Privacy Policy
Last updated: March 4, 2026
ShareTree Inc. (“ShareTree,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our character assessment platform, AI coaching services, and CharaCards trading card game (collectively, the “Platform”).
We specialize in helping students discover their character strengths through research-backed archetype assessments, AI-powered career guidance, and gamified learning experiences. By using our Platform, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Personal Information
When you create an account, we collect personal information that can be used to identify you:
- Full name and email address
- Grade level or educational status
- Profile photo (optional, user-uploaded)
- Authentication credentials (passwords are hashed; we use Supabase Auth and Google OAuth)
- Organization or school affiliation (if provided)
1.2 Character Assessment Data
Our core service involves research-backed character assessments. We collect:
- Quiz responses from pairwise comparisons and value rankings
- Your top and least dominant character archetypes from the 12 archetype model
- Detailed archetype scores across Wisdom, Courage, Compassion, Trustworthiness, Tolerance, Self-Discipline, Mindfulness, Respect, Love, Truthfulness, Hope, and Purposefulness
- Career priority rankings and preferences
- Assessment metadata (time spent, completion date, device type)
1.3 AI Coaching Interaction Data
When you interact with Charo, our AI coach, we collect:
- Conversation history and chat messages
- Your character archetype profile used for personalized coaching context
- Career guidance questions and AI-generated recommendations
1.4 CharaCards Game Data
For our trading card game, we collect:
- Card collection inventory and deck configurations
- Match history and game results (PvP and vs. AI)
- Player ELO ratings and leaderboard rankings
- PvP room participation and challenge completion records
- Game statistics including wins, losses, and play patterns
1.5 Technical and Usage Information
We automatically collect certain technical information:
- IP address and browser type
- Device information and operating system
- Usage patterns and feature interactions
- Error logs and performance data (via Sentry)
- Cookies and similar tracking technologies
2. Character Assessment Data
Our proprietary 12-archetype character assessment is based on established positive psychology research. The archetypes we measure are:
Wisdom
Courage
Compassion
Trustworthiness
Tolerance
Self-Discipline
Mindfulness
Respect
Love
Truthfulness
Hope
Purposefulness
Your assessment results are used to:
- Generate personalized career pathway recommendations via AI
- Provide contextualized coaching conversations with Charo
- Create archetype-matched card decks in CharaCards
- Enable character strength development tracking over time
- Produce research-aggregated insights (anonymized only)
We do not sell your individual assessment results. Aggregated, anonymized data may be used for educational research and platform improvement.
3. AI Coaching Conversations
Charo, our AI coach, is powered by Google Genkit and Google AI services. When you use the coaching feature:
- Your messages are processed by AI systems to generate contextual responses
- Your character archetype profile provides personalized coaching context
- Conversation history is stored to maintain continuity across sessions
- We do not use your conversations to train AI models without explicit consent
- Sensitive personal disclosures are treated with additional confidentiality
Important: While Charo provides guidance based on character strengths and career interests, it is not a substitute for professional mental health counseling, therapy, or crisis intervention. If you are experiencing a mental health emergency, please contact emergency services or a licensed professional.
4. CharaCards Game Data
CharaCards is a trading card game that gamifies character development. Game data includes:
- Card Collections: Cards owned (0-4 copies per card), including Character, Action, Reaction, and Trait cards
- Decks: Your saved 20-card deck configurations organized by archetype tiers (Professional, Social, Spiritual)
- Match History: Game results, opponent information (for PvP), and performance metrics
- Ratings: ELO scores for competitive matchmaking and leaderboard positioning
- Challenges: Single-player scenario completions and progress tracking
Game data may be displayed on public leaderboards (showing username and rating only). You can adjust privacy settings in your profile to control leaderboard visibility.
5. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: Providing character assessments, AI coaching, career guidance, and the CharaCards game
- Personalization: Tailoring content, recommendations, and coaching to your unique character profile
- Account Management: Maintaining your account, authentication, and profile settings
- Gamification: Tracking points, levels, badges, and achievements
- Communication: Sending service updates, assessment results, and optional newsletters
- Platform Improvement: Analyzing usage patterns to improve features and user experience
- Security: Detecting fraud, abuse, and unauthorized access
- Legal Compliance: Fulfilling legal obligations and protecting our rights
6. Data Sharing and Disclosure
We do not sell your personal information. We may share data in the following circumstances:
6.1 Service Providers
We engage trusted third-party providers for:
- Supabase (database hosting and authentication)
- Google AI/Genkit (AI coaching and career guidance generation)
- Sentry (error monitoring and performance tracking)
- Cloud storage and CDN services
All service providers are contractually bound to process data only for specified purposes and maintain appropriate security measures.
6.2 Educational Institutions
If your account is associated with a school or organization:
- Aggregated, anonymized reports may be shared with authorized administrators
- Individual student data is only shared with explicit consent or as required by educational agreements
- Parents/guardians may access dependent student data through verified family accounts
6.3 Legal Requirements
We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety.
6.4 Business Transfers
In the event of a merger, acquisition, or asset sale, your information may be transferred as a business asset, subject to the same privacy commitments.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Row-Level Security (RLS) in our PostgreSQL database ensuring users can only access their own data
- Secure authentication via Supabase Auth with bcrypt password hashing
- Regular security audits and penetration testing
- Employee access controls and confidentiality agreements
- Automated monitoring for suspicious activity via Sentry
While we take reasonable precautions, no internet transmission is completely secure. We encourage you to use strong passwords and enable any available security features.
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal information
- Correction: Update inaccurate or incomplete information
- Deletion: Request deletion of your account and associated data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your information
- Objection: Object to certain processing activities
- Withdrawal of Consent: Revoke consent for optional data uses
To exercise these rights, visit your Profile Settingsor contact us at privacy@sharetree.org. We will respond within 30 days of receiving a verified request.
Data Export: You can download your complete data including assessment results, coaching history, and game data from your profile settings at any time.
9. Children and Students
ShareTree is designed for students and young adults exploring their character strengths and career paths.
9.1 Age Requirements
- Users under 13 must have verifiable parental consent to create an account
- Users aged 13-16 should review this policy with a parent or guardian
- We comply with applicable children's privacy laws including COPPA (US), GDPR-K (EU), and similar regulations
9.2 Parental Rights
Parents and guardians can:
- Review their child's personal information
- Request deletion of their child's account and data
- Refuse further collection or use of their child's information
- Contact us to exercise these rights at privacy@sharetree.org
9.3 Educational Contexts
When ShareTree is used through a school or educational institution, we work with administrators to ensure compliance with FERPA (Family Educational Rights and Privacy Act) and equivalent educational privacy laws. Student data is used solely for educational purposes with appropriate consent and safeguards.
10. International Data Transfers
ShareTree is operated from the United States. If you access the Platform from outside the US, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) with our service providers
- Adequacy decisions where applicable
- Data processing agreements ensuring GDPR-compliant handling
By using our Platform, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.
11. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active; deleted within 30 days of account closure
- Assessment Data: Retained indefinitely for longitudinal character development tracking (unless deletion requested)
- AI Conversations: Retained for 2 years to maintain coaching continuity, then anonymized or deleted
- Game Data: Retained indefinitely for historical leaderboard integrity; anonymized after account deletion
- Technical Logs: Retained for 90 days for security and debugging purposes
You can request earlier deletion of your data at any time through your profile settings or by contacting us.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or Platform features. We will:
- Post the updated policy with a new “Last updated” date
- Notify you via email or platform notification for material changes
- Obtain renewed consent where required by law
Your continued use of the Platform after changes constitutes acceptance of the updated policy. We encourage you to review this page regularly.
By using ShareTree, you acknowledge that you have read, understood, and agree to this Privacy Policy.