MAS Review

Last updated 29 September 2026

Privacy Policy

Who is responsible

MAS Review is in closed beta. During the beta, the controller of the personal data described in this policy — the person who decides what is collected and why — is Mohammad Ali Shakeri, acting in a personal capacity. You can reach him through the contact form, choosing “Privacy request”.

If MAS Review is transferred to a company, that company will become the controller. We will tell you by email before that happens, and update this policy with the company’s name, registered number and address.

The media, comments and other content a studio uploads belong to that studio. We process them on the studio’s instructions, to provide the service the studio asked for. If you have a question about content in a studio you do not own, ask that studio’s owner first.

What we collect

Account

Your email address, your name (which starts as the part of your email before the @, and you can change it) and a display colour, which is derived from your email and which you can change. There are no passwords.

Sign-in codes and sessions

Signing in sends a six-digit code to your email, which expires after five minutes. Each signed-in session records its expiry, the IP address and the browser (user agent) it was created from.

Studios and invitations

The studio’s name and plan, who its members are and their roles, and the email addresses of people who have been invited but have not yet signed in.

Content and what is derived from it

Everything you upload: video, images, audio, PDFs, documents, 3D models and their side-car files. Everything we make from it to show it to you: video renditions, thumbnails, display copies and converted files. And everything the generation features produce when you ask for them: transcripts, subtitles, translations, automatic captions and tags, text recognised in frames, colour palettes, generated images and re-voiced audio (spoken by a fixed set of stock voices).

Comments and activity

Comments, replies, drawings, pins, statuses, folders and the names shown on them. An activity log per studio records who did what (name, action, a short snippet of the comment, time). Notifications hold the same snippet for each recipient, together with your notification preferences.

Reviewers on a share link

A display name and, when the link requires it, an email address verified by a code. The name appears on every comment the reviewer posts.

Billing

Billing runs through Stripe. Stripe holds the studio’s name, the owner’s email and the payment details; Stripe handles card details. We keep the subscription status, the credit balance and a record of each credit pack bought.

Camera-to-cloud devices

If a studio connects a camera or upload device, we keep its name and credential, who created it and when it was last seen.

Contact form

What you type into the contact form (reason, name, email, studio and message) is sent to us by email, together with the IP address and browser it came from. The message is delivered to our mailbox, which is hosted by Google.

Technical data

Rate-limit counters keyed by IP address, account, email address, share link, studio or device, kept for the length of the limit window. Our hosting provider keeps basic request logs, which include IP addresses, for its standard period.

We run no analytics or tracking scripts, and we set no advertising cookies.

How we use it

  • to run the service: store, play, convert and show your content, and keep studios and projects in sync between members;
  • to sign you in and keep you signed in;
  • to send transactional email: sign-in codes, invitations, share-link codes, and notifications about mentions, replies and project activity according to your preferences, plus billing notices to the studio owner;
  • to produce the generation results you ask for;
  • to bill Pro seats and credit packs, and to count Generation credits;
  • to limit request rates and prevent abuse;
  • to answer your requests and support questions.

We do not sell your data and we do not use it for advertising.

Why we are allowed to use your data

We use your account, sign-in and studio data because we need it to provide the service you asked for (contract). Content a studio uploads is used on that studio’s instructions, as described above. We keep session records, rate-limit counters and request logs to keep the service secure and prevent abuse, we let reviewers on a share link take part in the review a studio invited them to, and we answer contact-form messages — we do these because we have a legitimate interest in them. We keep or share data when the law requires it (legal obligation).

Who we share it with

We use these providers to run MAS Review. Each receives only what its job needs.

  • Vercel — hosting. Runs the application and serves every request. Also stores some files (images, PDFs, audio, generated images and comment attachments).
  • Neon — the database. Accounts, sessions, studios, memberships, share links, notifications, activity and billing state. No media files.
  • Cloudflare R2 — object storage. Your uploaded originals, converted files, thumbnails and attachments.
  • Mux — video processing. Transcodes uploaded video into playable renditions, thumbnails and storyboards, and streams them back.
  • Liveblocks — realtime collaboration. Holds the project document (comments, drawings, media names, statuses, transcripts, subtitles and the visual index) and the presence of who is in a room.
  • Resend — email delivery: sign-in codes, share-link codes, invitations, notifications, billing notices and contact-form messages.
  • Stripe — payments for Pro seats and credit packs.
  • Upstash — the counters behind rate limiting and reviewer credit allowances.
  • ElevenLabs — transcription (audio tracks, sent in chunks) and the speech behind re-voice, spoken by a fixed set of stock voices.
  • OpenAI — image generation, transcription and re-voice scripts when you choose that engine, the default engine for palettes, and the English translation of subtitles, which runs automatically whenever a transcript is not in English.
  • Google — the default engine for generated images from a captured frame and your note, an option for palettes, and the mailbox that receives contact-form messages.
  • Anthropic — automatic captions, tags and text recognition for visual search (sampled frames), and an option for palettes.
  • Modal — file conversion and rendering: decoding camera stills, converting office documents and audio, and converting and rendering 3D models.

Content sent to a generation provider is used to produce the result you asked for, or that a feature you turned on (such as subtitles) needs. After each transcription with ElevenLabs we ask it to delete the transcript it holds; other providers keep what they process for their own standard period.

We share data with nobody else, unless the law requires it.

Cookies and local storage

We set only the cookies the service needs to work.

  • Session cookie — keeps you signed in. It lasts seven days and is refreshed while you use the service.
  • Share-link cookie (named mm_guest) — remembers you as a reviewer on a share link, with your display name and, if given, your email. It lasts seven days.

Your browser’s local storage keeps preferences that never leave your device: the studio you last used, the generation and transcription engines you chose, drawing settings, recent searches and similar. The browser also caches frames and document tiles so that scrubbing and page turns stay fast, and it queues comments posted from a share link while you are offline.

There are no advertising cookies, no third-party cookies and no analytics.

Retention and deletion

Media, comments and project documents stay until the studio deletes them. Deleting a file removes its original and its video renditions. Deleting a project hides it at once and revokes its share links at once; its files, renditions and project document are deleted from our storage after a 14-day grace period. Copies held in provider backups or object versions follow those providers’ standard periods. Deleting a studio deletes each of its projects the same way, and the studio itself is removed once its last project has been purged.

Revoking a share link stops new visitors from opening the project. A file address that was copied out while a link was live may stay reachable until the file itself is deleted.

To delete your account, ask us through the contact form. Deletion removes your account, sessions, memberships, notifications and preferences, and any unfiled uploads of your own. Your name is removed from the studio activity log, where your actions are shown as “Former member”. The name on comments you posted inside a studio’s projects stays with those comments, because they are part of that studio’s record; the studio owner can delete the comments. If you own a studio, transfer it to another member or delete it before asking for account deletion.

Sign-in codes expire after five minutes. Sessions last seven days. Share-link cookies last seven days. Rate-limit counters expire with their window.

Backups and provider logs are kept for our providers’ standard periods.

International transfers

Our providers operate in the United States and other regions. When you use MAS Review, your data is processed where these providers operate, which may be outside the country you are in.

Your rights

You can ask us for a copy of your account data, to correct it, to delete it, or to export it. Send the request through the contact form, choosing “Privacy request”. We may ask you to confirm the request from the email address on the account.

You can change your name, display colour and notification preferences in the app.

You can also ask us to limit how we use your data, and you can object to any use we base on legitimate interest. If you are unhappy with how we use your personal data, tell us first through the contact form(“Privacy request”). We will acknowledge your complaint within 30 days and tell you the outcome. You can also complain to your data protection authority; in the UK that is the Information Commissioner’s Office (ico.org.uk).

Children

MAS Review is a tool for studios and their reviewers, not for children. If you believe a child has given us data, tell us through the contact form and we will delete it.

Changes

We may update this policy. The date at the top shows the current version. If a change matters to you, we tell you by email or in the app before it takes effect.

Contact

Privacy questions and requests go through the contact form at https://mas-review.com/contact. We reply by email.