Privacy
What we store, and what we don't.
MechCompass is an independent learning platform. You can use the roadmap and every module without signing in. If you make an account, we keep only what it takes to sign you in and save your progress, nothing more.
Without an account
You can browse the whole roadmap and every module signed out, and we do not build any profile of you. Like any website, the server that hosts us keeps standard request logs, which include your IP address, to keep the site running and secure. That is all that happens.
If you make an account
An account saves your place across devices. Once you sign up and use it, we keep your email and a password (the password is stored only as a secure cryptographic hash by our sign-in provider, so we never see it), a display name you choose, your self-assessment result and recommended starting point, and your course progress: what you have finished, your next step, review reminders, and any notes you save.
Who else touches your data
Several service providers help run MechCompass, and each receives only the information needed to provide its service.
Netlify hosts the website and keeps standard technical request logs. Supabase provides account authentication and stores account and learning-progress data. jsDelivr delivers the Supabase JavaScript library used for account functionality.
Resend delivers transactional account emails, such as email confirmations and password-reset messages. For this purpose, Resend receives information such as your email address, the content of the message, and technical delivery information.
ImprovMX forwards messages sent to MechCompass email addresses, including messages sent to privacy@mechcompass.com. When you contact us by email, ImprovMX may process your email address, message content, email headers, and any attachments as necessary to forward the message.
Some of these providers may process data outside the European Economic Area using the applicable contractual or legal safeguards.
We do not use analytics, advertising, or tracking cookies. Your signed-in session is stored in your browser's local storage. We send only necessary account emails or messages that you request.
Seeing or deleting your data
Your progress is always on your Progress page once you sign in. To export or delete your account and everything stored with it, email privacy@mechcompass.com and we will sort it out, usually within 30 days. There is no self-service delete button yet, so for now it is by email. After a deletion, backups and provider logs may hold a copy for a short while before they rotate out on their own.
Who runs MechCompass, and your rights
MechCompass is the data controller for the information described above. You can reach the operator about any of this at privacy@mechcompass.com.
We rely on these legal bases under the GDPR: your account email, display name, and saved progress are processed to provide the account you asked for (Article 6(1)(b), performance of a contract); standard server and email-delivery logs are processed for the security and reliability of the service (Article 6(1)(f), legitimate interests).
You have the right to access your data, correct it, delete it, restrict or object to its processing, and receive a portable copy. To use any of these, email privacy@mechcompass.com. You can also lodge a complaint with your local data-protection supervisory authority.