Read this file before using the associated MEGA service. Plain language is intentional; professional jurisdictional review is still required.
Account and authentication data
MEGA uses account information such as email address, Supabase user identifier, authentication provider and session state, display name, profile role, and account timestamps to sign users in and operate private areas. Google sign-in is available through Supabase OAuth in addition to email authentication.
Membership and billing records
MEGA stores membership tier and status, voting power, the first verified paid-membership date and its display preference, billing-period state, cancellation state, and limited Stripe identifiers and event references needed to synchronize access, prevent parallel subscriptions, reconcile accounting, and support billing operations.
Stripe processes payment-card and payment-method details. MEGA does not receive or store full card details in its application database.
Voting, governance, and Impact data
Voting records use a private account reference and preserve the membership tier and voting weight attached to an accepted vote. Public voting and Impact reports show combined results rather than voter identities.
Impact accounting, project decisions, publication actions, proof links, corrections, and administrative records are retained so the original history remains available and later corrections are recorded separately. Public reports deliberately withhold administrator identities, private veto notes, customer data, and financial allocation amounts.
Protected content, security, and operational logs
MEGA processes security and service data such as sign-in and access checks, protected-video requests, abuse-prevention counters, request outcomes, and limited error details to protect accounts, billing, voting, video access, and administrative features. Logs must not intentionally contain raw passwords, secret keys, authorization headers, cookies, session tokens, full payment data, or complete provider records.
Email communications
MEGA currently uses email for authentication and necessary account or transactional communications. No public newsletter subscription or marketing-email programme is currently active.
Cookies, local storage, and analytics
Supabase authentication uses strictly necessary session cookies or equivalent storage to keep users signed in and secure private routes. A non-production demo preference may use local storage when demo mode is explicitly enabled.
MEGA does not currently run advertising trackers, marketing cookies, or a product analytics service. On that current basis, there is no non-essential tracking consent banner to operate.
Service providers and international processing
MEGA relies on Supabase for authentication and database services, Stripe for billing, Mux for protected video delivery, Google for optional OAuth sign-in, and Vercel for application hosting. These providers may process data in countries other than the user's country under their own applicable safeguards and terms.
Retention and user rights
MEGA retains data only for as long as reasonably needed for the purposes described here, including account operation, paid access, fraud prevention, security, financial and legal obligations, audit integrity, dispute handling, and backup cycles. Exact schedules still require professional privacy and operational review.
Depending on applicable law, users may have rights of access, correction, deletion, restriction, objection, portability, or withdrawal of consent. MEGA does not currently claim a self-service account-deletion workflow; the verified request process and response timelines remain a launch TODO.
Operator and privacy contact
The verified data-controller or legal-operator identity, registered address, privacy contact, jurisdiction-specific lawful-basis notices, and rights-request channel are not yet supplied. These details must be completed and professionally reviewed before live launch.