Last updated: 2024-08-15
Privacy Policy
We believe emotional safety starts with data safety. This Privacy Policy describes how Mindsle collects, uses, and protects your personal information.
Information we collect
- Account details such as email, display name, and subscription status.
- Wellness content you create including journal entries, chat transcripts, audio recordings, and generated art (currently stored in controlled environments; at-rest encryption is planned).
- Device metadata and diagnostics to ensure secure access and continuous improvement.
- Third-party billing identifiers required for subscription management.
How we use your information
- Deliver journaling, chat, and emotion tools with personalisation.
- Provide human-quality AI summaries while enforcing guardrails against unsafe responses.
- Fulfil contractual obligations including support, invoicing, and compliance.
- Monitor anonymised trends to improve our wellbeing recommendations.
Data controller & contact
- The App Store Connect registered entity (the “Developer”) acts as the data controller for Mindsle.
- You can reach us at [email protected] GDPR/CCPA requests receive a response within 30 days, subject to identity verification.
- If a local representative is appointed, we will publish their details on the website.
Retention & cross-border transfers
- Journal content and account data are retained for the minimum period needed; inactive records older than 24 months are anonymised or deleted.
- Infrastructure may rely on cloud regions outside your country; before any transfer we ensure equivalent protection and contractual safeguards.
- Backups and logs follow least-privilege retention and are regularly purged.
Subprocessors we rely on
- AI inference vendors (OpenAI, Google Gemini, Qwen, etc.) process text/voice strictly under our instructions and do not reuse the data.
- Object storage/CDN providers (AWS S3, CloudFront, MinIO) host media and static assets with signed URLs and access controls.
- Apple handles in-app purchases; optional logging/analytics providers receive only anonymised or masked data.
Minors & guardians
- Mindsle is designed for users aged 18+. Minors must use the app only with parental consent and supervision.
- If we learn that a minor submitted data without consent, we will suspend the account and help delete the information.
Device permissions & on-device processing
- Microphone & speech recognition: enable voice journaling/chat; no audio is captured without permission and some transcription may run on-device.
- Photos/media: required to upload attachments or save Emotion Art; accessed only during user-initiated actions.
- Notifications, calendars, or health integrations (if enabled later) require additional consent and work independently from core features.
Cookies & analytics
- The marketing site uses privacy-friendly analytics (e.g., Plausible/PostHog) without advertising trackers.
- The app contains no third-party ad SDKs; if we introduce any, opt-out controls and policy updates will be provided.
Your rights & how to exercise them
- Export, access, and delete your data within the app, or email [email protected] to request restriction or objection.
- Switch AI providers, disable personalised analysis, or withdraw consent via the privacy settings at any time.
- Deletion requests are honoured within 30 days and propagated to relevant subprocessors.
Policy updates
- We will announce material changes at least 7 days in advance via in-app messaging and the website; continued use after the effective date means acceptance.
- If you disagree with changes, you may stop using the app and request account deletion.