Privacy
This is a minimal v1 policy describing what mahir_data actually does today. It isn't legal advice, and it will be revised as the product grows.
When you write and run a query, it executes entirely client-side against PGlite (Postgres compiled to WebAssembly). Your query text and results never leave your browser for grading — nothing is sent to a server.
If you use “Ask the coach”, your SQL query and the relevant question context are sent to OpenAI's API to generate feedback. This only happens when you explicitly trigger it, and requires you to be signed in.
If you create an account, we store your email, sign-in method, and your progress (which questions and lessons you've completed) in Supabase, a hosted Postgres provider. This data is scoped to your account and not shared with other users.
If you subscribe to Basic, payment is handled by Stripe. We store your Stripe customer and subscription IDs to manage your plan status — we never see or store your card details.
If you have an account on the free plan, we may send a weekly email reminding you of a streak, a question due for review, or a new practice question. Every email has an unsubscribe link that stops it immediately. You can also change this preference from your account page. We don't email paying subscribers this way.
Your account page can export your learning attempts, completion state, and mock interview history. A deletion request starts a manual review; it does not immediately lock the account. We cancel active billing separately, remove your Supabase sign-in and learning data, and ask analytics providers to remove identifiable account data. Stripe may retain invoices and transaction records where financial, tax, fraud, or dispute rules require it.
We use PostHog to collect basic usage and pageview analytics (e.g. which pages are visited) to understand how the product is used and improve it.
Email hello@mahirdata.com if you have questions about your data.