Privacy Policy

Last updated: February 25, 2025

1. Introduction

MindList ("we", "us", or "our") operates the MindList application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using MindList, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your email address and password (stored securely as a cryptographic hash). If you sign in with Google, we receive your name, email address, and profile picture from Google.

User Content

We store the outlines, notes, and other content you create within MindList in order to synchronize it across your devices and provide the Service.

Usage Data

We may automatically collect certain information when you access the Service, including your browser type, operating system, access times, and pages viewed. This data helps us improve performance and reliability.

Local Storage

MindList uses your browser's IndexedDB to store data locally for offline access. This data remains on your device and is not transmitted to our servers unless you initiate a sync.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To synchronize your content across devices in real time
  • To authenticate your identity and secure your account
  • To send important service-related communications such as security alerts and account verification
  • To respond to your support requests
  • To detect, prevent, and address technical issues or abuse

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:

  • Service Providers: We use Supabase for authentication and data storage, and Cloudflare for hosting. These providers process data on our behalf under strict contractual obligations.
  • Legal Requirements: We may disclose your information if required to do so by law or in response to valid legal process.
  • Safety: We may disclose information when we believe it is necessary to protect the safety, rights, or property of MindList, our users, or the public.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encrypted connections (TLS), secure password hashing, and support for multi-factor authentication (TOTP). However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

6. Data Retention

We retain your account information and content for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal obligations.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for data processing

You can export your data at any time from the Settings page within the application. To exercise other rights, please contact us using the information below.

8. Third-Party Services

When you sign in with Google, Google's Privacy Policy applies to the data they collect. We only receive the profile information described above and do not have access to your Google account beyond the scopes you authorize.

9. Cookies and Tracking

MindList uses essential cookies and local storage for authentication and session management. We do not use third-party advertising or analytics trackers. We do not track you across other websites.

10. Children's Privacy

MindList is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

[email protected]