Think Margin

Privacy Policy

Effective date: October 1, 2026

1. Who This Policy Applies To

This policy applies to the English version of Question Genome offered by Think Margin. The English launch is currently intended for users aged 18 or older in the United States (50 states and District of Columbia only), Canada, Australia, and New Zealand.

2. Information We Process

Question Genome processes service progress, responses to questions, thinking-move observations derived from responses, feedback about observations, access and session information, and payment-related identifiers needed to confirm a purchase, such as a Stripe Checkout Session ID.

An email address received from Stripe for payment verification is converted to an HMAC hash using a secret key before storage. The Question Genome database does not store the email address itself. A partially masked representation may be retained for administration. Access Codes used to restore progress are stored in hashed form.

Technical information such as IP address, browser information, device information, access logs, and security-related data may also be processed as part of operating the website, Cloudflare services, abuse prevention, and support.

3. Cookies

Question Genome uses a session cookie with HttpOnly, Secure, and SameSite=Strict attributes to maintain the equivalent of a signed-in service session. It is not used as an advertising cookie.

4. Please Avoid Unnecessary Personal or Confidential Information

Question Genome is designed to work without names, addresses, telephone numbers, passwords, or other confidential information in your answers. Please do not include such information unless genuinely necessary.

5. Why We Process Information

We process information to provide the service, save progress, observe thinking moves in responses, create reports, verify purchases and refunds, respond to support requests, investigate technical problems, improve classification quality, maintain service security, and prevent misuse.

6. OpenAI

Response text is sent to the OpenAI API for the purpose of observing thinking moves. Question Genome sends these classification requests with application-state storage disabled (store=false). OpenAI states that data sent to its API is not used to train or improve its models unless the API customer explicitly opts in. Standard abuse-monitoring logs may still retain customer content for up to 30 days, subject to OpenAI's applicable data controls and legal or safety requirements.

7. Cloudflare

Question Genome uses Cloudflare Workers and D1 for application hosting and storage, and Cloudflare Turnstile to reduce automated abuse. Data may be processed in locations used by Cloudflare's infrastructure. Cloudflare states that D1 data is encrypted at rest and in transit.

8. Stripe

Stripe is used to process payment for the 30-Response Version. Payment-card details are processed by Stripe; Question Genome does not store card numbers. Payment and billing information is processed by Stripe under Stripe's own privacy and security practices.

9. No Ability or Personality Assessment

Question Genome is not intended to assess intelligence, personality, aptitude, ability, superiority, or inferiority.

10. Retention and Deletion

Responses, progress, and observation results are retained while needed to provide the service and until the user deletes stored Question Genome data through the service or requests deletion through support, unless a longer period is required for legal, security, dispute, accounting, or payment-related reasons.

Payment processors and infrastructure providers may retain information under their own retention requirements.

11. User Requests

Users may contact Think Margin to request access, correction, or deletion of personal information where applicable law provides such rights. Identity verification may be required before a request is completed.

12. International Processing

Think Margin is operated from Japan. OpenAI, Cloudflare, Stripe, and other service providers may process information outside the user's country. By using the service, users understand that service data may be transferred and processed internationally as described in this policy and subject to applicable law.

13. Security

Think Margin uses reasonable safeguards appropriate to the nature and scale of the service, including access controls, data minimization, hashed access codes, limited storage of payment-identification data, and secure transport provided by the relevant infrastructure services.

14. Changes to This Policy

This policy may be updated for legal, operational, security, or service-related reasons. Material changes will be communicated through the service or official website when reasonably possible.

15. Contact

Think Margin Support
thinkmargin.jp@outlook.com