My Challenge Studio
FeaturesUse CasesPricing
Sign inGet started free

Privacy Policy

Challenge Studio by Smartstack Platforms LLC · Effective 16 September 2026

This explains what Challenge Studio collects, why, who else handles it, and how to get it removed. It is written to be specific rather than broad — every claim here describes what the software actually does.

The short version: we collect what running a challenge requires, we set one cookie and it keeps you signed in, we use no advertising or analytics trackers, and we never sell anything about you.

Contents

  1. 1.Who we are
  2. 2.What we collect
  3. 3.What we do not collect
  4. 4.Private submissions
  5. 5.Why we use it
  6. 6.Cookies and rate limiting
  7. 7.Who else processes it
  8. 8.Where it is held
  9. 9.How long we keep it
  10. 10.Your rights
  11. 11.Children
  12. 12.Security
  13. 13.Changes to this policy
  14. 14.Contact

1.Who we are

Challenge Studio is software for building and running multi-day challenges, operated by Smartstack Platforms LLC. This policy covers the Challenge Studio application and its marketing website.

Two kinds of person use it, and the difference matters throughout. A creator builds and runs challenges inside a workspace. A participant takes part in someone’s challenge. For the content a participant submits into a challenge, the creator’s workspace decides what happens to it and we act on their instructions.

2.What we collect

Only what the product needs to work. Specifically:

  • Your account. Email address, the name you give us, and an avatar image URL if you set one. Your password is handled by our authentication provider and is stored only as a hash — we never see it.
  • What you submit to a challenge. Written answers, assignments and reflections, and whether you marked each one private.
  • What you post publicly in a challenge. Feed posts, comments and reactions.
  • Your progress. Which steps you completed and when, points earned, badges awarded, and your streak.
  • Email we send you. A log of which message was sent to which address, when, and whether it was delivered, skipped or failed. We keep this so we can tell whether a message reached you and never send it twice.
  • Your notification preferences. Including whether you have unsubscribed from a particular workspace.
  • IP addresses, briefly. Used as a counter key to rate-limit registration forms and sign-in attempts. It is not attached to your account and is discarded when the time window passes — see Cookies and rate limiting.

3.What we do not collect

Stating this plainly is more useful than leaving it to be inferred:

  • No payment details. Challenge Studio does not process payments at all. A paid challenge checks an entitlement the creator grants elsewhere; card details never reach us because there is nothing here to reach.
  • No advertising or tracking. No advertising network, no analytics script, no tracking pixel, and no cross-site profiling. The application sets no cookie other than the one that keeps you signed in.
  • No sale of your data. We do not sell, rent or trade personal information, and we do not share it for anyone else’s advertising.
  • No file uploads yet. Uploading files to a challenge is not available, so no documents or images of yours are stored.

4.Private submissions

Some challenge steps let you mark an answer private. When you do, that answer is withheld on the server: other participants cannot see it, and within the creator’s team only members whose role includes permission to view private submissions can open it.

The creator’s participant export also excludes it. The export contains counts, dates and progress — it never contains the text of any submission, private or otherwise.

Two honest limits. The creator, as the workspace owner, can grant that permission to their own team members, and we have no way to know who they trust. And private means private from other participants and from unauthorised team members — not encrypted such that we could not read it if legally compelled.

5.Why we use it

  • To let you sign in and keep you signed in.
  • To run the challenge — unlock the right day, record what you finished, and show your progress.
  • To send the challenge email you would expect: confirmations, a nudge when a day opens, feedback on your work.
  • To show creators how their challenge is going, in aggregate and per participant.
  • To keep the service standing up — rate limits against spam and abuse, and error logs to fix faults.

6.Cookies and rate limiting

Challenge Studio sets one kind of cookie: the session cookie issued by our authentication provider, which is what keeps you signed in between page loads. It is necessary for the application to function and cannot be switched off while you are using your account.

There are no analytics, advertising or preference cookies, which is why you will not find a cookie banner — there is nothing to consent to.

Separately, the public registration form and the sign-in page count attempts per IP address so that neither can be flooded. Those counts hold an address and a timestamp, are not linked to any account, and expire on their own — within fifteen minutes for sign-in attempts and an hour for registrations.

Fonts are served from our own domain rather than fetched from a font network, so loading a page does not disclose your address to a third party for that purpose.

7.Who else processes it

We use a small number of service providers, each handling data only on our instructions:

  • Supabase — database and authentication. This is where your account and challenge data live, in AWS us-west-2 (Oregon, United States).
  • Vercel — application hosting and delivery.
  • Resend — sending transactional email. Receives the recipient address and the message.
  • Upstash — shared counters for the rate limits described above, where configured.

One thing worth flagging, because it is not obvious: if a creator embeds a video from YouTube or Vimeo into a challenge day, your browser contacts that service directly when the page loads, and their own privacy terms apply to that request. We do not send them anything about you, and we cannot control what they collect.

8.Where it is held

Your data is stored in AWS us-west-2 (Oregon, United States). If you are in the United Kingdom, the European Economic Area or another region with data transfer rules, using Challenge Studio involves a transfer of your information to the United States. We rely on standard contractual clauses with our providers for that transfer.

9.How long we keep it

  • Your account — until you ask us to delete it.
  • Challenge content and progress — for as long as the creator’s workspace exists. If they delete the challenge or the workspace, it goes with it.
  • The email delivery log — kept while your account exists, because it is what stops a message being sent to you twice and lets us answer whether something reached you.
  • Rate-limit counters — minutes to an hour, then gone.

10.Your rights

You can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete your account and the data attached to it;
  • stop sending you challenge email — you can also do this yourself, per workspace, in your notification settings.

Email privacy@mychallengestudio.com and we will respond within 30 days.

Deletion, honestly: there is not yet a button in the product that deletes your account, so for now it is a request to us rather than something you can do yourself. When we delete your account, the workspaces you own and the records attached to them are removed with it. Content you posted into someone else’s challenge is removed too; what may remain is the fact that a participant completed a step, inside that creator’s aggregate figures, with no link to you.

11.Children

Challenge Studio is not directed at children under 13, and we do not knowingly collect their information. A creator running a challenge for under-16s is responsible for obtaining whatever consent their own jurisdiction requires. If you believe a child has given us information, write to privacy@mychallengestudio.com and we will remove it.

12.Security

Every request is served over HTTPS. Passwords are stored as hashes by our authentication provider. Access between workspaces is separated in the application and that separation is covered by automated tests, including tests that sign in as one customer and attempt to reach another’s data.

No system is perfectly secure, and we would rather say so than imply otherwise. If you find a vulnerability, please report it to legal@mychallengestudio.com before disclosing it publicly.

13.Changes to this policy

Challenge Studio is in beta and still changing. If we start collecting something new, or add a provider that handles your data, we will update this page and change the effective date at the top. Where the change is significant we will email you before it takes effect rather than relying on you to re-read this page.

14.Contact

Smartstack Platforms LLC
Privacy: privacy@mychallengestudio.com
Everything else: legal@mychallengestudio.com

See also our Terms of Service.

Questions about this document? Email legal@mychallengestudio.com.

Privacy Policy·Terms of Service·Back to Challenge Studio