Legal

Privacy Policy

Last updated: 21 July 2026. This policy covers the Miatz website (miatz.com), the Miatz web application, and the Miatz mobile apps for iOS and Android. Miatz is operated byMiatz Private Limited.

Miatz is a selective engineering-training platform. We collect only the data needed to run the program, mentor you, keep your account secure, and improve the product. We do not sell your personal data. We do not use it for cross-app advertising or third-party ad tracking.

1. Who we are

The data controller is Miatz Private Limited (“miatz”, “we”, “us”), registered in Karnataka, India. For any privacy request, contact hello@miatz.com.

2. Data we collect

We collect the following categories of data, depending on how you use miatz:

  • Account & identity. Your name, email address, and a hashed password. If you sign in with Google, Microsoft, GitHub, or Apple, we receive a provider account identifier and your email (name where provided). Optional profile fields include a public handle, learning track/persona, and designation.
  • Learning & assessment data. Your entrance-test (Chuun) and quiz/exam answers and reasoning, coding submissions, prompt-lab attempts, incident (War-Room) runs, daily reflections and weekly reviews (including confidence ratings), flashcard reviews, skill/mastery assessments, XP, streaks, badges, and issued credentials.
  • Usage & activity. Product events (e.g. lesson completed, submission made), time-on-platform and presence signals (active vs. idle time, pages visited, session timing, coarse device/browser type), and — for assigned videos — how much of a video you watched. On the public marketing site we record anonymous page views (path, referrer, UTM parameters) with a random local identifier, not tied to your name.
  • Device & notifications. A web-push subscription and/or a native push token (Apple APNs on iOS, Google FCM on Android) so we can send the reminders and alerts you enable, plus your notification preferences.
  • AI assistant. Your conversations with the Xook AI tutor and the prompts/answers you submit for AI grading, plus usage metering (token counts, model, success/latency). If you bring your own AI provider key (BYOK), the key is stored encrypted in a server-side vault and is never returned to the browser; if you choose device-only mode, the key stays in your browser/device and is never sent to us.
  • Calendar (optional). Only if you connect Google or Microsoft Calendar: we read your events to show your agenda and write miatz study events into a dedicated calendar. OAuth tokens are encrypted server-side and never exposed to the browser.
  • Profile photo (optional). If you set a profile picture, you choose an existing image or take one with your device’s camera through the standard system picker; the image is stored with your profile. We do not otherwise access your camera or photo library.
  • The public AI Readiness Check. The free check at /check can be taken with no account at all. We store your answers, the band they produce, the profession you picked and a self-declared age band (“18 or over” or “Under 18”), keyed to a random token held in your browser — no name, no email address, no account. Section 8 covers the age band specifically.
  • Support & community. Support tickets, bug reports, and any content you post in the community forum.
  • Cookies & local storage. A session cookie to keep you signed in and local preferences (e.g. theme, navigation and launcher settings). The mobile apps keep your session in secure device storage rather than cookies.

3. How we use data

  • To provide the program: deliver lessons, grade work, track progress, and issue credentials.
  • To mentor and personalize: adapt your plan, ground the AI tutor in your own history, and let mentors give feedback.
  • To send the reminders and notifications you turn on.
  • To keep accounts secure, prevent abuse, and enforce fair use.
  • To operate and improve the product and understand how people find us (aggregate analytics).
  • To comply with legal obligations.

Our legal bases (where applicable) are performance of our agreement with you, your consent (e.g. notifications, calendar, profile photo), and our legitimate interests in a secure, working product.

4. Who we share data with (processors)

We share data only with service providers that process it on our behalf under contract, and only as needed to run miatz:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and delivery.
  • AI inference providers — NVIDIA NIM and, where you enable them, other model providers (e.g. Groq, Google AI Studio, OpenRouter, Cerebras, Together, Fireworks, Mistral) to power the AI tutor and grading. Your prompts/answers are sent to the selected provider to generate a response.
  • Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) — to deliver mobile push notifications.
  • Identity providers — Google, Microsoft, GitHub, and Apple, if you use them to sign in (and Google/Microsoft if you connect your calendar).
  • Resend — transactional and reminder email.
  • Slack — internal staff notifications about program events (e.g. a new submission).
  • YouTube (privacy-enhanced mode) — embedded lesson videos; loaded from youtube-nocookie.com.

The dated register — each provider’s contracting entity, country and purpose, and the notice we give before adding one — is published at miatz.com/subprocessors. It versions separately from this policy, so a vendor change does not restate the whole notice.

For business tenants (organizations that enroll their people), that organization’s administrators can see their own members’ learning progress and engagement, under the data processing agreement between us and them. We do not sell personal data or share it with advertisers.

5. Data retention

We keep your data while your account is active and as needed to provide the program. When you delete your account we delete or de-identify your personal data, except where we must retain limited records to meet legal or security obligations. Some short-lived operational logs are pruned automatically. Where a record carries its own deletion date, a scheduled job enforces it rather than a person remembering to.

Two limits worth stating exactly. A public AI Readiness Check attempt is not attached to an account, so deleting an account does not reach it. And that attempt carries no deletion date of its own, so it is kept until somebody asks us to remove it — see section 8 for how to ask.

6. Your choices and rights

  • Access & export. You can view your data in the app and request an export.
  • Correction. Update your profile and settings at any time.
  • Deletion. Delete your account in Profile → Account → Delete account. This permanently removes your data and, if you used Sign in with Apple, revokes the associated Apple token. You can also email us to request deletion.
  • Notifications, calendar, profile photo. These are opt-in; you can turn them off in Settings or in your device settings, and disconnect calendar at any time.
  • Depending on your location, you may also have rights to object to or restrict processing and to lodge a complaint with your local data-protection authority.

To exercise any of these — a copy of your data, a correction, or erasure — make a request here. You do not need an account, and we confirm the address before acting on it.

7. Security

Data is encrypted in transit (HTTPS) and access is restricted by database row-level security so users can only reach their own data (and, for business tenants, strictly within their organization). Sensitive secrets — such as AI provider keys and calendar tokens — are encrypted and are never returned to the browser. No system is perfectly secure, but we work to protect your information.

8. Children and young people

Miatz is built for adults. The program, the mentoring and the credentials all assume an adult learner, and we do not market to children. Creating an account is not age-gated: we do not ask your age at signup, and nothing in the app checks it.

One page asks, and we keep the answer. The free AI Readiness Check at /check asks whether you are “18 or over” or “Under 18”, because the law treats the two differently. If you answer “Under 18” we accept that answer and we store it with your attempt. It is self-declared and we do not verify it — it is what you told us, and nothing checks it against anything else. So it would not be true to say we do not knowingly hold data from anyone under 18, and this page used to say exactly that.

The attempt itself carries no name, no email address and no account — only your answers and a random token held in the browser that took the check. Answering “Under 18” changes three things, each enforced in the product rather than promised here:

  • the result is never given a shareable public link;
  • it is never placed on the public board, and a request to be listed is refused;
  • we never email the report anywhere.

What we do not have. There is no way in Miatz to verify a parent’s or guardian’s consent — no such step exists anywhere in the product, and we would rather say so than imply one. We therefore cannot claim that a young person’s use of that page was consented to by their guardian. What we can tell you is what the page collects, that the age answer is unverified, and what the product refuses to do with it.

If you are a parent or guardian. Email hello@miatz.com and we will delete the attempt. Because the record holds no name and no email address, we will need the link to the result, or the browser it was taken on, to find the right one — and if we cannot identify it with confidence we will tell you that rather than delete somebody else’s.

9. Where your data is stored, and what leaves India

Your account, learning and assessment data is stored in India. The database, authentication and file storage run on Supabase in the ap-south-1 (Mumbai) region, and the application’s server-side compute is pinned to Vercel’s bom1 (Mumbai) region, in the same city as the database. Public marketing pages are cached on Vercel’s global edge network; that cache holds published page content, not your personal data.

These categories do leave India. Each is limited to what the feature needs, and each provider processes it on our instruction under our contract with them (see §4):

  • AI inference. The prompt, answer or conversation turn you submit — plus the context needed to respond to it — goes to the model provider serving that request (NVIDIA NIM by default, or a provider you enable). We send no more of your record than the request needs. In device-only BYOK mode the call goes from your own device to the provider you chose, and never through us.
  • Mobile push. Your device push token and the text of the notification go to Apple APNs or Google FCM so the message can reach your phone. Nothing else is included, and turning notifications off ends the transfer.
  • Email. Your email address and the content of the message go to Resend, which delivers our transactional and reminder email.
  • Sign-in and connected accounts. If you sign in with Google, Microsoft, GitHub or Apple, the authentication exchange happens with that provider; if you connect a calendar, the events we read and the study events we write pass to that calendar.
  • Internal staff notifications. Slack messages telling our team about a program event may name the learner it concerns.

Embedded lesson videos load from youtube-nocookie.com when you play them, which is a request from your browser to Google rather than a transfer by us.

For transfers out of India we rely on our data-processing agreement with each provider named above. The Digital Personal Data Protection Act permits transfer to any country the Central Government has not restricted; if such a restriction is notified, we will stop sending affected data to a provider in that country. Where a transfer is also subject to EU or UK law, we rely on the transfer mechanism in that provider’s data-processing terms, typically the standard contractual clauses.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date, and where appropriate we will notify you in the app.

11. If there is a data breach

If personal data we hold is exposed, lost, or accessed without authorization, we will notify the Data Protection Board of India and every affected person without undue delay, by email and — where the account is active — in the app. The notice will say what happened, which categories of data were involved, what we have done to contain it, and what you can do to protect yourself. We record every such incident internally, including the ones that did not meet the notification threshold, and we review what let it happen.

12. Grievance redressal

If you are not satisfied with how we handled your data, your request, or any other complaint about miatz, write to our Grievance Officer. This is the contact of record under the Digital Personal Data Protection Act 2023 and the Consumer Protection (E-Commerce) Rules 2020 — a named person, not a queue. We acknowledge every complaint on receipt and resolve it within 30 days.

Aishwarya
Grievance Officer, Miatz Private Limited
C-101, Lotus Tower, Arge Urban Bloom, 30/A, 4th Main, 2nd Stage, Yeswanthpur, Bengaluru, Karnataka 560022
Response: within 30 days of receipt.

If you are still not satisfied after we respond — or if we do not respond in that window — you may complain to the Data Protection Board of India. The full procedure — what to put in a complaint, what happens after you send it, and where else you can take it — is on grievance redressal.

13. Contact us

Questions or requests? Email hello@miatz.com. See also our Terms of Service. For a formal complaint, write to the Grievance Officer. Our registered particulars — registered office, CIN and GSTIN — are published in the statutory disclosure and in the footer of every page.