Legal
Mindleaf is a stress-relief breathing app. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
When you use Mindleaf without an account (as a guest), we store a random device identifier on your device to track your session history locally. This identifier is not linked to your identity.
When you create an account, we collect:
Your session data is used solely to:
Your email is used solely for authentication and password resets. We will never send marketing emails without your explicit consent.
Your data is stored securely on Supabase (hosted on AWS). All data is protected by Row Level Security — you can only access your own data. All connections use HTTPS encryption.
Sound files are stored in a private cloud storage bucket and accessed via time-limited signed URLs.
If you use Mindleaf without creating an account, your session history is linked to a random device token stored on your device. This data cannot be used to identify you. If you later create an account, your guest sessions are migrated to your account.
Your data is retained for as long as your account exists. When you delete your account, all associated data (sessions, plan status, email) is permanently and immediately deleted from our servers. This action cannot be undone.
You have the right to:
If you are in the EU/UK, you have additional rights under GDPR including the right to rectification and the right to lodge a complaint with a supervisory authority.
Mindleaf is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We use the following third-party services:
We do not use any advertising networks, analytics platforms, or data brokers.
We may update this policy from time to time. If we make significant changes, we will notify you through the app. Continued use of Mindleaf after changes constitutes acceptance of the updated policy.