Skip to content
Back to home

Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains what personal data MindMe collects, why, how long it is kept, and what rights you have over it. MindMe is operated by Michal Vranovsky ("we", "us", "our"). By creating an account you confirm that you have read this policy and give your consent to the processing described below.

1. Who Is Responsible for Your Data?

Data controller: Michal Vranovsky
Email: [email protected]
Website: https://mindme.today

If you have any questions about how your data is handled, or wish to exercise any of your rights, please contact us at the email address above.

2. What Data We Collect and Why

2.1 Account data

When you register, we collect:

Data Purpose Legal basis
Username Identify your account and display your name in the app Contract performance
Email address Account login, account recovery Contract performance
Password (stored as a one-way hash — we never store the plain-text password) Authenticate your identity Contract performance
Registration timestamp Detect unusual account activity Legitimate interest
Consent record Proof that you accepted this policy Legal obligation

If you sign in with Google, Facebook, or Apple instead of a password, we receive your email address and a unique identifier from that provider. We do not receive your social-media password.

2.2 Game state

To run the game we store:

Data Purpose
Diamonds balance In-game currency
Current streak and last-solved date Streak tracking
Streak freezes held Streak-freeze feature
Questions completed, hints used, answers revealed Progress tracking across devices
Date of last daily diamond award Prevent duplicate daily rewards
Premium status (is_paying_customer) Remove ads and unlock premium features

2.3 Social data (Pokes)

If you use the Pokes feature, we store:

Data Purpose
Sender user ID and receiver user ID Deliver the poke to the right user
Timestamp the poke was sent and seen Show "seen" status

2.4 Advertising data

If you choose to watch a rewarded video ad to earn diamonds, we pass your consent decision to Unity Ads (Unity Technologies). Unity may collect device identifiers and usage data to serve and measure ads. This only happens after you have given explicit consent inside the app.

Unity's privacy policy: https://unity.com/legal/privacy-policy

We do not sell your personal data to advertisers.

2.5 Server logs

Our servers automatically record:

Data Purpose Retention
Your user ID (numeric, not your name or email) Diagnose errors and monitor abuse 30 days, then deleted automatically
Request path, HTTP status code, timestamp Performance monitoring 30 days, then deleted automatically

We deliberately do not log your username, email, or password in server logs.

2.6 Waitlist signup

If you join the waitlist on our website, we store:

Data Purpose Legal basis
Email address Notify you when MindMe launches Consent

We keep your waitlist email until launch or until you ask us to remove it, whichever is sooner. Email [email protected] at any time to be removed from the waitlist.

2.7 Friend Challenges

If you challenge a friend or are challenged, we store:

Data Purpose
Challenger and opponent user ID Match the challenge to both participants
Categories and questions selected Run the challenge
Each participant's submitted answers and score Show the head-to-head result to both participants

A challenge's answers and score are visible only to the two participants — never to other users.

2.8 Push notifications

If you allow notifications, we store:

Data Purpose Legal basis
Push notification token (device identifier issued by Expo) Deliver streak-reminder and other in-app-triggered notifications to your device Consent (device notification permission)

You can revoke this at any time by disabling notifications for MindMe in your device settings; we delete the stored token the next time it fails to deliver.

3. Who We Share Your Data With

We share data only where strictly necessary:

Recipient What is shared Why
Unity Technologies (Unity Ads) Device advertising identifier, consent status Serve rewarded video ads — only with your consent
Google (Sign in with Google) You initiate the connection; Google sends us your email and Google ID OAuth authentication
Facebook (Log in with Facebook) You initiate the connection; Facebook sends us your email and Facebook ID OAuth authentication
Apple (Sign in with Apple) You initiate the connection; Apple sends us your email (or relay address) and Apple ID OAuth authentication
Our hosting provider (server infrastructure) All account and game data, as necessary to run the service Contract performance
Lemon Squeezy (payment processor) Your email address and purchase details (diamond pack or subscription plan), when you buy diamonds or MindMe Plus Contract performance — process your payment
Plausible Analytics (Plausible Insights OÜ) Aggregated, anonymous page-view statistics (page URL, referrer, country, device type). No cookies set, no personal data collected, no cross-site tracking. Legitimate interest — understanding how visitors use the website
Sentry (Functional Software, Inc.) IP address, user ID, and diagnostic context (error messages, stack traces, request data) captured when the app or server encounters an error Legitimate interest — diagnose crashes and bugs
Expo (Expo Technologies, Inc.) Push notification token and notification content, only if you enabled notifications Consent — deliver notifications you opted into
Other MindMe users Your username (via in-app search and friend requests); your rank and weekly solved-count on the leaderboard; challenge scores and answers, visible only to your challenge opponent; poke sent/seen status, visible only to sender and receiver Contract performance — these are the social and competitive features you choose to use

Sentry and Expo are located in the United States. Where we transfer personal data outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) with the recipient as a safeguard.

We do not share your data with any other third party for marketing or profiling purposes.

4. How Long We Keep Your Data

Data Retention period
Account and game data Until you delete your account
Pokes Until either the sender or receiver deletes their account
Friend challenges Until either participant deletes their account
Push notification token Until you disable notifications, log out, or delete your account
Revoked authentication tokens Until the token's natural expiry, then deleted automatically
Server logs 30 days, then deleted automatically
Waitlist email Until launch or removal request
Backups 14 days

When you delete your account, we immediately and permanently erase your username, email address, password hash, OAuth identifier, and all linked game-progress and poke records. A placeholder row containing only your numeric user ID is retained to preserve referential integrity; it contains no information that identifies you.

5. Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights:

Right of access (Art. 15)

You can request a copy of all personal data we hold about you. Inside the app, go to Settings → Export My Data to download your data as a JSON file immediately, free of charge.

Right to erasure (Art. 17)

You can delete your account at any time. Inside the app, go to Settings → Delete Account. This permanently erases all identifying data as described in section 4 above.

Right to rectification (Art. 16)

You can update your username or email address at any time in Settings → Account.

Right to data portability (Art. 20)

Your data export (see Right of access above) is provided in machine-readable JSON format, which you can import into any compatible service.

Right to withdraw consent

If you previously gave consent to receive personalised ads, you can withdraw it at any time in Settings → Ad Preferences. Withdrawing consent does not affect data already processed.

Right to lodge a complaint

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority. In Slovakia: Úrad na ochranu osobných údajov (www.dataprotection.gov.sk).

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

6. Data Security

  • Passwords are stored as bcrypt hashes; we cannot recover your plain-text password.
  • All communication between the app and our server uses HTTPS (TLS 1.2+).
  • Authentication tokens are short-lived (30 minutes) and revoked immediately on logout.
  • Access to production systems is restricted to the data controller.

7. Children

MindMe is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.

8. Cookies and Local Storage

MindMe is a mobile app and does not use browser cookies. On your device we store:

Storage Contents Purpose
Secure device storage (expo-secure-store) Authentication tokens Keep you logged in
Local device storage (AsyncStorage) Game state, theme preference, onboarding flags Offline-first gameplay; synced to server when online

This data stays on your device and is cleared when you uninstall the app or reset your progress.

8.2 Website analytics

The MindMe website (mindme.today) uses Plausible Analytics, a privacy-first analytics service operated by Plausible Insights OÜ (Estonia). Plausible does not use cookies, does not collect personal data, and does not track you across websites. The data processed is limited to: page URL, referrer, country (derived from IP address — IP is never stored), device type, and browser name. This processing is performed under our legitimate interest in understanding how visitors use the site. Plausible's privacy policy: https://plausible.io/privacy.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by displaying a notice in the app the next time you open it. The "Last updated" date at the top of this page will always reflect when the most recent version was published. Continued use of the app after a change constitutes acceptance of the updated policy.

10. Contact

Questions, requests, or complaints:

Michal Vranovsky
Email: [email protected]
Website: https://mindme.today

We aim to respond to all privacy-related enquiries within 30 days.