MindDeck is committed to protecting your mental wellness privacy while providing meaningful AI-enhanced support. This policy explains how we handle your data in our wellness companion app.
1. Information We Collect
All journal entries, survey responses, custom toolkits, wellness theories, mood tracking, and app preferences are stored exclusively on your device using secure local storage.
Subscription receipts are validated through Apple App Store or Google Play Store to confirm premium feature access. This verification happens client-side with no purchase data stored by MindDeck.
When you use premium AI features, necessary prompts are securely sent through our backend proxy (hosted on Supabase) to our AI provider (xAI) for processing. Your data passes through Supabase infrastructure in transit but is not stored there. No AI conversation history or personal context is retained beyond the immediate response.
Anonymous usage patterns and feature engagement are only collected if you explicitly consent to participate in wellness research. All research data is de-identified and aggregated.
2. How We Use Information
Core App Functionality
- Personalized Recommendations: Your local wellness data helps suggest relevant tools and strategies
- Progress Tracking: Journal entries and survey responses create personalized growth insights
- Premium Feature Access: Purchase verification ensures you can access subscribed AI tools
- Crisis Resources: Emergency contacts are always available regardless of subscription status
External Services (Premium Only)
- AI Tool Suggestions: Analysis of your wellness patterns helps our AI suggest more effective personalized strategies
- Journal Insights: AI analyzes your entries to identify patterns and offer motivational support
- Personalized Quotes: Your current mood and goals help generate meaningful daily affirmations
- Data Export: Premium users can export complete wellness histories for personal backup
3. Information Sharing & Third Parties
We Do NOT Share Your Data With:
- Marketing companies or data brokers
- Social media platforms
- Any advertising networks
- Health insurance providers
- Government agencies without legal requirement
Third-Party Services We Work With:
- xAI (Grok): AI service provider for premium features - receives only necessary prompts via our Supabase backend proxy, no personal data
- Supabase: Backend proxy for secure API routing - data passes through in transit but is not stored
- Firebase: Optional analytics if you consent - completely anonymous usage tracking only. Crash reports are sanitized to remove sensitive data before transmission
- App Store Platforms: Apple App Store and Google Play Store handle purchase processing
- Your Device: Local sharing services (mail, messaging, cloud storage) when you choose to export data
4. Data Security & Controls
Your Control Over Data:
- Local Device Storage: All personal data stays on your device - delete the app to remove everything
- Optional Analytics: Research participation is completely opt-in with specific consent
- Data Export: Premium users can export all wellness data in standard formats (JSON, CSV, PDF)
- Data Portability: Export your complete wellness history for use with other health apps
- Right to Delete: Uninstalling MindDeck permanently removes all your data
Security Measures:
- Local-First Architecture: Sensitive data never leaves your device except for AI processing on premium features
- AES-256 Encryption: All sensitive wellness data — including survey responses, mood history, and battle entries — is encrypted at rest using AES-256 encryption
- Secure Key Storage: Encryption keys are stored securely using platform-specific secure storage (iOS Keychain/Android Keystore)
- Automatic Data Migration: Existing user data is automatically migrated to encrypted storage on app updates
- Zero-Knowledge Architecture: Encryption happens locally on your device - we never have access to your encryption keys
- Encrypted Communication: All external communications use HTTPS encryption
- API Rate Limiting: Premium features are rate-limited to prevent abuse and resource overuse
- Secure Purchase Verification: Receipt validation happens through official app store systems
5. Children's Privacy
MindDeck is designed for adult wellness and self-improvement. While we don't collect information to determine age, the app is intended for users 18 years and older. Mental health is serious, and younger users should consult appropriate professionals or parental guidance.
6. Changes to This Policy
We may update this privacy policy occasionally to reflect changes in our practices or for legal requirements. Users will be notified of significant changes through the app. Continued use after changes indicates acceptance of the updated policy.
Contact Us
Questions about this privacy policy? We're here to help:
Your privacy is our priority. MindDeck is built to protect you.