Privacy Policy
How MustMock handles account, study, authentication, support and payment-related information.
Last updated: October 2026.
This Privacy Policy explains the categories of information MustMock may process when you use the website, student workspace, assessments, memberships, support and related services.
1. Information you provide
Depending on how you use MustMock, we may process your name, mobile number, email address, password hash, exam date, profile preferences, support requests, private bookmark notes and information you submit through account or support forms.
2. Authentication information
We process account and session information needed to authenticate users, maintain secure sessions, enforce single-session rules and respond to suspected account misuse. Raw passwords are not intended to be stored; password hashes and security metadata are used instead.
3. Google sign-in
If you choose Continue with Google, MustMock requests only identity information needed for sign-in, such as the Google account identifier, name and email address. MustMock does not request access to your Gmail inbox merely to provide sign-in.
4. Password-recovery OTP
If enabled, MustMock may send a one-time password to a verified recovery channel such as email or SMS. The OTP, delivery destination, expiry, retry information and related security records may be processed to complete the recovery request and prevent abuse.
5. Study and assessment information
We process assessment attempts, selected answers, correctness, time spent where recorded, flags, completion status, scores, topic performance, practice history, bookmarks, notes and Error Notebook activity to provide the study service.
6. Readiness and analytics
MustMock may derive rule-based readiness bands, topic-strength signals, consistency measures, trend indicators and pacing signals from your study activity. These are educational analytics, not official examination scores or pass-probability predictions.
7. Membership and order information
We process selected membership plans, exam windows, coupons, order totals, payment status, provider references, refund or reconciliation status and access activation records for billing, account access and support.
8. Payment-provider information
External payment providers may independently process card, UPI, banking or wallet information under their own privacy terms. MustMock stores only the order and payment references reasonably necessary to verify payment, activate access, reconcile transactions and provide support.
9. Referral information
Where the referral program is active, MustMock may process referral codes, referrer and referred-account relationships, qualifying transactions, reward status and anti-fraud information.
10. Device, session and technical information
For security and reliability, we may process IP address, request logs, browser or device information, timestamps, session identifiers, error logs and related technical information generated when the service is used.
12. Why information is used
Information may be used to create and secure accounts, authenticate users, deliver assessments, calculate results, provide analytics, enforce access rules, operate memberships, payments, coupons and referrals, answer support requests, prevent abuse, maintain backups and improve service reliability.
13. Legal bases and mandatory rights
The lawful basis for processing may depend on the user's location and the nature of the information. It may include performing a contract, legitimate interests, consent or compliance with legal obligations, where applicable.
14. Service providers
We may use hosting, database, backup, authentication, email, messaging, payment, error-monitoring or analytics providers. Providers should receive only information reasonably necessary for their role and should be subject to appropriate contractual or legal safeguards.
15. International processing
Service providers may operate infrastructure in more than one country. Where personal information is transferred across borders, appropriate safeguards should be used where required by applicable law.
16. Security
We use server-side authorization, password hashing, protected sessions, role-based access, backups, encrypted storage for supported provider credentials and other reasonable technical measures. No internet service can guarantee absolute security.
17. Retention
Records are retained only as long as reasonably necessary for product operation, security, accounting, dispute handling, legal obligations and legitimate business needs. Retention periods may differ for account, study, payment and security records.
18. Account and data requests
Subject to applicable law, users may contact support about correction, access, deletion, restriction or other legally available requests. Some records may need to be retained for accounting, fraud prevention, legal claims, security or other lawful purposes.
19. Children and age requirements
MustMock is intended for users who are legally able to create and use the service in their jurisdiction. Where parental or guardian consent is legally required, the user must obtain it before using the service.
20. Policy changes
This Policy may change as features, providers or legal requirements change. Material changes should be posted with an updated date and, where required, additional notice or consent.
21. Contact and grievances
Privacy questions and requests may be sent through the Support page or the privacy/contact details published on the website.
Contact
Questions about this policy can always be sent through the Support page.
MustMock
https://mustmock.com