Privacy Policy

Last Updated: August 29, 2026

TL;DR: Your journal entries are end-to-end encrypted — we literally cannot read them. We collect only your email (for login) and entry metadata (dates, tags) to make the app work. We never sell your data. AI features send your content to our backend and then to AI providers (DeepSeek, with Google Gemini as backup) only when you actively request analysis — your content is never used to train public models. Demo mode stores everything locally in your browser.

1. Overview & Our Commitment

MindsKeep is built on a foundational belief: your private thoughts should remain private. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your data.

Our approach is simple by design: we encrypt your journal content on your device before it reaches our servers, so we cannot read it even if we wanted to. This is not a marketing claim — it is a technical constraint of client-side encryption.

2. Information We Collect

2.1 Account Information

When you create a cloud account, we collect your email address (used solely for authentication and account recovery) and a hashed representation of your password (we never store your plaintext password). Your password also serves as your encryption key — we do not have access to it.

2.2 Journal Content (Encrypted)

Your journal entry content (the text you write) is encrypted on your device using AES-GCM-256 before being transmitted to Firebase Firestore. We store only the encrypted ciphertext. We cannot decrypt, view, or analyze your entry content.

2.3 Entry Metadata

To enable search, tagging, and organization, we store the following unencrypted metadata for each entry:

Note: Tags and titles are not encrypted. If you include sensitive information in tags or titles, it may be visible in metadata. We recommend keeping tags general (e.g., "reflection," "anxiety") rather than containing personal details.

2.4 Demo Mode

Demo mode does not send any data to our servers. All demo entries are stored locally in your browser's localStorage as plain JSON and are cleared when you log out or clear your browser data. Demo entries are not encrypted.

2.5 Usage & Analytics

We may collect minimal, anonymized usage data (e.g., page views, feature usage counts) to improve the Service. This data does not include your journal content or personally identifiable information beyond what is necessary for authentication.

3. How We Use Your Information

We use your information solely to provide, maintain, and improve the MindsKeep service:

We do not use your journal content for advertising, marketing, or any purpose other than providing the features you explicitly request.

4. AI Data Processing

This section explains exactly how AI features handle your data — transparency is especially important when AI is involved.

4.1 When AI Processes Your Content

AI processing occurs only when you actively trigger it by:

We never automatically scan, analyze, or process your journal entries in the background. Your content is not sent to any AI provider unless you explicitly click an AI button.

4.2 How It Works

  1. Your encrypted entry is decrypted in your browser (only you can do this — your key never leaves your device).
  2. The decrypted text is sent to our backend Cloud Function over HTTPS, authenticated with your Firebase ID token.
  3. Our backend forwards the content to the AI provider's API.
  4. The AI response is returned to your browser and displayed in the app.

4.3 AI Providers

We use the following AI providers to power AI features:

We may change or add AI providers in the future. Any material change to how your content is processed will be notified in advance and reflected in this policy.

4.4 Data Retention by AI Providers

Content sent to AI providers via their APIs is typically processed and not retained for training purposes. However, we cannot guarantee the retention policies of third-party providers. If you have concerns, you may choose not to use AI features — the core journaling functionality works entirely without AI.

4.5 Your Control

You are in full control of AI processing:

5. Third-Party Services

We use the following third-party services to operate MindsKeep:

Each third-party service has its own privacy policy and data processing terms. We only share data with these providers as necessary to deliver the Service, and we require them to handle data in accordance with applicable privacy laws.

6. Cookies & Local Storage

6.1 Cookies

MindsKeep uses minimal cookies, primarily for authentication sessions (Firebase Auth) and language preference. We do not use tracking cookies, advertising cookies, or third-party analytics cookies that profile you across the web.

6.2 Local Storage

We use your browser's localStorage and indexedDB to store:

You can clear this data at any time through your browser settings, though doing so will log you out and clear demo entries.

7. Data Retention

We retain your data for as long as your account is active:

Upon account deletion, your encrypted data is permanently removed from our active databases within 30 days. Backups may retain data for up to 90 days before being purged.

8. Your Rights

Depending on your jurisdiction (including GDPR for EU/EEA residents and CCPA/CPRA for California residents), you have the following rights regarding your personal data:

To exercise any of these rights, contact us at mindskeepsupport@gmail.com. We respond to all data rights requests within 30 days.

9. Children's Privacy

MindsKeep is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete that information.

Parental supervision is recommended for minors using the Service. Parents should be aware that journal entries are encrypted and cannot be accessed by us or by parents without the child's password.

10. International Data Transfers

MindsKeep uses Google Firebase, which stores data in Google Cloud data centers (primarily in the United States). If you are accessing the Service from outside the United States, your data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

We rely on appropriate safeguards for international data transfers, including Google's compliance with the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.

11. Security

We take the security of your data seriously:

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. The single most important security step you can take is to use a strong, unique password and keep it safe — we cannot recover it if lost.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. Material changes (e.g., changes to how we process your data, new third-party providers, or changes to your rights) will be notified via email or a prominent in-app notice at least 14 days before taking effect.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: mindskeepsupport@gmail.com

Website: https://mindskeep.com

We aim to respond to all privacy-related inquiries within 48 hours.