MastLog
Your account. Your choices.Terms of usePrivacy policySecurity policy

Privacy policy

Last updated: October 7, 2026

On this page

  1. Who handles your information
  2. Information the application uses
  3. Provider credentials and cached information
  4. Private and sensitive information
  5. Why information is used
  6. Legal grounds and separate choices
  7. How long records remain
  8. Public profiles, friends and recipients
  9. How information is protected
  10. Your controls and rights
  11. Hosting and international transfers
  12. No accounts for children
  13. Keeping this notice current
  14. Requests and questions

Who handles your information

This policy describes MastLog at mastlog.com. The person or entity operating the installation is responsible for its data processing. Support, privacy and security requests go to support@mastlog.com. The hosting location and legal operator's country are different facts. The operator's registered identity and business address must be supplied accurately; they are not established merely by using the MastLog name or domain.

Support, privacy and security
support@mastlog.com
Privacy requests
support@mastlog.com
Security reports
support@mastlog.com
Copyright notices
dmca@mastlog.com
Suggestions and inspiration
insprations@mastlog.com

MastLog is the service at mastlog.com. The legal operator's registered identity, operating country and business address have not yet been published for this installation.

Information the application uses

Account information includes your email, password hash, profile identity, optional gender, saved timezone and country when supplied by a trusted location source. Journal information includes dates, ratings, triggers and notes you enter. Check-ins, quiz answers and favorites, XP, social relationships and policy acknowledgments are stored to operate those features. A session cookie signs you in; local storage remembers interface preferences such as theme. Session validity is currently 30 days.

Provider credentials and cached information

When you sign in or connect, the backend adapter receives credentials and challenge answers and sends the required information to the relevant provider. Application code does not persist your provider password. Provider subjects, display names, encrypted reusable sessions and available cached history or showcase metadata can be retained. A provider's own processing follows its policies. Disconnecting removes local sessions and caches, not the provider's own records.

Private and sensitive information

Journal entries, optional gender and provider activity can reveal intimate or other sensitive information. Enter only what you want the service to process; avoid other people's intimate details. Journal records are scoped to your account, with any friend entry sharing governed by mutual consent. Reading this policy is an acknowledgment, not blanket consent to every possible use of sensitive information. Applicable special-category processing requirements still apply.

Why information is used

The application uses information to authenticate accounts, save and display your records, compute progress, provide requested quizzes and social connections, fetch authorized provider data and enforce access and abuse controls. Profile discovery and public showcases follow their visibility settings. This application does not include advertising trackers or analytics scripts; deployment infrastructure and a provider's challenge widget may have their own processing.

Legal grounds and separate choices

The operator must determine and document the applicable legal grounds for each purpose, including account services, security and mandatory legal obligations. Where consent is required, it must be specific and valid and provide an appropriate withdrawal mechanism. Sensitive-data conditions and international-transfer requirements are additional obligations. Accepting the terms or acknowledging this notice does not replace a required separate consent.

How long records remain

Account and journal records remain until they are removed through available controls or handled by the operator on a valid request. Disconnecting a provider deletes its local connection and cached information; disabling an additional-provider showcase clears its published snapshot. Sessions expire after their stated validity, which does not itself promise automatic removal of every expired database row. Backup and infrastructure-log retention depend on the deployment and must be disclosed by its operator.

Public profiles, friends and recipients

A completed non-private profile exposes its public identity and quiz score by default; quiz favorites are also public by default and can be hidden using their visibility setting. A provider showcase publishes the selected cached items only with its separate permission. Friends receive only the data allowed by the friendship's consent settings. Hosting and authentication providers may process the information necessary for their role. A valid legal request may require disclosure. The application has no feature for selling private journal content.

How information is protected

Passwords are stored as Argon2 hashes and application session tokens are stored as hashes. Reusable provider sessions are encrypted and bound to the owning user, with additional sessions also bound to the provider. Account authorization and server-side checks protect journal access. Journal content itself is not end-to-end encrypted. HTTPS, storage encryption, backups and administrative access depend on a properly secured deployment.

Your controls and rights

Use profile privacy, favorite visibility, friend consent, provider disconnect and journal edit/delete controls to manage available features. Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection or withdrawal of consent, and complain to a competent authority. Send account-wide requests to support@mastlog.com; the current interface does not provide a complete account export or deletion workflow. Rights may have lawful exceptions.

Hosting and international transfers

Connecting an external provider may send authentication information to that provider and its infrastructure outside your country. Hosting, support and backup locations depend on the installation. The operator must identify actual recipients and countries and arrange the safeguards required by applicable law. A suggested hosting country alone does not establish those safeguards or make an international transfer lawful.

No accounts for children

MastLog is intended for people aged 18 and over, subject to higher local limits. The signup checkbox records an age declaration and does not independently verify age. If a minor's account or information is suspected, contact support@mastlog.com so access and retention can be reviewed. Do not send identity documents or private records through public channels.

Keeping this notice current

The page displays its policy version and update date. Changes must reflect the application's actual behavior and the installation's providers and retention practices. New purposes, recipients or sensitive-data processing may require additional notice or consent rather than a silent edit.

Requests and questions

Send privacy and account-wide requests to support@mastlog.com. Describe the request using the minimum information needed; never send passwords, session cookies or complete journal entries. The operator may need proportionate proof of account control before fulfilling a request. The MastLog name, domain and contact address do not substitute for publishing the legal operator's full identity and applicable processing information.

Policy version: 2026-10-07
Terms of usePrivacy policySecurity policy
Terms of usePrivacy policySecurity policy
MastLog contributors © 2026 · AGPL-3.0 · No warrantyAGPL-3.0