Last updated: October 3, 2026
Privacy Policy
The short version. What you write is encrypted on your device before it is stored, and we do not hold the key that decrypts it, so those stored content fields contain ciphertext. Readable account, operational, support, and email records are separate. When you choose to use an AI feature, your device decrypts what that request needs and sends it through our AI proxy to our AI provider. Some AI context also passes through our application server. Provider retention and safety exceptions apply; Section 5 explains the limits. We do not sell your information, we do not advertise to you, and we use no advertising networks or cross-site advertising tracking. Our abuse-prevention providers process request and device signals separately from advertising. We do keep a small amount of information we can read, such as your email address, cookieless measurements of which pages get visited and how fast they load, and records of which features get used. Section 4 describes what that is.
On this pageContents · 20 sections
1. Introduction and Scope
KindMind Labs LLC (“Company,” “we,” “us,” or “our”) operates KindMind, BookPath, and other websites and applications that link to this policy (each, and together, the “Service”). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use the Service. Features and controls differ between products. This policy applies to the processing described here where the relevant feature is available; it does not authorize undisclosed uses of your information.
2. How This Policy Stays Accurate As the Product Changes
The Service is actively developed, and features are added, renamed, and removed over time. So this policy describes categories of information and processing rather than a fixed list of features. Where a feature is named below, it is an example, not a limit.
Two commitments make that workable, and they hold regardless of what we ship next:
- The private-content rule. We store the substance of what you write, your journal entries, your conversations with AI features, your responses inside guided programs, the summaries built from them, and your display name, only in client-side encrypted form. Readable exceptions include messages you address to us, such as support, testimonials, and feedback; AI processing described in Section 5; and importing from an older service described in Section 18. Operational and email records are described separately below.
- Readable information stays in stated categories. Section 4.2 lists the categories of information we currently hold in a form we can read. We will update this policy before we start collecting a materially different category, or using readable information for a materially different purpose, and where the change is material we will tell you by email before it takes effect. Where the law requires your consent for a new category or purpose, we will ask for it first.
3. Information We Collect
3.1 Information you provide
- Account information: your email address, password, and display name.
- Content you create: everything you write inside the Service, such as journal entries, conversations with AI features, responses within guided programs, and anything the Service summarizes from them on your behalf.
- Content you send to us on purpose: support and contact messages, product feedback, and testimonials you choose to submit. These are addressed to us, so they are not encrypted from us.
- Payment information: collected and processed directly by our payment processor. We do not store card numbers, bank details, or other payment instrument information.
- Referral, invite, and promotional codes you share or redeem, and the fact that they were used.
- Settings and preferences, such as whether you have opted out of AI, whether your journal entries may inform AI responses and memory, and which optional emails you want.
3.2 Information collected automatically
- Authentication cookies: session tokens managed by our authentication provider to keep you logged in.
- Product usage events: our own first-party records of what happened in the app, described in Section 6.
- Technical request data: our hosting and infrastructure providers process ordinary web request metadata, including IP addresses, for delivery, reliability, abuse prevention, and security. We do not use it to build profiles, to track you across sites, or for advertising.
- Abuse and AI-usage controls: we use Vercel BotID to check protected requests and IP-derived identifiers, request identifiers, usage counters, and cost records to enforce limits before signup. These identifiers are not a guarantee of anonymity. These controls are separate from page analytics.
- Time zone: your browser’s time zone name, recorded when you sign up and when you sign in, so that dates, streaks, and scheduled emails line up with your day. A time zone is approximate location information, so we are naming it here rather than filing it under settings.
- Page performance and traffic measurement: our hosting provider measures page views and page load performance for the site. See Section 3.3 for what this does and does not include.
- Local preferences: theme, font settings, and dismissed prompts stored in your browser. These stay on your device.
3.3 Measurement, and what we do not collect
We use the built-in page analytics and page speed measurement offered by Vercel, who host the site. Between them they record which page was viewed, how quickly it loaded, the site you arrived from, and general device and browser type and country.
These measurements use no analytics cookies. Vercel describes using a temporary hash derived from request information to distinguish visits. We do not attach your account identifier or private writing to these measurements or use them for advertising. Cookieless measurement still involves processing request and device information.
We also rewrite the address before either measurement is sent. Pages inside the app are reported as the section you were in and nothing more, so that you opened a guided program is measured, while which one is not. Public pages, including blog posts and feature pages, report their page path. A page topic may suggest an interest, including a sensitive interest; a public URL is not necessarily free of privacy implications. The query string is dropped entirely, so it is not included in the page URL sent by these measurement components. This does not remove information from the underlying request received by our hosting provider. Anything we add later is treated as part of the app, and therefore trimmed, until we decide otherwise.
Beyond that, we use no advertising networks, no tracking pixels, no session recorders, and no cross-site advertising technology. We do not collect your contacts, precise device location, or browsing history from other sites. Infrastructure providers may use request characteristics to detect abuse and measure traffic. We do not buy personal information from data brokers. We never send anything you write to any analytics provider.
4. What We Can and Cannot Read
4.1 Encrypted content, which we cannot read where it is stored
Private account content is encrypted with AES-256-GCM on your device before it is saved to your account. This covers your journal entries, your conversations with AI features, your responses inside guided programs, plans, AI memory summaries, and your private profile display name. Messages you address to us and the temporary processing described below are exceptions.
Your device generates a random key that encrypts your content. That key is itself locked with a second key derived from your password, and only the locked version is ever sent to us. To be precise about the password: the one you use to sign in does travel, over an encrypted connection, to the service that authenticates you, exactly as it would on any site. What never leaves your device is the key derived from it and the unlocked key it protects, which is why we cannot decrypt the content we store. This is commonly called zero-knowledge encryption. Two honest notes about the limits of that. First, because the locked key we hold is unlocked by your password, the protection is only as strong as the password you choose. Second, this describes content as we store it. When you choose a feature that needs to work with your words, such as an AI feature, your device unlocks what that request needs and sends it through the path described in Section 5.
A recovery key is generated when you create your account so you can regain access if you forget your password. That recovery key is the key to your content, not a code we can look up, so treat it like the content itself and do not share it. You are solely responsible for storing it. If you lose your password, recovery key, and access to any device that can still unlock your content, we cannot restore that content for you.
4.2 Information we can read
A limited set of information is stored in a form we can read, because the Service cannot function otherwise or because you sent it to us deliberately. These are the categories we currently hold:
- Account and billing data: your email address, account identifiers, subscription and plan status, trial dates, promotional and referral code usage, and timestamps. Your email address and sign-in details are held by our authentication provider.
- Settings and preferences: whether you have opted out of AI, whether your journal entries may inform AI responses and memory and when you decided that, which optional emails you want, which prompts you have dismissed, backup reminders, and similar choices we need in order to apply them.
- Structural metadata: how many items you have, when they were created or updated, how long an entry is, which guided program you selected, which day you are on, and similar non-content details needed to render the app. To keep that category from quietly growing: structural metadata does not include the text of your private writing. Program selections and automated safety classifications can nevertheless reveal or suggest sensitive information about you. The categories of sensitive information we currently process are described here and in our Consumer Health Data Privacy Policy.
- Which guided program you chose. Guided programs are named, and the name is stored in a form we can read, so we can tell that an account is working through a program on, for example, grief or sobriety. We also store the selected approach and progress; these choices may reveal sensitive information. What you write inside it stays encrypted. If that matters to you, the whole catalog is browsable without starting anything.
- Product usage events: see Section 6.
- Automated safety records: see Section 5.
- Records of automated decisions: a content-safe record of what the Service decided to show or send you, and why, as described in Section 7.
- Messages you address to us: support and contact messages, product feedback replies, and testimonials. These are plaintext by design. We can read them, which is the point of them. Please do not include anything in them you would not want us to see.
- Saved catalog selections: where a feature lets you save an item from a public catalog, such as a book or a guided program, we store which catalog item you saved.
- Support identifier: a code derived from your account ID that you can safely paste into an email so support can find your account without you sharing anything you wrote. It cannot be turned back into your account ID by anyone who only has the code, but we can match it to your account.
- AI usage records: per-request feature, action, model, token counts, and associated account identifiers for metering and abuse prevention. Account-linked token-usage rows are deleted with the account; retained product events described in Section 6 are a different category.
- Import fingerprints: some imported journal entries have readable hashes derived from their text for duplicate detection. A hash is not the entry itself, but may allow comparison with guessed text; we do not treat it as anonymous.
- Email delivery records: recipient email addresses, subjects, message bodies, delivery status, and related provider identifiers for emails we send. These records are readable and are separate from your encrypted writing.
- Request and infrastructure metadata: the ordinary web request data described in Section 3.2, handled by our providers for delivery, reliability, and security.
5. AI Features and the Automated Safety Check
When you use an AI feature, your device sends the content needed for that request over HTTPS through our Cloudflare AI proxy to Anthropic. This is readable processing by KindMind-operated infrastructure and the AI provider, not end-to-end encryption from you to another person. Chat text and memory extraction normally pass through the proxy. Separately, Guide and Path plans, titles, goals, and related context may be sent in readable form to our application server to assemble AI instructions. The Path finder also sends your free-text description to the application server and then through the proxy to Anthropic; its recommendation request does not use the chat safety check. Those routes do not intentionally persist that content in readable form; private content saved to your account is encrypted on your device. We keep operational logs and the content-free records described below.
Anthropic processes these requests under its commercial API terms, which provide for no model training by default. Its published standard API retention period is up to 30 days, with exceptions that can be substantially longer, including for safety and legal obligations. Provider safety processes may include authorized human review. This is not a zero-retention service, and provider personnel may have authorized access to a request. Provider caching also applies. See AI Privacy for the provider disclosures and their limits.
Before you have an account. If you answer the questions on our signup flow, those answers are sent through the same AI proxy so the flow can respond to them. That happens before an account or an encryption key exists. The answers are protected by HTTPS in transit, but are readable to the proxy and AI provider. Provider retention still applies. If you go on to create an account, they are encrypted on your device and saved as part of your account. If you do not create an account, we do not save those answers as account content. Provider copies, ordinary request metadata, signup usage events, and safety operational records may still exist.
Try without an account. The try-before-signup experience stores writing in your browser using a separate encryption key stored in the same browser. It does not have the password and recovery protections of an account vault. AI conversations, including an opening message submitted from the homepage, still go through our proxy and provider, with the retention and safety processing described here. Try-mode journal entries are not automatically sent to AI. Local records expire when the app next reads them more than 30 days after their creation; this is not a timed deletion from a closed browser. Clearing this site’s browser data removes the local copy. Browser storage may also be cleared by your browser, and when persistent storage is unavailable, content may last only for the current tab. Signing in or creating an account in the same browser automatically claims unclaimed try writing for that account without a separate import confirmation. Supported writing is imported using your account encryption key. Guide and Path writing can be skipped if the account lacks the necessary plan; the local record is then cleared, including skipped writing. Failed imports can also be cleared on sign-out or a later try-mode visit after the retry limit is reached. Avoid using a shared browser for private try writing, and keep your own copy of anything you need to preserve. Imported chats can contribute to account AI memories. Clearing local data does not erase provider or operational records.
On the web, AI memory passes summarize eligible conversations and, if Journal memory is enabled, journal entries. Guide conversations are summarized oldest first, with the guide’s replies included as context: right after you unlock, and on later page loads until older messages are caught up (up to 50 of your messages each time), and as you keep chatting (25 at a time). Path conversations, and journal entries if Journal memory is enabled, are summarized in a daily pass that selects up to 25 not-yet-summarized records per feature. Neither has a date cutoff, so repeated passes can include older writing. Recap and compaction requests also process conversation text and existing memories. The summaries are encrypted on your device before saving. Journal memory also permits up to 5,000 characters of your latest entry from the current day to be included on each web Guide or Path chat turn, including the entire entry if shorter. Mobile uses the same account setting, but currently does not send this direct journal excerpt or run the web memory pass; on mobile the switch also controls inclusion of saved memories and recaps in chats. This setting defaults off. Turning it off stops new journal context and memory requests; it does not remove existing memories or recall requests already sent. You can review or clear memories in the available account controls. This switch does not disable Guide or Paths. See AI Privacy for choices and contact us to request help withdrawing consent.
Automated safety check. Messages you send to certain AI features, including the signup questions above, pass through an automated check intended to recognize signs of crisis or risk so the Service can show supportive resources. The check is a separate automated call to an AI model under the same terms. Two kinds of record can result, and neither ever contains your words:
- For account chats, if the check flags a concern, or if the check itself fails to run, we store a record linked to your account containing the category, a severity level, the action taken, for example “crisis resources shown,” and related technical details such as which feature it came from and how confident the check was. We never store the message content or the check’s reasoning.
- Separately, we keep operational records of supported input checks, noting the category it saw and how long it took, so we can confirm the check is working. These carry no account identifier of any kind. We avoid calling them anonymous, because one is written at the same moment as the account-linked record above, and we could in principle line the two up by their timestamps. We do not use these timestamps to identify you. These records are scheduled for removal from the live database within 90 days; backup copies are addressed in Section 12. Try-mode checks do not create account-linked safety records, and their operational classification records are not currently saved.
This check is not a monitoring service. KindMind does not provide human monitoring of your private writing or an emergency response service. This does not describe support messages you ask us to read or a provider’s safety review. It is not infallible, and it can be wrong in both directions: it will miss things, and it can also offer you crisis resources when you were not in crisis, or set aside a reply it misjudged. Do not treat its classification or response as an assessment of your condition. Please see Section 4 of our Terms of Service, and never rely on the Service in an emergency.
A fuller technical description is on our How AI Works page.
6. Product Usage Events
We keep our own first-party record of what happens in the app: which feature was opened, which action succeeded or failed, which route an error came from, and similar operational facts, along with your account identifier and a timestamp. We use these to keep the Service working, to diagnose errors, and to understand which parts of the product are useful.
These records are designed never to contain the content you write, and we review them against a list of what is allowed in them. They are stored on our own infrastructure. They are not sold, and they are not sent to any advertiser or data broker. When you delete your account, we permanently remove your account identifier from these records. The remaining rows may still contain event properties, timestamps, and record identifiers. Removing the account identifier alone does not guarantee legal anonymization. We use retained events for operations and aggregate analysis, and applicable deletion rights still apply.
7. Automated Decisions
The Service decides automatically what to show you and when. It may decide to display a prompt or supportive message, or to grant an account benefit such as a trial extension. These decisions use account and usage signals and, in some cases, AI. Where a decision draws on what you have written, your browser unlocks that content and sends it along the same AI path described in Section 5, and the record we keep of the outcome is redacted in your browser before it reaches us, so that what we store notes only that content was involved. Some of these records hold the wording the AI chose to show you.
These decisions affect only what appears in the app, whether a safety response replaces an AI reply, and whether you receive an optional benefit. They are not used to make decisions with legal or similarly significant effects on you. We do not use these decisions to determine employment, housing, credit, insurance, or medical treatment. Safety and abuse controls may limit a response or access to a feature. You can choose whether to use AI features and unsubscribe from optional emails. Contact us for help with AI preferences or to request human review of a decision affecting you.
8. How We Use Your Information
We use your information to:
- Provide, operate, maintain, and improve the Service.
- Authenticate you and secure your account.
- Store and return your encrypted content to you.
- Route content you submit to an AI feature to our AI provider, including the automated safety check described in Section 5.
- Process subscription payments, trials, promotions, and referrals.
- Send you the emails described in Section 9.
- Detect, investigate, and prevent fraud, abuse, and security incidents, and enforce our Terms.
- Respond to your support requests.
- Comply with legal obligations.
We do not use your personal information for advertising, for advertising profiles, for training AI models, or for any purpose other than operating the Service.
9. Emails We Send
We send the account messages listed below, plus optional tips and notes if you have them turned on.
- Account emails, which you cannot unsubscribe from while you have an account: welcome and verification, password and security notices, billing and trial notices, and legal or policy notices.
- Optional tips and notes from Garrett: a few emails during and after your trial (a getting-started tip, a request for feedback, and a note after your trial ends), plus occasional product news. New KindMind accounts start with these on; you can turn them off at signup, from the link in every one of these emails, or in Settings. Which of these emails you receive depends only on account information such as your signup date, trial dates, plan, and whether you have written anything recently, never on what you wrote. Unsubscribing costs you nothing and never limits your access.
Email delivery records may include your address and the subject and body of the message we sent, including account or usage information in that message. These are not your encrypted journal or chat records.
10. Service Providers and Sharing
We use a small number of third-party providers, solely as necessary to operate the Service, in the following categories: application hosting and page measurement; database and authentication; encrypted backup storage; AI processing; edge request routing; payment processing; transactional email; and rate limiting and abuse prevention. Providers process information under the terms and data-protection arrangements applicable to their services. Some also process information for their own legal, security, fraud-prevention, or payment obligations; those activities may be governed by their own privacy notices.
Our AI provider is Anthropic PBC. Because AI processing involves readable content, we name that provider here rather than describing it only by category. If we ever change it, we will update this policy before a different provider begins handling your content. A current list of all the providers we use is available on request at hello@kindmind.com.
We may change, add, or remove other providers as needed to operate the Service, and we will update this policy to reflect material changes.
We may also disclose information if required by law, subpoena, or valid legal process, to protect our rights, safety, or property or those of others, or in connection with a merger, acquisition, or sale of assets, in which case the successor remains bound by this policy or gives you notice before changing it. Because your stored content is encrypted with a key we do not hold, our storage system cannot decrypt those records in response to a legal request. This does not prevent disclosure of encrypted records, readable communications you sent us, or readable copies held by an AI provider. What we could produce is the readable information in Section 4.2, which includes the automated safety records described in Section 5.
We will never sell, rent, trade, or share your personal information for advertising or cross-context behavioral advertising. We do not share your data with advertisers or data brokers, and we never send anything you write to an analytics provider.
11. Cookies and Local Storage
We use only essential cookies required for authentication, session management, and security. We do not use tracking cookies, advertising cookies, or any non-essential cookies. Our page measurement sets no cookies at all. Your browser stores preferences and session information locally. On the web, the unlocked encryption key is held in memory and session storage and is not sent to us. Browser session restoration may preserve a tab’s session storage, so closing a tab is not a reliable substitute for signing out. In our mobile app, your key is held in the device’s secure keychain, protected by the app’s biometric keychain integration, so that it survives closing the app. It is removed when you sign out or delete your account.
Do Not Track. Some browsers can send a “Do Not Track” signal. Our processing does not change in response to that signal. We do not use cross-site advertising, but service-provider analytics and abuse-prevention processing still apply as described in this policy and our Consumer Health Data Privacy Policy. This does not limit any right to opt out or withdraw consent under applicable law.
12. Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide the Service.
Deleting one item. You may delete individual items through the Service. Deleting one removes it from our live database outright. Two things do not go with it: a separate copy may remain in an encrypted backup, subject to the backup treatment below, and if an AI feature had already drawn a memory from that item, the memory is a separate record that you delete separately in your account settings.
Deleting your account. You may delete your entire account from your account settings. Successful account deletion removes your account and its linked content from the live application database; there is no in-app undo. The deleted records include linked content, memories, safety events, in-app support messages, feedback, and testimonials. Please export anything you want to keep before you delete. KindMind and BookPath share an account identity, so deleting the account affects both products. Your product usage records are stripped of your account identifier and kept in the de-linked form described in Section 6. Account deletion does not immediately erase backup copies, provider records, email correspondence, or our separate outbound email delivery ledger. Backup retention depends on the backup system. A verified privacy request also covers remaining identifiable records, subject to applicable legal exceptions and deadlines. You may also request deletion at hello@kindmind.com.
The deletion process attempts to cancel web subscriptions for both products, but a payment-provider failure can prevent cancellation even if account deletion succeeds. Cancel in the billing portal before deletion and keep the confirmation; contact us if a charge continues. App-store subscriptions must be managed through the store. Billing records may remain where required for legal, tax, fraud-prevention, or accounting purposes.
How long we keep things. Encrypted content, until you delete it or your account. Account and settings data, while your account is active. Automated safety records linked to your account, while your account is active. Safety operational records carrying no account identifier are scheduled for removal from the live database within 90 days; backup copies follow the separate retention and deletion treatment above. In-app support messages, feedback, and testimonials, until you delete your account or ask us to remove them; separate email correspondence is not removed by account deletion. Contact us to request removal of that correspondence. Billing and tax records, for the period required by law, held by our payment processor. Product usage and outbound email delivery records currently have no automatic fixed expiry. The former lose their account identifier on account deletion; the latter may retain your email address and message details. You may request deletion of remaining personal information; applicable statutory deadlines and exceptions govern that request.
13. Security and Breach Notification
We use layered technical and organizational safeguards suited to how sensitive the information is. These include client-side AES-256-GCM encryption of private content, database access controls intended to separate accounts, encrypted transport, and rate limiting on sensitive endpoints. These measures reduce risk.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident triggers a notification obligation under applicable law, we will notify you and any required regulator within the time that law requires. We may also tell you about an incident when we think you should know, even where no law requires it. You are responsible for maintaining the security of your credentials and recovery key, and because the strength of your encryption depends on your password, please choose a strong one.
14. Your Rights
Depending on where you live, you may have the right to:
- Access: request a copy of the personal information we hold about you.
- Correction: update your display name, email address, or password in your account settings.
- Deletion: delete individual items or your whole account, at any time, yourself.
- Portability: export your data from the web account menu in a machine-readable format, at any time and on any plan. The export covers your profile, your encryption key material, your journal entries, your AI memories, your Guide threads and messages, and your Paths with their messages and day plans. Encrypted content comes out encrypted, because the export preserves the stored encrypted records, and your password or recovery key unlocks it.
- Objection or restriction: object to or request restriction of certain processing.
- Withdraw consent: where processing relies on your consent, withdraw it at any time.
- Non-discrimination: exercise rights without unlawful discrimination. Deleting information or withdrawing consent can prevent a feature that needs it from working.
Contact hello@kindmind.com to exercise any right. We will respond without undue delay and within the period the applicable law allows, and we will tell you if we need more time where the law permits it. We may need to verify your identity through the email address on your account. You may use an authorized agent where law permits. If we decline a request, we will tell you why and how to appeal.
We cannot decrypt stored private content for a request. Where the app provides editing, viewing, or export controls, you can use your own key. Contact us for requests about other records, including metadata; the self-service export is not a complete response to every statutory access request.
15. United States State Privacy Rights
We make the rights in Section 14 available to you as described there, whether or not a particular state privacy statute applies to us or to your account. Where a state law gives you additional rights that apply to us, we will honor those too. That includes the right to appeal a denied request by replying to our response. This section is written with residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Washington, and Nevada particularly in mind.
Notice at collection. The categories of personal information we collect are identifiers (email address, account and support identifiers), commercial information (subscription and payment status), internet activity and device information (the product usage events in Section 6, the page measurement in Section 3.3, and ordinary request metadata), approximate location (your time zone, and the country the page measurement in Section 3.3 derives), your settings and the choices you have made, the guided programs and catalog items you select, the automated safety records in Section 5, communications you send us, and the content you create. Private account content is stored encrypted; AI processing and other readable-content exceptions are described above. We collect these categories for the purposes in Section 8, from you and from your use of the Service. We retain them as described in Section 12.
Sensitive personal information. Private writing may touch on health, beliefs, sexuality, or other sensitive subjects. Its account storage is encrypted, while selected text is readable during AI processing. Safety records, program choices, and support communications may also contain sensitive information in readable form. We never use sensitive information to infer characteristics about you for advertising, pricing, eligibility, employment, housing, insurance, credit, or other similarly consequential decisions. We do disclose information to providers as described in Section 10; that is different from selling information or sharing it for advertising.
Automated processing can derive sensitive information from your writing. The automated safety check in Section 5 classifies a message by risk category and severity so the Service can decide whether to show supportive resources. And when you choose a guided program, the program you chose and the approach the AI selected for it are stored in a form we can read. AI replies, plans, and memories may also contain inferences; their stored private text is encrypted.
We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 18. We do not use or disclose personal information for cross-context behavioral advertising or targeted advertising, and we do not profile you in furtherance of decisions producing legal or similarly significant effects. No provision of our Terms or of this policy waives or limits any right that a state privacy law makes non-waivable.
Washington and Nevada consumer health data. Private writing, selected topics, activity, and automated inferences can qualify as consumer health data under these laws. Stored encryption does not by itself remove that protection. Our separate Consumer Health Data Privacy Policy describes the relevant categories, purposes, recipients, and how to exercise your rights.
16. European Economic Area, United Kingdom, and Switzerland
KindMind Labs LLC is the controller of your personal information. Our legal bases for processing are: performance of a contract (operating the Service, your account, and your subscription); legitimate interests (security, fraud prevention, keeping the Service working, and understanding which features are used, balanced against your rights); consent (optional AI features that use your journal entries, and optional emails, each of which you can withdraw at any time); and legal obligation (tax, accounting, and responding to lawful requests).
Special categories. Content you choose to send to an AI feature may contain information treated as a special category of personal data, such as information about health, beliefs, political opinions, or sexuality. Processing special-category data requires an additional legal condition under applicable law, such as explicit consent for specified purposes. Accepting the Terms or acknowledging this policy is not, by itself, that consent. Journal memory has a separate opt-in; it is not a general consent to every use of sensitive data. Contact us to exercise withdrawal rights, including where a setting is unavailable. Withdrawing does not affect processing that was lawful before you withdrew.
What we need in order to provide the Service. We need an email address, a password, and the account and subscription information required to run your account. Without those we cannot provide the Service at all. AI features, journal-informed AI memory, and optional emails are optional, and declining them costs you nothing but those features.
Where your data goes. Our service providers may store or process personal information in the United States and in other countries where they operate. Our AI proxy runs on a global edge network. Request routing and processing locations depend on provider infrastructure; we do not guarantee processing in your country or region. Requests sent to our AI provider may be kept by that provider for the period described in Section 5, so that leg is not only transit.
Where European, UK, or Swiss law requires a transfer mechanism, we rely on the appropriate one for that transfer, which may include the European Commission’s Standard Contractual Clauses for transfers under the EU GDPR, the UK International Data Transfer Agreement or UK Addendum for transfers under the UK GDPR, and any Swiss adaptations required. Encryption of private account storage is an additional safeguard; it does not protect the readable AI requests and metadata described above from their recipients. You may contact us for more detail about the safeguards that apply to you.
You have the rights listed in Section 14, and the right to lodge a complaint with your local supervisory authority. Regarding automated decision-making under Article 22, please see Section 7: the automated decisions we make do not produce legal effects or similarly significant effects, you may request human review and exercise applicable objection or withdrawal rights.
17. Children’s Privacy
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe someone under 18 has provided us with personal information, please contact us at hello@kindmind.com.
18. Importing Data From an Earlier Version
If you move an account from an earlier version of KindMind, the import works differently from everything else described above, and only during the import itself. With your authorization, content from the older service is transferred to your browser, encrypted there with your new key, and then stored. During that transfer the content is protected in transit by encryption, but it is briefly readable to the migration process on our server so it can be handed to your browser. The migration route is designed to return the source content to your browser without saving a readable copy as account content. The unexpected-error handler avoids logging exception messages that could echo imported text. Once the import finishes, the content is subject to Section 4 like everything else, and the import path is retired once migration closes on December 31, 2026.
Importing is entirely optional, and you can start a new account instead.
19. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy here with a revised “Last updated” date. Changes apply going forward, from their effective date. Where the law requires your consent to a change, or where we would begin processing a materially new category of information about you, we will ask before the change applies to you. If you do not accept a change, you may delete your account.
20. Contact Us
KindMind Labs LLC
Email: hello@kindmind.com