Privacy Policy — Mastera

Effective: 20 September 2026
Last updated: 20 September 2026

This policy explains what Mastera does with your data. It describes the app as it is actually built, not as we might like it to sound.

The data controller is {{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. Privacy questions: [email protected].


1. The short version

2. What the app does today

We think a privacy policy should say which parts are live. Right now:

ThingStatus today
Progress, streaks, quiz answers, settingsStored on your device only
Analytics eventsGenerated but not sent anywhere. The analytics provider is not connected; events are written to a local debug log during development
Account / email sign-inScreen exists; the backend is not connected, so no email is actually sent or stored by us
PurchasesThe billing provider is not connected. No real charges are taken in the current build
Crash reportingNot connected
Advertising / attribution SDKNot present in the app
Push notifications from our serversNot connected. The daily reminder is scheduled locally by your phone
Font loadingThe app downloads its typeface from Google's font servers the first time you run it (see section 8)

This policy also describes what each service will do once we connect it, so the rules don't change under you without notice. We will update the table above and the "Last updated" date, and tell you in the app, before any of those services starts collecting.

3. What we collect, why, and on what legal basis

"Legal basis" is a GDPR term (Article 6). If you're not in the EU or UK you can ignore that column; the purposes are the same either way.

3.1 Data stored on your device

This stays on your phone. We can't read it. It's deleted when you uninstall the app or clear its storage.

WhatExamplesWhyLegal basis
Learning progresslessons completed, courses started, certificates earnedShow you where you areArt 6(1)(b) — providing the service
Engagementdaily streak, lessons today, one forgiven missed dayStreaks and the daily goalArt 6(1)(b)
Onboarding quiz answerswhat you want to get better at, how much you've used AI, why you're here, minutes a dayOrder the courses and set the toneArt 6(1)(b)
Settingstheme, reminder on/off, reminder time, promotional opt-inRemember your choicesArt 6(1)(b)
Lifecycle timestampsfirst open, last open, last lesson, paywall shown count, purchase started / succeeded / failedInput to the lifecycle stage (section 6)Art 6(1)(f) — legitimate interest in sending relevant, infrequent messages
Lesson feedbackyour rating and tags on a lessonImprove lessonsArt 6(1)(f)
Install ida 16-byte random value created on first runJoin your own events into one timelineArt 6(1)(f); consent in the EEA/UK before it is transmitted
Sign-in stateyour email address and session token, if you sign inKeep you signed inArt 6(1)(b)

3.2 Analytics (once the analytics provider is connected)

Events. Each event is an action plus a few parameters. The full list we instrument:

app_open · screen_view · notification_opened · cta_tapped · onboarding_started · onboarding_completed · quiz_started · quiz_step_answered · quiz_completed · course_opened · lesson_started · lesson_completed · course_completed · certificate_earned · paywall_shown · paywall_dismissed · plan_selected · purchase_started · purchase_succeeded · purchase_failed · purchase_restored · lesson_survey_submitted · rating_prompt_shown · streak_incremented · daily_goal_reached · reminder_scheduled · reminder_prompt_shown · reminder_prompt_accepted · reminder_prompt_declined · reminder_action_pressed · sign_in_started · sign_in_completed

That is the whole list. If we add an event we add it here.

Attributes attached to you. These describe your account or device, not a single action:

AttributeWhat it holdsNote
planfree or pro
lessons_donea band, e.g. 6-20not the exact number
courses_starteda band
certificatesa band
streak_daysa band
reminder_onyes / no
reminder_hour_localthe hour you chose, e.g. 19so a message lands at your hour, not ours
tz_ianayour IANA time zone, e.g. Europe/Berlina region, not a location
lifecycle_stageone of 12 values — section 6
overlayse.g. streak_at_riskshort-lived flags
quiz_goals, quiz_experience, quiz_goal, quiz_timeyour onboarding quiz answers
signed_inyes once you sign in

We deliberately store counts as bands rather than exact values. "6-20 lessons" is enough to decide what to say to you; "17" is not needed.

Purpose: understand which lessons work, which screens lose people, and whether a change helped. Legal basis: your consent in the EEA and the UK, because analytics reads and writes identifiers on your device; legitimate interests (Art 6(1)(f)) elsewhere, where you can object at any time.

3.3 Account data (once the backend is connected)

WhatWhyLegal basis
Email addressIt is your account key. We email you a sign-in link or codeArt 6(1)(b)
Account idLinks your purchases, progress and events to one accountArt 6(1)(b)
Sign-in timestamps and IP address at sign-inSecurity, abuse preventionArt 6(1)(f)

We do not use passwords, so we never store one.

3.4 Purchases

We never see or store your card details. Apple, Google, or our web payment processor handle the payment.

WhatWhyLegal basis
Which plan you bought, when, currency, renewal and trial status, store receipt / transaction idGive you access, handle renewals, support and refundsArt 6(1)(b)
Purchase records for tax and accountingWe have to keep themArt 6(1)(c) — legal obligation

3.5 Crash and performance data (once crash reporting is connected)

Error messages, stack traces, app version, OS version, device model, and a breadcrumb trail of the screens you visited before the crash. Purpose: fix crashes. Basis: Art 6(1)(f). We configure the crash tool not to attach your email address or to record screen contents.

3.6 Messaging

WhatWhyLegal basis
The fact that you turned the study reminder on, and at what timeSchedule itArt 6(1)(a) — consent (you also grant the OS notification permission)
Promotional opt-inSend offers and new-course newsArt 6(1)(a) — consent, separately given
Transactional emails: sign-in link, purchase receipt, auto-renewal acknowledgement, renewal reminder, failed-payment noticeRun your account and meet our legal obligationsArt 6(1)(b) and Art 6(1)(c)
Link clicks in our emailsKnow whether a message was usefulArt 6(1)(f)

3.7 What we never collect

No precise or coarse location. No contacts. No photos, camera or microphone. No health data. No biometrics. No advertising identifier (IDFA / GAID) in the current build. No browsing history outside our app. We ask for two Android permissions only — post notifications, and receive boot-completed so a scheduled reminder survives a restart.

4. The install id, in plain terms

On first run the app generates 16 random bytes and stores them on your device. That is your install id.

5. Where your data goes

RecipientWhat it would receiveStatusRole
Google (Firebase Analytics / Remote Config)events, the attributes in 3.2, install idPlanned, not connectedProcessor
Adaptypurchase and entitlement state, account idPlanned, not connectedProcessor
Supabaseemail address, account id, progress if you syncPlanned, not connectedProcessor
Sentrycrash reportsPlanned, not connectedProcessor
AppsFlyerinstall attribution, campaign, device signalsPlanned, not present in the appProcessor
no email provider (we do not send marketing email yet) (email + push)email address, lifecycle stage, click eventsPlanned, not connectedProcessor
Apple / Googleyour purchase, as the store that sold itLive for any store purchaseIndependent controller
not applicable (we do not sell on this website)payment details for website purchasesPlanned, not builtSee their own policy
Google Fontsyour IP address, when the app fetches its typefaceLive today — see section 8Independent controller

We do not sell your data. We do not give it to data brokers. We would disclose data if the law required it, or to a buyer if the business were sold — in which case we'd tell you first.

6. The lifecycle stage — what it is and why we're telling you

We want this in the open rather than buried.

Your phone works out a single label describing where you are with Mastera. It is computed on the device, from data already on the device, with a fixed set of rules. One of these applies at a time:

trial_active · new_payer · engaged_payer · at_risk_payer · payer_grace · lapsed_payer · trial_lapsed · paywall_bounced · activated_free · dormant_free · never_activated · abandoned

Short-lived flags can sit on top: streak_at_risk, finisher_no_next, stalled_starter.

The inputs are: whether you're a subscriber now, whether you ever were, how many lessons you've done, certificates earned, courses started, your streak, days since you installed, days since you last opened the app, days since your last lesson, how many times you've seen the paywall and whether you closed it, and whether a purchase was started, succeeded or failed.

What we use it for: deciding whether to send you a message, which message, and on which channel. For example, if you haven't opened the app in 60 days you are abandoned and we stop sending you anything at all — the label is used to protect you from us as often as the other way round.

What we do not use it for: we don't change your price, restrict your access, refuse you a refund, or make any other decision about you based on it. There is no automated decision that produces a legal or similarly significant effect on you, so GDPR Article 22 doesn't apply. We do not profile you against other people's data, and we don't buy data about you from anyone.

How to stop it. Turn off the study reminder and leave the promotional opt-in off, and no message is sent on the strength of it. Once analytics is connected you can also object at [email protected] and we'll stop sending the attribute and exclude you from stage-based messaging.

7. Notifications and email — two separate permissions

We keep these apart on purpose, and the app is built that way.

1. The study reminder. A once-a-day nudge at a time you pick. It's scheduled by your own phone; nothing about it goes to a server. It's off until you turn it on. It schedules at most 3 days ahead and then stops, rather than nagging forever.

To turn it off: the toggle in Profile; or the "Turn off reminders" button on the notification itself; or your phone's notification settings. On Android it lives in its own "Study reminders" channel.

2. Promotional messages. Offers and new courses. Separate opt-in, off by default. Turning on the study reminder does not opt you into these — a study nudge is not marketing consent.

To turn it off: the promotional toggle in Profile; the "Offers and new courses" channel in Android settings; the unsubscribe link in any marketing email; or email [email protected].

3. Account and billing messages. Sign-in links, receipts, auto-renewal acknowledgements, renewal reminders, failed-payment notices. These are part of your contract with us, so they aren't subject to a marketing opt-in. You can't turn them off while you have a paid subscription — a renewal or payment failure notice is exactly the kind of thing you'd want to see. On Android they're in their own "Payments and renewals" channel so that muting offers never mutes them.

Email consent specifics:

8. The font download

The app renders its typeface with the google_fonts package, which fetches the font from Google's servers the first time you run the app, then caches it.

That request tells Google your IP address, the font requested, and standard network metadata. We don't receive anything from it and it carries no id of ours. Google's handling is covered by its own privacy policy.

We consider this avoidable and intend to bundle the font with the app so no request is made. Until we do, this section stays here, because a policy that didn't mention it would be wrong.

9. Keeping data, and for how long

DataHow long
Everything on your deviceUntil you uninstall or clear app storage
Analytics events and attributes14 months, then deleted or aggregated
Crash reports90 days
Account (email, account id, progress)While your account exists, then 30 days, then deleted
Purchase and tax records7 years — we're required to keep these
Marketing consent and unsubscribe recordsWhile you're subscribed, plus 3 years, as proof we had consent
Support emails2 years from the last message

10. Where data is processed

We're based in Israel. Our providers process data in the United States, the EU and elsewhere. Where personal data leaves the EEA or the UK we rely on the European Commission's Standard Contractual Clauses with the UK Addendum or the UK IDTA, or on an adequacy decision — including the EU-US Data Privacy Framework where the provider is certified. Ask [email protected] for a copy of the relevant safeguards.

Once the backend is connected, our primary data store will be in on your own device (no analytics or backend service is connected yet).

11. Security — honestly stated

12. Your rights

If you're in the EU, the UK, Switzerland, or a country with similar law

You can ask us to: see your data, correct it, delete it, restrict what we do with it, export it in a portable format, or object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time — that doesn't undo what we did before.

Email [email protected]. We answer within 30 days. If your request is complex we may take up to 60 and we'll tell you why. We may ask you to confirm you control the email address on the account — we won't ask for ID documents unless there's a real doubt.

Most of your data is on your phone and we can't reach it. Deleting the app deletes it. If you want that data gone and you've signed in, delete the app and email us to close the account.

You can complain to your data protection authority at any time. In the UK that's the ICO (ico.org.uk). {{LEAD_SUPERVISORY_AUTHORITY}}.

EU representative (Art 27): {{EU_REPRESENTATIVE}}
UK representative: {{UK_REPRESENTATIVE}}
Data protection contact: {{DPO_CONTACT}}

If you're in California

Categories of personal information we collect, under the CCPA/CPRA:

CCPA categoryDo we collect it?Examples
IdentifiersYesinstall id, account id, email address (if you sign in), IP address at sign-in
Customer records (Cal. Civ. Code §1798.80)Yesemail, purchase record
Commercial informationYeswhich plan you bought, renewal status
Internet / app activityYeslessons opened and completed, screens viewed, paywall interactions
Geolocation dataNowe collect a time zone, not a location
Biometric, sensory, health dataNo
Employment or education recordsNothe quiz asks what you want to get better at; that is not an employment or education record
InferencesYesthe lifecycle stage in section 6
Sensitive personal informationNowe don't collect any category of sensitive PI, so there's nothing to limit

Sources: you, and your device. Purposes: sections 3 and 6. Disclosure: to the service providers in section 5, for those purposes only.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the last 12 months, and we don't today. If that changes — for example if we add an advertising or attribution SDK — we will update this policy, add a "Do Not Sell or Share My Personal Information" control, and honour Global Privacy Control signals on our website before it changes.

Your rights: know, access, delete, correct, portability, opt out of sale or sharing, limit use of sensitive PI, and not be discriminated against for using any of them. We don't offer financial incentives for data. An authorised agent can act for you with written permission. Email [email protected].

If you're in Virginia, Colorado, Connecticut, Texas, Oregon, or a similar state

You have broadly the same rights — access, correct, delete, portability, and opt out of targeted advertising, sale, and profiling with significant effects. We don't do targeted advertising or that kind of profiling. Same address: [email protected]. If we refuse a request you can appeal by replying, and we'll answer the appeal within 45 days.

13. Children

Mastera is for people aged 13 and over, and it is not directed at children. It isn't in the Kids category on the App Store, we don't declare a child audience on Google Play, and nothing in it is designed to appeal to under-13s rather than adults.

This position is what we declare on the Google Play Data Safety form (target audience 13+, not designed for children) and in the App Store age rating. If one ever changes, the other two change with it.

14. Store disclosure map

One source of truth for whoever fills in Apple's Privacy Nutrition Label and Google's Data Safety form. Anything marked planned is declared only once that service is actually connected and shipping.

Our dataApple label categoryApple: linked to you?Apple: used to track?Play Data SafetyPlay: collected / sharedOptional?
Email addressContact Info → Email AddressLinkedNoPersonal info → Email addressCollected, not sharedOptional
Account idIdentifiers → User IDLinkedNoPersonal info → User IDsCollected, not sharedRequired once signed in
Install idIdentifiers → Device IDNot linked until you sign inNoDevice or other IDsCollected, not sharedRequired (planned)
Purchase / plan / renewal statePurchases → Purchase HistoryLinkedNoFinancial info → Purchase historyCollected, not sharedRequired for purchases
Lesson, screen and paywall eventsUsage Data → Product InteractionLinked if signed in, else not linkedNoApp activity → App interactionsCollected, not sharedRequired (planned)
Quiz answersUsage Data → Other Usage DataSameNoApp activity → Other actionsCollected, not sharedOptional
Lifecycle stage and bandsUsage Data → Other Usage DataSameNoApp activity → Other actionsCollected, not sharedRequired (planned)
Lesson feedback / surveyUser Content → Other User ContentSameNoApp activity → Other user-generated contentCollected, not sharedOptional
Time zone, reminder hourUsage Data → Other Usage DataSameNoApp activity → Other actionsCollected, not sharedOptional
Crash reports, performanceDiagnostics → Crash Data, Performance DataNot linkedNoApp info and performance → Crash logs, DiagnosticsCollected, not sharedOptional (planned)
IP address at sign-inIdentifiers → Device ID (server-side; not collected by the app)LinkedNoNot declarable as app-collected; disclosed here
LocationNot collected
Contacts, photos, files, health, messagesNot collected
Advertising id (IDFA / GAID)Not collected

"Tracking" in Apple's sense — linking your data with data from other companies' apps or websites for advertising or data-brokerage — is "No" throughout. The app does not present Apple's App Tracking Transparency prompt because it does nothing that requires one. If we add an attribution SDK, that changes, and both this table and the store declarations change with it.

Data deletion: because everything is either on your device or tied to an account you can close, our Play Data Safety answer is that users can request deletion, via [email protected] and the account deletion route described in section 12.

15. Changes to this policy

If we change something that matters — a new category of data, a new recipient, a new purpose — we'll tell you in the app before it takes effect, and where the law requires it, ask you again. The "Last updated" date at the top is always accurate.

16. Contact us

{{LEGAL_ENTITY}}
{{POSTAL_ADDRESS}}
Privacy: [email protected]
Support: [email protected]