Privacy Notice (Aviso de Privacidad)
Last updated: August 25, 2026
1. Identity and Address of the Data Controller
Carlos A Galvez Diaz Barriga and Gabriel Gutiérrez Guerra, natural persons with registered business activity (personas físicas con actividad empresarial) operating the Mindle application and website (collectively, the "Service") — hereinafter, "the Controller," "we," or "our" — are responsible for the processing of your personal data. Mindle is a personal knowledge management platform that allows users to capture, organize, and interact with their knowledge using artificial intelligence.
This Comprehensive Privacy Notice is issued in compliance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Official Gazette of the Federation on March 20, 2025 (as amended), and its applicable secondary regulations.
Our Service allows you to create text notes, record voice notes, record or transcribe meetings, attach images, and organize everything through AI-extracted concepts, semantic search, and a visual knowledge graph.
Data Controllers: Carlos A Galvez Diaz Barriga and Gabriel Gutiérrez Guerra (Mindle)
Address: Jardines del Pedregal, Álvaro Obregón, Mexico City, C.P. 01900, Mexico
Contact email: a@mindle.mx
For any questions or clarifications regarding the processing of your personal data, you may contact us at the email address indicated above.
2. Personal Data We Collect
To fulfill the purposes described in this Privacy Notice, we collect the following categories of personal data:
2.1 Identification and Account Data
When you create an account, we collect your full name and email address. Authentication is handled by Firebase Authentication, a Google service: if you sign up with email and password, your password is stored and secured by Firebase — we never receive or store it on our own servers. We store your name, email, the unique Firebase identifier of your account, and the sign-in method used.
If you choose to register with your Google account, we receive your name and email address from Google through Firebase. We do not receive your Google password and do not access any other Google service or data. Email verification is required before using the Service.
2.2 User Content
The core of Mindle is the content you create: text notes, voice notes, meetings you record or paste transcripts of, and images attached to your notes or meetings. Each piece of content is stored with metadata such as creation date, modification date, word count, language, and audio duration where applicable.
Audio is not stored. When you record a voice note or meeting, the audio is sent to a transcription service, converted to text, and then discarded — we keep only the transcript and its duration. Meeting transcripts include generic speaker labels ("Speaker 1", "Speaker 2"); we do not create or store voiceprints or any biometric identifier. Important: when recording a meeting, Mindle may capture your microphone and, in supported browsers, your computer's system audio, so other participants' voices may be recorded and transcribed. You are responsible for informing all participants and obtaining any legally required consent before recording.
Uploaded images are re-encoded (location and camera metadata is removed) and stored on our servers. Each image is analyzed by an AI vision model to generate a description and extract visible text (OCR) so it can be found in search. You retain full ownership of all content you create in Mindle.
legal.aviso.data_collected.content.p4
2.3 AI-Derived Data
When your content is processed by our AI systems, derived data is created and stored: rewritten and structured versions of your text, extracted concepts, detected tasks, content classifications, AI-generated meeting notes, and on-demand artifacts (summaries, bullet points, translations, mind maps).
We also generate vector embeddings — mathematical representations of the meaning of your content — that power semantic search, the "ask" feature, and concept connections. A copy of your content is indexed in our search system, and we store a personal vocabulary of corrections you teach the Service to improve your transcriptions.
2.4 Technical and Usage Data
To operate the Service we use a small number of functional cookies and browser storage (Section 12), and we store your preferences (language, auto-processing, onboarding progress) on our servers. Your Firebase session is kept in your browser by the Firebase SDK.
We meter your usage (counts of notes, meetings, transcription seconds, AI actions, images) to enforce plan limits and billing. Our error-monitoring service (Sentry) receives technical data when failures occur — IP address, browser information, and internal user ID — configured to exclude your content and email. Cloudflare processes your IP address to route and protect traffic.
2.5 Billing Data
If you purchase a subscription, payment is processed by Stripe. Card details are collected and stored directly by Stripe and never reach our servers. We store your Stripe customer and subscription identifiers, plan, subscription status, and billing period dates, and we share your name and email with Stripe to create your customer record.
2.6 Newsletter Information
We collect your email address and, optionally, your full name in two ways: when you subscribe to the newsletter from our site, and when you create a Mindle account. In the second case you are subscribed to product updates by default, and you can unsubscribe from the link in any of those emails without affecting your account or your access to the Service. Both paths are synced to a private Notion workspace, which we use as a mini-CRM for manual follow-up. If you have an account, that workspace also receives aggregate indicators of your use of the Service: how many notes you have created, how many of them arrived through WhatsApp, the date of your last activity and of your last search, and whether you have WhatsApp linked. It never receives the content of your notes, the text of your searches, or your messages.
2.7 Sensitive Personal Data
We do not request or intentionally collect sensitive personal data (racial or ethnic origin, health status, genetic information, religious, philosophical, or moral beliefs, union membership, political opinions, or sexual preference), and we do not process biometric data: meeting transcripts label speakers generically and no voiceprint is generated or stored.
However, as a free-form note-taking tool, any information you voluntarily write, record, or photograph — including, potentially, sensitive data about yourself or third parties — becomes part of your stored content and is processed under this Notice solely to provide you the Service.
We do not collect geolocation data, advertising identifiers, or browsing history from other websites, and we do not use advertising tools. Our only measurement is aggregate page analytics on our public website, which stays off unless you accept it.
3. Purposes of Data Processing
In accordance with the LFPDPPP, your personal data will be processed for the following purposes, distinguishing those necessary for the legal relationship between you and the Controller from those that require your consent.
3.1 Primary Purposes (necessary for the service relationship)
The following purposes are necessary to provide the Service you request when creating an account:
- Create, manage, and maintain your user account, and authenticate your identity through Firebase
- Store, organize, and display the content you create (notes, transcripts, meetings, images)
- Process your content with artificial intelligence (rewriting, concept extraction, task detection, classification, image description, embeddings, semantic search, and answers) — this is the essential functionality of the Service
- Transcribe your voice notes and meetings through speech-to-text services, discarding the audio afterwards
- Process subscription payments through Stripe and meter usage to enforce your plan limits
- Send you transactional emails (email verification, password reset) and respond to support requests
- Protect the Service against fraud, misuse, and security threats, and comply with applicable legal obligations
3.2 Secondary Purposes (require your consent)
The following purposes are not necessary for the service relationship and require your consent. You may refuse or revoke consent for them at any time through the means indicated in Section 9, without affecting your access to the Service:
- Sending you promotional communications, product news, and feature updates by email
Refusing these secondary purposes will never be grounds for denying you the Service. If you create an account, we treat your consent to these communications as given where this notice has been made available to you and you do not object. Every email carries a one-click unsubscribe link, which is a sufficient means of objecting at any time.
4. AI Processing and Automated Decisions
Because artificial intelligence is the core of the Service, and in accordance with the LFPDPPP provisions on automated processing, we provide the following detailed information:
4.1 How AI Processing Works
When you create content, it is sent through a multi-step AI pipeline: your text (or transcribed audio) is processed by OpenAI language models, which rewrite and structure it, identify key concepts, detect tasks, and classify your note. For meetings, an AI model generates structured meeting notes from the transcript. Images are analyzed by an OpenAI vision model to generate a description and extract visible text.
Separately, your content is converted into vector embeddings using OpenAI embedding models, stored in our database and search index, and used to find semantically similar notes, build concept connections, and answer questions about your own knowledge base.
Voice notes are transcribed with OpenAI Whisper. Meeting audio is transcribed by Modulate AI with generic speaker separation. In both cases the audio is processed for transcription only and is not retained by us.
4.2 Implications of Automated Processing
Mindle's automated processing organizes your content; it does not make decisions that produce legal effects on you or significantly affect your rights. Concept extraction, task detection, and classification are navigation tools — they do not restrict features, set prices, or evaluate you as a person.
You can always edit, override, or delete any AI-generated content. Concepts can be renamed, merged, or removed; tasks can be modified or dismissed. You remain in full control of how your knowledge is organized.
4.3 Your Data at Our AI Providers
We use OpenAI's API tier, not consumer products like ChatGPT. Under OpenAI's API data usage policy, content submitted through the API is not used to train or improve its models unless the customer opts in — and we have not opted in. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted. OpenAI processes data as our processor under a Data Processing Addendum.
Meeting audio is processed by Modulate AI solely to produce the transcript returned to you. Our AI providers are contractually restricted from using your data for their own purposes.
4.4 Right to Object to Automated Processing
Under the LFPDPPP you have the right to object to fully automated processing of your personal data that produces unwanted legal effects or significantly affects you. Mindle does not carry out processing of that nature; nevertheless, you may exercise your right of opposition to AI processing of your content following the procedure in Section 9. Because AI processing is the essential functionality of the Service, exercising this right may significantly limit the usefulness of the Service.
5. Processors and Data Transfers
To operate the Service we rely on service providers that process your personal data on our behalf and under our instructions (data processors / "encargados"). These communications are remissions ("remisiones"), not transfers, under the LFPDPPP and its regulations. Each provider is contractually prohibited from using your data for its own purposes.
5.1 Service Providers (Processors)
The following providers process your data on our behalf:
OpenAI (USA)
Data: text of notes and meetings, voice note audio (transcription), images, search queries
Purpose: AI text processing, transcription (Whisper), image description/OCR, and embeddings. Not used for model training; abuse-monitoring retention of up to 30 days.
Modulate AI (USA)
Data: meeting audio
Purpose: speech-to-text transcription of meetings with generic speaker separation. Audio is not retained by us after transcription.
Google Firebase (USA)
Data: email, password (if email sign-in), name, sign-in method
Purpose: authentication — account creation, sign-in, email verification, password reset.
Meta Platforms — WhatsApp Business (USA)
Data: your phone number and whatever you send us on WhatsApp (text, voice notes, images, and documents), plus message metadata
Purpose: receiving in Mindle what you send us on WhatsApp, and replying to you. This applies only if you connect your number; it is an optional feature you can disconnect at any time from Settings. Retention: for a number that is NOT connected to a Mindle account we do not store the message content. We record only the message type and, if the text contains something shaped like a connection code, that code. That is the minimum needed to connect your account and to throttle automated attempts.
Stripe (USA)
Data: name, email, card details (collected directly by Stripe), billing history
Purpose: subscription payments and billing management.
Sentry (USA)
Data: error reports with IP address, browser information, and internal user ID (content and email excluded)
Purpose: error monitoring to detect and fix failures.
Resend (USA)
Data: email address and the content of transactional and newsletter emails
Purpose: delivery of email verification, password reset and product-update messages.
Cloudflare (USA, global network)
Data: IP address and request metadata of all traffic
Purpose: content delivery, TLS encryption, and protection against attacks.
Vercel (USA)
Data: IP address, HTTP headers, request metadata
Purpose: hosting of the web application (frontend).
IONOS Inc. (United States)
Data: all stored data (account, content, AI-derived data, database, backups)
Purpose: hosting of our backend, API, PostgreSQL database, and image storage.
Notion (USA)
Data: name, email, subscription status, and aggregate usage indicators (number of notes, number of notes received through WhatsApp, date of last activity and last search, and WhatsApp link status)
Purpose: mini-CRM for manual follow-up of subscribers and users.
Google Analytics (USA)
Data: pages visited on our public website, referring source, approximate location derived from a truncated IP address, browser and device type, and a randomly generated identifier if you accept measurement cookies
Purpose: aggregate measurement of public website traffic. Loaded with Google Consent Mode v2 denied by default, without advertising features, and never active inside the logged-in app.
5.2 Transfers to Third Parties
We do not currently transfer your personal data to any third party that would process it for its own purposes. If a transfer requiring your consent ever becomes necessary, we will update this Notice and request your consent through the Service before carrying it out, except in the cases where the LFPDPPP permits transfers without consent (for example, legal requirements or protection of your vital interests).
5.3 No Data Selling
We do not sell, trade, or assign your personal data to third parties for their own purposes. We do not participate in data broker networks and do not display third-party advertising in the Service.
6. International Data Processing
Your personal data is processed outside Mexico by the providers listed in Section 5, specifically:
- United States: OpenAI and Modulate (AI processing and transcription), Google Firebase (authentication), Stripe (payments), Sentry (error monitoring), Resend (email), Notion (mini-CRM), Vercel and Cloudflare (hosting and traffic), Google Analytics (public website measurement, only with your consent)
- United States: our backend servers, PostgreSQL database, image storage, and backups, hosted with IONOS Inc.
These remissions to processors are necessary to provide the Service. All providers process your data under contractual data protection obligations and industry-standard security measures, and assume obligations equivalent to those of the Controller.
By using the Service and accepting this Privacy Notice, you acknowledge that your personal data will be processed in the countries indicated above for the purposes described herein.
If in the future we carry out transfers that require your consent under the LFPDPPP, we will request it expressly before doing so.
7. Data Retention and Deletion
We retain your personal data only for the time necessary to fulfill the purposes for which it was collected. Retention periods by data type:
- Account data (name, email, settings): retained while your account is active; deleted within 30 days of a verified account-deletion request
- User content (notes, transcripts, meetings, images) and AI-derived data: retained until you delete it or delete your account. Deleted content immediately stops being accessible in your account and residual copies are permanently purged from our systems within 30 days
- Audio recordings: not retained — discarded immediately after transcription
- Billing records: retained as required by accounting and tax obligations
- Newsletter subscriber data: retained while you remain subscribed. If you unsubscribe, we keep your email and the date you left so we do not write to you again; backups are kept 7 days before being overwritten
7.1 Account Deletion
You may request deletion of your account at any time by writing to a@mindle.mx from the email address associated with your account. Upon verifying your request, we will permanently delete your account and all associated data within 30 calendar days, including notes, transcripts, meetings, images, AI-derived data, concepts, tasks, embeddings, and search index entries.
Some data may be retained beyond this period only where required by applicable law (for example, billing records for tax purposes), in which case it will be blocked, isolated, and deleted once the legal requirement expires.
7.2 Backups
Our database and image storage are backed up nightly for disaster recovery. Backups may contain your data and are kept for 7 days before being overwritten, so deleted data leaves backups within at most 7 days after being purged from our primary systems.
8. ARCO Rights
Under the LFPDPPP, you have the right to Access, Rectify, Cancel, and Oppose the processing of your personal data (ARCO rights), as well as to revoke your consent and to limit the use or disclosure of your data:
8.1 Right of Access
You have the right to know what personal data we hold about you, how we use it, the conditions of use, and the remissions to processors we make. You may request a copy of your personal data in a readable and commonly used format.
8.2 Right of Rectification
You have the right to request correction of your personal data when it is inaccurate, incomplete, or outdated. You can edit your content directly in the Service, or contact us to correct account data.
8.3 Right of Cancellation
You have the right to request the deletion of your personal data from our records and databases when you consider that it is not being processed in accordance with the principles and duties of the LFPDPPP, when it is no longer necessary for the purposes for which it was collected, or when the retention period has expired. Cancellation proceeds after a blocking period during which data is retained solely for liability purposes arising from the processing.
8.4 Right of Opposition
You have the right to oppose the processing of your personal data for specific purposes, including AI processing of your content and any fully automated processing that could significantly affect you. If you oppose AI processing, your content will be stored but not processed by our AI systems, which will substantially limit the functionality available to you.
8.5 Revocation of Consent
You may revoke the consent you have given for the processing of your personal data at any time, without retroactive effects. To revoke your consent, follow the procedure in Section 9.
8.6 Limitation of Use or Disclosure
You have the right to request limitation of the use or disclosure of your personal data. You may ask us to stop sending you promotional communications at any time. For other limitations, contact us through the procedure in Section 9.
9. Mechanisms and Procedures for Exercising Rights
To exercise your ARCO rights, revoke consent, or limit the use of your personal data, send a request to a@mindle.mx containing:
- Your full name and the email address associated with your account
- A clear and precise description of the right you wish to exercise and the personal data involved
- Any documentation that helps locate your personal data
- A means to communicate our response to you (by default, your registered email)
Response Timelines
We will communicate our determination within a maximum of 20 business days following receipt of your request. This period may be extended once for an equal period when justified, with prior notice to you.
If the request is granted, it will be made effective within 15 business days following the date on which we communicate the response, extendable once for an equal period when the circumstances justify it. Exercising ARCO rights is free of charge; only justified shipping or reproduction costs may apply.
Identity Verification
To protect your privacy and security, we will verify your identity before processing any request, by confirming the information associated with your Mindle account (registered email address). If we cannot verify your identity, we reserve the right not to process the request, notifying you of the reasons.
10. Security Measures
In accordance with the LFPDPPP, we implement administrative, technical, and physical security measures to protect your personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing:
Technical Measures
- All data transmitted between your device and our servers is encrypted using HTTPS/TLS, with Cloudflare providing an additional protection layer against attacks
- Login credentials are managed by Firebase Authentication (Google); we never store passwords on our servers
- Every API request is authenticated by verifying your identity token; unauthenticated requests are rejected
- All data is isolated per account — your content is only ever returned to your authenticated session
- Database access is restricted to our application servers, with no direct public access
- Location and camera metadata (EXIF) is stripped from every image you upload before storage
Organizational Measures
- Access to production systems and user data is limited to the two founders
- We conduct regular security reviews of our codebase and infrastructure
- Service providers are vetted for their security practices before engagement
Despite these measures, no method of electronic transmission or storage is 100% secure. If we detect a security breach that materially affects your personal data, we will notify you and the competent authorities as required by law.
If you discover a security vulnerability in the Service, please report it immediately to a@mindle.mx.
11. Age Restriction
The Service is intended exclusively for persons 18 years of age or older. We do not knowingly collect, store, or process personal data of persons under 18.
We do not direct the Service at children or adolescents. Our marketing, features, and use cases are designed for adults — knowledge workers, professionals, university students, researchers, and entrepreneurs.
Under the LFPDPPP, processing minors' data requires parental or guardian consent — consent we do not request because the Service is not directed at minors. If we become aware that we have inadvertently collected personal data from a person under 18, we will immediately delete that data and terminate the associated account.
If you are a parent or guardian and believe a minor has provided personal data to Mindle, please contact us at a@mindle.mx and we will address the situation immediately.
13. Changes to This Privacy Notice
We reserve the right to modify or update this Privacy Notice at any time to reflect legislative changes, internal policies, or new Service requirements.
For significant changes — new categories of data, new processors, or changes in how AI processes your content — we will provide prominent notice through one or more of: an in-app notification at your next login, an email to your registered address, or a banner on our website.
We encourage you to review this Notice periodically. The "Last updated" date at the top indicates the most recent changes. Continued use of the Service after changes are published constitutes acceptance of the updated Notice.
14. Contact Information and Competent Authority
If you have questions, concerns, or requests regarding this Privacy Notice or the processing of your personal data, you may contact us at:
Email: a@mindle.mx
We commit to responding to all privacy-related inquiries within 10 business days. For formal ARCO requests, we will respond within the timelines established in Section 9.
Competent Authority
If you consider that your right to personal data protection has been violated, or you are not satisfied with our response, you may file a complaint with the Secretaría Anticorrupción y Buen Gobierno, the authority competent in matters of personal data protection held by private parties in Mexico under the 2025 LFPDPPP (successor to INAI in this function).
For more information about your rights, visit the website of the Secretaría Anticorrupción y Buen Gobierno.
15. Consent
By creating an account on Mindle and using the Service, you consent to the processing of your personal data in accordance with the purposes described in this Privacy Notice, in a free, specific, and informed manner.
For the secondary purposes described in Section 3.2 (promotional communications), your consent is collected separately and expressly — through the corresponding opt-in — and can be withdrawn at any time.
You may revoke your consent at any time, without retroactive effects, following the procedure in Section 9. Revoking consent for the purposes essential to the Service may make it impossible for us to continue providing it.
This Notice is available at all times at mindle.mx. A simplified version is presented at the points where we collect your data, indicating where to consult this comprehensive Notice.