Privacy Policy — Mastera
Effective: 20 September 2026
Last updated: 20 September 2026
This policy explains what Mastera does with your data. It describes the app as it is actually built, not as we might like it to sound.
The data controller is {{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. Privacy questions: privacy@masteraai.com.
1. The short version
- You can use the whole free part of Mastera without giving us your name or email.
- Your lesson progress, streak, quiz answers and settings are stored on your phone, not on our servers.
- We give your device a random install id. It is not your name, your email, or a device advertising id. It becomes connected to you only if you choose to sign in.
- We work out a "lifecycle stage" for you on your own device — roughly, how engaged you are and whether you've paid — and use it to decide what messages you get. Section 6 explains it fully, because we think you should be able to see it rather than find it.
- The study reminder and promotional messages are two separate permissions. Turning one on never turns the other on.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- We do not use open tracking in email. We don't try to detect whether you opened a message.
2. What the app does today
We think a privacy policy should say which parts are live. Right now:
| Thing | Status today |
|---|---|
| Progress, streaks, quiz answers, settings | Stored on your device only |
| Analytics events | Generated but not sent anywhere. The analytics provider is not connected; events are written to a local debug log during development |
| Account / email sign-in | Screen exists; the backend is not connected, so no email is actually sent or stored by us |
| Purchases | The billing provider is not connected. No real charges are taken in the current build |
| Crash reporting | Not connected |
| Advertising / attribution SDK | Not present in the app |
| Push notifications from our servers | Not connected. The daily reminder is scheduled locally by your phone |
| Font loading | The app downloads its typeface from Google's font servers the first time you run it (see section 8) |
This policy also describes what each service will do once we connect it, so the rules don't change under you without notice. We will update the table above and the "Last updated" date, and tell you in the app, before any of those services starts collecting.
3. What we collect, why, and on what legal basis
"Legal basis" is a GDPR term (Article 6). If you're not in the EU or UK you can ignore that column; the purposes are the same either way.
3.1 Data stored on your device
This stays on your phone. We can't read it. It's deleted when you uninstall the app or clear its storage.
| What | Examples | Why | Legal basis |
|---|---|---|---|
| Learning progress | lessons completed, courses started, certificates earned | Show you where you are | Art 6(1)(b) — providing the service |
| Engagement | daily streak, lessons today, one forgiven missed day | Streaks and the daily goal | Art 6(1)(b) |
| Onboarding quiz answers | what you want to get better at, how much you've used AI, why you're here, minutes a day | Order the courses and set the tone | Art 6(1)(b) |
| Settings | theme, reminder on/off, reminder time, promotional opt-in | Remember your choices | Art 6(1)(b) |
| Lifecycle timestamps | first open, last open, last lesson, paywall shown count, purchase started / succeeded / failed | Input to the lifecycle stage (section 6) | Art 6(1)(f) — legitimate interest in sending relevant, infrequent messages |
| Lesson feedback | your rating and tags on a lesson | Improve lessons | Art 6(1)(f) |
| Install id | a 16-byte random value created on first run | Join your own events into one timeline | Art 6(1)(f); consent in the EEA/UK before it is transmitted |
| Sign-in state | your email address and session token, if you sign in | Keep you signed in | Art 6(1)(b) |
3.2 Analytics (once the analytics provider is connected)
Events. Each event is an action plus a few parameters. The full list we instrument:
app_open · screen_view · notification_opened · cta_tapped · onboarding_started · onboarding_completed · quiz_started · quiz_step_answered · quiz_completed · course_opened · lesson_started · lesson_completed · course_completed · certificate_earned · paywall_shown · paywall_dismissed · plan_selected · purchase_started · purchase_succeeded · purchase_failed · purchase_restored · lesson_survey_submitted · rating_prompt_shown · streak_incremented · daily_goal_reached · reminder_scheduled · reminder_prompt_shown · reminder_prompt_accepted · reminder_prompt_declined · reminder_action_pressed · sign_in_started · sign_in_completed
That is the whole list. If we add an event we add it here.
Attributes attached to you. These describe your account or device, not a single action:
| Attribute | What it holds | Note |
|---|---|---|
plan | free or pro | |
lessons_done | a band, e.g. 6-20 | not the exact number |
courses_started | a band | |
certificates | a band | |
streak_days | a band | |
reminder_on | yes / no | |
reminder_hour_local | the hour you chose, e.g. 19 | so a message lands at your hour, not ours |
tz_iana | your IANA time zone, e.g. Europe/Berlin | a region, not a location |
lifecycle_stage | one of 12 values — section 6 | |
overlays | e.g. streak_at_risk | short-lived flags |
quiz_goals, quiz_experience, quiz_goal, quiz_time | your onboarding quiz answers | |
signed_in | yes once you sign in |
We deliberately store counts as bands rather than exact values. "6-20 lessons" is enough to decide what to say to you; "17" is not needed.
Purpose: understand which lessons work, which screens lose people, and whether a change helped. Legal basis: your consent in the EEA and the UK, because analytics reads and writes identifiers on your device; legitimate interests (Art 6(1)(f)) elsewhere, where you can object at any time.
3.3 Account data (once the backend is connected)
| What | Why | Legal basis |
|---|---|---|
| Email address | It is your account key. We email you a sign-in link or code | Art 6(1)(b) |
| Account id | Links your purchases, progress and events to one account | Art 6(1)(b) |
| Sign-in timestamps and IP address at sign-in | Security, abuse prevention | Art 6(1)(f) |
We do not use passwords, so we never store one.
3.4 Purchases
We never see or store your card details. Apple, Google, or our web payment processor handle the payment.
| What | Why | Legal basis |
|---|---|---|
| Which plan you bought, when, currency, renewal and trial status, store receipt / transaction id | Give you access, handle renewals, support and refunds | Art 6(1)(b) |
| Purchase records for tax and accounting | We have to keep them | Art 6(1)(c) — legal obligation |
3.5 Crash and performance data (once crash reporting is connected)
Error messages, stack traces, app version, OS version, device model, and a breadcrumb trail of the screens you visited before the crash. Purpose: fix crashes. Basis: Art 6(1)(f). We configure the crash tool not to attach your email address or to record screen contents.
3.6 Messaging
| What | Why | Legal basis |
|---|---|---|
| The fact that you turned the study reminder on, and at what time | Schedule it | Art 6(1)(a) — consent (you also grant the OS notification permission) |
| Promotional opt-in | Send offers and new-course news | Art 6(1)(a) — consent, separately given |
| Transactional emails: sign-in link, purchase receipt, auto-renewal acknowledgement, renewal reminder, failed-payment notice | Run your account and meet our legal obligations | Art 6(1)(b) and Art 6(1)(c) |
| Link clicks in our emails | Know whether a message was useful | Art 6(1)(f) |
3.7 What we never collect
No precise or coarse location. No contacts. No photos, camera or microphone. No health data. No biometrics. No advertising identifier (IDFA / GAID) in the current build. No browsing history outside our app. We ask for two Android permissions only — post notifications, and receive boot-completed so a scheduled reminder survives a restart.
4. The install id, in plain terms
On first run the app generates 16 random bytes and stores them on your device. That is your install id.
- It is not the device advertising identifier, and not a hardware id.
- It does not contain your name, email, phone number or location.
- It is pseudonymous, not anonymous. By itself it identifies a phone, not a person. We still treat it as personal data under GDPR.
- It becomes linked to a person only if you sign in. At that moment we connect the install id to your account id so your earlier lessons aren't orphaned from your account. That linking is described in the app's code as "alias", and it is one-way: your account gains your earlier activity.
- To reset it: delete the app and reinstall, or clear the app's storage. A fresh install id is generated and nothing from the old one follows you.
5. Where your data goes
| Recipient | What it would receive | Status | Role |
|---|---|---|---|
| Google (Firebase Analytics / Remote Config) | events, the attributes in 3.2, install id | Planned, not connected | Processor |
| Adapty | purchase and entitlement state, account id | Planned, not connected | Processor |
| Supabase | email address, account id, progress if you sync | Planned, not connected | Processor |
| Sentry | crash reports | Planned, not connected | Processor |
| AppsFlyer | install attribution, campaign, device signals | Planned, not present in the app | Processor |
| no email provider (we do not send marketing email yet) (email + push) | email address, lifecycle stage, click events | Planned, not connected | Processor |
| Apple / Google | your purchase, as the store that sold it | Live for any store purchase | Independent controller |
| not applicable (we do not sell on this website) | payment details for website purchases | Planned, not built | See their own policy |
| Google Fonts | your IP address, when the app fetches its typeface | Live today — see section 8 | Independent controller |
We do not sell your data. We do not give it to data brokers. We would disclose data if the law required it, or to a buyer if the business were sold — in which case we'd tell you first.
6. The lifecycle stage — what it is and why we're telling you
We want this in the open rather than buried.
Your phone works out a single label describing where you are with Mastera. It is computed on the device, from data already on the device, with a fixed set of rules. One of these applies at a time:
trial_active · new_payer · engaged_payer · at_risk_payer · payer_grace · lapsed_payer · trial_lapsed · paywall_bounced · activated_free · dormant_free · never_activated · abandoned
Short-lived flags can sit on top: streak_at_risk, finisher_no_next, stalled_starter.
The inputs are: whether you're a subscriber now, whether you ever were, how many lessons you've done, certificates earned, courses started, your streak, days since you installed, days since you last opened the app, days since your last lesson, how many times you've seen the paywall and whether you closed it, and whether a purchase was started, succeeded or failed.
What we use it for: deciding whether to send you a message, which message, and on which channel. For example, if you haven't opened the app in 60 days you are abandoned and we stop sending you anything at all — the label is used to protect you from us as often as the other way round.
What we do not use it for: we don't change your price, restrict your access, refuse you a refund, or make any other decision about you based on it. There is no automated decision that produces a legal or similarly significant effect on you, so GDPR Article 22 doesn't apply. We do not profile you against other people's data, and we don't buy data about you from anyone.
How to stop it. Turn off the study reminder and leave the promotional opt-in off, and no message is sent on the strength of it. Once analytics is connected you can also object at privacy@masteraai.com and we'll stop sending the attribute and exclude you from stage-based messaging.
7. Notifications and email — two separate permissions
We keep these apart on purpose, and the app is built that way.
1. The study reminder. A once-a-day nudge at a time you pick. It's scheduled by your own phone; nothing about it goes to a server. It's off until you turn it on. It schedules at most 3 days ahead and then stops, rather than nagging forever.
To turn it off: the toggle in Profile; or the "Turn off reminders" button on the notification itself; or your phone's notification settings. On Android it lives in its own "Study reminders" channel.
2. Promotional messages. Offers and new courses. Separate opt-in, off by default. Turning on the study reminder does not opt you into these — a study nudge is not marketing consent.
To turn it off: the promotional toggle in Profile; the "Offers and new courses" channel in Android settings; the unsubscribe link in any marketing email; or email privacy@masteraai.com.
3. Account and billing messages. Sign-in links, receipts, auto-renewal acknowledgements, renewal reminders, failed-payment notices. These are part of your contract with us, so they aren't subject to a marketing opt-in. You can't turn them off while you have a paid subscription — a renewal or payment failure notice is exactly the kind of thing you'd want to see. On Android they're in their own "Payments and renewals" channel so that muting offers never mutes them.
Email consent specifics:
- In the EU and UK, if you sign up for a free account in the app we do not add you to marketing email. There was no sale, so no soft opt-in applies. We ask with an unticked box, and an unticked box is a "no".
- If you bought something, we may email you about similar things under the soft opt-in, with an opt-out on every message. In Ireland that stops 12 months after the sale. In Germany we rely on it only where a contract was actually concluded.
- Every marketing email identifies itself as such, carries a one-click unsubscribe, includes our postal address ({{POSTAL_ADDRESS}}), and is honoured within 48 hours.
- We do not use open tracking. Our email provider's tracking pixel is turned off. We don't measure, report on, or trigger anything from whether you opened a message. We do count clicks on links, which we tell you here rather than in a footnote.
8. The font download
The app renders its typeface with the google_fonts package, which fetches the font from Google's servers the first time you run the app, then caches it.
That request tells Google your IP address, the font requested, and standard network metadata. We don't receive anything from it and it carries no id of ours. Google's handling is covered by its own privacy policy.
We consider this avoidable and intend to bundle the font with the app so no request is made. Until we do, this section stays here, because a policy that didn't mention it would be wrong.
9. Keeping data, and for how long
| Data | How long |
|---|---|
| Everything on your device | Until you uninstall or clear app storage |
| Analytics events and attributes | 14 months, then deleted or aggregated |
| Crash reports | 90 days |
| Account (email, account id, progress) | While your account exists, then 30 days, then deleted |
| Purchase and tax records | 7 years — we're required to keep these |
| Marketing consent and unsubscribe records | While you're subscribed, plus 3 years, as proof we had consent |
| Support emails | 2 years from the last message |
10. Where data is processed
We're based in Israel. Our providers process data in the United States, the EU and elsewhere. Where personal data leaves the EEA or the UK we rely on the European Commission's Standard Contractual Clauses with the UK Addendum or the UK IDTA, or on an adequacy decision — including the EU-US Data Privacy Framework where the provider is certified. Ask privacy@masteraai.com for a copy of the relevant safeguards.
Once the backend is connected, our primary data store will be in on your own device (no analytics or backend service is connected yet).
11. Security — honestly stated
- Traffic to our services uses HTTPS/TLS. Cleartext traffic is disabled in the app.
- The app ships with no secret keys inside it. Keys are injected at build time and are the public, scoped kind.
- Sign-in is passwordless, so there's no password of yours to steal from us.
- Data on your device sits in the app's private storage, protected by your phone's own sandbox and, if you use one, your device encryption. We do not add a second layer of encryption on top, and your sign-in token is stored in ordinary app preferences. On an unlocked, rooted or jailbroken device, another app with enough privilege could read it. We're saying so rather than claiming protection we haven't built.
- No system is perfectly secure. If a breach affects you, we'll notify you and the relevant regulator as the law requires — within 72 hours of becoming aware, where GDPR applies.
12. Your rights
If you're in the EU, the UK, Switzerland, or a country with similar law
You can ask us to: see your data, correct it, delete it, restrict what we do with it, export it in a portable format, or object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time — that doesn't undo what we did before.
Email privacy@masteraai.com. We answer within 30 days. If your request is complex we may take up to 60 and we'll tell you why. We may ask you to confirm you control the email address on the account — we won't ask for ID documents unless there's a real doubt.
Most of your data is on your phone and we can't reach it. Deleting the app deletes it. If you want that data gone and you've signed in, delete the app and email us to close the account.
You can complain to your data protection authority at any time. In the UK that's the ICO (ico.org.uk). {{LEAD_SUPERVISORY_AUTHORITY}}.
EU representative (Art 27): {{EU_REPRESENTATIVE}}
UK representative: {{UK_REPRESENTATIVE}}
Data protection contact: {{DPO_CONTACT}}
If you're in California
Categories of personal information we collect, under the CCPA/CPRA:
| CCPA category | Do we collect it? | Examples |
|---|---|---|
| Identifiers | Yes | install id, account id, email address (if you sign in), IP address at sign-in |
| Customer records (Cal. Civ. Code §1798.80) | Yes | email, purchase record |
| Commercial information | Yes | which plan you bought, renewal status |
| Internet / app activity | Yes | lessons opened and completed, screens viewed, paywall interactions |
| Geolocation data | No | we collect a time zone, not a location |
| Biometric, sensory, health data | No | |
| Employment or education records | No | the quiz asks what you want to get better at; that is not an employment or education record |
| Inferences | Yes | the lifecycle stage in section 6 |
| Sensitive personal information | No | we don't collect any category of sensitive PI, so there's nothing to limit |
Sources: you, and your device. Purposes: sections 3 and 6. Disclosure: to the service providers in section 5, for those purposes only.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the last 12 months, and we don't today. If that changes — for example if we add an advertising or attribution SDK — we will update this policy, add a "Do Not Sell or Share My Personal Information" control, and honour Global Privacy Control signals on our website before it changes.
Your rights: know, access, delete, correct, portability, opt out of sale or sharing, limit use of sensitive PI, and not be discriminated against for using any of them. We don't offer financial incentives for data. An authorised agent can act for you with written permission. Email privacy@masteraai.com.
If you're in Virginia, Colorado, Connecticut, Texas, Oregon, or a similar state
You have broadly the same rights — access, correct, delete, portability, and opt out of targeted advertising, sale, and profiling with significant effects. We don't do targeted advertising or that kind of profiling. Same address: privacy@masteraai.com. If we refuse a request you can appeal by replying, and we'll answer the appeal within 45 days.
13. Children
Mastera is for people aged 13 and over, and it is not directed at children. It isn't in the Kids category on the App Store, we don't declare a child audience on Google Play, and nothing in it is designed to appeal to under-13s rather than adults.
- We don't knowingly collect personal data from anyone under 13. If we learn we have, we delete it. Tell us at privacy@masteraai.com.
- In the EEA, where consent is the basis and the national digital-consent age is higher than 13 (it ranges from 13 to 16), a parent or guardian must consent.
- Under 18 you can't buy a subscription — see the Terms, section 2.
- We do not verify age. We rely on the store's age rating and on this statement. We're telling you that rather than implying a check we don't run.
This position is what we declare on the Google Play Data Safety form (target audience 13+, not designed for children) and in the App Store age rating. If one ever changes, the other two change with it.
14. Store disclosure map
One source of truth for whoever fills in Apple's Privacy Nutrition Label and Google's Data Safety form. Anything marked planned is declared only once that service is actually connected and shipping.
| Our data | Apple label category | Apple: linked to you? | Apple: used to track? | Play Data Safety | Play: collected / shared | Optional? |
|---|---|---|---|---|---|---|
| Email address | Contact Info → Email Address | Linked | No | Personal info → Email address | Collected, not shared | Optional |
| Account id | Identifiers → User ID | Linked | No | Personal info → User IDs | Collected, not shared | Required once signed in |
| Install id | Identifiers → Device ID | Not linked until you sign in | No | Device or other IDs | Collected, not shared | Required (planned) |
| Purchase / plan / renewal state | Purchases → Purchase History | Linked | No | Financial info → Purchase history | Collected, not shared | Required for purchases |
| Lesson, screen and paywall events | Usage Data → Product Interaction | Linked if signed in, else not linked | No | App activity → App interactions | Collected, not shared | Required (planned) |
| Quiz answers | Usage Data → Other Usage Data | Same | No | App activity → Other actions | Collected, not shared | Optional |
| Lifecycle stage and bands | Usage Data → Other Usage Data | Same | No | App activity → Other actions | Collected, not shared | Required (planned) |
| Lesson feedback / survey | User Content → Other User Content | Same | No | App activity → Other user-generated content | Collected, not shared | Optional |
| Time zone, reminder hour | Usage Data → Other Usage Data | Same | No | App activity → Other actions | Collected, not shared | Optional |
| Crash reports, performance | Diagnostics → Crash Data, Performance Data | Not linked | No | App info and performance → Crash logs, Diagnostics | Collected, not shared | Optional (planned) |
| IP address at sign-in | Identifiers → Device ID (server-side; not collected by the app) | Linked | No | Not declarable as app-collected; disclosed here | — | — |
| Location | — | — | — | — | Not collected | — |
| Contacts, photos, files, health, messages | — | — | — | — | Not collected | — |
| Advertising id (IDFA / GAID) | — | — | — | — | Not collected | — |
"Tracking" in Apple's sense — linking your data with data from other companies' apps or websites for advertising or data-brokerage — is "No" throughout. The app does not present Apple's App Tracking Transparency prompt because it does nothing that requires one. If we add an attribution SDK, that changes, and both this table and the store declarations change with it.
Data deletion: because everything is either on your device or tied to an account you can close, our Play Data Safety answer is that users can request deletion, via privacy@masteraai.com and the account deletion route described in section 12.
15. Changes to this policy
If we change something that matters — a new category of data, a new recipient, a new purpose — we'll tell you in the app before it takes effect, and where the law requires it, ask you again. The "Last updated" date at the top is always accurate.
16. Contact us
{{LEGAL_ENTITY}}
{{POSTAL_ADDRESS}}
Privacy: privacy@masteraai.com
Support: support@masteraai.com