Mastify

Privacy Policy

Effective 15 July 2026

Mastify is a study tool that helps computer science students practice course material through spaced-repetition flashcards and exam-style problems. This policy explains what data we collect, why we collect it, and how it is handled.

1. What we collect

  • Account data — your name and email address, provided when you sign up.
  • Study activity — your answers to practice questions, timestamps, and self-assessment ratings on exam problems.
  • Progress data — XP, level, streak, and per-topic mastery scores derived from your activity.
  • Session data — a session token stored in your browser to keep you logged in.

We do not collect payment information, location data, or any data from the websites you visit beyond what is needed to operate the Chrome extension (see below).

2. Chrome extension

The Mastify browser extension blocks distracting websites and shows a flashcard before granting access. The extension:

  • Reads the hostname of the page you visit to determine if it is on your blocked list.
  • Stores your blocked-site list and session token in Chrome local storage — this data never leaves your device except to communicate with mastify.app.
  • Does not read page content, track browsing history, or send data to any third party.

3. How we use your data

  • To operate the app — schedule questions, track mastery, and display your progress.
  • To send transactional emails — password reset and account-related notifications only. We do not send marketing email.
  • To diagnose errors — unhandled runtime errors are emailed to the developer to help fix bugs.

4. Third-party services

We use the following sub-processors:

  • Neon — Postgres database hosting (your data at rest).
  • Vercel — web app hosting and edge infrastructure.
  • Resend — transactional email delivery.

No data is sold or shared with advertisers or data brokers.

5. Data retention and deletion

Your data is kept for as long as your account is active. You can delete your account at any time from the Settings page — this permanently removes your account, all study history, and progress data. Backups may retain data for up to 30 days after deletion.

6. Security

Passwords are hashed and never stored in plaintext. All data in transit is encrypted via HTTPS. Session tokens are stored in HTTP-only cookies where possible.

7. Children

Mastify is intended for university students (18+). We do not knowingly collect data from anyone under 13.

8. Changes to this policy

If we make material changes, we will update the effective date at the top of this page. Continued use of Mastify after changes are posted constitutes acceptance.

9. Contact

Questions or requests (access, correction, deletion): arnavgupta09au@gmail.com