Privacy Policy
Last updated · July 2026
masst.ai is a personal knowledge graph — a place to store your context once so any AI you choose can know you. Because that context is personal by nature, privacy isn't a footnote here; it's the product. This page explains, plainly, what we collect, how it's used, and the controls you have.
What we collect
- Account data — your email address and authentication details, handled by our auth provider (Supabase). If you sign in with Google, we receive your basic profile (name, email) from Google.
- Context you add — the strands and fields you create (your role, skills, preferences, and anything else you choose to store).
- Integration data — when you connect an integration (e.g. GitHub, Google Calendar) or upload a resume, we read only what's needed to propose fields for your strands. Nothing is written to your profile without your approval.
- Usage & device data — basic technical information (browser, device, API-key usage) needed to operate the service securely.
Sensitive data & your encrypted vault
Fields you mark as sensitive (passwords, financial details, government IDs, and anything our detector flags) are protected by a client-side encrypted vault. They are encrypted in your browser before they reach our servers, using a key derived from your passphrase that we never receive. This means:
- We cannot read your sensitive fields — we only ever store ciphertext.
- Sensitive fields are excluded from AI context, your public profile, and integration reads.
- If you lose your passphrase and recovery key, we cannot recover that data — that's the trade-off for true zero-knowledge encryption.
How your context reaches AI
Your context is only shared with an AI when you direct it to be — via a Pollen link, the browser extension, or an integration you connect. You control the visibility of every strand (private, grove, link, or public), and sensitive fields are never included. We don't sell your data or use it to train models.
To structure uploads (like a resume) into fields, we use a language-model provider (Groq). Only the text needed for that extraction is sent, and it isn't used to train their models.
How we use your data
- To operate the service — store your context, serve it to the AIs and links you authorize, and run the integrations you connect.
- To secure your account — authentication, per-device API keys, and abuse prevention.
- To communicate with you — account emails (confirmation, password reset). We don't send marketing without consent.
Who we share with
We share data only with the infrastructure providers needed to run masst.ai — our database/auth host (Supabase), our hosting platform (Vercel), our email sender, and the LLM provider used for parsing. Each processes data only to provide their service. We do not sell your personal data.
Your controls & rights
- Edit or delete any strand or field at any time from your dashboard.
- Set per-strand visibility, and encrypt sensitive fields into your vault.
- Revoke integrations and per-device API keys whenever you like.
- Request export or deletion of your account data by emailing us.
Data retention
We keep your data while your account is active. When you delete your account, your strands, fields, and connections are removed. Some minimal records may persist briefly in backups before being overwritten.
Contact
Questions about privacy, or a data request? Email hi@masst.ai. See also our Terms of Service.