Who handles your information
This policy describes MastLog at mastlog.com. The person or entity operating the installation is responsible for its data processing. Support, privacy and security requests go to support@mastlog.com. The hosting location and legal operator's country are different facts. The operator's registered identity and business address must be supplied accurately; they are not established merely by using the MastLog name or domain.
- Support, privacy and security
- support@mastlog.com
- Privacy requests
- support@mastlog.com
- Security reports
- support@mastlog.com
- Copyright notices
- dmca@mastlog.com
- Suggestions and inspiration
- insprations@mastlog.com
MastLog is the service at mastlog.com. The legal operator's registered identity, operating country and business address have not yet been published for this installation.
Information the application uses
Account information includes your email, password hash, profile identity, optional gender, saved timezone and country when supplied by a trusted location source. Journal information includes dates, ratings, triggers and notes you enter. Check-ins, quiz answers and favorites, XP, social relationships and policy acknowledgments are stored to operate those features. A session cookie signs you in; local storage remembers interface preferences such as theme. Session validity is currently 30 days.
Provider credentials and cached information
When you sign in or connect, the backend adapter receives credentials and challenge answers and sends the required information to the relevant provider. Application code does not persist your provider password. Provider subjects, display names, encrypted reusable sessions and available cached history or showcase metadata can be retained. A provider's own processing follows its policies. Disconnecting removes local sessions and caches, not the provider's own records.
Private and sensitive information
Journal entries, optional gender and provider activity can reveal intimate or other sensitive information. Enter only what you want the service to process; avoid other people's intimate details. Journal records are scoped to your account, with any friend entry sharing governed by mutual consent. Reading this policy is an acknowledgment, not blanket consent to every possible use of sensitive information. Applicable special-category processing requirements still apply.
Why information is used
The application uses information to authenticate accounts, save and display your records, compute progress, provide requested quizzes and social connections, fetch authorized provider data and enforce access and abuse controls. Profile discovery and public showcases follow their visibility settings. This application does not include advertising trackers or analytics scripts; deployment infrastructure and a provider's challenge widget may have their own processing.
Legal grounds and separate choices
The operator must determine and document the applicable legal grounds for each purpose, including account services, security and mandatory legal obligations. Where consent is required, it must be specific and valid and provide an appropriate withdrawal mechanism. Sensitive-data conditions and international-transfer requirements are additional obligations. Accepting the terms or acknowledging this notice does not replace a required separate consent.
How long records remain
Account and journal records remain until they are removed through available controls or handled by the operator on a valid request. Disconnecting a provider deletes its local connection and cached information; disabling an additional-provider showcase clears its published snapshot. Sessions expire after their stated validity, which does not itself promise automatic removal of every expired database row. Backup and infrastructure-log retention depend on the deployment and must be disclosed by its operator.
How information is protected
Passwords are stored as Argon2 hashes and application session tokens are stored as hashes. Reusable provider sessions are encrypted and bound to the owning user, with additional sessions also bound to the provider. Account authorization and server-side checks protect journal access. Journal content itself is not end-to-end encrypted. HTTPS, storage encryption, backups and administrative access depend on a properly secured deployment.
Your controls and rights
Use profile privacy, favorite visibility, friend consent, provider disconnect and journal edit/delete controls to manage available features. Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection or withdrawal of consent, and complain to a competent authority. Send account-wide requests to support@mastlog.com; the current interface does not provide a complete account export or deletion workflow. Rights may have lawful exceptions.
Hosting and international transfers
Connecting an external provider may send authentication information to that provider and its infrastructure outside your country. Hosting, support and backup locations depend on the installation. The operator must identify actual recipients and countries and arrange the safeguards required by applicable law. A suggested hosting country alone does not establish those safeguards or make an international transfer lawful.
No accounts for children
MastLog is intended for people aged 18 and over, subject to higher local limits. The signup checkbox records an age declaration and does not independently verify age. If a minor's account or information is suspected, contact support@mastlog.com so access and retention can be reviewed. Do not send identity documents or private records through public channels.
Keeping this notice current
The page displays its policy version and update date. Changes must reflect the application's actual behavior and the installation's providers and retention practices. New purposes, recipients or sensitive-data processing may require additional notice or consent rather than a silent edit.
Requests and questions
Send privacy and account-wide requests to support@mastlog.com. Describe the request using the minimum information needed; never send passwords, session cookies or complete journal entries. The operator may need proportionate proof of account control before fulfilling a request. The MastLog name, domain and contact address do not substitute for publishing the legal operator's full identity and applicable processing information.