1. Overview & Our Commitment
MindsKeep is built on a foundational belief: your private thoughts should remain private. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your data.
Our approach is simple by design: we encrypt your journal content on your device before it reaches our servers, so we cannot read it even if we wanted to. This is not a marketing claim — it is a technical constraint of client-side encryption.
2. Information We Collect
2.1 Account Information
When you create a cloud account, we collect your email address (used solely for authentication and account recovery) and a hashed representation of your password (we never store your plaintext password). Your password also serves as your encryption key — we do not have access to it.
2.2 Journal Content (Encrypted)
Your journal entry content (the text you write) is encrypted on your device using AES-GCM-256 before being transmitted to Firebase Firestore. We store only the encrypted ciphertext. We cannot decrypt, view, or analyze your entry content.
2.3 Entry Metadata
To enable search, tagging, and organization, we store the following unencrypted metadata for each entry:
- Creation and modification dates/timestamps
- Tags you assign to entries
- Entry titles (if separately provided)
- Word count and character count
Note: Tags and titles are not encrypted. If you include sensitive information in tags or titles, it may be visible in metadata. We recommend keeping tags general (e.g., "reflection," "anxiety") rather than containing personal details.
2.4 Demo Mode
Demo mode does not send any data to our servers. All demo entries are stored locally in your browser's localStorage as plain JSON and are cleared when you log out or clear your browser data. Demo entries are not encrypted.
2.5 Usage & Analytics
We may collect minimal, anonymized usage data (e.g., page views, feature usage counts) to improve the Service. This data does not include your journal content or personally identifiable information beyond what is necessary for authentication.
3. How We Use Your Information
We use your information solely to provide, maintain, and improve the MindsKeep service:
- Authentication: Your email and password hash are used to verify your identity and secure your account.
- Storage & Sync: Your encrypted entries and metadata are stored and synced across your devices.
- Search & Organization: Metadata (dates, tags) enables you to search, filter, and organize your journal.
- AI Features: When you actively request AI analysis (tags/summary generation or monthly review), your entry content is temporarily decrypted in your browser, sent to our backend proxy, and forwarded to an AI provider. See Section 4 for details.
- Customer Support: We may use your email to respond to support inquiries.
- Service Improvement: Anonymized usage data helps us understand which features are valuable and where to focus improvements.
We do not use your journal content for advertising, marketing, or any purpose other than providing the features you explicitly request.
4. AI Data Processing
This section explains exactly how AI features handle your data — transparency is especially important when AI is involved.
4.1 When AI Processes Your Content
AI processing occurs only when you actively trigger it by:
- Clicking the "AI Insight" / "Generate Tags & Summary" button in the editor
- Requesting a monthly AI summary from your timeline
We never automatically scan, analyze, or process your journal entries in the background. Your content is not sent to any AI provider unless you explicitly click an AI button.
4.2 How It Works
- Your encrypted entry is decrypted in your browser (only you can do this — your key never leaves your device).
- The decrypted text is sent to our backend Cloud Function over HTTPS, authenticated with your Firebase ID token.
- Our backend forwards the content to the AI provider's API.
- The AI response is returned to your browser and displayed in the app.
4.3 AI Providers
We use the following AI providers to power AI features:
- DeepSeek (primary model) — via api.deepseek.com. DeepSeek states that API data is not used for model training.
- Google Gemini (fallback model) — used only if DeepSeek is unavailable or returns an error. Google's API terms state that customer data sent via the API is not used for training.
We may change or add AI providers in the future. Any material change to how your content is processed will be notified in advance and reflected in this policy.
4.4 Data Retention by AI Providers
Content sent to AI providers via their APIs is typically processed and not retained for training purposes. However, we cannot guarantee the retention policies of third-party providers. If you have concerns, you may choose not to use AI features — the core journaling functionality works entirely without AI.
4.5 Your Control
You are in full control of AI processing:
- AI features are opt-in only — nothing is automatic.
- You can use MindsKeep entirely without ever using an AI feature.
- AI-generated tags and summaries are stored as metadata alongside your entry; you can edit or delete them at any time.
5. Third-Party Services
We use the following third-party services to operate MindsKeep:
- Google Firebase — Authentication (email/password), Firestore (encrypted data storage), and Cloud Functions (backend proxy). Firebase is GDPR-compliant and part of Google Cloud.
- Stripe — Payment processing for Premium subscriptions. Stripe handles all card data; we never store full credit card numbers.
- DeepSeek — AI text generation (see Section 4).
- Google Gemini — AI text generation fallback (see Section 4).
Each third-party service has its own privacy policy and data processing terms. We only share data with these providers as necessary to deliver the Service, and we require them to handle data in accordance with applicable privacy laws.
6. Cookies & Local Storage
6.1 Cookies
MindsKeep uses minimal cookies, primarily for authentication sessions (Firebase Auth) and language preference. We do not use tracking cookies, advertising cookies, or third-party analytics cookies that profile you across the web.
6.2 Local Storage
We use your browser's localStorage and indexedDB to store:
- Your encryption key (derived from your password) during an active session — this is what allows you to read your entries without re-entering your password every time
- Demo mode entries (plain JSON, not encrypted)
- Application preferences (language, theme settings)
- Cached entry data for offline access
You can clear this data at any time through your browser settings, though doing so will log you out and clear demo entries.
7. Data Retention
We retain your data for as long as your account is active:
- Encrypted journal entries and metadata: Retained until you delete them or your account is terminated.
- Account information (email, password hash): Retained for the life of your account.
- AI-generated content (tags, summaries): Stored as entry metadata; retained until you delete the entry or the specific AI-generated field.
- Demo mode data: Stored only in your browser's localStorage; cleared on logout or browser data clearing.
Upon account deletion, your encrypted data is permanently removed from our active databases within 30 days. Backups may retain data for up to 90 days before being purged.
8. Your Rights
Depending on your jurisdiction (including GDPR for EU/EEA residents and CCPA/CPRA for California residents), you have the following rights regarding your personal data:
- Right of Access: You can view all your data directly in the app. You can also request a complete export of your data in JSON format.
- Right to Data Portability: Export your entries and metadata as JSON at any time from the app settings.
- Right to Rectification: You can edit your entries, tags, and account information at any time.
- Right to Erasure ("Right to be Forgotten"): You can delete individual entries or your entire account. Upon account deletion, your data is permanently removed.
- Right to Restrict Processing: You can choose not to use AI features, which restricts processing of your content by AI providers.
- Right to Object: You may object to processing of your data for purposes beyond the core service.
- Right to Withdraw Consent: You may withdraw consent at any time by deleting your account.
- Right to Lodge a Complaint: You may lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at mindskeepsupport@gmail.com. We respond to all data rights requests within 30 days.
9. Children's Privacy
MindsKeep is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete that information.
Parental supervision is recommended for minors using the Service. Parents should be aware that journal entries are encrypted and cannot be accessed by us or by parents without the child's password.
10. International Data Transfers
MindsKeep uses Google Firebase, which stores data in Google Cloud data centers (primarily in the United States). If you are accessing the Service from outside the United States, your data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
We rely on appropriate safeguards for international data transfers, including Google's compliance with the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.
11. Security
We take the security of your data seriously:
- Client-side encryption: Entry content is encrypted with AES-GCM-256 before leaving your device.
- Transport security: All data in transit uses HTTPS/TLS 1.2+.
- Authentication: Firebase Auth with secure token-based sessions.
- Access control: Our backend requires a valid Firebase ID token for all API calls; anonymous access to AI endpoints is blocked.
- No plaintext password storage: Passwords are hashed using Firebase Auth's secure hashing.
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. The single most important security step you can take is to use a strong, unique password and keep it safe — we cannot recover it if lost.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. Material changes (e.g., changes to how we process your data, new third-party providers, or changes to your rights) will be notified via email or a prominent in-app notice at least 14 days before taking effect.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: mindskeepsupport@gmail.com
Website: https://mindskeep.com
We aim to respond to all privacy-related inquiries within 48 hours.