Authenticated study sets
Study-set pages require a signed-in user and server-side ownership checks. Private routes are marked noindex and excluded from the XML sitemap. Changing a study-set ID should not grant access to another user’s data.
Upload safeguards
- Allowed file extensions are restricted
- File signatures are checked for common formats
- File and request sizes are limited by plan
- Duplicate uploads are rejected where detected
- Remote URLs pass server-side safety checks
Storage and processing
Mindley uses infrastructure and AI service providers to store and process account data and requested study content. Access and retention details are described in the Privacy Policy. No online system can promise absolute security.
What students should do
- Use only material you have permission to upload
- Do not upload passwords, identity documents, or confidential records
- Sign out on shared devices
- Delete study sets you no longer need
- Report suspected unauthorized access promptly
Report a security issue
Use the Contact page and select a security or privacy-related reason. Do not include an exploit payload, password, secret key, or another person’s private data in the first message.