Data Collected
Email, username, test results, settings, and usage statistics are collected.
🌐 monkeytype.com
Lists collected data and explicitly states what is NOT collected, but lacks details on safeguards for sensitive data like IP addresses and cookie IDs.
Covers GDPR rights (access, rectification, erasure, etc.) and mentions CMP for EU users, but has vague conditions and no mention of CCPA or data breach notification.
Allows unilateral policy changes without notice and retains hashed data indefinitely for anti-cheat, which may be seen as one-sided.
Uses plain language and a table of contents, but some sections (e.g., 'under certain conditions') are vague and could be clearer for non-lawyers.
- The policy states it can be changed at any given time without notice, so you may not learn about new data practices until after they have taken effect.
- Server-side collection of typing test data and settings may record sensitive or unique personal patterns that could be used to identify you.
- The right to access personal data can be arbitrarily limited by the company based on the "size of the request," with no clear definition of what that means.
- The right to erasure explicitly excludes hashed data used to prevent "exploitation," but it is vague about what qualifies as exploitation and how long this data will be kept.
- The analytics section uses Google Analytics but incorrectly claims this data "DOES NOT CONTAIN ANY PERSONALLY IDENTIFIABLE INFORMATION," which is misleading because IP addresses can be personal data under many laws.
- Sentry crash reporting may collect an "anonymized replay of your session," which could still contain sensitive information or personal interactions with the site.
- Advertisements are managed by a third party (Playwire) that uses cookies and tracking technologies, and the policy does not clearly explain which data is shared with them.
- The Common ID cookie tracks users across sites for advertising, and while an opt-out link is provided, you have to actively find and use it.
- Cookie consent preferences are buried in a "Danger Zone" settings section, making it less obvious how to change or withdraw consent later.
- The policy does not specify where data is stored or what security measures are used to protect it beyond mentioning MongoDB.
- There is no clear data retention period for most data types, so personal information could be kept indefinitely without clear justification.
- For users outside the EU, there are no stated protections or rights regarding advertising and data processing.
- The policy does not address whether data is transferred across borders or what safeguards apply if it is.
Email, username, test results, settings, and usage statistics are collected.
Custom texts are stored locally, not on servers.
Hashed data may be stored to prevent account abuse.
Users can access, correct, delete, or transfer their data.
Optional ads use cookies; consent can be withdrawn.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free