Future Studio privacy
Your private workspace
Private Future Studio plans contain the profile, grade and budget estimates you enter, plus any blueprint evidence notes, programme shortlist, CV, research notes, practice records and personal outcome assumptions you choose to save. They are linked to your sign-in identity. Exports contain that private information, so store them carefully.
Guest profile and CV recovery
Guest Future plans are kept in local storage on this device without an automatic expiry; browser data clearing may remove them. Anyone using the same browser profile can access a guest copy. Sign in for an account backup or download a backup file. A device plan can seed a new account workspace after sign-in. If that account already has a saved plan, you choose which plan to keep and can download both first. A device copy is removed after its exact version is successfully saved to the account. Separate CV tab recovery lasts up to 24 hours; invalid or incomplete fields remain in tab recovery until fixed. Account recovery is scoped to the authenticated account.
CV exports and Share my star images are created locally. Personal name and goal fields are off by default in the star share preview. Opening WhatsApp or your device share sheet passes only the content you selected; nothing is posted automatically. The cinematic sky was generated without student data and is served as a local Future asset. Your profile, CV and documents are not sent to Runway.
Local practice and vision
Communication practice uses a local timer and your script. It does not access the microphone or record speech. The public vision studio processes a selected portrait in your browser; you choose whether to include personal details in an exported or shared card.
Documents
Uploaded documents are private to your account. Supported PDF, JPEG, PNG and WebP files are limited to 5 MiB each, 50 documents and 100 MiB in total. Files are checked for size, format and signatures. New uploads stay inaccessible while a configured scanner checks them. Clean results allow access; unsafe results block release. If scanning is unavailable or inconclusive, files remain quarantined until their owner explicitly reviews and releases them. Manual release is not a malware-free guarantee. No scanner is configured in this release. Existing files uploaded before this release were not scanned retrospectively. A future operator-configured HTTPS scanner receives document bytes and MIME type, not your identity or plan; its retention terms require separate review before activation. Do not upload patient information, executable or untrusted documents. Documents are excluded from family snapshots and plan backups. Download originals separately if you need a copy.
Family snapshots
Family sharing creates a separate snapshot containing only your selected sections. Bearer links are stored as hashes, and revoked snapshots are removed. Anyone holding the link can read the selected snapshot until you revoke it or it expires. New links last 1, 7, 30 or 90 days; existing links created before expiry controls receive at most 30 days from their original creation. Expiry blocks access immediately; expired snapshots are scrubbed when the owner opens the share list. No scheduled purge is promised. Revocation cannot erase copies already kept by a recipient or cached WhatsApp previews. Comparison and outcome sharing is opt-in and contains dated assumptions, never live private records. Family-view pages do not send analytics events.
Reports and preferences
Funding reports should contain public source corrections, not personal records. Future’s theme preference is stored separately from the main Meyshan site.
Mitski and CV wording
CV AI wording requires a separate checkbox. Only the notes you type and selected template are sent; the rest of the CV is excluded. Local formatting and pasted-CV restructuring work without sending text to an AI provider.
Mitski sends your question and the explicitly listed saved-plan fields to OpenAI only after consent. The server selects the model and supplies currently human-reviewed source excerpts. Names, CV, research notes and documents are excluded. Your question may still contain personal information you type; avoid identifying details.
Response storage is disabled. This does not establish zero provider retention; see OpenAI’s data controls. Future does not retain the prompt or reply. It keeps hashed-owner token, model, estimated-cost and status records, removing records older than 14 days on the next mentor request. Non-personal daily spending totals are retained separately. This is request-triggered maintenance, not a scheduled deadline.
Study and Future connections
Study and Future use the same platform account. Future supplies the canonical career profile to the signed-in Study view. Existing Study records, study preferences and dates stay intact. Exam-date and recall connections are separately opt-in, reversible and off by default. While enabled, they read the current saved source; they do not copy or overwrite the other workspace. Recall shows self-rated practice, not exam readiness. Turn either connection off in its connection panel.
Deletion and retention
Your saved plan and documents remain until you remove them. Data controls closes this Future workspace for the sign-in identity, removes the private plan, files, family snapshots, owner-linked alerts and mentor usage, and retains a minimal account tombstone to prevent stale requests recreating deleted data. This does not delete your ChatGPT identity or other Meyshan services. No automatic recreation flow is provided.
Deletion blocks access immediately. If storage removal fails, cleanup remains pending and can be retried. Keys for uploads still in flight are retained until their writer acknowledges cleanup; an interrupted writer can require operator reconciliation. We do not claim physical deletion is complete while these remain. Already downloaded copies, public human review/audit records and provider retention are outside this private-workspace deletion. Browser recovery is cleared when deletion is acknowledged in that browser; inaccessible or offline devices may retain local copies.