MindPad Privacy notice

Do not enter or store sensitive, confidential, secret, health, financial, authentication, or private personal information in MindPad.

Version beta-2026-09-04

1. Scope and controller

This notice applies to the private, experimental MindPad test made available only to selected users. The service controller is Mind Vault Associates. For privacy requests, contact mike@mindpad.app.

2. What the test stores

MindPad may store your account email address, a securely generated password hash, document names and content, document revisions, save times, word and character counts, AI requests and responses, error records, session data, and basic technical or security logs.

Your browser also keeps a local draft and a pending-save queue so work can be recovered and synchronized after a connection problem. Other people using the same browser profile may be able to access locally cached data.

3. Human access to content

The service owner and authorized technical administrators can access stored document content and revisions. Access may occur while operating, securing, backing up, debugging, or improving this experimental service. When debug mode is enabled, diagnostic files may contain document text, AI prompts, responses, errors, and timing data.

4. AI processing

When automatic AI insights are enabled or you request an insight, content from the current document and its own revision history may be sent to OpenAI for processing. MindPad may calculate writing-behavior statistics across your documents, such as work times, revision frequency, or typical edit size. The system is designed to send only abstract behavior or writing-style metrics from other documents, not their text, titles, named topics, or summaries.

MindPad asks the OpenAI Responses API not to store application state by sending store: false. OpenAI states that API data is not used to train its models unless the relevant account opts in, but its standard abuse-monitoring logs may contain prompts and responses and are generally retained for up to 30 days. The exact controls and retention that apply depend on the service owner's OpenAI account and OpenAI's current terms.

5. Why data is processed

Data is processed to authenticate test users, save and recover documents, provide requested AI assistance, protect the service, diagnose faults, and evaluate the test. The legal basis depends on the operator and your location and may include performance of the test arrangement, legitimate interests in operating a secure test, and consent where required.

6. Service providers and transfers

Data may be handled by the hosting provider and, for AI functions, OpenAI. These providers may process data outside your country. Their contractual safeguards and current privacy terms apply to their processing. Ask the service administrator for the current provider details before using the test if this affects your decision.

7. Retention, security, and deletion

Test data is kept only as long as needed for the experiment, account operation, backups, security, and applicable legal obligations. No internet service can promise absolute security or recovery. You may ask the administrator to provide information about your data, correct account data, export or delete stored content, restrict processing, or address another privacy request. You may also have a right to complain to your local data-protection authority.

8. Changes

This notice may change as the experiment develops. A new version may require a fresh acknowledgment at login.