Privacy Policy
Last updated: DRAFT FOR REVIEW (not yet in effect)
Mindima (“we”, “us”) is a mental-training app. We built it to be private by default: your personal data lives on your device, no account is required, and there are no ads. Some features are optional and work differently: creating an account stores your email with us, and turning on encrypted sync stores an encrypted copy of your record that we cannot read. Nothing leaves your device unless you choose one of these features. This policy explains what we handle, why, and the choices you have. It is written for users in Canada and the United States.
Who is responsible
Mindima is operated by Noah Kanyo, 5005 Dalhousie Dr NW, Unit 175 #1332, Calgary, AB T3A 5R8, Canada. For any privacy question or request, contact us at support@mindima.com. We are the organization accountable for the personal information described in this policy under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta’s Personal Information Protection Act (PIPA), and applicable U.S. state privacy laws.
This website (mindima.com)
Hosting and server logs. This site is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you visit, Cloudflare processes the data your browser transmits (IP address, date and time, requested page, and user agent) in standard server logs to deliver the site and keep it secure against abuse. We rely on this processing for our legitimate business interest in operating a secure website. These logs are retained for up to 30 days and are not combined with any other data. Because Cloudflare is a U.S. provider, this information may be processed in the United States; Cloudflare maintains its own safeguards and data-processing commitments for the data it handles on our behalf.
No tracking. This website uses no analytics scripts, no advertising trackers, no third-party embeds, and no advertising cookies. Nothing on this site reports you to anybody else.
The pricing page, and only the pricing page.We measure whether our pricing page works: whether people read the comparison table, which questions they open in the FAQ, and whether they go on to subscribe. Those events go to our own server, not to anyone else’s.
Here is exactly what that means, because it is the sort of thing people are right to be sceptical about. We do not set a cookie. We do not store anything on your device, not in local storage and not in session storage. We do not record your IP address: our host hands it to our server on every request and our server throws it away. We do not record your browser, your screen size, your timezone, or the page you came from, because those things together identify a person whether or not they were meant to. The only identifier is a random number generated when you open the pricing page, held in memory, which ceases to exist when you close the tab. Reload the page and it is a different number. It exists so we can tell “one person looked and then subscribed” from “two people, one of whom did not”, and for nothing else.
The practical consequence is that we cannot tell a returning visitor from a new one, and we have chosen not to be able to. If you would rather we did not do even this, blocking requests to /api/e costs you nothing: the site works identically without them.
Launch updates list.If you enter your email in the “get notified” form, we store that email address, the page it came from, your browser’s user-agent string, and a country-level location derived from your IP (never the IP itself), so we can send you the launch announcement and understand where interest comes from. Unsubscribe links are in every email, and you can ask us to delete your address at any time.
Email.Email sent to our support address is routed through Cloudflare Email Routing and delivered to a mailbox we monitor. We use your email address and message only to respond to you, and we keep that correspondence only as long as needed to handle your request. Sign-in codes and account emails are sent through Cloudflare’s email service.
Fonts. The fonts on this site are hosted on our own server. No connection to Google or any other third-party font service is made when you load this site.
Local storage.We store your light/dark theme choice in your browser’s localStorage, and, if you sign in on the web, your session tokens, so the site remembers you. These stay in your browser; we set no advertising cookies and no third-party cookies.
The mindima app
- On-device app data (the default). Your game results, progress, stats, streaks, moods, reflections, journal entries, survey answers, and settings are stored locally on your device. Without an account, we never receive this data and there is no server-side copy of it.
- Anonymous usage diagnostics (opt-in, off by default).If you turn on “Share anonymous diagnostics” in Settings, the app sends anonymous event counts (for example, that a session was completed) tied only to a random, app-generated identifier. Never your moods, journals, surveys, or anything you typed. Off by default; nothing is sent until you opt in.
- Crash reports (opt-in, off by default).If you turn on “Crash reports” in Settings, a crash sends a technical report via Sentry: the stack trace and your device model, never your content. Off by default.
- Update checks.The app checks for updates against Expo’s update service (a CDN). Like any internet request, that check transmits your IP address and the app version. It carries none of your personal app data.
- Notifications. If you enable reminders, we schedule local notifications on your device. They are not sent through our servers.
Accounts (optional)
You can use Mindima fully without an account. An account exists for two things: unlocking Premium on all your devices, and the optional sync and dashboard features below. If you create one, we store: your email address, whether it is verified, the devices and sessions signed in to the account, and your purchase and subscription state. Sign-in works by emailing you a one-time code; we store a hashed copy of that code briefly (10 minutes) to verify it, and a hashed recovery code for encrypted backup. We never store a password because there is none.
Encrypted sync (opt-in, off by default)
Premium members can turn on encrypted backup of their record. Before anything is uploaded, your record is encrypted on your device with a key derived from a recovery code that only you hold. Our servers store the encrypted bytes and cannot decrypt them; we do not have your key, and losing the recovery code means the backup cannot be recovered by anyone, including us. Encrypted backups are stored with Cloudflare (R2) and are deleted immediately when you delete your account.
Progress dashboard (opt-in, off by default)
Separately from encrypted sync, Premium members can turn on a web progress dashboard. To power it, the app uploads a small, fixed set of aggregate statistics: metric trends, level, streak days, session counts, games played, and badges. This aggregate set is readable by our servers (that is how the dashboard, and optional weekly progress emails, work), and it never includes your reflections, journal text, moods, or raw survey answers. You can turn it off at any time; deleting your account deletes it.
AI-generated summaries (opt-in, Premium)
If you have turned on the progress dashboard, Premium can also show short summaries and suggestions written by an artificial-intelligence model. These are generated only from the same fixed aggregate statistics described above, on our existing infrastructure at Cloudflare; your reflections, journal text, moods, and raw survey answers are never used, and your data is not used to train AI models. If you use a feature where you type a goal, that text is processed transiently to compose your plan and is not stored on our servers. Generated summaries are stored with your account, are included when you delete it, and are labelled as AI-generated in the app. AI-written content can be inaccurate and is not medical or professional advice.
Purchases
In the app, subscriptions and one-time purchases are processed by the Apple App Store or Google Play. We receive your purchase and entitlement status from the store, never your card number or full payment details. On the web, payments are processed by Stripe, Inc.; Stripe handles your card and payment details under its own policy, and we receive your subscription status and transaction references, not your card number. A purchase made on any platform unlocks Premium on all of them through your account.
Sensitive information and your consent
Mood check-ins, reflections, and survey answers can reveal information about your mental state, which is sensitive personal information. Before any of it is recorded, the app asks for your express consent on an in-app consent screen. By default all of this processing happens on your device. If you turn on encrypted sync, this content leaves your device only in encrypted form that we cannot read. The optional dashboard aggregates described above never include this content. You can withdraw consent at any time by turning those features off, deleting your data in-app, deleting your account, or deleting the app.
How we use it
To run the app and, if you choose them, the account features: save your progress, keep Premium unlocked across devices, store encrypted backups we cannot read, show your dashboard, process purchases, fix crashes you have chosen to report, and improve the app from anonymous counts you have chosen to share. Mindima shows no ads and we do not use your data to build advertising profiles.
What we never do
We do not sell your personal information, and we do not share it with third parties except the service providers needed to run the app and website (below). We do not “sell” or “share” personal information as those terms are used under U.S. state privacy laws, and we do not use it for cross-context behavioural advertising.
Service providers
- Cloudflare (website hosting, security, email routing and sending, site analytics, and storage for account data and encrypted backups).
- Apple App Store / Google Play (in-app payments, subscriptions).
- Stripe (web payments; receives your payment details directly and processes them under its own policy).
- Expo (app update delivery via CDN; sees your IP address and app version when the app checks for an update).
- Sentry (crash reporting, only if you opt in; receives stack traces and device model, never your moods, journals, or surveys).
These providers handle data under their own privacy policies and only as needed to provide their service to us. Some are based in the United States, so data described above may be processed there.
Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you. For on-device data, the in-app export gives you a complete copy; for account data, you can request an export of everything we hold.
- Correct inaccurate information.
- Delete your information: delete your account (and all synced data) from the Account screen in the app or on mindima.com/account, use the delete controls in Settings for on-device data, delete the app, or email us. See mindima.com/delete-account for the exact steps.
- Withdraw consent at any time, without affecting processing that already took place.
- Data portability: the in-app backup exports everything as a single JSON file you control, and account data can be exported on request.
- Non-discrimination: we will not deny you service or charge you a different price for exercising any privacy right.
To make a request, email us at support@mindima.com. We will respond within the timeframe required by applicable law (generally within 30 days) and may need to verify your identity first. You may also authorize someone to make a request on your behalf. Most of your data never leaves your device, so you can exercise the access, correction, and deletion rights directly in the app at any time.
Canada. If you have a concern we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada, or the Office of the Information and Privacy Commissioner of Alberta.
United States. Residents of California and other states with privacy laws have the rights described above, including the right not to be discriminated against for exercising them. Because we do not sell or share personal information or use it for targeted advertising, there is no need to opt out of those activities.
Data retention
On-device data remains until you clear it or delete the app. Website server logs are kept for up to 30 days. Account data (email, devices, purchase state, encrypted backups, dashboard aggregates) is kept while your account exists and is permanently deleted when you delete your account; encrypted backups are purged immediately as part of that deletion. Launch-list emails are kept until you unsubscribe or ask us to delete them. Opt-in diagnostics and crash reports are kept only as long as needed to improve and debug the app. If you ask us to delete information we hold, we will do so within 30 days, except where we are required to keep it to meet a legal obligation (for example, purchase records for tax purposes).
Children
Mindima is intended for users aged 13 and over. We do not knowingly collect personal information from children under 13, consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and Canadian privacy guidance. The in-app consent screen requires confirmation that you are 13 or older. If you believe a child under 13 has provided us with personal information, contact us and we will delete it.
Security
No method of storage or transmission is perfectly secure, but we keep data on-device by default, encrypt synced records end to end with a key only you hold, encrypt all traffic in transit, offer an optional app lock, and minimize what we collect to reduce risk.
Changes
We may update this policy; we’ll revise the “last updated” date above and, for material changes, notify you in the app.
Contact
Questions or requests: support@mindima.com, or write to Noah Kanyo, 5005 Dalhousie Dr NW, Unit 175 #1332, Calgary, AB T3A 5R8, Canada.