Privacy Policy

Last updated: August 25, 2026

1. Introduction

Mindle ("we," "us," or "our") operates the Mindle application and website (collectively, the "Service"), a personal knowledge management platform that helps users capture, organize, and interact with their knowledge using artificial intelligence. Our Service allows you to create text notes, record voice notes, record or transcribe meetings, attach images to your notes, and organize everything through AI-extracted concepts, semantic search, and a visual knowledge graph.

This Privacy Policy explains in detail how we collect, use, store, share, and protect your personal information when you use our Service. We believe in transparency: you should always know what data we have, why we have it, and what we do with it.

This policy applies to all users of the Service, regardless of location. It is written with the requirements of U.S. state privacy laws (including the California Consumer Privacy Act as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Texas, and other states) and the FTC Act in mind. Whether or not a given statute technically applies to an operation of our size, we honor the rights described in Section 8 for all users.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices described here, please do not use the Service. For users in Mexico, please refer to our separate Aviso de Privacidad, which addresses your rights under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP).

Data Controller: Mindle, operated by Carlos A Galvez Diaz Barriga and Gabriel Gutiérrez Guerra — a@mindle.mx

2. Information We Collect

We collect information that you provide directly, information generated through your use of the Service, and information created by our AI systems. Below is a detailed breakdown of each category.

2.1 Account Information

When you create an account, we collect your full name and email address. Authentication is handled by Firebase Authentication, a service operated by Google: if you sign up with email and password, your password is stored and secured by Firebase — we never receive or store your password on our own servers. We store your name, email address, the unique Firebase identifier assigned to your account, and the sign-in method you used.

If you choose to register using your Google account, we receive your name and email address from Google through Firebase. We do not receive your Google password, and we do not access any other Google services or data on your behalf. We require email verification before you can use the Service.

2.2 User Content

The core of Mindle is the content you create and capture. This includes text notes you write, voice notes you record, meetings you record or paste transcripts of, and images you attach to notes or meetings. Each piece of content is stored with metadata including its creation date, last modification date, word count, language, and audio duration where applicable.

Audio is not stored. When you record a voice note or a meeting, the audio is sent to a transcription service, converted to text, and the audio itself is then discarded — we keep only the resulting transcript and its duration. Meeting transcripts include speaker labels (for example "Speaker 1", "Speaker 2"); we do not create or store voiceprints or any biometric identifier. Important: when you record a meeting, Mindle can capture your microphone and, on supported browsers, your computer's system audio — meaning other participants' voices may be recorded and transcribed. You are responsible for informing all participants and obtaining any consent required by the laws that apply to your meeting before recording. Several U.S. states require the consent of all parties to record a conversation.

Images you attach are re-encoded (location and camera metadata is stripped) and stored on our servers. Each image is analyzed by an AI vision model to generate a description and extract any text visible in the image (OCR), so it can be found through search. Be aware that if you photograph documents, the text in them becomes part of your searchable data. You maintain full ownership of all content you create in Mindle; we claim no intellectual property rights over it.

When a note contains a link on its own line, our servers fetch that page to build a preview card, reading its title, description and preview image, and we store a copy of that image so it loads from our servers rather than the linked site. The fetch is made by us, not by your browser, so the site you linked to does not see your IP address or that you opened the note. Only the link itself leaves our systems; the rest of the note never does. Previews are cached and shared across accounts, so a link someone else already saved may load without a new request.

2.3 AI-Generated Data

When your content is processed by our AI systems, several types of derived data are created and stored: rewritten and structured versions of your text, extracted concepts (key topics identified in your content), detected tasks, content classifications, AI-generated meeting notes, and on-demand artifacts you request (summaries, bullet points, translations, mind maps).

We also generate vector embeddings — mathematical representations of the meaning of your content — which power semantic search, the "ask" feature, and automatic concept connections. A copy of your content is indexed in our search system for this purpose. We additionally store a personal vocabulary of corrections you teach the Service (for example, how to spell names or technical terms), which is used to improve your transcriptions.

2.4 Technical and Usage Data

To operate the Service we use a small number of cookies and browser storage (described fully in Section 12), and we store your preferences (language, auto-processing settings, onboarding progress) on our servers. Your Firebase login session is kept in your browser by the Firebase SDK.

We meter your usage of the Service — counts of notes, meetings, transcription seconds, AI actions, and images — to enforce plan limits and billing. Our error-monitoring service (Sentry) receives technical data when something goes wrong, including your IP address, browser information, and your internal user ID; we configure it to exclude the content of your notes and your email from error reports. Our infrastructure provider Cloudflare processes your IP address to route and protect traffic.

2.5 Billing Information

If you purchase a subscription, payment is processed by Stripe. Your card details are collected and stored by Stripe directly — they never touch our servers. We store your Stripe customer and subscription identifiers, your plan, subscription status, and billing period dates, and we share your name and email with Stripe to create your customer record.

2.6 Newsletter Information

We collect your email address and, optionally, your full name in two ways: when you subscribe to the newsletter from our site, and when you create a Mindle account. In the second case you are subscribed to product updates by default, and you can unsubscribe from the link in any of those emails without affecting your account or your access to the Service. Both paths are synced to a private Notion workspace, which we use as a mini-CRM for manual follow-up. If you have an account, that workspace also receives aggregate indicators of your use of the Service: how many notes you have created, how many of them arrived through WhatsApp, the date of your last activity and of your last search, and whether you have WhatsApp linked. It never receives the content of your notes, the text of your searches, or your messages.

2.7 Information We Do Not Collect

We want to be clear about what we do not collect: we do not collect location data or GPS coordinates; we do not collect advertising identifiers; we do not track your browsing on other websites; we do not use advertising tools, and our only measurement is aggregate page analytics on our public website, which stays off unless you accept it; we do not sell data to anyone; and we do not create biometric identifiers — meeting transcripts label speakers generically and no voiceprint is generated or stored. We do not ask for or intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation — though as a free-form note-taking tool, any information you choose to write, record, or photograph becomes part of your stored content.

3. How We Use Your Information

We use your information only for the purposes described below. We do not use your data for advertising, profiling for third parties, or any purpose unrelated to providing and improving the Service.

Primary Purposes (necessary to provide the Service):

  • Account Management: Creating your account, authenticating your identity through Firebase, and managing your session so you can access the Service securely
  • Content Storage and Display: Storing the notes, transcripts, meetings, and images you create and displaying them back to you in an organized interface
  • AI Processing: Sending your content to AI providers to generate rewritten text, extract concepts, detect tasks, classify content, describe images, and create semantic embeddings — this is the core functionality of Mindle
  • Transcription: Converting your voice notes and meeting recordings to text using third-party speech-to-text services, after which the audio is discarded
  • Semantic Search and Answers: Using embeddings and a search index of your content so you can search by meaning and ask questions answered from your own notes
  • Billing and Plan Limits: Processing subscription payments through Stripe and metering usage to enforce the limits of your plan
  • Organization: Organizing your content chronologically, by concept, and in your knowledge graph

Secondary Purposes:

  • Service Improvement and Error Monitoring: Diagnosing errors through Sentry and analyzing aggregate usage patterns to fix bugs and improve performance. We do not review individual user content for this purpose
  • Communications: Sending you essential service emails (email verification, password resets) and product updates. If you have an account, you receive product updates by default. You can unsubscribe from the link in any of those emails at any time
  • Security and Fraud Prevention: Monitoring for unauthorized access, abuse, or security threats to protect your account and the Service
  • Legal Compliance: Responding to valid legal requests and complying with applicable laws and regulations

4. AI Processing and Automated Decisions

Artificial intelligence is central to how Mindle works. We want you to fully understand how your data is processed by AI, what happens during that processing, and what rights you have regarding automated decisions.

4.1 How AI Processing Works

When you create content, it is sent through a multi-step AI pipeline. Your text (or transcribed audio) is sent to OpenAI language models, which rewrite and structure your content, identify key concepts, detect actionable tasks, and classify your note. For meetings, an AI model also generates structured meeting notes from the transcript. Images are sent to an OpenAI vision model to generate a description and extract visible text.

Separately, your content is converted into vector embeddings using OpenAI's embedding models. These embeddings are stored in our database and search index and are used to find semantically similar notes, build concept connections, and answer questions you ask about your own knowledge base.

Voice notes are transcribed by OpenAI's Whisper model. Meeting audio is transcribed by Modulate AI's speech-to-text service, which separates the transcript by speaker ("Speaker 1", "Speaker 2"). In both cases the audio is processed for transcription and not retained by us.

4.2 Your Data at Our AI Providers

We use OpenAI's API tier, not consumer products like ChatGPT. Under OpenAI's API data usage policy, content submitted through the API is not used to train, improve, or develop OpenAI's models unless the customer explicitly opts in — and we have not opted in. Your notes, transcripts, images, and personal knowledge are not used as training data. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted. We have a Data Processing Addendum in place with OpenAI, under which it acts as a processor on our instructions.

Meeting audio is processed by Modulate AI solely to produce the transcript we return to you. Our AI providers process your data on our behalf and are contractually restricted from using it for their own purposes.

4.3 Automated Decision-Making

Mindle uses automated processing to organize your content, but these automations do not make decisions that produce legal effects or similarly significant impacts on you. Concept extraction, task detection, and content classification are tools to help you navigate your knowledge — they do not restrict your access to features, determine pricing, or affect your rights in any way.

You always have the ability to edit, override, or delete any AI-generated content. Concepts can be renamed, merged, or removed. Tasks can be modified or dismissed. You remain in full control of how your knowledge is organized.

5. Third-Party Service Providers

We share your data only with the service providers necessary to operate the Service. Each provider is identified below with a description of what data it processes, why, and where it is located. All of them act on our instructions and are prohibited from using your data for their own purposes.

5.1 OpenAI (USA)

San Francisco, California, USA

Data processed: text of your notes and meetings, voice note audio (transcription), images, search and ask queries

Purpose: AI text processing, transcription (Whisper), image description and OCR, and semantic embeddings

Processes data as our processor under a Data Processing Addendum. Not used for model training. Inputs may be retained up to 30 days for abuse monitoring, then deleted.

5.2 Modulate AI (USA)

USA

Data processed: meeting audio recordings

Purpose: speech-to-text transcription of meetings with speaker separation

Receives meeting audio solely to produce the transcript. We do not retain the audio after transcription.

5.3 Google Firebase (USA)

Google LLC, Mountain View, California, USA

Data processed: email address, password (if you use email sign-in), name, sign-in method

Purpose: authentication — account creation, sign-in, email verification, and password reset

Firebase Authentication stores and secures your login credentials. We never see your password.

5.4 Stripe (USA)

San Francisco, California, USA

Data processed: name, email, payment card details (collected by Stripe directly), subscription and billing history

Purpose: subscription payments, invoicing, and billing management

Stripe is a certified payment processor; your card details are held by Stripe and never reach our servers.

5.5 Sentry (USA)

Functional Software, Inc., San Francisco, California, USA (US data region)

Data processed: error reports including IP address, browser/device information, and internal user ID

Purpose: error monitoring so we can detect and fix failures in the Service

We configure Sentry to exclude note content, request bodies, and your email from error reports.

5.6 Resend (USA)

USA

Data processed: your email address and the content of transactional and newsletter emails

Purpose: delivery of email verification, password reset and product-update messages

Used only for email delivery.

5.7 Cloudflare (USA, global network)

San Francisco, California, USA — global edge network

Data processed: IP address and request metadata for all traffic to our servers

Purpose: content delivery, TLS encryption, and protection against attacks (WAF/DDoS)

Sits in front of our servers as a security and delivery layer; does not access stored content.

5.8 Vercel (USA)

San Francisco, California, USA

Data processed: IP address, HTTP request headers, and request metadata

Purpose: hosting and serving the Mindle web application (frontend)

Does not access your account data, notes, or content — only the technical data needed to deliver pages to your browser.

5.9 Backend Hosting Provider

IONOS Inc., data center located in the United States

Data processed: all stored data (account information, content, AI-derived data, database records, backups)

Purpose: hosting our backend application, API, PostgreSQL database, and image storage

Provides the infrastructure our application runs on; does not access or process your data for its own purposes.

5.10 Notion (USA)

Notion Labs, Inc., San Francisco, California, USA

Data processed: name, email, subscription status, and aggregate usage indicators (number of notes, number of notes received through WhatsApp, date of last activity and last search, and WhatsApp link status)

Purpose: mini-CRM for manual follow-up of subscribers and users

Receives contact details and aggregate usage indicators; never receives the content of your notes, the text of your searches, or your messages.

5.11 Google Analytics (USA)

Google LLC, Mountain View, California, USA (Google Ireland Limited for visitors in the EEA)

Data processed: pages visited on our public website, referring source, approximate location derived from a truncated IP address, browser and device type, and a randomly generated identifier if you accept measurement cookies

Purpose: aggregate measurement of which public pages people find and which ones bring them to sign up

Loaded with Google Consent Mode v2 denied by default. GA4 does not record full IP addresses, and we do not enable Google Signals, advertising features, or data sharing for advertising. It never runs on pages inside the logged-in app, so your notes, meetings and usage of the product are outside its reach.

5.12 No Data Selling or Sharing for Advertising

We do not sell your personal information. We do not share your personal information with third parties for their own marketing or advertising purposes. We do not participate in data broker networks. We do not display third-party advertisements in the Service. The only third parties who process your data are the service providers listed above, and only for the specific purposes described.

6. International Data Transfers

Depending on your location, your data may be transferred to and processed in countries other than your own. Our infrastructure spans multiple locations:

  • AI processing, authentication, payments, email, error monitoring, and website measurement: performed by the U.S.-based providers listed in Section 5
  • Backend servers, database, and backups: hosted with IONOS Inc. in the United States
  • Frontend hosting and traffic protection: served through Vercel and Cloudflare's global networks, with primary infrastructure in the United States

These transfers are necessary to provide the Service. All providers maintain industry-standard data protection measures and process data under contractual restrictions. If you are located outside the United States, by using the Service you acknowledge that your data will be transferred to and processed in the United States and in the country where our backend is hosted.

For users in Mexico, please refer to our Aviso de Privacidad for specific information about international data processing under the LFPDPPP.

7. Data Retention and Deletion

We retain your data only for as long as necessary to provide the Service and fulfill the purposes described in this policy. Here is how long we keep each type of data:

  • Account data (name, email, settings): retained for as long as your account is active, and deleted within 30 days of a verified account-deletion request
  • User content (notes, transcripts, meetings, images) and AI-derived data: retained until you delete it or delete your account. When you delete content in the app it immediately stops being accessible in your account; residual copies are permanently purged from our systems within 30 days
  • Audio recordings: not retained — audio is discarded immediately after transcription
  • Billing records: subscription and payment records are retained as required for accounting and tax obligations
  • Newsletter subscriber data: retained while you remain subscribed. If you unsubscribe, we keep your email and the date you left so we do not write to you again
  • Database and image backups: encrypted nightly backups are kept for 7 days and then overwritten, so deleted data leaves backups within 7 days of being purged

7.1 Account Deletion

You may request deletion of your account at any time by contacting us at a@mindle.mx from the email address associated with your account. Upon verifying your request, we will permanently delete your account and all associated data within 30 calendar days. This includes your notes, transcripts, meetings, images, AI-derived data, concepts, tasks, embeddings, and search index entries.

Some data may be retained beyond this period only where required by applicable law (for example, billing records needed for tax compliance or records relevant to a legal dispute). In such cases, the retained data will be isolated and protected, and deleted as soon as the legal requirement expires.

7.2 Backups

Our database and image storage are backed up nightly for disaster recovery. Backup copies may contain your data and are retained for 7 days before being overwritten. If you delete content or your account, your data will persist in backups for at most 7 days after the deletion is processed in our primary systems.

8. Your Privacy Rights

Depending on where you live, you may have specific rights regarding your personal information. Some state privacy laws apply only to businesses above certain size thresholds; regardless of whether a given law technically applies to us, we honor the rights below for all users.

8.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to Know: You have the right to request that we disclose what personal information we have collected about you, including the categories of information, the sources, the business purposes for collecting it, and the categories of third parties with whom we shared it. You may also request the specific pieces of personal information we hold about you.
  • Right to Delete: You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions (for example, if we need the data to complete a transaction, detect security incidents, or comply with a legal obligation).
  • Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
  • Right to Opt Out: You have the right to opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of — but we honor the right nonetheless.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. We will not deny you the Service, charge you different prices, provide a different quality of service, or retaliate in any way.

8.2 Other U.S. State Residents

If you reside in Virginia, Colorado, Connecticut, Texas, or another state with a comprehensive privacy law, you generally have similar rights to those described above, including the right to access, correct, and delete your data, to obtain a portable copy, and to opt out of data sales (which we do not engage in).

Some states also provide the right to appeal our decision regarding a privacy request. If we deny your request and your state provides an appeal right, we will inform you of how to submit an appeal.

8.3 How to Exercise Your Rights

To exercise any of the rights described above, contact us at a@mindle.mx. Please include your full name, the email address associated with your account, a description of the right you wish to exercise, and any details that help us identify and respond to your request.

We will verify your identity before processing your request by confirming information associated with your account. We will respond to your request within 45 calendar days of receiving it. If we need additional time (up to an additional 45 days), we will notify you of the extension and the reason for it.

You may also designate an authorized agent to submit a request on your behalf. The agent must provide written authorization from you, and we may still require you to verify your identity directly.

9. Do Not Sell or Share My Personal Information

We do not sell your personal information to anyone. We do not share your personal information with third parties for purposes of cross-context behavioral advertising. This has been our practice since the founding of Mindle, and we have no plans to change it.

Under the CCPA, "sale" includes any exchange of personal information for monetary or other valuable consideration. We confirm that no such exchange occurs with any third party. The only data sharing we engage in is with the service providers identified in Section 5, and solely for the purposes of operating the Service.

Because we do not sell or share personal information, Global Privacy Control (GPC) signals do not require any action on our part — there is no sale or sharing to opt out of.

10. Security Measures

We take the security of your personal information seriously. Protecting your knowledge is fundamental to the trust you place in Mindle. We implement the following technical and organizational measures:

Technical Measures

  • All data transmitted between your device and our servers is encrypted using HTTPS/TLS, with Cloudflare providing an additional protection layer against attacks
  • Login credentials are managed by Firebase Authentication (Google); we never store passwords on our servers
  • Every API request is authenticated by verifying your identity token; unauthenticated requests are rejected
  • All data is isolated per account — your content is only ever returned to your authenticated session
  • Database access is restricted to our application servers, with no direct public access
  • Location and camera metadata (EXIF) is stripped from every image you upload before storage

Organizational Measures

  • Access to production systems and user data is limited to the two founders
  • We conduct regular security reviews of our codebase and infrastructure
  • Third-party service providers are vetted for their security practices before engagement

Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data. If we become aware of a security breach that affects your personal information, we will notify you and any applicable regulatory authority as required by law.

If you discover a security vulnerability in the Service, please report it to us immediately at a@mindle.mx. We take all reports seriously and will investigate promptly.

11. Age Restriction

The Service is intended exclusively for users who are 18 years of age or older. We do not knowingly collect, store, or process personal information from individuals under the age of 18.

We do not target the Service at children or adolescents. Our marketing, features, and use cases are designed for adults — knowledge workers, professionals, students in higher education, researchers, and entrepreneurs.

If we become aware that we have inadvertently collected personal information from a user under 18, we will take immediate steps to delete that data from our systems and terminate the associated account. If you are a parent, guardian, or other adult who believes a minor has provided personal information to us, please contact us at a@mindle.mx and we will promptly address the situation.

12. Cookies, Local Storage, and Tracking Technologies

We use a small number of first-party cookies and browser storage entries. All of them are functional except one optional group used to measure which pages people find, which is off unless you accept it. Here is a complete accounting:

What We Use

  • mindle_session (cookie): a simple flag indicating you have an active session, used to route you correctly between the marketing site and the app. It contains no personal data
  • NEXT_LOCALE (cookie): remembers your language preference (English or Spanish)
  • mindle_create_mode (cookie): remembers whether you last used recording or writing mode when creating content
  • Browser storage (localStorage/IndexedDB): the Firebase SDK keeps your login session in your browser so you stay signed in, and we store interface preferences (auto-processing setting, onboarding and tutorial progress, graph layout) locally on your device
  • mindle_consent (cookie): records whether you accepted or declined measurement cookies, so we do not ask again. Expires after six months
  • _ga, _ga_8JGWEN3977 and _ga_JSL1JX2BSH (Google Analytics cookies): set only if you accept measurement, on our public website. They hold a randomly generated identifier used to count returning visits, expire after two years, and are never set inside the logged-in app

What We Do Not Use

We do not use advertising cookies, tracking pixels, web beacons, or fingerprinting techniques. We do not run advertising, we do not track you across other websites, and we do not embed social media tracking widgets. For measurement we use Google Analytics 4 on our public website only, loaded with Google Consent Mode v2 set to denied by default: until you accept, it stores nothing on your device and receives no identifier. Advertising signals stay denied permanently. Our other monitoring tool is Sentry, which reports errors (not your browsing behavior) as described in Section 5.5.

You can change your mind at any time through the Cookies link in the footer of our website, which reopens the choice. You can also delete or block cookies from your browser settings; blocking the functional cookies may prevent the Service from working correctly. Google Analytics never runs inside the logged-in app.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the "Last updated" date at the top of this policy.

For significant changes — such as new categories of data collection, new third-party processors, or changes to how AI processes your content — we will provide prominent notice through one or more of the following methods: an in-app notification the next time you log in, an email to the address associated with your account, or a banner on our website.

We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes your acknowledgment of the updated policy. If you disagree with any changes, you may delete your account at any time.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, we want to hear from you.

Email: a@mindle.mx

We aim to respond to all privacy-related inquiries within 10 business days. For formal rights requests (access, deletion, correction), we will respond within the timeframe required by applicable law (typically 45 calendar days).

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. For California residents, you may contact the California Privacy Protection Agency (CPPA) or the California Attorney General's office. For residents of other U.S. states, you may contact your state's attorney general.

For users in Mexico, please refer to our Aviso de Privacidad for contact information specific to Mexican data protection law.