Privacy Policy
Effective date: August 28, 2026
This Privacy Policy explains what MindDrive collects, how we use and disclose information, and the choices you have when you use the app, website, AI features, support, subscriptions, and optional integrations.
It covers account data, journal content, AI processing, health and sleep data, regional data storage, subscriptions, support, retention, deletion, and privacy rights.
English version controls. If MindDrive provides a translation of this document, it is for convenience only. To the fullest extent permitted by applicable law, the English version controls if there is a conflict between versions.
At a glance
MindDrive is a private AI journaling, reflection, memory, and personal insight app. You create journal folders, write entries, review them, and may use AI features to summarize, search, reflect on, and chat with your own content.
MindDrive is not a medical device, therapy service, crisis service, diagnosis tool, or substitute for professional advice. AI-generated insights may be incomplete, inaccurate, or not appropriate for your situation.
We collect account information, journal and user-generated content, AI-generated or AI-derived information, optional health, sleep, fitness, connected activity, Apple Journaling Suggestions, calendar, and image information, subscription and support information, approximate location and weather context, device and diagnostic information, and local app settings.
Some MindDrive features require your content to be processed by MindDrive servers and service providers, including AI providers, to provide the feature you requested. Do not use MindDrive for content you are not comfortable having processed this way.
MindDrive assigns each account to a regional data bucket during signup based on the country you confirm. Core MindDrive app data is stored in the assigned North America, UK, EU, or APAC Firestore database and served through the matching regional backend where the feature allows it.
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising or targeted advertising. We do not use journal content or health data for advertising.
Apple and Google process app-store payments. MindDrive does not directly receive your payment card number.
Account deletion deletes your MindDrive account and core MindDrive account data, but it does not cancel subscriptions purchased through Apple or Google. You must cancel those subscriptions through the applicable app store.
Manage Your Data in Settings lets you manage Weather and Analytics preferences, export entries and saved chats, and delete specific AI-generated data.
MindDrive encrypts meaningful user data at rest for supported app data, such as journal entries, entry names, chats, AI-derived memories, folder names, tag names, Home Insights, and reminder titles. Operational metadata may remain readable where needed for authentication, billing, delivery, safety, routing, debugging, or app performance. Support submissions are readable to support systems and staff when you send them, exports are plaintext by your action, and AI features decrypt selected content transiently to provide requested features.
Scope
This Privacy Policy applies to:
- the MindDrive mobile app;
- the MindDrive website and legal pages;
- account, subscription, and support services;
- AI journaling, reflection, memory, chat, summarization, OCR, text-to-speech, and insight features;
- integrations or permissions you choose to enable, such as Apple Journaling Suggestions, HealthKit, Health Connect, Strava, Garmin Connect, Wahoo, Google Health, or connected fitness services, selected Gmail, Google Drive, YouTube, or Outlook email imports, calendar, camera, photo library, notifications, weather, and support attachments.
This Privacy Policy does not apply to third-party services that you access outside MindDrive, such as Apple App Store, Google Play, Apple Health, Apple Journaling Suggestions, Android Health Connect, Strava, Garmin Connect, Wahoo, Google services, Microsoft services, Apple Sign In, Google Sign-In, Facebook Login, or third-party websites. Those services have their own privacy practices.
Who is responsible for your information
MindDrive Inc. is responsible for personal information processed through MindDrive, except where a third party acts as an independent controller under its own terms, such as Apple or Google for app-store billing and account services or Meta for Facebook authentication.
You can contact MindDrive about privacy questions at support@minddrive.io.
Personal information we collect
We collect personal information from you, from your device and app activity, from permissions or integrations you enable, from service providers, and from AI-generated or AI-derived processing.
Account and authentication information may include:
- email address, display name, account ID, authentication provider IDs, email verification status, login timestamps, account creation date, and session ID;
- authentication settings, MFA/TOTP metadata, hashed recovery codes, security settings, PIN settings, biometric app-lock settings, and account security settings.
MindDrive may use a name or display name you provide, or that an authentication provider shares with MindDrive, to address you in account, security, support, and optional onboarding emails you have agreed to receive.
MindDrive may use the name you set for yourself in MindDrive, or a display name an authentication provider provides for your account, to select male, female, or neutral imagery and messaging for a subscription paywall shown when your trial or paid access has ended. MindDrive stores the selected paywall version solely so it can show the same version in the future. It does not use journal content, health data, or connected-service data for this selection, or send the name or selected version to advertising or analytics providers.
Journal, user-generated content, and selected view-only app context may include:
- rich text journal entries, plaintext versions of entries, custom entry names, dates and times, tags, folders, folder cards, favorites, and scratchpad content;
- chat messages in MindDrive, prompts sent to AI features, assistant responses, feedback, comments, text extracted from imported images, selected calendar event details, selected Apple Journaling Suggestions details, selected Outlook email details, selected Strava view-only activity snapshot details, selected Garmin Connect activity or daily health details, selected Wahoo workout details, selected Gmail thread details, selected Google Drive file content or metadata, selected YouTube video or channel details, and optional sleep, health, or weather summaries inserted into journal entries.
Your journal content may include sensitive personal information depending on what you write, including information about your mental health, physical health, relationships, beliefs, location, work, family, finances, or other personal matters.
AI-generated and AI-derived information
MindDrive may create information from your content to power app features. This may include:
- journal and folder summaries; mood, sentiment, emotion, or reflection labels; search tags; search representations used for semantic search; mood statistics; and personal insight summaries built from your content;
- saved chat context, cross-chat memory that is on by default unless you turn it off in MindDrive chat settings, AI-generated chat titles, summaries from calendar, sleep, health, Garmin Connect, Wahoo, Google, or Outlook data you choose to import, selected Apple Journaling Suggestions details, text extracted from images, text-to-speech output, and related metadata.
AI data controls may delete saved MindDrive chats, chat memory, folder-level memories, cross-folder memory, Home Insights, and generated editor prompts.
This information may be linked to your account and may itself be sensitive if it reflects or infers mental, emotional, physical, health, or behavioral information.
Optional Facebook authentication
If you choose Facebook Login, Meta authenticates your Facebook account and may provide MindDrive and Firebase Authentication with the provider identifier, email address, and optional display name needed to create, sign in to, link, secure, and manage your MindDrive account.
On Android, MindDrive requests your email address once from Facebook during authentication. When Facebook provides an acceptable display name during a new signup, MindDrive may store it in encrypted form for internal customer recognition, support, and the limited subscription-paywall personalization described above. MindDrive does not import your Facebook posts, friends, photos, messages, or other Facebook profile content, and provider credentials are handled transiently for authentication rather than stored as MindDrive content.
MindDrive does not use Facebook authentication data, including the optional display name, for analytics, third-party advertising, targeting, or audience segmentation. MindDrive may use the optional display name only for the limited subscription-paywall personalization described above. Meta processes Facebook Login information under its own terms and privacy practices.
You can disconnect Facebook authentication in MindDrive Account settings after adding another authentication method, and you can manage MindDrive access in your Facebook account settings.
Optional health and fitness information
If you choose to enable Apple Health / HealthKit, Android Health Connect, Oura, Garmin Connect, Wahoo, Google Health, or another connected fitness or recovery service and take action to import information, MindDrive may process sleep sessions, sleep stages, time in bed, sleep efficiency, heart rate, respiratory rate, heart rate variability, oxygen saturation, steps, distance, active calories, exercise time, workout sessions, workout distance, cadence, power, speed, ascent, training stress, activity details, daily readiness or activity summaries, recovery, strain, VO2 max, sleep temperature, skin temperature, body temperature, body composition, energy score, stress, Body Battery, and related health, sleep, or fitness summaries you choose to include in MindDrive.
If you connect Strava and view an activity from the editor import tool, MindDrive shows the selected activity as a transient view-only snapshot. The Strava connector does not paste Strava API data into journal entries, summarize it with AI, generate embeddings from it, index it for search, or make it available to MindDrive chat.
MindDrive uses this information for journaling, reflection, context, and personal insight features. MindDrive does not use this information for medical diagnosis, treatment, emergency intervention, advertising, credit decisions, insurance decisions, employment decisions, data broker sales, or unrelated profiling.
You can manage HealthKit permissions through Apple Health and iOS settings. You can manage Health Connect permissions through Android settings and Health Connect controls. You can manage Strava, Oura, Garmin Connect, Wahoo, and Google Health access through MindDrive connected app settings and the relevant provider account settings.
Optional Google import information
If you choose to connect a Google account and take action to import information, MindDrive may process selected Gmail thread subjects, senders, dates, snippets, and message text, the names, metadata, and content of Google Drive files you explicitly choose through Google Picker, and selected liked YouTube video metadata, channel details, and video descriptions for videos you choose to import through the YouTube Data API.
MindDrive uses this information for journaling, reflection, context, and personal insight features. MindDrive does not send email, modify your Gmail account, write to Google Drive, modify YouTube activity, run background inbox or file sync, or import a full mailbox or Drive account.
You can manage Google import access through MindDrive connected app settings and your Google Account permissions.
MindDrive's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
MindDrive's use of information received from the Google Health API will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
MindDrive does not use raw or derived Google user data to create, train, or improve general or foundational AI models.
Optional Outlook email import information
If you choose to connect Outlook and take action to import information, MindDrive may process selected email subjects, sender names and email addresses, received dates, recipient counts, body previews, web links, attachment indicators, limited Microsoft account metadata needed to show connection status, and related email details for the messages you choose.
MindDrive uses this information for journaling, reflection, context, and personal insight features. MindDrive does not send email, modify your Microsoft account, write to your mailbox, run background inbox sync, or import your full mailbox.
You can manage Outlook access through MindDrive connected app settings and Microsoft account permissions.
Calendar, media, location, and weather context
If you grant permission and choose to import calendar or reminder information, MindDrive may process calendar list names, selected event titles, start and end times, recurrence information, notes or descriptions, and selected calendar details you choose to summarize or include in a journal entry.
Custom reminder titles are encrypted in MindDrive storage. Reminder names appear in notification previews by default unless you choose to hide the name for a reminder. When a name appears, MindDrive sends the reminder title through Firebase Cloud Messaging so it can appear in your device notification preview. You can change this choice when you create or edit the reminder.
If you grant permission and choose images or media, MindDrive may process selected images, resized or compressed image versions, text extracted from images, OCR results, and support-ticket attachments. Images may be sent to MindDrive servers and AI providers for text extraction or other requested features.
If you use Apple's Journaling Suggestions, iOS may suggest moments based on signals such as photos, places visited, workouts, nearby contacts, music, podcasts, motion activity, Health state-of-mind entries, events, and reflection prompts. MindDrive receives only the suggestion details you select through Apple's picker. The first implementation creates a text-only draft and does not store photo or video files from the suggestion.
MindDrive may use IP-based approximate location lookup for region assignment, production infrastructure routing, weather context, location history, security and fraud prevention, support routing, analytics, and service operations.
- Approximate location fields may include IP address, city, region or province/state, country, approximate latitude and longitude, timezone, visit counts, last known approximate location, and location or region history.
- We do not use GPS location unless we separately disclose that and obtain any required permissions. IP-based location may be inaccurate and may still be considered location information under some laws.
Subscriptions, support, analytics, and diagnostics
MindDrive uses app-store billing and subscription entitlement providers. We may collect or receive RevenueCat customer ID, app user ID or account ID, entitlement IDs, subscription plan identifiers, such as annual or monthly plan identifiers, subscription status, cancellation status, expiration status, payment-error flags, app-store environment, webhook IDs, subscription management URL, and related metadata.
If you contact us, use live chat, or submit a support request, we may process request reason, message content, account ID, email address, timezone, app version, build, runtime version, release channel, device name, operating system, network status, recent failed API requests, backend error metadata, subscription state, approximate region, support attachments, support ticket identifiers, ticket numbers, and live chat metadata.
Support messages, live chat messages, and attachments are separate from encrypted journal storage. They are readable to support systems and staff when you choose to send them.
We may collect app interactions, feature usage, device and app information, crash logs, performance logs, backend route, status, timing metadata, release channel, operating system, device identifiers or installation identifiers, network status, Cloudflare Turnstile tokens, Firebase App Check app or device integrity signals, reCAPTCHA Enterprise tokens and risk assessments, email validation or reputation results, IP-based geolocation results, security events, authentication events, and anti-abuse signals.
If you click a link in an optional MindDrive marketing email, we may record the campaign, link, time, approximate region, and click count to measure campaign performance and prevent abuse. We do not use journal content or other user-authored content for this purpose. Click records are kept for up to 90 days, while non-identifying campaign totals may be kept longer.
Signup admission, rate-limit, and usage-control records may contain short-lived grant state, timestamps, app identifiers, region assignment, account status, counters, and pseudonymous digests derived from email or network identifiers. MindDrive does not store raw email addresses or raw IP addresses in those grant and quota records, although network and security providers may process IP addresses to provide their services.
MindDrive does not intentionally send raw journal entries, custom entry names, MindDrive chat prompts, AI responses, or health summaries to analytics or diagnostics tools unless we disclose that clearly and obtain any required consent.
Local and on-device information
MindDrive may store information locally on your device, including:
- theme and UI preferences; weather, calendar, and sleep preferences; sort and filter order; selected folders and tags; scratchpad content; text-to-speech voice preference; session ID;
- review, search, and chat caches; local PIN; local security data; app-lock information; encrypted local search or chat indexes; and searchable entry or chat text protected with a device key where available.
MindDrive uses platform security tools, such as secure device storage, for sensitive local settings where available.
Sources and uses of personal information
We collect personal information from:
- you, when you create an account, write entries, use AI features, contact support, or enable settings;
- your device, app, browser, permissions, and local storage;
- Apple, Google, Meta, Firebase, RevenueCat, and other service providers;
- Apple Journaling Suggestions, HealthKit, Health Connect, Garmin Connect, Wahoo, Google Health, Google services, Microsoft services, or connected services, only if you enable permissions or connect an account and import information, and Strava only if you connect an account and view activity snapshots;
- calendar or photo services, only if you enable permissions and choose information to import;
- AI processing, when MindDrive generates summaries, semantic search representations, insights, titles, tags, OCR, chat responses, or saved context.
We use personal information to:
- create, authenticate, secure, and manage accounts;
- provide journaling, folders, review, MindDrive chat, saved context, search, reflection, AI summaries, insights, tags, semantic search, chat responses, titles, OCR, calendar summaries, sleep summaries, fitness summaries, and text-to-speech features;
- process optional health, sleep, fitness, selected Apple Journaling Suggestions, selected Google import, Outlook email import, calendar, photo, image, weather, and location-context features;
- personalize your experience within MindDrive; manage subscriptions and entitlements; provide support and live chat;
- detect, prevent, and respond to fraud, abuse, errors, outages, and security incidents;
- monitor app performance, reliability, and crashes; maintain logs and operational records;
- communicate with you about your account, security, support, subscriptions, changes, and service messages;
- comply with legal obligations, enforce our Terms, and protect the rights, safety, and property of MindDrive, users, and others.
Legal bases where applicable
Where laws such as GDPR, UK GDPR, or similar frameworks apply, we rely on one or more legal bases, including contract, consent, legitimate interests, legal obligations, and vital interests or public interest where necessary and legally permitted.
- We rely on contract to provide MindDrive, manage your account, process subscriptions, and deliver features you request.
- We rely on consent for optional permissions and features, such as Apple Journaling Suggestions, HealthKit, Health Connect, Garmin Connect, Wahoo, connected fitness imports, Strava activity snapshots, selected Gmail, Google Drive, YouTube, or Outlook email imports, calendar imports, photo/image processing, certain AI features, optional weather context, certain communications, and any processing requiring consent.
- We rely on legitimate interests to secure the service, prevent abuse, debug, improve performance, provide support, understand general app usage, and operate MindDrive where those interests are not overridden by your rights.
- We rely on legal obligations to comply with applicable law, tax, accounting, consumer protection, app-store, court, or regulatory obligations.
For Canadian users, we seek meaningful consent appropriate to the sensitivity of the information and the reasonable expectations of users. You may withdraw consent to optional processing, subject to legal or contractual limits, by changing app settings, revoking device permissions, deleting content, deleting your account, or contacting us.
Sensitive information, health data, and mental-wellbeing content
MindDrive may process sensitive information because journaling and reflection can involve deeply personal content. Sensitive information may include:
- mental health or emotional wellbeing information you write or infer through AI features;
- physical health, sleep, fitness, Apple Journaling Suggestions, email, file, or video information you import;
- intimate, family, relationship, religious, political, financial, employment, or similar information you choose to write;
- biometric-related app-lock settings or Face ID / biometric authentication status, where processed by the device;
- precise or approximate location information, depending on the feature and applicable law;
- contents of journal entries, prompts, AI chats, and support messages.
MindDrive processes sensitive information only to provide requested app features, operate the service, maintain security, provide support, comply with law, or as otherwise disclosed with your consent.
MindDrive does not use Apple Journaling Suggestions details, HealthKit, Health Connect, Strava connected fitness data, Garmin Connect data, Wahoo data, Google Health data, selected Google import data, Outlook email import data, journal content, or health-related information for advertising, credit, insurance, employment, lending, data broker sales, or unrelated profiling.
MindDrive is not HIPAA-covered unless a separate written agreement says otherwise. Do not use MindDrive as a substitute for medical, mental health, legal, financial, or other professional advice.
AI processing
MindDrive uses AI to provide features such as journal and folder summaries, mood and emotion reflections, personal insight summaries, search tags, semantic search, chat responses, saved chat context, cross-chat memory, AI-generated titles, image text extraction, calendar summaries, sleep summaries, fitness summaries, selected Google import summaries, Outlook email import summaries, text-to-speech output, and auto-editing or writing assistance.
Cross-chat memory is on by default and can be turned off in MindDrive chat settings. MindDrive may save encrypted summaries from chats and journal entries to help future chats use useful context without carrying every source forward. You can review active memory, remove individual details from active use, and restore them in AI Memory. When you remove a detail from active memory, MindDrive keeps an encrypted copy on an exclusion list so the detail is not added back to active memory. Removing a detail does not delete its source chat or journal entry.
To provide AI features, MindDrive may process selected content on MindDrive servers and may send relevant content, prompts, metadata, or selected context to AI providers such as OpenAI or Google Vertex AI / Gemini. We share only what is reasonably needed for the requested feature.
Subject to provider agreements and technical settings, we require AI providers not to use your journal content to train their general models unless you have expressly opted in or we clearly tell you otherwise and obtain any required consent. Provider retention, abuse monitoring, and endpoint-specific storage may vary.
AI outputs may be incomplete, inaccurate, biased, or inappropriate. AI mood, sentiment, emotion, or health-related reflections are informational only and are not medical, mental health, diagnostic, therapeutic, legal, financial, or professional advice.
MindDrive does not promise to monitor journal entries or AI chats for emergencies, self-harm, abuse, or crisis situations. If you may be in danger or need urgent help, contact emergency services, a crisis hotline, or a qualified professional.
When we disclose personal information
We use service providers to operate MindDrive. These may include:
- Google Firebase and Google Cloud for Auth, App Check, reCAPTCHA Enterprise risk assessment, Firestore, Storage, Cloud Functions, Cloud Run, KMS, Secret Manager, Firebase Analytics, Crashlytics, and Performance;
- OpenAI for AI analysis, chat, semantic search support, TTS, and image/text extraction;
- Google Vertex AI / Gemini for AI fallback or selected AI features;
- RevenueCat for subscription entitlement management;
- Apple and Google for app stores, billing, sign-in, Apple Journaling Suggestions, HealthKit, Health Connect, and platform services;
- Meta for Facebook Login authentication when you choose it;
- Garmin Connect, Wahoo, Google Health, and connected fitness services when you choose to enable a permission or connect an account and import activity or health information, and Strava when you choose to connect an account and view activity snapshots;
- Google services when you choose to connect a Google account and import selected Gmail, Google Drive, or YouTube information;
- Microsoft services when you choose to connect Outlook and import selected email information;
- Zoho SalesIQ and Zoho Desk for live chat and support tickets;
- Cloudflare for bot protection and the isolated email-action callback page;
- email delivery providers, IP geolocation providers, email validation or reputation providers, analytics, diagnostics, hosting, security, logging, and operational vendors.
These providers may process personal information only as needed to provide services to MindDrive or as otherwise permitted by their agreements and applicable law.
We may disclose information at your direction or with your consent, including when you use Apple, Google, or Facebook sign-in, import Apple Journaling Suggestions, HealthKit, Health Connect, connected fitness data, view Strava activity snapshots, selected Google information, selected Outlook email information, or calendar events, upload images for OCR, contact support, or request AI processing.
We may disclose information for app-store billing and subscriptions, legal and safety obligations, fraud and abuse investigations, rights protection, disputes, audits, compliance obligations, and business transfers such as a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use journal content, Apple Journaling Suggestions details, HealthKit data, Health Connect data, Strava connected fitness data, Garmin Connect data, Wahoo data, selected Google import data, Outlook email import data, or health-related information for advertising.
International processing and data residency
MindDrive uses regional Firestore databases and regional Cloud Run backends for core app data in the currently supported countries. During signup, MindDrive asks you to confirm your country and assigns your account to one of four data regions.
| Country group | Data region | Core Firestore database | Primary backend location |
|---|---|---|---|
| United States and Canada | North America | (default), using Firestore multi-region nam5 in the United States | northamerica-northeast2 in Toronto, Canada |
| United Kingdom | UK | ukdb in europe-west2 in London, United Kingdom | europe-west2 in London, United Kingdom |
| Ireland, Netherlands, Denmark, Sweden, Norway, Finland, Germany, Austria, Switzerland, Belgium, Luxembourg, Iceland, Malta, Portugal, Estonia, Czechia, Poland, Croatia, and Slovakia | EU | eudb in europe-west3 in Frankfurt, Germany | europe-west3 in Frankfurt, Germany |
| Australia, New Zealand, and Singapore | APAC | apac in australia-southeast1 in Sydney, Australia | australia-southeast1 in Sydney, Australia |
If your country is not in the supported country list, or if a country code cannot be recognized, MindDrive may assign the account to North America unless we provide another supported option.
Regional routing applies to core MindDrive app records such as account app data, journal entries, folders, chats, AI-derived app data, notification state, support mirrors, subscription entitlement mirrors, and regional operational records stored in Firestore. It does not mean every service provider or every processing step is located only in that region.
Firebase Authentication, app-store billing, RevenueCat entitlement services, AI providers, support providers, email providers, analytics, diagnostics, bot protection, security tools, website forms, legal or compliance workflows, and provider logs may process personal information in other countries where those providers or their subprocessors operate.
Some account, security, and support workflows intentionally check across regional databases so MindDrive can prevent duplicate accounts, verify recovery or lockout tokens, find the right support ticket, process a regional webhook, or route a user back to the correct account region. These workflows use limited identifiers or operational records for that purpose and update only the matched account region where the workflow affects user data.
Where personal information is transferred internationally, MindDrive relies on provider agreements, contractual safeguards, adequacy decisions, data privacy frameworks, standard contractual clauses, or other lawful transfer mechanisms as applicable.
Retention
We keep personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
| Category | General retention approach |
|---|---|
| Account data | Kept while your account is active and for as long as needed after deletion for security, fraud prevention, legal, tax, accounting, or compliance purposes. Expired free-trial accounts that are not upgraded within the post-trial window may be deleted for security and privacy, subject to retained records described below. |
| Journal entries and user content | Kept until you delete the content or your account, subject to backups, logs, and processor retention. |
| AI-derived data, search indexes, and memory exclusions | Kept while needed to provide AI, search, memory, insight, and chat features. Active memory may be removed through AI Memory. Encrypted exclusion items are kept to prevent removed details from being added back until you restore them, delete the applicable memory category, delete your account, or the record is no longer needed. |
| Health, sleep, calendar, image, and weather summaries | Kept as part of journal content, AI-derived data, or feature metadata until deleted or no longer needed. |
| Subscription records | Kept as needed to manage entitlements, resolve billing issues, comply with app-store rules, and maintain business records. Apple, Google, and RevenueCat may retain records under their own policies. |
| Support records, analytics, diagnostics, and security logs | Kept as long as needed for support, reliability, security, abuse prevention, legal, and operational purposes, or according to provider settings. |
| Backups and local device data | Backups are deleted or overwritten according to backup cycles. Local device data remains until cleared through app features, logout/account deletion flows, cache clearing, app deletion, or device settings. |
Deleting content, deleting your account, and canceling subscriptions
MindDrive may allow you to delete entries, chats, active AI memory, and AI memory exclusions separately. Delete History for cross-chat memory clears the saved cross-chat memory and its chat-memory exclusions without deleting saved chats. Future memory may be built again from chats you keep. When you delete content, we delete or de-identify the relevant records according to MindDrive's deletion workflow.
Manage Your Data may also let you delete saved MindDrive chats and their chat memory, folder-level memories, cross-folder memory, source-specific AI memory exclusions, Home Insights, and generated editor prompts. These controls do not delete your journal entries unless you separately delete entries or your account.
If you delete your MindDrive account in the app, MindDrive deletes your account record and associated MindDrive app content according to the account deletion workflow. Some records may remain where retention is required or permitted, as described in this Privacy Policy.
Some information may remain after account deletion, including:
- subscription and transaction records held by Apple, Google, or RevenueCat;
- support tickets, attachments, and emails retained for support, legal, security, or compliance purposes;
- cancellation feedback or administrative records, such as account ID, reason, feedback, and timestamp;
- security, fraud, and operational logs;
- backup copies until overwritten;
- records retained by service providers according to their policies and our agreements;
- information we must retain for legal, tax, accounting, dispute, or compliance purposes.
Deleting your MindDrive account, deleting the app, or stopping use of MindDrive does not cancel subscriptions purchased through Apple App Store or Google Play. You must cancel your subscription through the applicable app-store subscription settings.
If you cannot access the app to request deletion, contact support@minddrive.io from the email address associated with your account.
Your choices and controls
Depending on your location and app version, you may have choices such as:
- update account information; delete entries; delete chats; delete cross-chat memory; delete your account;
- export entries and saved chats from Manage Your Data in Settings;
- disable analytics where the app provides an analytics setting;
- revoke HealthKit permissions in Apple Health or iOS settings; revoke Health Connect permissions in Android settings; disconnect Strava, Oura, Garmin Connect, Wahoo, or Google Health in MindDrive connected app settings or provider account settings; disconnect Google imports in MindDrive connected app settings or Google Account permissions; disconnect Outlook in MindDrive connected app settings or Microsoft account permissions; disconnect Facebook authentication in MindDrive Account settings after adding another authentication method, or manage MindDrive access in Facebook account settings;
- revoke calendar, reminder, camera, photo library, microphone, notification, or biometric permissions in device settings;
- disable weather context if the app provides that setting; turn off cross-chat memory in MindDrive chat settings; disable optional AI features where available;
- unsubscribe from non-essential emails; contact support to request access, correction, deletion, or other privacy rights.
Bulk entry exports may include all folders or selected folders. Entry and chat exports may be saved as Markdown or plain text through the device sharing flow.
Export files are intentionally readable once you create them. Protect exported copies through your device, storage provider, or sharing destination.
Some features may not work if you revoke permissions or disable optional processing.
Marketing and communications
We may send service, account, security, support, subscription, and transactional messages. These are not marketing and may be necessary to provide MindDrive.
We will send marketing communications only where permitted by law or with any required consent. You can opt out of marketing communications using the unsubscribe link or by contacting us. Opting out of marketing does not stop service or security messages.
California and US state privacy rights
Depending on your state, you may have rights to:
- know or access personal information we collect, use, disclose, sell, or share;
- receive a portable copy of personal information;
- delete personal information;
- correct inaccurate personal information;
- opt out of sale or sharing for targeted advertising;
- limit certain uses or disclosures of sensitive personal information;
- opt out of certain profiling decisions, where applicable;
- appeal a privacy request decision;
- not be discriminated against for exercising privacy rights.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use sensitive personal information for purposes requiring a right to limit under California law unless we provide the required notice and choice.
| Category | Examples | Sources | Purposes | Disclosed to |
|---|---|---|---|---|
| Identifiers and contact information | Email, account ID, provider IDs, session ID, IP address, name/display name | You, device, providers | Account, security, support, subscriptions, communication | Hosting, auth, support, subscription, security, and email providers |
| Commercial information | Subscription products, entitlement status, purchase metadata | App stores, RevenueCat | Billing, entitlements, support | Apple, Google, RevenueCat, support providers |
| Internet or device activity | App interactions, diagnostics, logs, performance data | Device, app, backend | Operations, analytics, reliability, security | Firebase/GCP and diagnostics providers |
| Geolocation | IP-based approximate city, region, country, timezone, approximate coordinates | Device/network, IP provider | Region assignment, weather, routing, security | Hosting, IP geolocation, analytics/operations providers |
| User content, health information, selected Apple Journaling Suggestions details, Strava view-only activity snapshots, and selected Google, Google Health, Garmin Connect, Wahoo, or Outlook imports | Journal entries, chats, prompts, images, support messages, sleep, fitness, steps, distance, active calories, exercise time, workout sessions, activity details, heart rate, HRV, respiratory rate, oxygen saturation, VO2 max, sleep temperature, skin temperature, body temperature, body composition, energy score, recovery, strain, sleep summaries, fitness summaries, selected Apple Journaling Suggestions details such as places, workouts, motion activity, nearby contacts, listening activity, state-of-mind counts, event details, reflection prompts, and media counts, selected Strava activity snapshot details shown only in the editor import modal, selected Garmin Connect activity or daily health details, selected Wahoo workout details, selected Gmail thread details, selected Google Drive file content or metadata, selected YouTube video or channel details, selected Outlook email details | You, Apple Journaling Suggestions, HealthKit, Health Connect, Strava, Garmin Connect, Wahoo, Google Health or connected fitness services, Google services, Microsoft services | Journaling, AI for non-Strava user content and imports, support, storage, optional reflection features, Strava activity snapshot display | Hosting, AI providers for non-Strava user content and imports, support providers |
| Sensitive personal information and inferences | Journal contents, health data, mental-wellbeing inferences, authentication/security data, location depending on law, mood, summaries, insights, tags, semantic search representations | You, device, providers, AI processing | App functionality, security, optional features, support | Service providers as needed |
To exercise state privacy rights, contact support@minddrive.io. We may need to verify your identity before responding. Authorized agents may submit requests where permitted by law, subject to verification.
Consumer health data privacy notice
This section applies where consumer health privacy laws, such as Washington's My Health My Data Act or similar laws, apply.
MindDrive may process consumer health data, which may include:
- health or mental-wellbeing information you write in journal entries;
- mood, sentiment, emotion, or wellness-related AI inferences;
- sleep information, heart rate, respiratory rate, heart rate variability, oxygen saturation, time in bed, and sleep efficiency;
- fitness information, steps, distance, active calories, exercise time, and workout sessions;
- health, sleep, or fitness summaries;
- health-related calendar, image, or support information you choose to provide;
- location or weather context if linked to health-related content or inferences.
We collect and use consumer health data to provide requested journaling, reflection, memory, AI, search, sleep, health, and support features; to secure and operate the service; to comply with law; and for other purposes you consent to.
We may disclose consumer health data to service providers needed to provide MindDrive, such as cloud hosting, AI providers, support systems, security providers, and app-store or entitlement providers when relevant. We do not sell consumer health data. We do not use consumer health data for advertising, credit, insurance, employment, lending, or data broker purposes.
You may request access, deletion, or withdrawal of consent by contacting support@minddrive.io or using in-app controls where available. Withdrawing consent may disable features that require the data.
Canadian, EU, UK, Swiss, and minors' privacy rights
If you are in Canada, you may request access to or correction of your personal information, ask questions about our practices, or withdraw consent to optional processing, subject to legal and contractual limits. We will respond in accordance with applicable Canadian privacy laws.
If you are in the European Economic Area, United Kingdom, or Switzerland, and GDPR, UK GDPR, Swiss data protection law, or similar laws apply, you may have rights to access, correct, delete, restrict, object to, or port personal information, withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority.
MindDrive is not directed to people under 16 and does not knowingly collect personal information from anyone under 16. If you are under 16, do not use MindDrive. If we learn that we collected personal information from someone under 16, we will take reasonable steps to delete it.
Security and human access to content
MindDrive uses technical, organizational, and administrative safeguards designed to protect personal information. These may include:
- TLS/HTTPS in transit;
- encryption at rest for supported app data;
- server-side encryption and key management for protected content fields;
- Firebase Authentication; optional TOTP MFA; PIN and biometric app lock; SecureStore for sensitive local items where appropriate;
- access controls, security rules, restricted human/admin access, logging, monitoring, and incident response processes.
MindDrive may need to decrypt or process user content transiently on its servers or with AI providers to provide requested AI features. For that reason, we do not describe MindDrive as end-to-end encrypted.
No method of transmission, storage, or security is perfect. We cannot guarantee absolute security.
MindDrive personnel do not routinely review journal content. Human access to user content is limited to circumstances such as providing support you request, investigating bugs or security issues, complying with legal obligations, preventing fraud, abuse, or harm to the service, enforcing our Terms, and operating or maintaining the service where necessary.
Privacy requests and contact
For privacy questions, access or correction requests, deletion requests, or complaints about MindDrive's privacy practices, contact MindDrive Inc.'s Privacy Officer at support@minddrive.io.
Privacy Officer, MindDrive Inc., 2967 Dundas St. W. #495, Toronto, ON M6P 1Z2, Canada.
App-store disclosures and changes
MindDrive's App Store privacy labels, Google Play Data Safety form, iOS privacy manifest, Health Connect declaration, and in-app permission prompts must match this Privacy Policy and actual engineering behavior.
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law, such as through the app, email, website, or app-store update notes. The Effective date shows when this Privacy Policy was last updated.
Questions or privacy requests may be sent to support@minddrive.io.