Skip to content
Mestre
  • Product
  • Made with Mestre
  • Blog
  • Mestre Products
Mestre Products

Legal / Privacy

Privacy Policy

Mestre collects the bare minimum. Here we explain, in plain language, what may be processed when you visit the beta site or write to us, with a global privacy layer on top of Brazil's LGPD.

Version 1.1 · Updated 5 August 2026

β

Beta transparency document

The technical inventory of this site has been verified. Before any sign-up, telemetry or commercial launch, it is still mandatory to publish the controller's legal name and location, along with the real hosting and email providers. None of that information has been invented in this document. Referring to international regimes widens transparency, but on its own it does not determine territorial applicability, nor does it replace legal analysis before launch.

In this policy

1. Controller 2. Scope 3. Data processed 4. Purposes and legal bases 5. Retention 6. Sharing 7. Transfers 8. Rights 9. International rules 10. Security 11. Contact

1. Who the controller is

Mestre is an independent project in beta, with no legal entity incorporated. The controller is the natural person responsible for decisions about processing within the project. The channel for data subjects is contactmestrelabs@gmail.com.

Public identification by the controller's legal name is pending before production with real collection. Until then, this page must not be read as a statement that a company, a tax registration or a formally appointed data protection officer exists.

2. Scope

This policy covers the public site mestre.studio. It does not cover a future version of the desktop application handling accounts, prompts, files or projects. Before that version collects data, it must present its own notice.

The interactive demonstration on the landing page runs locally in the browser. Text typed into the demonstration is not sent by the current code to any Mestre server.

3. Data processed

ContextPossible dataSource
Site access IP, date and time, route, headers, browser, device and security events in the infrastructure's technical logs. Generated on connecting to the hosting server.
Contact by email Address, name provided, message content and attachments sent voluntarily. Provided by you.
Privacy preferences Policy version, chosen categories and the dates of the decision and its expiry. Stored only in your browser via localStorage.

The site does not ask for sensitive data, identity documents, payment, accounts or profiles. Do not send sensitive data by email unless it is strictly necessary.

4. Purposes and legal basis

  • Deliver and protect the site: operation, abuse prevention and technical diagnosis; legitimate interest and, where applicable, the regular exercise of rights (LGPD, art. 7, IX and VI).
  • Reply to your contact: handling your message and taking steps at your request; pre-contractual procedures, consent or legitimate interest, depending on context (art. 7, V, I or IX).
  • Keep your choice: remembering which purposes you accepted or refused; protection of rights and compliance with the duties of transparency and demonstration (art. 7, VI).
  • Enable optional technologies: only with free, informed, unambiguous and purpose-specific consent (art. 7, I and art. 8). No optional technology is installed today.

Mestre does not sell personal data, does not build advertising profiles and does not make automated decisions about visitors on this site.

Where the GDPR or UK GDPR apply, equivalent bases — such as consent, pre-contractual measures, legal obligation and legitimate interest after balancing — will be documented for each purpose. Under PIPEDA, the purpose and meaningful consent will be assessed according to context.

5. Retention and deletion

  • Local preferences: up to 180 days, until the version changes, or until you clear your browser data.
  • Emails: for as long as needed to reply and keep a legitimate history; operational target of review after 12 months without interaction, save for legal obligation or defence of rights.
  • Technical logs: according to the hosting provider's configuration and obligations, to be confirmed before production. Mestre's target is not to retain beyond 90 days without a security or legal need.

Data is deleted or anonymised when the purpose ends, except where retention is permitted under art. 16 of the LGPD.

6. Sharing and processors

Data may be processed by strictly necessary providers of hosting, DNS, security and email, under instructions and controls compatible with the purpose. The repository does not identify those contracts; provider names and terms must be filled in before a launch with real collection.

Sharing may also occur to comply with the law, a valid order, or to defend rights. There is no sale, rental or sharing for advertising.

7. International transfer

Hosting or email may involve processing outside Brazil. The countries, recipient companies and legal mechanism still depend on operational choices. Before production, Mestre must document and disclose the transfer and adopt a valid basis under arts. 33 to 36 of the LGPD and applicable regulation.

8. Your rights

You may request, as applicable:

  • confirmation and access; correction; anonymisation, blocking or deletion;
  • information about sharing and about the possibility of refusing consent;
  • portability, where regulated and applicable;
  • withdrawal of consent, deletion of data processed on that basis, and objection;
  • review of automated decisions, should processing of that nature ever exist.

Write to contactmestrelabs@gmail.com with the subject “Data subject request”. We may ask only for the information needed to confirm your identity. There is no charge. If the matter is not resolved, you may petition Brazil's ANPD and seek consumer protection bodies.

9. International layer and applicability

Applicability depends on factors such as the location of the visitor and of the controller, targeted offerings, monitoring, commercial activity and legal limits. The rules below form a global design standard; mentioning them does not declare that all of them apply to Mestre automatically.

European Union and EEA — GDPR and ePrivacy

Where applicable, Mestre will observe lawfulness, transparency, purpose limitation, minimisation, accuracy, storage limitation, security and accountability. Data subjects may have rights to information, access, rectification, erasure, restriction, portability and objection, as well as to complain to the competent data protection authority. Non-essential technologies on the device depend on a prior choice under the ePrivacy rules.

United Kingdom — UK GDPR and PECR

Where applicable, the UK GDPR protects equivalent rights and PECR requires clear information and active consent before non-essential storage or access on the device. Users may complain to the ICO. The need for a local representative must be assessed before targeting services at, or monitoring people in, the United Kingdom.

California — CCPA, as amended by the CPRA

Should the project become subject to the CCPA/CPRA, consumers will be able to exercise rights to know, access, delete and correct information, limit certain uses of sensitive data, opt out of sale or sharing, and not suffer discrimination. Mestre does not sell and does not share personal data for behavioural advertising on the current site. The Global Privacy Control (GPC) signal is recognised by the system and keeps marketing switched off.

Canada — PIPEDA

If PIPEDA reaches a commercial activity of the project, its ten fair information principles will be observed: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access and the ability to challenge compliance.

Other local laws may grant similar or additional rights. The channel below accepts requests from any region and will apply the most protective standard supported, without reducing mandatory rights in the competent jurisdiction.

Official references: European Commission, ICO, California Department of Justice and Office of the Privacy Commissioner of Canada.

10. Security

The project adopts minimisation, prior blocking of optional scripts, local dependencies, limited access and inventory updates as controls for this site. No environment is infallible. Incidents with relevant risk or damage will be assessed and communicated in line with the LGPD and the applicable international regimes.

11. Contact, authorities and changes

Privacy channel: contactmestrelabs@gmail.com. Material changes to the cookie inventory require a new version and a new choice. The date and version at the top let you identify the applicable text. Depending on the jurisdiction, you may also complain to Brazil's ANPD, your local European authority, the ICO in the United Kingdom, the competent California authorities, or the Office of the Privacy Commissioner of Canada.

© 2026 Mestre

Home The library Journal Privacy Cookies Terms contactmestrelabs@gmail.com