Mister EducationMister Education

Privacy Policy

How we collect, use and protect your data.

Last updated: 2026-08-25

1. Who we are

Mister Education ("we", the "Platform") takes your privacy seriously. This Privacy Policy describes how we process your personal data, in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Brazilian General Data Protection Law (Lei nº 13.709/2018, "LGPD").

Data controller: Mister Education.
Data Protection contact: info@mistereducation.com.

2. Data we collect

  • Account and profile: name, email, username, display name, avatar, bio, the language you are learning, your interface language and your time zone. Your password is stored hashed by our authentication provider. We also record whether you opted in to marketing email and when you accepted the Terms.
  • Signing in with Google: Google is the only social login we offer. If you use it, we receive your name, email address and profile picture from Google.
  • What you write and do: messages you exchange with the tutor, essays and their corrections, exercise answers, vocabulary and its review history, placement test answers including how long you spent on each question, mission progress, streaks, XP and achievements.
  • Your onboarding answers: how many minutes a day you want to study, why you are learning, what you are worried about, your three month goal and the name you would like to be called.
  • Voice: recordings you make on the pronunciation screens are uploaded to private storage so that you can play them back, and may be transcribed. How the microphone itself works is described in 4.2, and it matters.
  • Social: friend requests and friendships, direct messages between you and a friend, and your likes, comments and reactions on essays.
  • Payment data: we never receive or store full card numbers. Payment is processed by Stripe or by Asaas, depending on the method and the country.
  • CPF (Brazilian taxpayer number): when you pay by Pix, the CPF you type passes through our server only to be validated and forwarded to the payment processor (Asaas), which requires the document to open the payer record. It is not written to our database. When you pay by card, the CPF is entered directly on the Asaas page.
  • Payment identity: we store a one-way, keyed hash derived from the identifier our payment processor assigns to your card or Pix key. It cannot be turned back into a card number or a Pix key. It exists for one purpose, which is recognising for fraud prevention when the same payment instrument appears across several accounts. We also keep a record of refunds we issue, with the amount, the currency, the reason and how much of the service had been used.
  • Support and feedback: bug reports, including any screenshot you attached, the page you were on, your browser and the email address you filed with; reports about a wrong grammar hint; coaching applications, which include your name, email, occupation and goal; and waiting list sign ups.
  • Technical data: IP address, device type, operating system, browser, session identifiers, and security event records such as sign in successes and failures (with the IP address, the email used and the browser). We also record what our AI providers cost us on your behalf.
  • On your device: cookies and local storage, described in section 9, and a copy of the vocabulary you are reviewing held in your browser so that review works offline.

2.1 What other people can see

Most of what you write is private to your account. Three things are not.

  • Your profile. Your username, display name, avatar and bio can be read by any signed in user of the Service. That is what makes friend search and profile pages work. Your email address is never part of it.
  • Essays you publish. If you set an essay to public it becomes readable by anyone on the internet, including people with no account, at its own address. Setting it back to private ends that access.
  • Direct messages. A message you send to a friend can be read by that friend, and is stored on our servers until one of you deletes it.

3. Purposes and lawful bases

We process personal data for the following purposes:

  • To provide and operate the Service, including AI conversation, basis: performance of contract (Art. 6(1)(b) GDPR / art. 7, V LGPD).
  • To process payments, basis: performance of contract.
  • To send transactional email such as receipts and account notices, basis: performance of contract.
  • To personalise your experience and adapt content, basis: legitimate interests (Art. 6(1)(f) GDPR / art. 7, IX LGPD).
  • To send marketing communications, basis: consent (Art. 6(1)(a) GDPR / art. 7, I LGPD), withdrawable at any time.
  • To prevent fraud and payment abuse, using the payment identity described in section 2, basis: legitimate interests.
  • To ensure security and meet legal obligations, bases: legitimate interests and legal obligation.
  • For aggregated, anonymised product analytics and for error monitoring, including masked session replay, basis: consent.

4. Sharing

4.1 Who we send data to

These are the processors that receive personal data, and what each one does for us. They act as processors under data protection agreements.

ProcessorWhat it does for us
SupabaseDatabase, sign in, and file storage for avatars and voice recordings.
VercelHosts and serves the site. Also provides cookieless traffic measurement, loaded only after you consent to analytics.
OpenAITutor replies, corrections, essay feedback, exercise and placement scoring, vocabulary help, the writing check in direct messages, and transcription of voice notes on the paid lane.
GoogleConverts practice text into spoken audio.
DeepInfraGenerates some of our pre-generated practice audio.
StripePayments outside Brazil, and fraud checks during payment.
AsaasPayments in Brazil, by Pix and by card.
ResendSends transactional email such as purchase receipts.
UpstashShort-lived rate-limit counters keyed to your IP address, which protect sign in and public forms from abuse.
CloudflareStores and serves our lesson and onboarding videos. When you play one, it receives your IP address and request details.
SentryError monitoring, including a masked replay of the session an error happened in. Loaded only after you consent to analytics.

We also disclose data to public authorities where required by law or court order.

We do not sell your personal data.

The Cookie Policy carries the full list of cookies and identifiers attributable to each processor, and links the Data Processing Agreement (DPA) of every third-party processor listed there.

4.2 Speech features and your browser

Two of the speech features run inside your browser rather than on our servers, and you should know what that means.

Speaking instead of typing. When you press the microphone, we use the speech recognition your browser provides. We do not run a recogniser of our own on that path and we never receive your audio. In Chrome, Edge and Safari that recognition is performed on the browser maker's own servers, which means the recording of your voice leaves your device and goes to Google, Microsoft or Apple, under their privacy policies and not under ours. What comes back to us is the text, not the sound. If you would rather that did not happen, do not use the microphone: everything it does can also be done by typing.

Recordings you keep. Separately, the pronunciation screens upload the clip you recorded to our own storage so that you can play it back. Those files are private, are reachable only through short-lived signed links, and are deleted when you delete your account.

Hearing words spoken. Audio is generated by Google, and for some pre-generated material by DeepInfra. Where no hosted voice is available, your browser's own speech synthesis is used instead, which on some devices also sends the text to the browser maker.

4.3 What we remove before text reaches a model

Before a chat message is sent to the model, we automatically replace anything that looks like an email address, a phone number, a card number, an IBAN or a long identification number with a placeholder. The same replacement is applied to text sent for speech synthesis from the chat and practice screens.

It does not happen everywhere. Essays, exercise answers, placement test answers, vocabulary requests and the writing check in the direct message composer are sent as you wrote them, because a correction has to be able to see the real sentence. Treat anything you type here as something a model will read, and keep personal details about yourself or anyone else out of it.

5. International transfers

Some processors are located outside the EU/Brazil (e.g., United States). Such transfers occur to countries with an adequacy decision or under appropriate safeguards: EU Standard Contractual Clauses (Art. 46 GDPR) and the equivalent guarantees under art. 33 LGPD.

The transfer described in 4.2 is not one we can place safeguards around. Your browser sends the audio to its maker directly, and the terms of that are between you and them.

6. Retention

We keep the data in section 2 for as long as your account exists. That is not a placeholder: your vocabulary, your corrections and your progress are what the Service is made of, and deleting them on a timer would destroy the thing you came for. What ends the retention is you. Deleting your account removes them, and 7.2 sets out exactly what that reaches and what it does not.

Where a period is fixed, it is fixed by law or by one specific purpose:

  • Security event records, including the IP address a sign in came from: 90 days.
  • Payment provider notification records: 60 days.
  • The payment identity hashes described in section 2: two years after the instrument was last seen.
  • Records that Brazilian law requires us to keep (Marco Civil da Internet, art. 15): six months.
  • Invoices and tax records: five years.
  • Data processed on consent: until consent is withdrawn.

We would rather be plain about the mechanism than tidy about it: the first three limits are enforced by routines we run against the database, not yet by an automatic scheduler, so a record can outlive its limit until the next run. None of this is a reason to keep data we no longer need. If you ask us to delete something, we delete it.

7. Your rights

You may exercise the following rights, free of charge, at any time:

  • Right of access (Art. 15 GDPR / art. 18 LGPD);
  • Right to rectification (Art. 16 GDPR);
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR);
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to object (Art. 21 GDPR);
  • Right to withdraw consent at any time;
  • Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR / art. 20 LGPD);
  • Right to lodge a complaint with a supervisory authority, namely your local EU Data Protection Authority, or the Brazilian National Data Protection Authority (ANPD).

7.1 Getting a copy

For access and portability you can use Account → Export your data directly inside the app. We generate a JSON file containing everything we hold about you. For other rights (rectification, objection, restriction) or to withdraw consent, write to info@mistereducation.com. We will respond within one month (GDPR) or fifteen days (LGPD), as applicable.

7.2 Deleting your account, and what deleting it does not remove

You can delete your account from your account settings. Doing so removes your profile, your conversations, your essays, your vocabulary, your exercise history, your progress, your direct messages, your friendships, your avatar and your voice recordings. It happens immediately rather than on a delay, and it cannot be undone.

Two things to know first.

We cannot delete an account while a paid subscription can still charge it. Cancel the subscription, then delete. This exists so that an account cannot disappear while a payment mandate keeps taking money from someone we no longer have any record of.

A small number of records are kept on purpose, with your account identifier removed from them, because they exist for reasons that outlive the account:

  • Security event records: the time, the IP address, the email address that was used and the browser. These are what an investigation into a break-in attempt is made of.
  • Records of what our AI providers cost us, which are accounting records.
  • Bug reports you filed, including any screenshot you attached and the email address you filed them with, so that a reported problem can still be fixed and answered.
  • Reports you sent us about a wrong grammar hint, kept as the evidence for fixing it.
  • Coaching applications you sent, which contain your name, your email address and what you wrote in the form.
  • Samples of tutor corrections kept to improve the correction engine, which can include a sentence you wrote.

Records held by Stripe and by Asaas are theirs, kept under their own legal obligations, and deleting your account here does not delete them there. Waiting list sign ups are held separately from accounts and are removed on request.

If you want any of the above removed as well, write to info@mistereducation.com and we will do it, unless a law requires us to keep it.

8. Automated decisions and AI

The Service uses generative AI models to write tutor replies, correct what you write, mark exercises and essays, place you at a level, choose what to show you next and produce grammar hints. Model output can be wrong, and it should be read as a teacher's suggestion rather than as a fact.

No decision that produces a legal or similarly significant effect about you is taken by a model on its own. In particular, a refund is never refused automatically: the fraud signals described in section 2 can mark a case for a person to look at, and only a person decides. You may request human review of automated decisions affecting your interests, in line with Art. 22 GDPR and art. 20 LGPD.

We do not use your content to train models of our own.

9. Cookies and local storage

  • Strictly necessary: required to operate the Service (authentication, session, your language, your currency and your time zone). No consent needed. This category also includes a cookie that records whether your device asked for a lighter version of the interface, worked out from signals your browser exposes such as how many processor cores it reports, how much memory it reports, whether a data saver is on and whether you have asked for reduced motion. It stores a yes or no answer and lasts 30 days. While the private beta gate is switched on, a further cookie records that you entered the access password.
  • Analytics/performance: with consent, to understand usage and improve the product. If you have consented and an error occurs, our error monitoring sends a replay of the moments leading up to it. All text, all form inputs and all images are masked out of that recording before it leaves your browser.
  • Marketing: we do not currently use marketing or advertising cookies; if that changes we will ask for your consent first.

Some things we keep on your device are not cookies. Your theme and text size are stored in local storage, and vocabulary you are reviewing is held in your browser's own database so that review works offline. Both stay on your device and are cleared when you clear site data.

You can manage your preferences at any time in your browser settings or in our cookie banner. The full inventory is in the Cookie Policy.

10. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS) and at rest, passwords hashed by our authentication provider, row level security so that one account cannot read another's data, private storage buckets served only through short-lived signed links, one-way keyed hashing of payment identifiers, rate limiting on sign in and public forms, a content security policy, and security audit logs. In case of a personal-data breach posing risk to data subjects, we will notify the relevant authority (ANPD or EU DPA) and affected users within the legal deadlines (Art. 33 to 34 GDPR / art. 48 LGPD).

11. Children

The Service is not directed to children under 13. In the EU, processing of children's data is subject to Art. 8 GDPR; in France the digital age of consent is 15. Minors must obtain parental consent. In Brazil, minors aged 13 to 17 may use the Platform only with specific parental consent (art. 14 LGPD).

We do not ask for your date of birth and we have no way to verify anyone's age, so this is a rule about who may use the Service rather than a control that prevents it. If you are a parent or guardian and believe a child has created an account, write to info@mistereducation.com and we will delete it.

12. Changes

We may update this Policy. Material changes will be notified via the Platform or by email with reasonable advance notice. The date of the last update appears at the top of this page.

13. Contact

For any question about this Policy or to exercise your rights, contact us at info@mistereducation.com.