Privacy Policy
Effective August 2, 2026
Mindlify (“we”, “us”) is a visual thinking tool at mindlify.co that turns your notes and AI conversations into connected knowledge maps. This policy explains what data we collect, how we use it, who else touches it, how long we keep it, and how to reach us. We have tried to write it the way we would want to read it: plainly.
What we collect
Account data. Your email address and login credentials, managed by our authentication provider (Supabase). If you sign up through an identity provider, we receive the profile details you approve.
Your content. The thoughts, connections, clusters, mindspaces, and labels you create, and any text you paste or import for Mindlify to transform into a map.
Payment data. Subscriptions are processed by Dodo Payments. We receive your subscription status and billing country — never your card number.
Technical data. Standard server logs (IP address, browser type, timestamps) used for security and debugging, and the essential cookies that keep you signed in. We do not run advertising trackers.
How we use your data
We use your data to operate Mindlify: storing your maps, syncing them across devices, processing payments, and sending transactional email (such as sign-in links and trial reminders) through Resend. We do not sell your data, and we do not use your content to train AI models.
AI processing
When you use an AI feature — unpacking a conversation into a map, suggesting connections, extracting actions — the text you submit is sent to a model provider (currently Google Gemini and Cerebras) solely to perform that transformation, under their API terms. This happens only when you invoke an AI feature, never in the background. AI-generated structures can contain mistakes or omissions; they are suggestions for you to review, not facts.
Agents and API access (MCP)
You can connect AI assistants like Claude, ChatGPT, or Gemini to your Mindlify account through our MCP server. Access requires either a personal access token (we store only a hash of it) or an OAuth authorization you grant on a consent screen. A connected agent can only reach your own account’s data, and destructive actions require explicit confirmation. You can revoke tokens and authorizations at any time in Settings → API tokens.
Sharing and visibility
Your mindspaces are private by default. They become visible to others only when you create a share link or explicitly publish a mindspace as public. Public mindspaces may be indexed by search engines; private ones are excluded from indexing. Review what a share contains before publishing it.
Who else processes your data
We rely on a small set of service providers, each only for the role named here:
- Supabase — authentication and database hosting
- Vercel — application hosting
- Google (Gemini API) and Cerebras — AI processing of content you submit to AI features
- Dodo Payments — payment processing
- Resend — transactional email
Retention and deletion
We keep your content for as long as your account exists. You can delete individual thoughts and mindspaces at any time. If you delete your account (or ask us to), your content is removed from our systems, with residual copies in encrypted backups expiring within 30 days.
Your rights
You can access and edit your data in the app, export any mindspace, and request a copy or deletion of everything we hold about you by emailing us. If you are in a region with data-protection laws such as the GDPR, these rights are yours by law; we honor them for everyone regardless of region.
Children
Mindlify is not directed at children under 16, and we do not knowingly collect their data.
Changes and contact
If this policy changes materially, we will note it here with a new effective date. Questions or requests: support@mindlify.co.