Not legal advice

This page describes what the product actually does today, verified directly against the codebase. It's written to be accurate and complete, but it isn't a substitute for review by a qualified lawyer before you rely on it as your finished, binding policy.

Privacy policy

What we collect, and why.

Last updated 21 July 2026.

Who we are

MINDSET is the data controller for the personal data described on this page. If you have questions or want to exercise any of the rights below, contact mindset@proton.me.

What we collect

  • Account & identity data — your name and email address, collected when you request access or are added by an admin. Sign-in itself is handled by Firebase Authentication (Google); we never see or store a password.
  • Organization data — your agency/organization's name and its seat pools, if you're part of one.
  • Usage & quota data — which topics your queries matched, when you queried, and how many queries you have remaining. We do not store the literal text of your questions — only topic matches, needed to enforce quotas and serve the response.
  • Device identifiers — a device ID tied to your account, used to enforce the concurrent-device limit on your plan. It's kept as part of your account's history (see "How long we keep it" below) — it isn't shared with anyone or used for advertising or cross-site tracking.
  • Account activity trail — if a seat is assigned, transferred, or removed, or your account is suspended, we record which MINDSET or organization admin took that action and when, so activity can be audited later.
  • Standard server logs — IP address and request metadata, generated automatically by Google Cloud (our infrastructure provider) and not stored in our own database.

Why we process it, and on what legal basis

  • To provide the service (contract) — account, organization, and usage data exist because they're what let us authenticate you, meter your queries, and run the product you or your agency signed up for.
  • Security and legitimate interest — device IDs, the activity trail, and server logs let us prevent abuse, enforce plan limits fairly, and investigate account issues.
  • Legal/accounting obligation — usage and billing history is kept long enough to answer license/billing questions and meet standard financial record-keeping requirements.

We don't use your data for advertising, profiling, or automated decisions with legal effect, so consent-based processing and related opt-outs don't apply here.

What we don't collect

We don't currently take card payments directly, so we don't collect or store payment card details — if online card billing is added in future, it will run through a dedicated payment processor that we won't have access to your full card details from. We don't use advertising cookies or trackers, we don't run analytics scripts, and we don't sell or share your data with third parties for marketing. The matching that powers search runs on our own servers, not a third-party AI or vector-database vendor — your query topics never leave our infrastructure to be processed elsewhere.

Who can see it

MINDSET staff can view account and usage data to provide support, enforce quotas, and manage the service. If you're part of an organization, your Organization Admin can see your seat's usage (queries remaining, activity) but not the content of your queries beyond topic matches.

Who we share it with

We use a small number of infrastructure providers to run the service — we don't sell data or share it for their own marketing purposes:

  • Google Cloud Platform — hosts our servers, database, and logs, in Google's London (europe-west2) region.
  • Firebase Authentication (Google) — handles sign-in. As a global Google service, account sign-in data may be processed on Google's infrastructure outside the UK; Google's own GDPR/UK GDPR commitments and standard contractual clauses govern that transfer.

Where it's stored

Our database and application servers run in Google Cloud's London (europe-west2) region. Sign-in data may also touch Google's global infrastructure, as described above.

How long we keep it

If your account is removed — by you, your organization admin, or MINDSET staff — we don't delete the record outright by default. We keep it (usage history, seat history, who removed it and when) so we can accurately answer questions like "how much of my license did I use" after the fact, and so a returning user's history stays intact if they sign up again. Removing an account does stop it from being able to sign in or use the API immediately.

If you'd rather we erase your personal data outright instead of just deactivating the account, see "Your rights" below — email us and we'll action it, subject to what we're legally required to keep (e.g. financial records).

Your rights

Under UK/EU GDPR, you have the right to:

  • Access what we hold about you.
  • Correct inaccurate data.
  • Erase your data, subject to what we're legally required to retain.
  • Restrict or object to certain processing.
  • Receive a copy of your data in a portable format.

Today, exercising these is a manual process rather than a self-service button in the product — email mindset@proton.me and we'll action your request. You also have the right to lodge a complaint with your local data protection authority — in the UK, that's the Information Commissioner's Office (ICO).

Cookies

We don't use cookies. Sign-in works entirely through bearer tokens (a Firebase sign-in token or your API key), sent with each request rather than stored by your browser — so there's nothing here that needs a cookie consent banner.

Changes to this policy

If how we handle your data changes meaningfully, we'll update this page and change the "last updated" date above.

Contact

Questions about this policy, or to exercise any of the rights above: mindset@proton.me.