⚠️ NOT A MEDICAL APP: MindShift is a self-improvement tool only. It is NOT a therapy service, medical device, or substitute for professional psychological care. If you are in crisis, call 112 (EU) or 10306 (Greece – EKEPSY).

🧠 MindShift Privacy Policy

Your mental wellness journey, handled with care and transparency.

Effective: February 24, 2026 · Version 1.0

Table of Contents

  1. About MindShift
  2. Medical Disclaimer
  3. Data We Collect
  4. How We Use Your Data
  5. Third-Party Services
  6. Data Sharing
  7. Data Storage & Security
  8. Data Retention
  9. Your Rights (GDPR)
  10. Children's Privacy
  11. Subscriptions & Billing
  12. Account Deletion
  13. Policy Changes
  14. Contact Us

ℹ️ 1. About MindShift

MindShift ("we", "us", "our") is a personal development and AI-assisted mental wellness application developed by an independent developer. The app is available on Google Play and the Apple App Store.

This Privacy Policy explains how we collect, use, store and protect your personal information when you use MindShift on any device. By using MindShift, you agree to the practices described in this policy.

Developer Contact: privacy@getmindshift.app

🚨 2. Medical Disclaimer

⚠️ IMPORTANT – Please Read MindShift is a self-improvement and personal growth tool. It is NOT a medical device, clinical mental health service, or a substitute for professional psychological or psychiatric care.

MindShift complies with Google Play's Health & Wellness category guidelines and does not make clinical claims.

📋 3. Data We Collect

3.1 Account Data (Required)

Data TypePurposeRequired?
Email addressAccount creation, login, password resetYes
Display namePersonalised greetingOptional
Password (hashed)Authentication — never stored in plain textYes

3.2 Wellness & App Data

📌 Self-reported data only: All wellness data is entered voluntarily by the user. MindShift does not collect clinical measurements, medical records, or data from health devices. This data is not used for medical diagnosis, treatment, or clinical assessment.
Data TypeExamplesPurpose
Mood ratings1–10 daily mood score (self-reported by user, not measured by device)Progress tracking & personalisation
Anxiety / energy levelsSelf-reported integers — not clinical measurementsTrend analysis & AI coaching
Assessment answersMindset questionnaire scoresPersonalised recommendations
AI chat messagesText conversations with the AI coachAI response generation & history
Check-in notesOptional free-text reflectionPersonal journaling
Streak & progress dataDays active, exercises completedMotivation & gamification

3.3 Technical Data (Automatic)

Data TypePurpose
Device type & OS versionBug fixing & compatibility
App versionFeature rollout management
Session timestampsSecurity & rate limiting
IP address (transient)API security, fraud prevention
📵 We do NOT collect: Precise GPS location · Camera or microphone data · Contacts or call logs · Biometric data · Payment card details · Social media credentials

⚙️ 4. How We Use Your Data

Legal basis (GDPR Art. 6): performance of contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), and — for sensitive wellness data — your explicit consent (Art. 9(2)(a)).

🔗 5. Third-Party Services

ServicePurposeData SharedPrivacy Policy
Supabase (EU Frankfurt) Database & authentication Email, hashed password, wellness data supabase.com/privacy
OpenAI (USA)
Role: Data Processor
AI coaching response generation — acts as a data processor on our behalf, not an independent data controller Chat message text only — no email, no name, no user ID is included. Data transfer covered by Standard Contractual Clauses (SCCs) per GDPR Art. 46. openai.com/privacy
Vercel (Edge Network) API hosting / serverless Server-side request logs (IP, timestamps) vercel.com/legal
Google Play Billing Subscription payments (Android) Purchase token, subscription status policies.google.com
Apple App Store (planned) Subscription payments (iOS) Purchase receipt apple.com/legal/privacy
Stripe (planned) Web payment processing Email, payment token (no card data stored by us) stripe.com/privacy
🇪🇺 OpenAI — Data Processor Role & GDPR Compliance:
  • OpenAI is our data processor (GDPR Art. 28) — it processes data only on our documented instructions.
  • Chat messages are sent without any personal identifiers (no email, no name, no user ID).
  • Cross-border transfer (EU → USA) is lawful under Standard Contractual Clauses (SCCs), GDPR Art. 46.
  • OpenAI's API policy: data sent via API is not used to train OpenAI models.
  • OpenAI is classified as a service provider, not a data broker or advertising partner.

🤝 6. Data Sharing

We never sell your personal data to any third party.

We share data only in these limited circumstances:

AI chat content sent to OpenAI is anonymised (no name or email is included in the API request).

🔒 7. Data Storage & Security

⚠️ No system is 100% secure. While we implement industry-standard protections, we cannot guarantee absolute security. In the event of a data breach, we will notify affected users within 72 hours as required by GDPR Art. 33.

📅 8. Data Retention

Data TypeRetention Period
Account data (email, name)Until account deletion
Wellness data (mood, check-ins)Until account deletion
AI chat logs90 days (then anonymised)
Server / access logs30 days
Billing records7 years (legal requirement)
Anonymised analyticsIndefinitely (no personal data)

⚖️ 9. Your Rights (GDPR)

As a user in the European Economic Area, you have the following rights:

👁️

Access

Request a copy of all data we hold about you.

✏️

Rectification

Correct inaccurate or incomplete personal data.

🗑️

Erasure

Request deletion of your account and all associated data.

⏸️

Restriction

Limit how we process your data in certain circumstances.

📦

Portability

Receive your data in a structured, machine-readable format (JSON/CSV).

🚫

Object

Object to processing based on legitimate interests.

↩️

Withdraw Consent

Revoke consent at any time without affecting prior processing.

📣

Lodge Complaint

File a complaint with your national Data Protection Authority (e.g., HDPA in Greece).

To exercise any right, email: privacy@getmindshift.app. We respond within 30 days.

👶 10. Children's Privacy

MindShift is intended for users aged 13 and older.

💳 11. Subscriptions & Billing

PlanFeaturesPrice
Free1 AI chat per day, basic mood tracking, check-ins€0
PremiumUnlimited AI coaching, full history, advanced analytics, priority support€9.99 / month

🗑️ 12. Account Deletion

You can delete your account and all associated data at any time:

Upon deletion, we will permanently erase: your email, name, all wellness data, chat logs, and assessment history. Anonymised aggregated statistics (not linked to you) may be retained. Billing records are retained for the legally required 7-year period.

🔗 Direct deletion request link (accessible without the app, as required by Google Play):
https://getmindshift.app/delete-account
This link works even if you have uninstalled the app. Requests processed within 30 days.

📝 13. Policy Changes

We may update this Privacy Policy periodically. When we do:

Previous versions of this policy are available upon request.

📬 14. Contact Us

ChannelDetails
Privacy emailprivacy@getmindshift.app
General supportsupport@getmindshift.app
GDPR / data requestsgdpr@getmindshift.app
Response timeWithin 30 days for GDPR requests; 2 business days for general queries

Supervisory authority (Greece): Hellenic Data Protection Authority (HDPA)www.dpa.gr