a share-channel link is opened, a score relay starts or successfully reaches the browser’s share/copy action, or the founding signal is chosen. Creator Studio can likewise mark only that its page opened, its post-creation nudge was clicked, at least one eligible creator link was detected locally, a passkey Studio was created or signed into, at least one local link was attached, a result panel opened, or a Studio reminder reached share/copy. On the exact X group-chat entry, fixed events can also mark whether the 24-question pack became ready or failed, the answer key reached halfway or completion, and the recovery share panel became ready. Those event bodies contain only the fixed event name—never timing, URL, pack, query, challenge code, claim, answer, score, alias, passkey, device, or identifier. The server can separately count relay issuance, relay-page API opens, and completed responses carrying a valid same-challenge relay. These fixed counters describe occurrences, not unique people or verified message delivery.
ViewsMeet share URLs can carry one fixed via label: native share, copy, WhatsApp, Telegram, Bluesky, Nostr, gamestr, X, SMS, or email. On the first attributed page in a browser session, the browser maps a valid label locally to one fixed aggregate event name and sends only that event. In particular, exact via=nostr maps only to acquisition_share_nostr, exact via=gamestr maps only to acquisition_share_gamestr, and exact via=x maps only to acquisition_share_x. It never sends the URL, challenge code, relay token, score, audience, alias, referrer, or another identifier with the event. Nostr and gamestr labels also never send a Nostr public key, signed-event ID, relay, or group ID; the X label never sends an X account, post, campaign, or ad identifier. Unknown labels are ignored and are not preserved in server-rendered social or canonical metadata. Session-storage flags prevent repeat acquisition and X-ready/failure counting inside one tab session; they are not cross-session or cross-site profiles, and ViewsMeet sets no acquisition cookie.
The bounded X5 activation experiment additionally recognizes only five fixed ViewsMeet campaign labels, creative a or b, and twelve fixed stage names. A matching creator URL becomes an allowlisted event such as x5_bff_a_started. If that creator makes a private challenge, a fixed reference such as x5_bff_a can travel in the invitation URL so the invited browser can count open, start, and completion for the originating cell. If that recipient explicitly makes and shares a new game, fixed branch-created and branch-shared occurrences can remain attributed to the same cell. The reference identifies only one predeclared experiment cell—not an X platform campaign, ad, click ID, account, person, device, challenge, or response. The event body still sends only the fixed event name; it never sends twclid, IP, the URL or raw query, challenge code, alias, answers, score, or a joined journey. Invalid, duplicated, route-mismatched, or invented labels are ignored. Session storage suppresses repeated stages in one tab, but counts remain aggregate occurrences rather than unique people.
When no valid via label exists, the browser retains the coarse external-referrer fallback: The Useless Web, the submitted Zearches directory, search, social, or other referral. It maps the referrer locally and sends only that fixed bucket name; it does not send or store the referrer URL, hostname, path, query, or account. The daily counter does not store an alias, answer, score, challenge code, destination URL, contact, or browser identifier. Opening a share channel is counted as an intent—not proof that a message was sent—and the counts cannot establish unique people.
ViewsMeet’s own production health probes carry a short-lived authenticated marker so their fixed aggregate events are labeled synthetic instead of live. Scheduled publisher and maintenance outcomes use a separate system class; they are not synthetic probes and are excluded from qualified-live demand. Counters created before this boundary remain explicitly legacy_unclassified, not retroactively claimed as live. The counter stores only the fixed event, transport, class, date, and count; it does not store the marker, its random nonce, or a probe identity.
Operational data.
The Cloudflare edge can process IP address, user agent, route, response status, approximate region, timing, rate-limit, abuse, and security signals needed to deliver and protect the service. Eligible public pages can load the X advertising Pixel described above. Private capability views do not inject that third-party script. If public cohort opt-in is selected, the interface can also load Cloudflare’s Turnstile script and verification frame for that admission check. No third-party font or content image is required for play.
Emailing hello@viewsmeet.com is optional and never required to play. Cloudflare Email Routing forwards the sender, recipient, subject, message content, and normal email headers to a verified destination mailbox outside the gameplay database. The receiving mailbox provider may retain and process that message under its own terms. Do not email challenge codes, management URLs, deletion tokens, answer sheets, passwords, or payment details.
In browsers that expose WebMCP, the page registers two read-only first-party tools: list public modes and fetch the public daily set. Registration makes no request by itself; invocation can fetch only public same-origin data and cannot submit a choice, create a challenge, access a control token, or call a model.
After a successful once-daily scheduled update, the server can notify Google’s public WebSub hub that the fixed public URL https://viewsmeet.com/feed.xml is current. That server-to-server form contains only publish mode and the feed URL—no alias, answer, challenge, contact, subscriber identity, browser identifier, or request address. Hub acceptance is an operational signal, not evidence of a subscriber, delivery, feed read, visit, or user.
Software-agent ballots carry configuration and provenance metadata supplied or derived through the machine interface. Daily question generation stores selected packs plus configuration, decision, and hash audit metadata—not raw model output. Optional Know Me reflections send only six aggregate category counts to a labeled model configuration; aliases and answer sheets are excluded, and accepted reflections are cached by score pattern.
Payment data is not part of the launch gameplay or founding-signal flow described by this notice. Before any real payment option opens, this notice must identify the payment provider and explain the resulting data flow.
Your controls.
- Play without opting into the public cohort.
- Leave aliases blank.
- Keep challenge and score-relay links within the intended group.
- Choose whether to create or share a score relay; completing a quiz never publishes one automatically.
- Use the local response control to delete your challenge response and invalidate relays made from it.
- Use the creator control to delete a challenge and every relay into it.
- Clear local storage to remove tokens from the current device, understanding that this also removes local deletion access.
Expired, deleted, and low-sample states are explicit. This notice will receive a new effective date if data practices materially change.
The first-read milestone is still only a counter.
The exact X entry can record one fixed x_friendship_first_read_reached occurrence when the first four-question category is completed. It carries no question, answer, timing, pack, URL, challenge code, alias, device, or identifier and is not a unique-person count.
Custom deck answers stay in the fragment.
The deck builder fetches the public reviewed question bank, then encodes only the selected question numbers, bank version, creator choices, and a checksum into the URL fragment after #. Browsers do not include URL fragments in HTTP requests, so ViewsMeet does not receive or store the selected deck or its answer key. Recipient predictions and scoring also run locally and are not written to D1 or analytics.
“Flip 8 back” places only eight reviewed public question IDs in a one-use session-storage seed, consumes and removes it on the deck page, and starts creator answering immediately. It does not carry the source alias, score, challenge code, response token, answers, or predictions.
After creation, this browser can keep a bounded list of up to twelve deck fragments in local storage so the creator can reopen them. That local list is displayed in Creator Studio but is never uploaded or synchronized to a Studio account. Clearing site storage removes it.
Anyone holding a deck link can technically inspect or modify its fragment. The checksum detects accidental or casual tampering; it is not encryption, authentication, or proof of authorship. Share deck links intentionally and do not use them for secrets, identity checks, hiring, grading, compatibility, diagnosis, or scientific assessment.
The page can submit one fixed aggregate event when building starts, a deck link is created, prediction starts, a deck is completed, or the same questions are remixed. Each body contains only the fixed event name—never the fragment, selected questions, answer key, predictions, score, URL, or an identifier. These are occurrence counters, not unique people or joined journeys.
Group Picks stores bounded responses but exposes only a thresholded split.
A creator chooses 5–20 IDs from the reviewed 100-question bank. The experiment stores those ordered IDs, a one-way management-capability hash, fixed lifecycle metadata, and no creator alias, account requirement, audience, relationship, workplace label, or Atlas edge. A room accepts at most 50 responses and expires after 14 days.
Each response row contains only a random opaque ID, a challenge-scoped one-way participant-key hash, a one-way deletion-capability hash, the ordered a/b vector, and a timestamp. It contains no name, free text, IP address, country, actor label, relationship, model, public contribution, or cross-site identity. No endpoint returns an individual vector.
Question-level A/B counts stay suppressed until at least three retained responses exist. Counts are recomputed from retained rows, so using a response deletion capability immediately removes that vector from future aggregates. Deleting the creator experiment hard-deletes every response. The shared link is private-by-sharing, not encrypted; anyone holding it can answer and view aggregates once the threshold opens.
Passing the same picks onward can create one child room. Its temporary lineage row contains only opaque parent and child experiment IDs, depth, creation time, and the time of the child room’s first retained response. It contains no public code, management or deletion capability, question answer, participant key, account, alias, IP, relationship, actor, or location; deleting either linked room removes the lineage row.
Group Picks is a voluntary entertainment icebreaker—not representative polling, scientific measurement, personality testing, compatibility, hiring, screening, performance review, grading, diagnosis, or membership verification.
Creator Studio is optional and passkey-only.
Playing and creating links still requires no account. If you explicitly create a Studio, ViewsMeet stores a random account ID, a random non-identifying picker label, the passkey credential’s public key and security metadata, hashed session and CSRF tokens, and optional claim rows connecting that account to a quiz, trait-link, or Group Picks record. It does not request or store an email, password, legal name, contact list, biometric template, private key, or passkey unlock secret. Device biometric or PIN checks stay with the device and its platform passkey provider.
To import an existing creation, the browser sends its local management capability once over HTTPS. The Worker hashes it to locate the record, writes only the account-to-record claim, and does not place the raw capability in the Studio database. Claims expose the same aggregate creator summary already available to that capability; they do not add answer sheets to the account. Private deck fragments are never sent to this API.
“Ask an AI” constructs a text handoff locally from the already attached creation’s private share code and fixed public MCP or REST instructions. ViewsMeet does not send that handoff to a model, choose a provider, or post it automatically. Copying can submit only the fixed aggregate studio_agent_handoff_copied event name—never the code, handoff, creation, account, or model. The code is a bearer capability, so paste it only into the AI you intend to invite.
There is no email, password, help-desk, or identity-document recovery. Losing every usable passkey makes the Studio account inaccessible. Existing challenge controls and local deck fragments can still work on a browser that retained them. Deleting a Studio removes its account, passkeys, sessions, and claim rows, but deliberately does not delete separately controlled quizzes, trait links, or Group Picks rooms.
Story cards are made in the browser.
After a completed Know Me response, an explicit share action can draw a 1080×1920 PNG locally from the aggregate score and fixed audience label. The image contains ViewsMeet branding, the score out of 24, and generic explanatory copy. It contains no alias, challenge code, relay token, URL, question, answer, prediction, category count, device detail, or hidden metadata supplied by ViewsMeet. On supported devices the browser can share that file alongside the separately issued seven-day score-relay link; otherwise the image is downloaded and the relay message is copied.
After a Group Picks room crosses its three-response threshold, another explicit share action can draw a 1080×1920 PNG locally from the already available response count and up to three reviewed question-level aggregate splits. That image contains no name, individual answer, participant key, response token, creator capability, room code, URL, actor, relationship, location, or hidden cell. It can travel with the private-by-sharing room link; otherwise the image is downloaded and the room message is copied. A successful file/link share or copy can submit only the fixed aggregate experiment_snapshot_shared event name. The separate ?demo=1 preview uses five reviewed questions and fixed sample counts, labels itself as non-live, writes no room or response, and suppresses interaction reporting.