Privacy Policy
Last Updated: January 16, 2026
At MindMate, we believe your thoughts are your most private property. This policy explains how we protect your data while providing a calm, reflective AI experience.
1. The Data We Collect
To provide the MindMate experience, we collect the following:
- Account Information: Name and email address (processed via Supabase Authentication).
- Reflection Data: Your chat logs and notes. Because these may contain sensitive information about your mental well-being, we process this as Special Category Data under GDPR, requiring your explicit consent.
- Anonymous Sessions: Messages sent before sign-up are stored locally in your browser. They are only moved to our secure servers if and when you create an account.
2. How We Process Your Data
- AI Context: Your messages are stored in a secure, plaintext format in our database. This allows MindMate to maintain context and “remember” your journey across sessions.
- Service Improvement: With your explicit checkbox consent, we may review anonymized patterns to improve MindMate's emotional intelligence and user experience.
- AI Safety: We use OpenAI's API to generate responses. We have opted out of all AI training. Your data is never used to train global AI models.
Note: OpenAI retains API data for up to 30 days solely for abuse monitoring, after which it is deleted from their systems.
3. Data Infrastructure & Processors
We host our services on high-security, EU-based infrastructure to comply with data residency preferences:
- Database & Auth: Supabase (EU Servers)
- Hosting: Vercel & Fly.io (EU Regions)
- AI Processing: OpenAI API (EU-based processing where available)
4. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your data:
- Right to Access: You may request a copy of all your chat logs and personal data at any time.
- Right to Erasure (“Right to be Forgotten”): If you delete your account, we will purge your personal data from our active databases.
- Right to Withdraw Consent: You can opt-out of “UX Improvement” data study at any time through your settings.
- Data Portability: We can provide your data in a machine-readable format (JSON/CSV) upon request.
5. Security
We take the security of your plaintext reflections seriously. Access to the database is strictly limited to essential service functions. We do not use third-party marketing trackers or sell your data to any third party.
6. Contact
For any data-related requests or questions, please contact us at: support@mindmate.online