Masterys

Privacy Policy

Effective and last updated August 10, 2026 · Version 2026-08-10

This Privacy Policy describes how Masterys (“we”, “us”, “our”) collects, uses, shares, and otherwise processes information about you when you visit masterys.org, install the Masterys progressive web app, use any associated iOS or Android application, or otherwise interact with our services (collectively, the “Service”). It applies in addition to the Terms of Service, which govern your use of the Service.

We are the controller of your personal data for the purposes of the European Union General Data Protection Regulation (“GDPR”) and the United Kingdom GDPR. If you have questions about this Policy or wish to exercise any of the rights described below, contact us using the methods in the “Contact us” section.

1. Information we collect

We collect information in the categories described below.

Account information. When you create an account through our authentication provider (Auth0 by Okta) we receive the email address you use to sign in, a unique user identifier, your display name, and (where you have authorised the provider to share it) a profile picture. We do not receive your password. If you sign in with a third-party identity provider (such as Google or Apple), the data we receive from that provider is governed by the privacy disclosures of the provider.

User content. We store the data you generate while using the Service, including the cards you add to your binder, the master-set goals you pin, the binder grid configuration you choose, the languages you select for tracking, and the preferences you set.

Card-scan images. When you scan a physical card with your device camera or upload an image for grading, the image is transmitted to our servers and then forwarded to OpenAI’s Vision API solely for the purpose of card recognition or condition estimation. We do not retain scanned images after recognition completes; OpenAI’s data-handling practices are described in its Privacy Policy. By using the scanning features you direct us to transmit your image to OpenAI for processing.

Payment information. If you subscribe to a paid plan, payment is processed by Stripe, Inc. (“Stripe”) acting as our payment processor. We do not collect or store full payment card numbers; Stripe transmits to us only a customer identifier, the last four digits of your card, the card brand, your billing country and postal code, the active subscription status, the renewal date, and the amount of each payment. Stripe’s processing of your payment data is subject to its Privacy Policy.

Device and usage data. When you use the Service we automatically collect technical information including your IP address, approximate geolocation derived from that IP, browser or app user-agent string, device model and operating-system version, the pages and screens you view, the searches you run, the actions you take, the timestamps of those actions, referring URLs, and basic diagnostic information (errors, crashes, latency). We use this information to operate, secure, and improve the Service.

Push-notification tokens. If you grant the Service permission to send push notifications, we receive and store the push token issued by your browser or device operating system. We use the token solely to deliver the notifications you have asked us to send and revoke it on request.

Customer-support correspondence. If you contact support, we collect your email address, your message, any attachments you choose to send, and the troubleshooting information needed to investigate and respond to your request.

Cookies and similar technologies. We use a small number of first-party cookies and local-storage entries that are strictly necessary to operate the Service (for example, to maintain your authenticated session and your theme preference). We do not deploy third-party advertising cookies or cross-site tracking pixels.

Legal-acceptance audit data. When you accept these terms or the Terms of Service in the in-app legal gate, we record the document identifier, the version you accepted, the date and time of acceptance, your IP address, and your User-Agent string. This audit record is retained for the duration of your account and for a reasonable period thereafter for evidentiary purposes under the U.S. Electronic Signatures in Global and National Commerce Act (“E-Sign Act”), the Uniform Electronic Transactions Act, and analogous laws including the EU eIDAS Regulation.

2. How we use information

We process personal information for the following purposes, relying on the following legal bases under GDPR/UK GDPR where applicable:

  • Service provision — to create and maintain your account, store your collection data, deliver scanning and master-set tracking features, process subscription payments, and operate the Service generally. Legal basis: performance of the contract between you and us.
  • Security and abuse prevention — to detect and prevent fraud, abuse, attacks on the Service, and violations of our Terms of Service. Legal basis: our legitimate interests and, where applicable, compliance with legal obligations.
  • Service improvement — to analyse usage trends, evaluate the performance of features, and improve reliability. Where we use diagnostic telemetry we aggregate or pseudonymise the data wherever practicable. Legal basis: our legitimate interests.
  • In-app personalisation and plan offers — to use your current plan, scan allowance, collection totals, and master-set progress to tailor Masterys feature suggestions and upgrade messages. We do not use this information for third-party advertising or cross-app tracking. Legal basis: our legitimate interests in presenting relevant first-party features and offers.
  • Communications — to send you transactional emails about your account (password changes, subscription receipts, security alerts) and push notifications you have opted in to receive. Legal basis: performance of the contract; your consent in respect of push notifications.
  • Legal compliance — to comply with applicable laws, respond to lawful requests from regulators or law-enforcement authorities, enforce our agreements, and protect the rights, property, and safety of Masterys, our users, and the public. Legal basis: compliance with legal obligations; our legitimate interests.

No sale or sharing for cross-context behavioural advertising. We do not sell your personal information for monetary or other valuable consideration and we do not share it for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), or analogous state laws.

3. Service providers and sub-processors

We share personal information with a limited number of vendors who process it on our behalf, under written agreements that restrict their use of the information to providing services to us and require appropriate safeguards. Our material vendors as of the effective date above are:

  • Auth0 by Okta, Inc. — identity provider and authentication.
  • Supabase Inc. — managed Postgres database, file storage, and authentication support.
  • Vercel Inc. — application hosting, edge networking, and analytics.
  • Stripe, Inc. — subscription billing and payment processing.
  • OpenAI, LLC — image-based card recognition and condition grading.
  • Cloudflare, Inc. — content delivery and security.

We may add, remove, or replace sub-processors over time. When we do, we will update this Policy and, where required by applicable law, notify affected users in advance.

4. Other disclosures

We may disclose personal information outside the service-provider relationships described above (a) in connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of our assets, in which case you will be notified by email or a prominent notice on the Service; (b) to respond to a valid legal process (such as a subpoena, court order, or government request) or to comply with applicable law; (c) to protect or enforce our rights, agreements, or property, or those of our users or the public; or (d) with your consent or at your direction.

5. International data transfers

We are based in the United States and process personal information there. If you access the Service from outside the United States, you understand and consent to the transfer, processing, and storage of your personal information in the United States and other jurisdictions in which we or our service providers operate. Those jurisdictions may have data protection laws that differ from those of your home country. When we transfer personal data of European Economic Area, United Kingdom, or Swiss residents to a country that has not received an adequacy decision from the European Commission, we rely on the Standard Contractual Clauses adopted by the European Commission (or the UK addendum thereto) and, where appropriate, on supplementary measures.

6. Data retention

We retain personal information for as long as your account is active, for as long as needed to provide the Service, and for additional periods as required to comply with our legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or de-identify your personal information within a commercially reasonable period, except that we may retain (a) records of subscription payments and invoices for as long as required by tax and accounting law (typically up to seven years in the United States), and (b) de-identified or aggregated information that no longer identifies you.

7. Your rights and choices

All users. You may access, update, or delete your account information at any time from the in-app Account dashboard. You may revoke push-notification permission through your device or browser settings.

EU, UK, and Swiss residents. You have the right under GDPR and UK GDPR (i) to request access to and a copy of the personal data we hold about you, (ii) to request correction of inaccurate or incomplete data, (iii) to request erasure of your data (the “right to be forgotten”), (iv) to restrict or object to certain processing, (v) to data portability where the processing is based on contract or consent and carried out by automated means, and (vi) to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

California residents. If you are a California resident you have the right under the CCPA (i) to know what categories and specific pieces of personal information we have collected about you, the sources and purposes of that collection, and the categories of third parties with which we share it; (ii) to request deletion of your personal information, subject to certain exceptions; (iii) to correct inaccurate personal information; (iv) to opt out of sale or sharing of personal information for cross-context behavioural advertising (which we do not do); and (v) not to be discriminated against for exercising any of these rights. We verify rights requests by matching the email address and account identifier in the request against the credentials of the corresponding account; we may decline a request that we cannot verify.

Other state residents. Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, Virginia, and other states with comprehensive consumer-privacy laws have rights similar to those described above. To exercise any of them, contact us as described below.

How to exercise. You can permanently delete your account from the Account dashboard. Other privacy requests may be submitted through the contact method published in the Service. We will respond within the timeframes required by applicable law.

8. Children

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, do not use the Service or provide any personal information to us. If you believe a child under 13 has provided us with personal information, please contact us so that we can promptly delete it in accordance with the U.S. Children’s Online Privacy Protection Act (“COPPA”).

9. Security

We use a combination of technical, administrative, and organisational safeguards designed to protect personal information against unauthorised access, disclosure, alteration, and destruction. These include encryption in transit (TLS 1.2 or higher) and at rest, access controls on our production environment, audit logging, and regular review of our security posture. No security control is impenetrable, and we cannot guarantee absolute security; you are responsible for choosing a strong password, keeping your sign-in credentials confidential, and notifying us promptly if you suspect unauthorised access to your account.

10. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the effective date and version number at the top of this page. If we make material changes we will provide additional notice, such as by email or a prominent notice in the Service, and where required by applicable law we will obtain your consent. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of that updated Policy.

11. Contact us

Privacy questions, data-subject requests, and complaints may be submitted through the contact method published in the Service. If you are an EEA, UK, or Swiss resident and have been unable to resolve a complaint with us, you may also lodge a complaint with your local data-protection supervisory authority.