MindStruo

Data handling

MindStruo Privacy Policy

How local files, account and billing records, and selected sources are handled when you use AI features.

Status
Preparing for launch · checkout closed
Last updated
August 23, 2026
Version
1.1 pre-launch
Effective
When paid sales begin
Production Google sign-in and Paddle checkout are not open. Before those features launch, processor location, retention, and seller details will be verified against the provider contracts and administration consoles.

1. Core principles

  • Local vaults, Markdown originals, and exported files are not uploaded to a company cloud content store unless the user separately sends or shares them.
  • File browsing, search, and graph rendering run on the user's computer.
  • When the user starts an AI feature or separately configures the optional Codex connection, selected sources, the request, and project context needed for that request may be sent to OpenAI Codex.
  • Google sign-in is used only for basic identity. MindStruo does not request Gmail or Google Drive access.

2. Purposes and information processed

Information is processed only as needed for account identity and sign-in, device and entitlement management, payment and subscription operations, security and abuse prevention, customer support, and AI features started by the user.

Information required only by an optional feature is not collected when that feature is not used. MindStruo does not request permission to read Gmail or Google Drive content.

Google sign-inIssuer, unique account identifier, verified email, name, and profile photo URL
Device and entitlementInternal account ID, device ID, platform, app version, timestamps, plan, and access state
Billing connectionPaddle customer, transaction, subscription, and price identifiers; status, term, errors, and scheduled changes
Billing eventsPaddle webhook ID, type, time, signature verification, processing, and error records
Founding 100 eligibilityA one-way SHA-256 eligibility marker made from the Google issuer and unique account identifier, Founding rank, Paddle subscription and transaction IDs, and assignment or forfeiture source and time
Security and operationsRequest time and route, rate-limit hashes, and necessary error data
SupportEmail, product and OS version, transaction ID, and problem description provided by the user

3. Local sources and AI requests

Imported research material may be received as a private temporary file. The app verifies the file, reads it into memory, and removes the temporary source before text extraction starts. A temporary file left after an abnormal interruption is deleted after it is one hour old by the next app start or periodic cleanup. Filename, format, MIME type, size, source and extraction hashes, extracted text, and location data may remain in local app state.

A local backup may copy every ordinary file in the vault, including attachments and the hidden project ledger, and does not expire automatically. Extracted material, recovery copies, backups, personal context, and user settings may remain locally until the user runs the relevant delete or reset action. Uninstalling the app does not guarantee deletion of the local vault or all app state.

Project checkpoints, decisions, status, and next actions are stored in a continuity ledger at `.mindstruo/project-memory/v1` inside the selected local vault. The ledger is excluded from ordinary Markdown search and has no automatic expiry. The SQLite search index is derived and can be rebuilt from the ledger, so a derived-data reset alone does not delete the ledger. Vault backups may include it.

The original writing sample is neither stored nor sent to the model after local style analysis. If the user selects the personal-style option, the categorical style fingerprint stored locally may be sent as writing instructions for that document request.

Before document generation, the preflight view shows the categories, item counts, and character counts of selected evidence, project or legal context, and writing-control data. The actual generation input is captured as a snapshot in local server-process memory, and a one-time receipt valid for at most five minutes is issued for the same generation settings. Preflight alone does not send the snapshot to an external AI.

If the user activates the optional external Studio MCP connection for the current vault, Codex may use a restricted local capability to read unsaved Studio state and only the exact active-window project context, and to queue a proposal for review. Linked-project and whole-vault expansion requires a separate five-minute approval in MindStruo. The external capability cannot apply, save, delete, or export changes. Revoking the connection discards the existing capability and connection file so later calls stop. The default configuration copied by MindStruo requests approval before each enabled MCP tool call; user changes to Codex configuration may alter that behavior.

Personal context analyzes only user messages from local Codex conversations. It does not copy the full conversation into the personal-context database, but may store the conversation identifier, title and message count, a generated memory summary, and limited supporting excerpts, positions, and hashes from user messages.

Local license state may contain an installation device ID, account identifiers, a raw device token, a signed entitlement receipt, trusted-time state, and a pending logout token. Signing out or deleting the cloud account may leave the installation ID and trusted-time state; a full app-state reset removes the license folder.

The local server log used by the browser fallback may contain absolute vault and database paths, error messages, and stack traces, and it has no automatic expiry. It can be removed through log-derived-data deletion or a full app-state reset. A diagnostic bundle created by the user is not uploaded automatically.

If web research is approved and an adopted public URL is verified, the local app may send a direct HTTPS request to that website. The site may process the IP address, request time and URL, and the MindStruo user agent under its own policy.

Do not include passwords, full payment-card data, national identifiers, or unnecessary sensitive information in selected material or project context.

4. External providers

Each provider processes the information needed for the feature over HTTPS. Card numbers and CVCs are collected directly by Paddle Checkout and are not stored in the MindStruo database.

GoogleAccount sign-in and identity verification
PaddlePayments, taxes, receipts, subscriptions, cancellations, refunds, and disputes
Cloudflare, Inc. (processor)Current product-site Worker, CDN, and security operations; future license-service execution
OpenAI CodexUser-started AI features and project-context requests through the separately configured local connection

5. Retention and deletion

Desktop authentication requestsValid for five minutes; deleted by the next normal maintenance run after expiry
Successfully processed billing-event bodyMinimized by the next normal maintenance run, normally scheduled about every five minutes
Failed billing-event bodyMay be retained until successful processing for an exact retry, then minimized by the next normal maintenance run. A long-running failure may remain longer until it succeeds or receives separate operational review
Minimum billing-event metadataDeleted by normal maintenance after 90 days
Account, device, and subscription-link dataFor the life of the account. Directly linked service-account data is deleted with the account; the detached billing-event ordering record, Founding ledger, and legally or dispute-required records below follow their separate retention rules
Detached billing-event ordering recordOn account deletion, the account ID, Paddle customer ID, bootstrap transaction ID, and its event reference are removed. To prevent delayed or replayed webhooks from reconnecting a deleted billing relationship or reactivating the same terminally canceled subscription, the Paddle subscription and price IDs, final status, period and scheduled change, last-event type, ID and time, and state-freshness and redaction times remain separately for the operating life of the service. This is a pseudonymous record that may be re-identifiable when combined with Paddle data; its period, legal basis, and deletion-right limits require independent legal review
Founding 100 ledgerTo prevent rank reuse and repeat assignment to the same account, an assigned rank, one-way eligibility marker, and Paddle source identifiers remain after cloud-account deletion for the operating life of the service. The raw Google account identifier is not stored in this ledger
Checkout policy-acceptance recordsUnused records are deleted after expiry. Records consumed by checkout are retained for the life of the account and deleted with it, subject to any legal retention duty
Contract, withdrawal, payment, and supply recordsFive years under Korean electronic-commerce law
Consumer complaint and dispute recordsThree years under Korean electronic-commerce law
Display and advertising recordsSix months under Korean electronic-commerce law
General support recordsOne year after the case is closed; three years where the record concerns a consumer complaint or dispute
Local sources and app stateUntil the user runs the relevant delete or reset action
Local license credentialsThe account session is deleted on sign-out or cloud-account deletion; installation ID and trusted-time state may remain until a full app-state reset
Browser-fallback local server logUntil log-derived-data deletion or a full app-state reset; no automatic expiry
Project-continuity ledgerUntil the user deletes the hidden technical folder from the selected vault or deletes the vault; no automatic expiry
Document-transmission preflight snapshot and receiptHeld in local server memory for at most five minutes or until first use; may be removed earlier by bounded-memory cleanup or server shutdown
External Studio MCP connection fileUntil revocation, vault change, or normal local-engine shutdown; expanded-context authorization remains valid for no more than five minutes

6. User rights and contact

Users may request access, correction, deletion, restriction, withdrawal of consent, and deletion of the cloud account. A privacy-rights request is accepted separately from subscription cancellation. To stop future billing, the subscription must also be canceled in the app or Paddle customer portal.

Deleting a cloud account does not delete the local vault, Markdown originals, project-continuity ledger, or downloaded outputs. Paddle transaction, tax, dispute, and legally required records may be retained separately. The one-way eligibility marker and minimum source record needed to prevent Founding-rank restoration, reuse, or duplicate assignment, and the detached billing-event ordering record needed to prevent reconnection or reactivation of a deleted billing relationship, remain for the retention periods above.

The purpose, legal basis, period, and deletion-right limitations for the Founding ledger and detached billing-event ordering record require independent legal approval. Production accounts and paid checkout will remain closed until an approved privacy notice is ready.

Rights requests are accepted at privacy@mindstruo.com. Minimum information appropriate to the request may be required to verify the requester or a lawful representative.

Privacy officerRepresentative 박기인
Privacy requests and complaintsprivacy@mindstruo.com
Telephone+82 10-3981-5924

7. Destruction and segregated retention

Personal information is destroyed without undue delay when its purpose or retention period ends. Electronic records are removed using a method intended to prevent practical recovery; any paper record is shredded or incinerated.

Records that must be retained by law are segregated from active account and support data and destroyed in the same manner when the statutory period ends. Local vaults and outputs remain under the user's control and must be removed through the applicable app reset or file-management action.

8. Current website hosting transfers and pre-sale verification

The current public product site uses the Worker, CDN, and security services of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When a visitor requests a page over HTTPS, the IP address, user agent, requested URL and path, time, and network, security, or error events may be processed continuously across Cloudflare's global network, including the United States, to deliver and cache pages, route traffic, mitigate DDoS attacks, secure the site, and diagnose failures.

MindStruo has not added advertising analytics or a separate visitor database to this product site, and Workers Logs is not enabled. Cloudflare's current DPA describes retention by the earlier of contract termination or the time processing is no longer necessary to provide the service. Actual retention for product-specific network and security logs may depend on the applicable service and operating configuration. A visitor who refuses this transfer may avoid the site and contact support@mindstruo.com instead.

Google, Paddle, and OpenAI may process information in multiple countries when their features open. Production Google sign-in and Paddle checkout are not open. Before paid sales, this policy will publish the verified recipient entity and contact, country, transferred items, purpose, timing and method, retention period, legal basis, and the method and effect of refusal based on the actual contracts and consoles.

When a user starts an AI feature through the user's own Codex account, selected material and request context are processed under the terms applicable to that OpenAI account. The user may review the transmission scope and choose not to start the AI feature.

9. Automatic collection, safeguards, and changes

The product-introduction site does not directly set advertising-tracking cookies. Web hosting and security operations may nevertheless process IP address, user agent, request time and path, and error information temporarily. The desktop app's local API may use an HttpOnly, SameSite security cookie to verify that a request came from the same computer, and the checkout handoff may use a strictly necessary security cookie for up to ten minutes to protect a one-time handoff value. These cookies are not used for advertising or cross-site tracking. Local app settings and recovery information are not browser advertising identifiers.

When the user checks for updates, the operating system, architecture, update channel, current version, a Windows updater request identifier, and IP or HTTP metadata may be processed by the Cloudflare-based update service. The app does not store this information in a separate database, and observability logs and tracing are disabled for the update service.

The service uses transport encryption, hashed authentication state and tokens, billing-event signature verification, rate limits, least privilege, and data minimization. The continuity ledger's hash chain detects integrity breaks; it is not encryption of the ledger contents. The service does not promise app-level encryption of every local file or automatic detection of every sensitive value.

Material changes to purposes, providers, or retention will be posted here with an effective date. Separate consent will be requested when required.

Questions about these terms

Contact support@mindstruo.com. Privacy requests may be sent to privacy@mindstruo.com.