Privacy Policy
Privacy Policy
Effective Date: October 25, 2025 Last Updated: October 25, 2025
1. Who We Are
Controller: MindPal ("we," "us," or "our") Contact: support@mindpal.io Website: https://mindpal.space
This Privacy Policy explains how MindPal collects, uses, discloses, and protects personal information when you use our AI-powered productivity platform, including all products and services accessible through https://mindpal.space and our related domains (collectively, the "Services").
2. What MindPal Does (AI & Agentic Platform)
MindPal provides an AI-powered platform that enables you to:
- Interact with AI systems and large language models
- Create and deploy AI agents that can perform automated tasks
- Connect third-party accounts (Google, Slack, GitHub, etc.) to enable agents to act on your behalf
- Upload, process, and chat with your documents and files
- Execute automated workflows at scale
Important: When you use MindPal, you are interacting with AI systems. Agents may perform automated actions based on your instructions, such as sending emails, creating tickets, searching documents, or posting content. You can revoke third-party access at any time through your connected service's settings or within MindPal. We maintain execution logs so you can audit agent actions.
3. Information We Collect
3.1 Account & Profile Data
- Name, email address, password (hashed and encrypted)
- Organization/company name
- Profile preferences and settings
- Billing information (processed by our payment provider)
3.2 Service Usage Data
- AI prompts, queries, and instructions you provide
- Files, documents, and content you upload
- Agent configurations, workflows, and instructions
- AI outputs, responses, and generated content
- Feedback, ratings, and corrections you provide
- Execution logs (what actions agents performed, when, and results)
- Safety and moderation logs
- Session metadata and timestamps
3.3 Integration & Connector Data
When you connect third-party services (optional), we access data according to the permissions you grant:
- Google Workspace: email metadata/content, calendar events, Drive files (scopes you approve)
- Slack/Teams: workspace content, channels, messages (per your authorization)
- GitHub: repositories, issues, pull requests (based on granted access)
- Other integrations: data specific to the scopes and permissions you authorize
You control these integrations and can revoke access at any time.
3.4 Device & Technical Data
- IP address, browser type, and version
- Device identifiers and operating system
- Language preferences and timezone
- Referral source and navigation paths
- Performance metrics, error reports, and crash logs
3.5 Communications
- Support tickets, chat messages, and email correspondence
- Call recordings (when we notify you in advance)
- Feedback and survey responses
3.6 Cookies & Analytics
We use cookies and similar technologies for essential functions, analytics, and (with your consent where required) marketing. See our Cookie Policy for details.
We do not intentionally collect sensitive personal information (health data, financial account details beyond billing, biometric data, etc.) unless you explicitly choose to include it in prompts or uploads. Please avoid sharing sensitive information unless necessary for your specific use case.
4. How We Use Your Information
We use the information we collect to:
4.1 Provide & Improve the Services
- Create and manage your account
- Process AI requests and run agents/workflows
- Execute actions on third-party services as you direct
- Store and retrieve your content
- Detect and prevent fraud, abuse, and security incidents
- Ensure platform availability, performance, and reliability
- Develop new features and improve existing ones
- Conduct quality testing, evaluation, and model performance analysis
4.2 Communicate With You
- Send service updates, security alerts, and important notices
- Respond to support requests and provide customer service
- Send marketing communications (with your consent; you can opt out anytime)
4.3 Compliance & Legal
- Comply with applicable laws and regulations
- Respond to legal requests and prevent illegal activity
- Enforce our Terms of Service and protect our rights
- Fulfill tax, accounting, and audit requirements
4.4 Legal Basis (where applicable)
- Contract performance: Providing the Services you've subscribed to
- Legitimate interests: Platform security, fraud prevention, analytics, product improvement
- Consent: Marketing communications, optional features, non-essential cookies
- Legal obligation: Compliance with applicable laws
5. AI & Automated Decision-Making
Transparency: When you use MindPal, you are knowingly interacting with AI systems. We clearly label AI-generated content and automated agent actions.
Model Training: We do not use your customer content (prompts, files, outputs, or third-party integration data) to train foundation AI models by default. If we offer an optional program to contribute anonymized data to improve our services in the future, we will obtain your explicit, separate consent that you can withdraw at any time.
Automated Decisions: Some features may use AI to make automated decisions (e.g., content suggestions, task prioritization, workflow recommendations). These decisions generally do not have legal or similarly significant effects. If you believe an automated decision has adversely affected you, please contact us at support@mindpal.io.
6. Data Retention
We retain personal information only as long as necessary for the purposes described above:
- Customer content (prompts, files, outputs): 90 days after creation, or until you delete it
- Agent execution logs: 180 days
- Account & billing data: Duration of your account + 7 years for legal/tax obligations
- Security & error logs: 12-24 months
- Backup copies: 35-day rolling retention
You can delete content directly in the product. Upon account closure, we delete or de-identify your data according to the schedule above, subject to legal holds or regulatory requirements.
7. How We Share Information
We do not sell your personal information. We do not share your information for cross-context behavioral advertising.
We share information with:
7.1 Service Providers & Subprocessors
Third parties that help us operate the Services, including:
- Cloud hosting & infrastructure: Amazon Web Services (AWS)
- AI model providers: OpenAI, Anthropic, Google, and others (depending on models you select)
- Payment processing: LemonSqueezy
- Email & communications: (your email provider)
- Analytics & monitoring: (your analytics tools)
- Customer support tools: (your support platform)
All service providers are bound by confidentiality and data protection obligations.
7.2 Third-Party Services You Connect
When you authorize MindPal agents to perform actions (e.g., send an email via Gmail, create a GitHub issue), we share necessary data with those services to execute your instructions.
7.3 Business Transfers
If MindPal is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you and ensure protections remain in place.
7.4 Legal & Safety
We may disclose information when required by law, to respond to legal process, to protect our rights and safety, or to prevent fraud and abuse.
8. Data Security
We implement industry-standard security measures to protect your information:
8.1 Infrastructure Security (AWS)
- Data encryption: TLS 1.3+ in transit; AES-256 encryption at rest (S3 default encryption)
- Access controls: AWS IAM least-privilege policies, multi-factor authentication, regular key rotation
- Network security: VPC isolation, security groups, network ACLs
- Logging & monitoring: AWS CloudTrail, CloudWatch, automated anomaly detection
- Vulnerability management: Regular security assessments, dependency scanning, patch management
8.2 Application Security
- Password hashing using bcrypt with strong salts
- Secrets management using encrypted vaults (AWS Secrets Manager)
- Code reviews and secure development lifecycle practices
- Regular security testing and vulnerability remediation
- Tenant data isolation and environment segregation
8.3 Organizational Security
- Employee security training
- Background checks for team members with data access
- Need-to-know access policies
- Incident response procedures
Important: No security system is perfect. While we implement strong safeguards, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at support@mindpal.io.
9. International Data Transfers
MindPal operates globally and stores data on AWS infrastructure primarily in [US regions]. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland: We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards for international transfers. We assess the legal environment and implement supplementary measures as needed.
If you have questions about international transfers, contact us at support@mindpal.io.
10. Your Rights & Choices
Depending on your location, you may have rights regarding your personal information:
10.1 Access & Correction
You can access and update most information directly in your account settings. To request a copy of your data, contact us at support@mindpal.io.
10.2 Deletion
You can delete content directly in the product. To request full account deletion, contact support@mindpal.io. We will delete your data according to our retention schedule (see Section 6).
10.3 Data Portability
You can export your content in common formats through your account settings. For assistance, contact support@mindpal.io.
10.4 Opt-Out & Objection
- Marketing emails: Click "unsubscribe" in any marketing email or adjust preferences in your account
- Cookies: Manage preferences through your browser settings or our cookie banner
- Third-party integrations: Disconnect integrations in your account settings or through the third-party service
10.5 Withdraw Consent
If we process your data based on consent, you can withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
10.6 How to Exercise Your Rights
Email us at support@mindpal.io with your request. We will verify your identity and respond within applicable legal timeframes (typically 30-45 days). We will not discriminate against you for exercising your rights.
10.7 Authorized Agents
You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.
11. Google API Services
MindPal's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
When you connect Google services:
- We only access data within the scopes you explicitly authorize
- We use Google data solely to provide the features you've requested
- We do not transfer Google user data to third parties except as necessary to provide/improve our Services, comply with applicable law, or as part of a merger/acquisition (with notice)
- We do not use Google data for serving advertisements
- We do not allow humans to read your Google data unless: (1) you give explicit consent, (2) it's necessary for security purposes, (3) it's required to comply with applicable law, or (4) our use is limited to aggregated and anonymized data
You can revoke MindPal's access to your Google account at any time through your Google Account permissions.
12. Cookies & Tracking Technologies
We use cookies, pixels, local storage, and similar technologies for:
- Essential functions: Authentication, security, preferences (always active)
- Analytics: Understanding how you use our Services to improve them (with consent where required)
- Marketing: Showing relevant ads and measuring campaign effectiveness (with your consent)
You can control cookies through:
- Our cookie banner/preferences (where applicable)
- Browser settings (block all cookies, third-party cookies, or specific domains)
- Do Not Track signals: We honor Global Privacy Control (GPC) signals where required by law
For details on specific cookies we use, their purposes, and retention periods, see our Cookie Policy.
13. Children's Privacy
Our Services are not directed to individuals under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@mindpal.io so we can delete it.
14. Third-Party Links
Our Services may link to external websites, applications, or services not operated by us (e.g., documentation, integrations, social media). We are not responsible for the privacy practices of these third parties. Please review their privacy policies before providing them with personal information.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email to your registered email address
- Displaying an in-app notification
Your continued use of the Services after the effective date constitutes acceptance of the updated policy. If you do not agree to the changes, you should discontinue use and close your account.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Email: support@mindpal.io Website: https://mindpal.space Support Portal: https://docs.mindpal.space
We will respond to your inquiry within 30 days.
Summary for Quick Reference:
- We collect account data, usage data, files/prompts you provide, and technical data
- We use it to provide AI services, run agents/workflows, improve our platform, and communicate with you
- We do not sell your data or use your content to train AI models (by default)
- We share data with service providers (AWS, AI model providers, etc.) and third-party services you connect
- We use AWS infrastructure with encryption, access controls, and security monitoring
- You can access, correct, delete, and export your data
- Contact support@mindpal.io for questions or to exercise your rights