Legal
Privacy Policy
Last updated: 21 July 2026. This policy covers the Miatz website (miatz.com), the Miatz web application, and the Miatz mobile apps for iOS and Android. Miatz is operated by Demystify Systems.
Miatz is a selective engineering-training platform. We collect only the data needed to run the program, mentor you, keep your account secure, and improve the product. We do not sell your personal data. We do not use it for cross-app advertising or third-party ad tracking.
1. Who we are
The data controller is Demystify Systems (“Miatz”, “we”, “us”). For any privacy request, contact hello@miatz.com.
2. Data we collect
We collect the following categories of data, depending on how you use Miatz:
- Account & identity. Your name, email address, and a hashed password. If you sign in with Google, Microsoft, GitHub, or Apple, we receive a provider account identifier and your email (name where provided). Optional profile fields include a public handle, learning track/persona, and designation.
- Learning & assessment data. Your entrance-test (DSAT) and quiz/exam answers and reasoning, coding submissions, prompt-lab attempts, incident (War-Room) runs, daily reflections and weekly reviews (including confidence ratings), flashcard reviews, skill/mastery assessments, XP, streaks, badges, and issued credentials.
- Usage & activity. Product events (e.g. lesson completed, submission made), time-on-platform and presence signals (active vs. idle time, pages visited, session timing, coarse device/browser type), and — for assigned videos — how much of a video you watched. On the public marketing site we record anonymous page views (path, referrer, UTM parameters) with a random local identifier, not tied to your name.
- Device & notifications. A web-push subscription and/or a native push token (Apple APNs on iOS, Google FCM on Android) so we can send the reminders and alerts you enable, plus your notification preferences.
- AI assistant. Your conversations with the Mysty AI tutor and the prompts/answers you submit for AI grading, plus usage metering (token counts, model, success/latency). If you bring your own AI provider key (BYOK), the key is stored encrypted in a server-side vault and is never returned to the browser; if you choose device-only mode, the key stays in your browser/device and is never sent to us.
- Calendar (optional). Only if you connect Google or Microsoft Calendar: we read your events to show your agenda and write Miatz study events into a dedicated calendar. OAuth tokens are encrypted server-side and never exposed to the browser.
- Profile photo (optional). If you set a profile picture, you choose an existing image or take one with your device’s camera through the standard system picker; the image is stored with your profile. We do not otherwise access your camera or photo library.
- Support & community. Support tickets, bug reports, and any content you post in the community forum.
- Cookies & local storage. A session cookie to keep you signed in and local preferences (e.g. theme, navigation and launcher settings). The mobile apps keep your session in secure device storage rather than cookies.
3. How we use data
- To provide the program: deliver lessons, grade work, track progress, and issue credentials.
- To mentor and personalize: adapt your plan, ground the AI tutor in your own history, and let mentors give feedback.
- To send the reminders and notifications you turn on.
- To keep accounts secure, prevent abuse, and enforce fair use.
- To operate and improve the product and understand how people find us (aggregate analytics).
- To comply with legal obligations.
Our legal bases (where applicable) are performance of our agreement with you, your consent (e.g. notifications, calendar, profile photo), and our legitimate interests in a secure, working product.
5. Data retention
We keep your data while your account is active and as needed to provide the program. When you delete your account we delete or de-identify your personal data, except where we must retain limited records to meet legal or security obligations. Some short-lived operational logs are pruned automatically.
6. Your choices and rights
- Access & export. You can view your data in the app and request an export.
- Correction. Update your profile and settings at any time.
- Deletion. Delete your account in Profile → Account → Delete account. This permanently removes your data and, if you used Sign in with Apple, revokes the associated Apple token. You can also email us to request deletion.
- Notifications, calendar, profile photo. These are opt-in; you can turn them off in Settings or in your device settings, and disconnect calendar at any time.
- Depending on your location, you may also have rights to object to or restrict processing and to lodge a complaint with your local data-protection authority.
7. Security
Data is encrypted in transit (HTTPS) and access is restricted by database row-level security so users can only reach their own data (and, for business tenants, strictly within their organization). Sensitive secrets — such as AI provider keys and calendar tokens — are encrypted and are never returned to the browser. No system is perfectly secure, but we work to protect your information.
8. Children
Miatz is intended for adults aged 18 and older. It is not directed to children, and we do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will remove it.
9. International transfers
We and our service providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date, and where appropriate we will notify you in the app.
11. Contact us
Questions or requests? Email hello@miatz.com. See also our Terms of Service.