Privacy Policy
Last updated: 16 August 2026
This policy is in effect. It is also under continuing legal review, and we will post any revision here with a new date.
Mindima is a mental performance app. It is built to be private by default: your record lives on your device, no account is required, and there are no ads. A few features work differently, and every one of them is off until you switch it on. This policy explains what we handle, why, what we can and cannot see, and the choices you have. It is written to be read, not to be survived; if a sentence in it is unclear, that is a defect and we would like to hear about it.
Where Mindima is offered
Mindima is currently offered in Canada, the United States, the United Kingdom, Australia and New Zealand. We are not yet available in the European Economic Area. If you are in the EEA or the UK, the section headed “If you are in the EEA or the UK” below sets out the rights that apply to you.
Who is responsible
Mindima is operated by Noah Kanyo, 5005 Dalhousie Dr NW, Unit 175 #1332, Calgary, AB T3A 5R8, Canada. For any privacy question or request, contact us at support@mindima.com. We are the organization accountable for the personal information described in this policy under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta’s Personal Information Protection Act (PIPA), and applicable U.S. state privacy laws.
If some of what follows reads as more detail than a privacy policy usually carries, that is deliberate. The claims in this document are the reason to trust the product, so each one is scoped to exactly what is true rather than stated as a slogan.
What stays on your device
Unless you turn on one of the optional features below, everything you do in Mindima is written to a database inside the app’s own storage on your device and stays there. We never receive it and there is no server-side copy of it. This covers:
- Your game results, scores, session history, streaks and progress.
- Mood check-ins, felt states, and the notes attached to them.
- Reflections and journal entries, including any voice note you record. Voice notes are audio files saved in the app’s own folder. They are never transcribed, never uploaded, and are not included in encrypted backup.
- Any photo you attach to a practice log. It is referenced from where your device already keeps it and is never uploaded.
- Survey answers, including partly finished ones, and your state check-ins.
- Practices, habits, commitments, saved quotes and collected items.
- Your settings, and a local log of which screens you opened, used to draw your own stats. That log is capped and never leaves the device.
What we work out from it, on your device
Mindima does not only store what you enter. It calculates things from it, and those calculations are personal information about you too, so they belong in this policy. All of the following are computed on your device and stay there unless you switch on encrypted backup, in which case they travel inside the encrypted record we cannot read:
- Ability estimates. Each round updates estimates across a set of cognitive sub-abilities, rolled up into six headline ones: speed, memory, focus, comprehension, periphery and accuracy.
- A brain age and a composite index. Your ability estimates are blended into a single index and mapped onto a modeled curve of typical scores by age. The curve is a modeled reference built from synthetic and public distribution samples. It is not census data, it is not a comparison against other Mindima users, and it is not a medical or diagnostic test.
- A trait profile. Your survey answers produce scores across a set of qualities, kept with a history so you can see movement.
- Patterns. Your best time of day, how your mood varies by day of week, consistency and streak figures, and which sessions tend to sit alongside your better days. These are differences between averages in your own data. They are not statistical tests and not findings about anyone else.
You can see this material in the app under “About your data”, export it, and delete any part of it there.
The optional features that send something
Every feature in this section is off until you turn it on, with no pre-ticked boxes, and each one can be turned off in a single step from the same place you turned it on.
An account
You can use Mindima fully without one. An account exists to unlock Premium on all your devices and to enable the two features below it. If you create one, we store your email address, whether it is verified, the devices and sessions signed in, your purchase and subscription state, and any display name, first and last name, username or profile picture you choose to add. Sign-in works by emailing you a one-time code; we store a hashed copy of that code for ten minutes to verify it. There is no password, so we never store one.
Each signed-in session also records a shortened browser or app user agent and a country derived from your IP address, so we can spot a session that is not you. We do not store the IP address itself.
Display name and profile picture
All four of these are optional and removable at any time. They are stored on your device and, when you are signed in, on our servers, so they follow you to your other devices. The picture is stored with Cloudflare (R2) and is served only to a request carrying your own signed-in token.
A profile picture is the one piece of content you give us that we can read. It is deliberately outside the encrypted backup described below, because a picture only your device can decrypt cannot be shown on your other devices or on the web. We never run face recognition, face matching or any other biometric analysis on it, we never include it in a shared or public link, and we never use it to train anything. It is deleted from our servers the moment you remove it, and as part of deleting your account.
Encrypted backup
Premium members can turn on encrypted backup of their record. Before anything is uploaded, your record is encrypted on your device with a key derived from your recovery code, and the key itself is never sent to us or stored by us. The encrypted bytes we hold cannot be read without that code. If you lose it, the backup cannot be decrypted and we cannot restore it for you.
Being precise about the recovery code, because this is the claim that matters most. Today the code is generated on our server when your account is created and shown to you exactly once, after which we keep only a one-way hash of it and the plaintext is not retained anywhere. So the accurate statement is that we do not hold your code and cannot read your backup, not that the code has never existed outside your hands. We are moving code generation onto the device, and we will state the stronger version here only once that ships.
This covers your record: moods, reflections, practice logs, survey answers and the derived material described above. It does not cover your profile picture, your voice notes, or your practice photos, which are described elsewhere in this policy.
Progress dashboard
Separately from encrypted backup, Premium members can turn on a web progress dashboard. It is off until you switch it on, in Settings in the app or on your account page on the web. To power it, the app uploads a small, fixed set of aggregate statistics: your normalized metric scores and their trend deltas per day, your level, streak days, session counts, games played and badges. That set is enforced in code on both the app and the server, and a write carrying anything outside it is rejected rather than trimmed.
This aggregate set is readable by us. That is how the dashboard works, and we would rather say so plainly than describe it as encrypted when it is not. It never includes your reflections, journal text, voice notes, moods or raw survey answers. When you switch the dashboard off, we delete the aggregates we are holding for you.
Progress emails
If you turn them on, we can send a weekly summary drawn from the same aggregate set, and an occasional nudge if you have been away. These are two separate switches, both off by default, both reversible in the app, on your account page, and from an unsubscribe link in every message.
Email about your subscription is different and is not a marketing choice: if you start a trial or hold a subscription, we will email you about it, including before a trial converts. That is part of providing the service you bought, so it has no off switch. It is never used to promote anything else.
Anonymous usage diagnostics
Off by default. When on, the app sends anonymous event counts, for example that a session was completed, tied only to a random, app-generated identifier. Never your moods, journals, surveys, or anything you typed. As of this policy’s date no diagnostics endpoint is configured, so nothing is transmitted even with the switch on. We will update this section, and the retention period below, before that changes.
Crash reports
Off by default. When on, a crash sends a technical report via Sentry: the stack trace and your device model, never your content. As of this policy’s date no crash-reporting key is configured, so nothing is transmitted even with the switch on.
Share cards
You can choose to create a shareable card from your own results. Doing so publishes a small aggregate snapshot at a public web address that anyone holding the link can open. It carries no reflections, no journal text, no survey answers and no contact details. You can see every link you have created, and revoke any of them, on your account page; revoking removes the snapshot from our servers and the link stops working. Anything already downloaded or reposted by someone else is, of course, beyond our reach.
Update checks, reminders, calendar and media
- Update checks.The app checks for updates against Expo’s update service. Like any internet request that transmits your IP address and the app version. It carries none of your record.
- Reminders. Scheduled locally on your device. They are not sent through our servers, and we hold no push token for you.
- Calendar.If you switch calendar sync on for a habit, the app writes that habit’s title and times into the calendar you pick, and removes them when you switch it off. It never reads your calendar.
- Audio and media. Some audio is streamed from our own content domain rather than bundled in the app. Playing it makes an ordinary web request, which transmits your IP address to that host as any request does. No account or record data is attached to it.
Sensitive information, and your consent to it
Mood check-ins, reflections, survey answers, state check-ins and the setup questions about focus, stress, memory, mood and sleep can reveal information about your mental state. We treat that as sensitive information wherever you live, and in several places the law treats it as a special category that needs its own explicit permission rather than a general acceptance of terms.
So we ask for it separately. When you first open Mindima you confirm your age, and you are then asked, as a distinct question with its own control, whether Mindima may record this kind of content. The two are not bundled and neither one carries the other. You can decline and keep using Mindima: the games, tools, puzzles and stats all work. The features that would write mood, reflection or survey content simply do not record it, and they tell you so rather than failing quietly.
We keep a record of what you agreed to, when, in what language, and which version of this policy and of the Terms was in force at the time. If you have an account, that record is also stored with it, so you can ask us what you consented to and get a real answer.
By default all of this stays on your device and we never receive it. If you turn on encrypted backup it leaves your device only as ciphertext we cannot read. The dashboard aggregates never include it. The diagnostics never include it.
You can withdraw at any time by switching the permission off in Settings, deleting the data in the app, deleting your account, or deleting the app. Withdrawing does not undo processing that already lawfully took place, and does not affect anything we must keep to meet a legal obligation.
If you are in Washington State, or another U.S. state with a dedicated consumer health data law, please also read our Consumer Health Data Privacy Policy, which sets out the additional rights those laws give you.
Purchases
In the app, subscriptions are processed by the Apple App Store or Google Play. We receive your purchase and entitlement status from the store, never your card number or full payment details. On the web, payments are processed by Stripe, Inc.; Stripe receives your payment details directly and handles them under its own policy, and we receive your subscription status and transaction references. We pass Stripe your email address so it can send you a receipt and so the subscription attaches to the right account. A purchase made on any platform unlocks Premium on all of them through your account.
This website (mindima.com)
Hosting and server logs. This site is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you visit, Cloudflare processes what your browser transmits (IP address, date and time, requested page, and user agent) in standard server logs to deliver the site and keep it secure against abuse. We rely on our legitimate business interest in operating a secure website. These logs are retained for up to 30 days and are not combined with any other data.
Request logs, and why we turned them on. We also keep a short-lived operational log of requests to our own server, held for a few days and then discarded. We switched it on deliberately: without it we could not tell whether a security problem had actually been exploited, and being unable to answer that question is worse for you than the log is. It is used only to run and secure the service, never to build a profile of you and never to measure you as a visitor.
No tracking, and what that does and does not mean. This site carries no advertising trackers, no advertising cookies, no third-party analytics and no cross-site profiling. Fonts are served from our own origin, so loading a page makes no connection to Google or any other font service.
The pricing page, and only the pricing page.We measure whether our pricing page works: whether people read the comparison table, which questions they open, and whether they go on to subscribe. Those events go to our own server and to nobody else’s.
Here is exactly what that means on the web, because it is the sort of thing people are right to be sceptical about. We do not set a cookie. We do not store anything on your device, not in local storage and not in session storage. We do not record your IP address: our host hands it to our server on every request and our server throws it away. We do not record your browser, your screen size, your timezone, or the page you came from. The only identifier is a random number generated when you open the pricing page, held in memory, which ceases to exist when you close the tab. Reload and it is a different number. It exists so we can tell “one person looked and then subscribed” from “two people, one of whom did not”, and for nothing else. We cannot tell a returning visitor from a new one, and we have chosen not to be able to. If you would rather we did not do even this, blocking requests to /api/e costs you nothing.
The same measurement inside the app works differently, and you should know how.When the app records a pricing event it uses the app’s own installation identifier, which is stable until you delete the app, rather than a per-visit random number. It carries the plan you looked at, your app language and your platform. In the app this is covered by the anonymous diagnostics switch and is off unless you turn that on.
Launch and newsletter list.If you enter your email in one of our signup forms, we store that email address, the page it came from, your browser’s user-agent string, and a country-level location derived from your IP (never the IP itself), so we can send you what you asked for and understand where interest comes from. Unsubscribe links are in every email and you can ask us to delete your address at any time.
Email and local storage.Mail to our support address is routed through Cloudflare Email Routing to a mailbox we monitor, and sign-in codes and account email are sent through Cloudflare’s email service. We store your light/dark theme choice in your browser’s localStorage and, if you sign in on the web, your session tokens. We set no advertising cookies and no third-party cookies.
Service providers
- Cloudflare (website and API hosting, security, email routing and sending, and storage for account data, profile pictures and encrypted backups).
- Apple App Store / Google Play (in-app payments and subscriptions).
- Stripe (web payments; receives your payment details directly and your email address for receipts, and processes them under its own policy).
- Expo (app update delivery; sees your IP address and app version when the app checks for an update).
- Sentry (crash reporting, only if you opt in and only once we configure it; would receive stack traces and device model, never your moods, journals or surveys).
These providers handle data under written terms and only as needed to provide their service to us. They are not permitted to use it for their own purposes. Several are based in the United States, so data described above may be processed there.
We do not sell your personal information and we do not share it for advertising.We do not “sell” or “share” it as those terms are used under U.S. state privacy laws, we do not use it for cross-context behavioral advertising, and Mindima carries no ads on any tier.
Security: what is protected, and what is not
We would rather tell you where the edges are than make a claim that sounds better than it is.
- In transit. All traffic between the app or the site and our servers is encrypted.
- Your record in our storage. Encrypted on your device before upload, with a key we never hold. We cannot read it.
- Everything else on our servers. Your email address, profile details, profile picture, dashboard aggregates, subscription state and session records are stored unencrypted at the application level, so we can operate the service. They are protected by access controls, not by a key only you have.
- On your device.The app’s database is not separately encrypted by us. It is protected by your device’s own operating system protections and, if you switch it on, by the optional app lock that requires Face ID or a fingerprint to open Mindima. If you sign out, your record remains on the device until you delete it or delete the app.
- On the web. When you open your record in a browser, it is decrypted inside that tab in order to be shown to you, so the readable version exists in your browser while you are using it. This is unavoidable for any web client and it means the end-to-end guarantee protects the data at rest with us, not the contents of your own open tab.
- Your exported file. The backup you export from the app is a plain, unencrypted JSON file, so that you can actually use it. Anyone with the file can read it. Sign-in credentials are stripped out of it before it is written.
No method of storage or transmission is perfectly secure. We minimize what we collect, keep the sensitive material on your device by default, and design so that the most revealing category is one we could not read even if we were compelled to.
If something goes wrong
If a security incident affects your personal information and creates a real risk of significant harm to you, we will notify you and the applicable regulator without undue delay, in the manner and within the time limits the law requires, and we will tell you what happened, what was affected and what to do about it. We keep a record of security incidents involving personal information as Canadian law requires. We have deliberately not promised a fixed number of hours here, because a commitment we could not keep in every case would be worth less than this one.
Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you. For on-device data, the in-app export gives you a complete copy; for account data, the download on your account page returns everything we hold, including the dashboard aggregates, your session records, your consent history and your share links.
- Correct inaccurate information.
- Delete your information: delete your account and all synced data from the Account screen in the app or on mindima.com/account, use the delete controls in Settings for on-device data, delete the app, or email us. See mindima.com/delete-account for the exact steps.
- Withdraw consent at any time, in the same place you gave it, without affecting processing that already took place.
- Portability: the in-app backup exports your record as a single JSON file you control, and account data can be downloaded the same way.
- Non-discrimination: we will not deny you service, charge you a different price, or give you a lesser experience for exercising any privacy right.
Most of your data never leaves your device, so you can exercise access, correction and deletion directly in the app at any time. For anything else, email support@mindima.com. We respond within the timeframe applicable law requires and in any case within 30 days. Where a request concerns account data we will ask you to make it from the email address on the account, or to confirm a code sent to it, so that we are not handing your record to somebody else. You may authorize someone to make a request on your behalf; we will ask for evidence of that authority.
Canada
We handle personal information in accordance with PIPEDA and, in Alberta, PIPA. If you have a concern we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada, or the Office of the Information and Privacy Commissioner of Alberta.
United States
Residents of California and other states with comprehensive privacy laws have the rights described above, including the right not to be discriminated against for exercising them. Because we do not sell or share personal information and do not use it for targeted advertising, there is nothing to opt out of in those categories. Residents of states with dedicated consumer health data laws should also read our Consumer Health Data Privacy Policy.
If you are in the EEA or the UK
Mindima is not currently offered in the European Economic Area, and we are completing the steps required before it is. If you are nonetheless in the EEA or the UK and using Mindima, we treat you as covered by the General Data Protection Regulation or the UK GDPR, and we act as the controller of your personal data within the meaning of Article 4(7).
Our lawful bases are:
- Running your account and signing you in (email address, one-time code hash, sessions and devices): necessary to perform our contract with you, Article 6(1)(b).
- Encrypted backup and restore (encrypted bytes, salt, recovery-code hash): Article 6(1)(b).
- Purchases, subscriptions and Premium, and the email we send you about them: Article 6(1)(b), and Article 6(1)(c) where we must keep transaction records to satisfy tax law.
- Keeping accounts secure and preventing abuse (coarse country, a shortened user agent, rate-limit counters): our legitimate interests, Article 6(1)(f). You may object.
- Mood, reflections, survey answers, state check-ins, the setup questions and the profile derived from them: your explicit consent, Article 6(1)(a) together with Article 9(2)(a), asked for separately from anything else.
- Your display name, names, username and profile picture: your consent, Article 6(1)(a). A profile picture is an ordinary photograph to us and is not processed by any means intended to identify a person uniquely, so it is not biometric data under Article 9.
- Anonymous diagnostics and crash reports: your consent, Article 6(1)(a). Both are off until you switch them on.
- The progress dashboard, progress emails and share cards: your consent, Article 6(1)(a), each with its own switch.
- Launch and newsletter list: your consent, Article 6(1)(a). Every email carries an unsubscribe link.
- Serving this website and its server logs: our legitimate interest in operating a secure site, Article 6(1)(f).
In addition to the rights listed above you have the right to object to processing carried out on the basis of our legitimate interests (Article 21), the right to restrict processing, and the right to lodge a complaint with a supervisory authority(Article 77). Because we are established outside the EU, you may complain to the authority where you live or work; a directory is published by the European Data Protection Board, and in the United Kingdom the authority is the Information Commissioner’s Office. You do not have to contact us first, though we would rather you gave us the chance to put something right.
International transfers
We are established in Canada, and several of our service providers, including Cloudflare, Stripe and Sentry, are established in the United States. Data described in this policy is therefore processed in Canada and in the United States.
We protect it in transit and at rest, we place written terms on every provider limiting them to processing on our instructions, and the most sensitive category, your record, is encrypted on your device before it crosses any border, so what travels is ciphertext we cannot read. Where a transfer of personal data out of the EEA or the UK requires a specific legal mechanism, we put an appropriate one in place before offering the service in that region, and we will name it here. You can ask us at any time for details of the safeguards applying to a particular provider.
Data retention
On-device data remains until you clear it or delete the app. On our servers:
- Account data (email, devices, purchase state, profile details and picture, encrypted backups, dashboard aggregates, consent records) is kept while your account exists.
- Website server logs: up to 30 days. Operational request logs: a few days, then discarded automatically.
- Sign-in codes: 10 minutes. Sessions: 60 days, after which the record is expired and removed.
- Dashboard aggregates: deleted when you switch the dashboard off, and when you delete your account.
- Superseded encrypted backups: replaced versions are removed once a newer backup is stored; the current one is kept until you delete your account or turn backup off.
- Share snapshots: until you revoke the link or delete your account.
- Pricing and product events: 14 months, then deleted.
- Security and account audit records: 24 months.
- Launch and newsletter list: until you unsubscribe or ask us to delete your address.
- Support correspondence: up to 24 months.
We have not stated a retention period for anonymous diagnostics or crash reports because neither is configured to receive anything today. We will state one here before either begins collecting.
Deleting your account. When you delete it, we erase your personal data from our systems: account details, devices, sessions, profile, picture, dashboard aggregates, encrypted backups, share snapshots and consent records. What remains is a minimal closed-account marker, so that a deleted account cannot be silently reopened, and the record of any transactions you made. Canadian tax law requires us to keep transaction records for six years, so for that period we retain the purchase, not your account or your app data. Deletion is not reversible. If you ask us to delete something by email, we will do so within 30 days unless the law requires us to keep it. Data on your own devices is not touched by account deletion; delete it in the app or delete the app.
Children and young people
Mindima is not built for children, and there is a minimum age to use it. It is 13 in most of the countries where we operate, 14 in Canada, and 16 in the European Economic Area, matching the strictest applicable threshold in each. The in-app screen asks you to confirm you meet the age that applies where you are, and shows the number that actually applies rather than the lowest one anywhere.
We want to be honest about what that gate is.It is a self-declaration, and it reads your device’s region to decide which number to show. It is not age verification and we do not present it as such. It is what the law asks for as a reasonable effort given available technology, and it is the same thing almost every app of this kind does. Someone determined to give a different answer can.
If you are under the applicable age, please do not use Mindima. If you believe a child has given us personal information they should not have, contact us and we will delete it.
Changes to this policy
We may update this policy. When we do, we revise the date at the top, and for changes that affect what you have agreed to, we tell you in the app or by email before they take effect and give you a chance to withdraw. Because your consent record names the version of this policy that was in force when you gave it, we can tell what you were shown, and so can you.
Contact
Questions or requests: support@mindima.com, or write to Noah Kanyo, 5005 Dalhousie Dr NW, Unit 175 #1332, Calgary, AB T3A 5R8, Canada.