1. Core principles
- Local vaults, Markdown originals, and exported files are not uploaded to a company cloud content store unless the user separately sends or shares them.
- File browsing, search, and graph rendering run on the user's computer.
- When the user starts document generation or analysis, sources selected for that task and the request may be sent to OpenAI Codex.
- Google sign-in is used only for basic identity. MindStruo does not request Gmail or Google Drive access.
2. Information processed
| Google sign-in | Issuer, unique account identifier, verified email, name, and profile photo URL |
|---|---|
| Device and entitlement | Internal account ID, device ID, platform, app version, timestamps, plan, and access state |
| Billing connection | Paddle customer, transaction, subscription, and price identifiers; status, term, errors, and scheduled changes |
| Billing events | Paddle webhook ID, type, time, signature verification, processing, and error records |
| Security and operations | Request time and route, rate-limit hashes, and necessary error data |
| Support | Email, product and OS version, transaction ID, and problem description provided by the user |
3. Local sources and AI requests
Imported research files may be held in a private temporary file while text and structure are extracted locally. After normal processing, temporary source bytes are removed; filename, format, hash, extracted text, and location data may remain in local app state.
Extracted material, recovery copies, backups, personal context, and user settings may remain locally until the user runs the relevant delete or reset action. Uninstalling the app does not guarantee deletion of the local vault or all app state.
The app shows the material selected for an AI task before the task starts. Do not include passwords, full payment-card data, national identifiers, or unnecessary sensitive information.
4. External providers
Each provider processes the information needed for the feature over HTTPS. Card numbers and CVCs are collected directly by Paddle Checkout and are not stored in the MindStruo database.
| Account sign-in and identity verification | |
| Paddle | Payments, taxes, receipts, subscriptions, cancellations, refunds, and disputes |
| Cloudflare | License-service execution, entitlement storage, security, and operations |
| OpenAI Codex | Document generation and analysis started by the user |
5. Retention and deletion
| Desktop authentication requests | Valid for five minutes; deleted by the next normal maintenance run after expiry |
|---|---|
| Successfully processed billing-event body | Minimized by the next normal maintenance run, normally scheduled about every five minutes |
| Failed billing-event body | Kept for retries for up to 72 hours, then minimized |
| Minimum billing-event metadata | Deleted by normal maintenance after 90 days |
| Account, device, and subscription data | For the life of the account and any period required by law or dispute handling |
| Local sources and app state | Until the user runs the relevant delete or reset action |
6. User rights and contact
Users may request access, correction, deletion, restriction, withdrawal of consent, and deletion of the cloud account. Active subscriptions or unsettled transactions may need to be handled in the Paddle customer portal first to prevent duplicate charges and entitlement errors.
Deleting a cloud account does not delete the local vault, Markdown originals, or downloaded outputs. Paddle transaction, tax, dispute, and legally required records may be retained separately.
Privacy contact: privacy@mindstruo.com
7. Safeguards and changes
The service uses transport encryption, hashed authentication state and tokens, billing-event signature verification, rate limits, least privilege, and data minimization. It does not promise app-level encryption of every local file or automatic detection of every sensitive value.
Material changes to purposes, providers, or retention will be posted here with an effective date. Separate consent will be requested when required.
Questions about these terms
Contact support@mindstruo.com. Privacy requests may be sent to privacy@mindstruo.com.