Privacy Policy
Effective date: 2026 · Data controller: CharyxLabs (charyxlabs.tech) · Contact: [email protected]
Plain-English summary: You can use the entire roadmap without an account and without giving us anything — your progress stays in your own browser. If you choose to sign up, we store your email and your progress, nothing more. We don't sell data, we don't run ad networks, and you can delete everything at any time.
1. Our approach
Data minimisation is the design principle. We collect the least we can get away with, and the core product is built to work with nothing at all.
2. What we collect
If you never create an account (default)
| Data | Where it lives | Why |
|---|---|---|
| Your day-by-day progress, streak and preferences | Your browser only (localStorage) |
So you can pick up where you left off |
This never leaves your device. We cannot see it. Clearing your browser data deletes it permanently.
If you create an account (optional)
| Data | Why we need it |
|---|---|
| Email address | To create the account, sign you in, and reset your password |
| Password | Stored only as a salted hash by our authentication provider — never in plain text, never visible to us |
| Display name and (optional) avatar | To show who you are in the community |
| Learning progress | So your roadmap syncs across devices |
| Community posts you write | To display them |
| Account timestamps (created/last sign-in) | Security and abuse prevention |
Automatically
Our hosting provider processes standard server logs (IP address, user agent, timestamp) for security and to serve the site. We keep these to a minimum and do not use them to build profiles of you.
We do not collect: your real name, address, phone number, date of birth, payment details (there's nothing to pay for), or precise location.
3. What we do NOT do
- ❌ No selling or renting of personal data. Ever. Non-negotiable.
- ❌ No advertising networks and no ad-tracking pixels.
- ❌ No cross-site behavioural tracking or data brokers.
- ❌ No email marketing unless you explicitly opt in.
4. Cookies and local storage
- Essential only. We use
localStoragefor your progress and, if you sign in, a session token to keep you signed in. No advertising or analytics cookies are set by us. - Embedded third-party content (for example YouTube players) may set its own cookies when it loads, under its own privacy policy — we have no control over that. If this concerns you, most browsers let you block third-party cookies, and every embedded resource is also available as a plain outbound link.
5. Processors we use
We rely on a small number of reputable providers who process data on our behalf:
| Provider | Role | Data involved |
|---|---|---|
| Vercel | Website hosting | Server logs, IP addresses |
| Supabase | Database & authentication (only if you create an account) | Email, password hash, profile, progress, posts |
| Cloudflare | DNS and email routing for our domain | Email you send us; DNS-level request metadata |
| YouTube (Google) | Embedded video playback | Whatever YouTube collects under its own policy |
These providers may store data outside your country, including in the EU and USA. Where required, transfers rely on the providers' own standard contractual clauses.
6. How long we keep it
- Local progress: until you clear your browser.
- Account data: until you delete your account.
- Deleted accounts: removed from live systems promptly (target: within 30 days), allowing for provider backup cycles.
- Server logs: short retention, per our hosting provider's defaults.
7. Your rights
Wherever you live — and specifically under the GDPR (EU/UK) and India's Digital Personal Data Protection Act, 2023 — you can:
- Access the data we hold about you
- Correct anything inaccurate
- Delete your account and data (right to erasure)
- Export your data in a portable format
- Object to or restrict processing
- Withdraw consent at any time
- Complain to your local data-protection authority
Most of these you can do yourself from account settings. For anything else, email [email protected] and we'll respond within 30 days.
8. Children
Michi is intended for users aged 13 and over. If you are under 16 (or the digital-consent age in your country), please get a parent or guardian's permission before creating an account.
We do not knowingly collect personal data from children below these ages. If you believe a child has given us data, email [email protected] and we will delete it promptly.
9. Security
Passwords are hashed by our authentication provider and never stored in plain text. All traffic is served over HTTPS. Database access is restricted with row-level security so that one user cannot read another user's data. No system is perfectly secure, but we take this seriously; if you find a vulnerability, please report it privately to [email protected] rather than opening a public issue.
10. Transparency
The application source is not public, so we won't ask you to take "read the code" as the guarantee. Instead, here is plainly what is and isn't true:
- Michi works without an account. If you never sign in, your progress never leaves your browser and we hold nothing about you.
- We run no advertising and no third-party analytics or tracking pixels. There is nothing following you between sites.
- We have never sold or shared personal data, and we won't.
- If you do create an account, everything we store is listed in §3, and you can export or delete all of it yourself from your account page — deletion is real deletion, not a flag.
The learning content is openly licensed (CC BY-SA 4.0) and every third-party resource names its creator and licence in the app, so the material itself is fully inspectable even though the application code is not.
If something here is unclear, ask: [email protected].
11. Changes
We'll update this policy as the project evolves. The effective date above changes whenever it does, and material changes are announced in-app.
12. Contact
Provided in good faith for a free, non-commercial educational project. Not legal advice; if you fork this for commercial use, have a lawyer review it.