Privacy, in plain words.
Likely has no accounts and no logins. Since August 2026 it does have a database, and finishing the six questions writes one row to it: your six answers as six small numbers, the name of your archetype, and the time. No name, no email, no account, nothing that identifies you. If you go on to join the pool to meet someone, that adds a second row — and it is the only place in Likely where anything you typed is stored, and only what you chose to type. You can delete all of it from inside the app in two taps.
STUDENT PROJECT · USE WITH CARELikely is an experimental student project, not a production identity or health service. No internet service can promise perfect security. Do not type or share information you consider sensitive, confidential, or unsafe to place in a browser or invitation link.
WHAT CHANGED, AND WHEN
Until August 2026 this page said your answers never left your device, and that was true — there was no server to send them to. There is one now, because the count on the screen and the map of minds are only worth showing if they are real, and a real count has to count something.
So this page has been rewritten rather than amended. What follows describes what happens today.
The second change came later in the same month. Meeting someone new used to be a queue with a real position and nothing at the end of it. It now really matches you with a real person, which means there is somewhere for a name and a link to be stored if you choose to give them. Joining the pool, below, is the whole of what that added — and it changed this page before it was switched on, not after.
WHAT IS STORED, EXACTLY
One row, written when you finish the sixth question:
- Six numbers. Your answers — one digit from 0 to 4 for the first question, one from 0 to 2 for the other five. That is the entire content of your map.
- The archetype name that came out of them, and which of the six signals was loudest — that is what colours your dot on the map.
- A pattern number, which is arithmetic over the six answers and nothing more.
- The time the row was written.
- A random key that we hand to your browser and to nothing else. It is the only proof that the row is yours, and it is what the delete button uses.
That is the complete list for the row your map lives in. There is no column on it for a name, an email address, an IP address, a device identifier, a location or an account, because none of those is collected. If you typed a first name for an invite, it stays on your device and inside the invite link — it is never written to the database with your answers.
A first name and one link can be stored, but only in one place and only if you type them: on your place in the pool, if you join it. They sit on a separate row from your answers, they are optional, and Joining the pool below is the complete account of them. Nothing on this page is stored anywhere else.
WHY
Four things, all visible on screen. The count in the corner — 7 minds — is a count of these rows. The map of minds plots one dot per row, coloured by its loudest signal. Joining the pool gives you a true position in it. And being matched puts a real person in front of you, or says the pool is empty — never a stand-in, and never an invented number. Every figure on screen is either true or absent; none of them is ever rounded, padded or invented.
HOW LONG
Until you delete it or the project is shut down. There is currently no automatic expiry. Because this is a student prototype, submit only information you are comfortable storing under that rule, and delete your Thoughtform when you no longer want it kept.
HOW TO DELETE IT
In the app: open your result screen and press Delete my Thoughtform at the bottom, then press it again to confirm. The row and everything attached to it — your dot, your place in the pool, the name and link on it, every record of a match either side of it, any invite you created — is deleted immediately, and your device forgets it too.
Also: Start over on the landing screen does the same thing. It clears the map saved on your device, and because the key that proves the row is yours lives only on that device, it deletes the row at the same moment. We do not leave behind rows that nobody can reach.
If your browser lost the key some other way — you cleared site data, or used a different browser — write to hello@likely.social and say roughly when you took it and what archetype you got. What is left is six anonymous digits; there is genuinely nothing there to link to you, which is the point, and also the reason we cannot find it for you afterwards.
WHAT STILL NEVER LEAVES YOUR DEVICE
The name you type for your own map, any optional open response, your corrections, the share card image, and the whole of the comparison with a friend. The two maps are woven together in the page you are looking at — the shared ground, the useful differences, the question for you both. None of that is sent anywhere or stored anywhere outside your browser.
The one exception is deliberate and is the whole of Joining the pool below: a first name and one link, typed on the screen that asks for them, plus your answer to the mirror-or-complement question. Nothing else from your guided reflection travels — not what you said would be useful today, not your written line, not your corrections.
SHARING WITH A FRIEND
Nothing is revealed to either of you until both maps are finished. That is not a promise about a server — it is how the page works.
The invite link carries your first name, one broad context word such as build or friendship, and your six answers inside the link itself, after the #. The context word is what stops a work or friendship invitation from appearing romantic. Text after a # is never sent to a web server by any browser, which is how this works with no signup on either side. The trade is that the link is as private as the place you put it: anyone holding it can read that context and the six answers in it. Send it to people you chose, not to a public post. The invite screen says so next to the button.
Opening an invite someone sent you writes nothing, anywhere. Their answers are not yours: they are not saved to your device and never become a row of yours. If you then make your own map, that one is registered like anybody else's.
JOINING THE POOL
Choosing to meet someone from your result opens two screens. The first asks what kind of connection would be useful right now and lets you add up to two topics. The second asks how the mind you meet should reach you, and asks you to confirm you are 18 or older.
What joining stores, on your place in the pool:
- The intent you picked, and up to two topics.
- Your answer to the mirror-or-complement question — whether the useful mind is usually one that runs like yours or one that runs differently. It is never scored and never appears in anyone’s result. It decides only who the pool looks at first.
- A first name, up to 16 characters — only if you type one.
- One link, up to 120 characters — only if you type one.
The name and the link are both optional, and blank means nothing is stored: an empty field is saved as nothing at all rather than as an empty one. Leave both out and you are still matched — you simply arrive as a mind with no way back to you. Clearing a field and joining again takes back what was there.
Who sees them. Only the minds you are matched with. They are never put on a page, in a post, in a search result or in an analytics event, and there is no directory, feed or profile anywhere in this product. No email address is collected, so there is still nothing here that could reach you uninvited.
What being matched shows the other person. Your archetype, what you came to the pool for, and a band-level comparison of your six answers — whether each one is shared, near, or a contrast. Never the answers themselves, and never a number. There is no compatibility score and there never will be. The two directions are not automatic — being shown someone does not show them you — but if the pool puts you in front of them as well, that list is exactly what they see.
A match is written down — as a pair of row identifiers and a time, nothing more — so that looking again shows you the same person instead of reshuffling the pool. We know nothing about whether you spoke, or what was said.
Matching is not exclusive. The pool is small, so the same mind can be the closest one to more than one person at once. The screen says so where it matters.
Deleting your Thoughtform deletes all of this with it — your place in the pool, the name, the link, and every match record on either side of it, in the same breath as the row itself.
WHAT IS STORED ON YOUR PHONE
Three small records in your browser's local storage. One holds your map so a refresh does not lose it: a version number, your six answers as six digits, your first name if you gave one, and a timestamp. A second holds the two unscored questions asked around the six — what you said would be useful today, and which kind of mind you find useful — plus your optional open response and any correction you make to the synthesis. The third holds the id of your anonymous row, its random key, and your place in the count. Of all of that, only the six digits and the map fields derived from them are sent to Likely’s database — and, if you join the pool, the mirror-or-complement answer out of the second record, because it is what orders the pool. The rest of the guided-experience record stays in your browser. Local storage is tied to this site in this browser, but any code running on the site can technically access it — another reason not to enter sensitive information.
An unfinished map is offered back to you for 24 hours and then discarded. A finished one is kept until you clear it, with “Start over” on the landing screen or by clearing site data for likely.social. If your browser blocks storage — Safari private browsing does — Likely notices, saves nothing, and works exactly the same for the rest of the visit.
WHAT WE MEASURE
The site uses Google Analytics 4 to see where people get stuck. Those events carry fixed labels and numbers only — which question you were on, how long a step took, which button you tapped, which archetype came out, your place in the count. Never your name, never free text, never your answers, never a transcript.
The pool adds three of those events: that you joined it and with which intent, that a mind was found and roughly how close the two maps ran, or that the pool was empty. Whether you shared a link is recorded as a yes or a no — the link itself never is, and neither is the other person’s name, link, or anything they answered.
The invite link is stripped out of the page address before analytics ever reads it, so the name and answers inside a link you were sent are never reported to Google.
Google receives the usual things any website's analytics receives: an approximate location from your IP address, your device and browser type, and the page address. If you would rather send nothing at all, any tracker blocker stops it, and the site works exactly the same without it.
Separately, the server keeps a small count of its own — that a map was registered, that a place in the pool was taken, that an introduction was made — with the same rule: enumerated labels and numbers, never anything you wrote or answered.
ADDRESSES AND ABUSE
Every request to a website carries the address it came from, and ours are handled by Vercel, who keep operational logs on our behalf. We use that address for one thing, for one minute: counting requests, so nobody can hammer the server. It is held in memory to do the counting and is never written to the database, never attached to a map, and never used to work out who anybody is.
VOICE
Every question has a microphone button next to the options. It is optional. Tapping an answer does exactly the same thing and always will — if the button is missing, your browser cannot do it, and nothing is lost.
Nothing is listening until you press it. Likely never opens the microphone on its own, and never keeps it open between questions. Pressing the button once starts a single short attempt, and it ends when you stop speaking, when you press it again, or after a few seconds — whichever comes first.
Where the sound goes depends on your browser, and there are only two possibilities.
Most browsers have dictation built in. In that case your speech is handled by the dictation service your browser already uses — Google’s in Chrome, Apple’s in Safari — under that company’s own privacy policy, exactly as it would be if you pressed the microphone key on your keyboard. It never passes through Likely at all.
Where a browser has no dictation of its own, Likely records a clip of a few seconds and sends it to our own server, which passes it straight to OpenAI to be turned into text and sends the text back to your browser. We use the API, not the consumer product: OpenAI states that API content is not used to train their models. The clip is held only for the moment it takes to make that one request. It is never written to a disk, never put in a database, and never logged.
What we keep from a choice question: nothing. Not the audio, not the transcript. The only thing that survives is the same single digit an option tap would have produced.
The words you spoke are shown back to you on screen so you can see what was understood before it becomes your answer, and if the answer is wrong you can change it with a tap. When the text does not clearly match one of the options, that text — and only that text, with the question and the options next to it — is sent to our server and on to OpenAI to work out which option you meant. Your name is not sent, your other answers are not sent, and no identifier of any kind is attached.
The open response is different. If you choose Dictate beside the text box, the transcript becomes editable text in that box, exactly as if you typed it. If you use it, it is stored only in your browser with the guided-experience record so your reflection survives a refresh. It is never sent to Likely’s database, analytics, or the invitation link. You can skip the response without penalty.
Analytics sees that voice was used, on which question, and whether it worked. It never sees a transcript. That rule has no exceptions.
If you would rather none of this happened, simply do not press the microphone — or deny the permission when your browser asks, which makes the button disappear for the rest of the visit. The six questions work the same either way.
Separately: the “voice intro” inside the flagged discovery preview is still simulated — no audio is captured there.
WHO ELSE IS INVOLVED
Three companies, doing three jobs. Vercel serves the site and runs the small pieces of server code. Supabase hosts the database those rows live in. OpenAI turns speech into text, and only when you press the microphone. Google receives the analytics events described above. Nobody is sent your answers except Supabase, which stores them, and nobody is sold anything, ever.
CHILDREN
Likely is intended for adults aged 18 or older and is not directed at children. Joining the pool to meet someone is 18+ and asks you to confirm it on the screen, before anything is stored. We have no way to verify an age, so that confirmation is what it says it is: a statement you make.
CHANGES
This is an early prototype, so this page will change as the product does. Anything that starts collecting data will be written here before it is switched on, not after — as it was this time.
CONTACT
Questions, corrections, or a request to delete something: hello@likely.social.
LAST UPDATED 23 AUGUST 2026 · RESEARCH · ABOUT & LIMITS · BACK TO THE APP