Back to home

Privacy Policy

Effective Date: May 1, 2026

1. Scope

This Privacy Policy applies to:

  • the MindMux desktop application;
  • MindMux websites;
  • MindMux cloud services;
  • account, backup, sync, publishing, and team features;
  • support and communications.

It does not apply to third-party services that you connect to MindMux, such as AI providers, GitHub, Linear, Notion, GitLab, Stripe, or other integrations. Those services have their own privacy policies.

2. Information We Collect

The information we collect depends on how you use MindMux.

2.1 Information You Provide

We may collect information you provide directly, such as:

  • name;
  • email address;
  • account login information;
  • company or workspace name;
  • billing details;
  • support messages;
  • feedback;
  • uploaded or synced content;
  • published brain content;
  • team member invitations;
  • connector configuration metadata.

2.2 Local Workspace Content

MindMux stores project knowledge in local files, including Markdown brain files.

If you use MindMux only locally and do not enable cloud features, your local workspace content may remain on your device and may not be sent to MindMux servers.

However, local content may be processed by third-party AI providers or connectors if you choose to use features that send that content outside your device.

2.3 Cloud Feature Content

If you enable cloud features, we may process content needed to provide those features, such as:

  • cloud backups;
  • synced workspaces;
  • published brain pages;
  • shared team brain content;
  • task metadata;
  • AI usage metadata;
  • cloud-hosted settings.

2.4 AI Inputs and Outputs

MindMux calls AI providers (such as Anthropic Claude or OpenAI Codex) directly from your device using your own API key. Your prompts, brain pages, conversation context, and AI outputs are sent directly from your device to the provider you configure — MindMux servers do not receive, route, or proxy your AI requests.

You are responsible for understanding your AI provider’s data handling and privacy practices.

2.5 Technical and Usage Information

We may collect technical information such as:

  • device type;
  • operating system;
  • app version;
  • IP address;
  • approximate region;
  • crash logs;
  • diagnostic logs;
  • feature usage events;
  • cloud request metadata;
  • authentication events;
  • security logs.

We use this information to operate, secure, debug, and improve the Service.

2.6 Cookies and Similar Technologies

Our website or cloud dashboard may use cookies or similar technologies for:

  • authentication;
  • preferences;
  • analytics;
  • security;
  • billing and checkout flows.

You can control cookies through your browser settings, though some features may not work without them.

3. How We Use Information

We use information to:

  • provide and operate MindMux;
  • authenticate users;
  • store, sync, back up, publish, or share content when requested;
  • connect third-party integrations;
  • respond to support requests;
  • improve product reliability and usability;
  • detect abuse, fraud, and security incidents;
  • comply with legal obligations;
  • enforce our Terms of Service.

We do not sell your local Markdown brain.

4. How AI Data Is Handled

AI features may require sending data to model providers.

Depending on your configuration, this may include:

  • prompts you type;
  • conversation history;
  • selected brain pages;
  • selected project files;
  • task context;
  • model outputs.

You should review the privacy and data-use terms of the AI provider you select. Different providers may have different practices for retention, training, logging, enterprise controls, and abuse monitoring.

Do not send sensitive or regulated information to AI providers unless you have verified that your configuration and provider terms are appropriate for that data.

5. How We Share Information

We may share information with the following categories of recipients.

5.1 Service Providers

Vendors that help us operate the Service, such as:

  • cloud hosting providers;
  • database and storage providers;
  • payment processors;
  • email providers;
  • analytics providers;
  • customer support tools;
  • security and monitoring tools;
  • AI infrastructure providers.

These providers are allowed to process information only as needed to provide services to us.

5.2 AI Providers and Connectors

When you use AI features or integrations, data may be sent to the provider or connector you choose, such as:

  • Anthropic;
  • OpenAI;
  • Google;
  • GitHub;
  • Linear;
  • Notion;
  • GitLab;
  • custom MCP servers;
  • other user-configured services.

5.3 Team or Sharing Features

If you use team, collaboration, publishing, or sharing features, content and metadata may be visible to people you invite or to anyone with access to a published link, depending on your settings.

5.4 Legal, Safety, and Compliance

We may disclose information if we believe it is necessary to:

  • comply with law, legal process, or government requests;
  • enforce our Terms of Service;
  • protect the rights, property, or safety of MindMux, users, or the public;
  • detect, prevent, or investigate fraud, abuse, or security incidents;
  • respond to emergencies.

5.5 Business Transfers

If MindMux is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.

We will use reasonable efforts to notify affected users if such a transfer materially changes how their information is handled.

6. Data Retention

We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Retention periods depend on the type of data:

  • Local workspace content: stored on your device unless you enable cloud features or send it to third-party providers.
  • Cloud backups and synced content: retained while your account or relevant cloud feature is active, unless deleted according to product controls.
  • Published content: retained until unpublished or deleted, subject to backup and cache retention.
  • Support messages: retained as needed to provide support and maintain records.
  • Security logs: retained for a limited period unless needed to investigate abuse or incidents.

When you delete content or close your account, we will delete or de-identify information within a reasonable period, unless retention is required by law, legitimate business needs, backup systems, security, or dispute resolution.

7. Your Choices and Controls

Depending on your location and how you use MindMux, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal information.

MindMux also gives you product-level controls:

  • keep workspaces local;
  • choose whether to enable cloud backup or sync;
  • choose whether to publish brain content;
  • configure your own AI API keys and provider;
  • remove or rotate API keys;
  • disconnect third-party integrations;
  • delete local files from your own device;
  • request account deletion.

To exercise privacy rights, contact us at [email protected].

We may need to verify your identity before completing certain requests.

8. Local-First Data Control

MindMux is designed so that core project knowledge can live in files you control.

However, local-first does not mean “nothing ever leaves your device.” Data may leave your device when you:

  • connect an AI provider using your own API key;
  • enable cloud backup or sync;
  • publish content;
  • share a workspace;
  • connect third-party services;
  • send logs or support requests;
  • use remote task or connector features.

You are responsible for understanding which providers and features you enable.

9. Security

We use reasonable technical and organizational measures to protect information, such as encryption in transit, access controls, secure storage practices, monitoring, and limited employee access.

However, no system is perfectly secure.

You are responsible for securing your local device, workspace files, operating system account, local API keys, third-party credentials, and backups.

If you believe your account or data has been compromised, contact us at [email protected].

10. International Data Transfers

MindMux may process information in countries other than where you live.

These countries may have data protection laws different from your jurisdiction. Where required, we use appropriate safeguards for international transfers.

11. Children's Privacy

MindMux is not directed to children under 13, or the minimum age required by applicable law.

We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.

12. California Privacy Notice

If you are a California resident, you may have rights under the California Consumer Privacy Act, as amended by the CPRA, including the right to:

  • know what personal information we collect, use, disclose, or share;
  • request deletion of personal information;
  • request correction of inaccurate personal information;
  • opt out of sale or sharing of personal information;
  • limit use of sensitive personal information, where applicable;
  • not be discriminated against for exercising your rights.

We do not sell personal information in the conventional sense. If our use of analytics or advertising technologies is considered “sharing” under California law, we will provide required controls where applicable.

To exercise your rights, contact [email protected].

13. EEA / UK Privacy Notice

If you are located in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing may include:

  • Contract: to provide the Service you requested;
  • Consent: where you choose optional features or communications;
  • Legitimate interests: to secure, improve, and operate the Service;
  • Legal obligations: to comply with accounting, tax, and regulatory requirements.

You may have rights to:

access your personal data; correct inaccurate data; delete data; restrict processing; object to processing; data portability; withdraw consent; lodge a complaint with a data protection authority.

Contact [email protected] to make a request.

14. Enterprise and Team Workspaces

If you use MindMux through an organization, your organization may control certain data and settings.

For team or enterprise workspaces, administrators may be able to:

  • invite or remove members;
  • manage access permissions;
  • view workspace metadata;
  • manage billing;
  • configure integrations;
  • access shared brain content;
  • enforce security settings;
  • export or delete organization data.

Your organization’s own policies may also apply.

15. Open Source and Public Contributions

If you contribute to MindMux open-source repositories, your contributions, username, profile information, commit metadata, issues, pull requests, and discussions may be public on platforms such as GitHub.

Do not include private information, credentials, secrets, or confidential content in public issues, pull requests, commits, discussions, or examples.

16. Changes to This Policy

We may update this Privacy Policy from time to time.

If changes are material, we will provide reasonable notice, such as by posting an update on our website or notifying account holders.

The “Effective Date” shows when this Privacy Policy was last updated.

17. Contact Us

For privacy questions or requests, contact:

MINDFLY INC. [email protected]

For security issues: [email protected]