Last updated: March 20, 2026
The controller responsible for data processing is:
Mindflex UG (haftungsbeschränkt)
Mariendorfer Damm 85
12109 Berlin, Germany
Commercial Register: Amtsgericht Berlin-Charlottenburg, HRB 276989 B
VAT ID: DE456508601
Email: hello@mindflex.world
Website: https://mindflex.world
Managing Directors: Felix Mai, Moritz Tiedemann, Julian Hecht
We have appointed an external Data Protection Officer:
heyData GmbH
Schützenstraße 5
10117 Berlin, Germany
Email: datenschutz@heydata.eu
We process personal data when you:
Personal data means any information that can identify you directly or indirectly.
| Data | Purpose | Stored where |
|---|---|---|
| Email address | Authentication & account management | Supabase (US-East-1) |
| Display name | Personalization within the app | Supabase |
| Chat messages | Conversation continuity | Supabase (AES-256 encrypted at rest) |
| Conversation memory | Long-term context for AI companion | Zep (SOC 2 Type II certified) |
| Device token | Push notifications (if enabled) | Supabase |
| Timezone / City | Reminder scheduling | Supabase |
When you sign in with Google, we receive:
Google user data is used exclusively to provide and improve your Mindflex experience:
We do not:
Google user data is only shared with the following service providers, strictly to operate the app:
Your Google user data is retained for as long as your account is active. You can delete your account at any time via Settings → Delete Account in the app. Upon deletion:
We process personal data based on the following legal grounds:
You have the right to:
To exercise your rights, contact: hello@mindflex.world
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database, storage | Email, name, chat data (encrypted) |
| Anthropic (Claude API) | AI conversation processing | Chat messages only (no email/account data); not used for AI training |
| Zep | Conversation memory | Pseudonymized conversation summaries |
| RevenueCat | Subscription management | Anonymous user ID, purchase status |
| Sentry | Error tracking | Anonymous crash reports (no personal data) |
| Brevo | Transactional email | Email address (for auth emails only) |
We store your personal data for as long as your account is active. Specifically:
When you delete your account, personal data is permanently removed within 30 days. Anonymized data (with no way to trace back to you) may be retained for service improvement.
Mindflex is intended for users aged 18 and older. We do not knowingly collect personal data from children under 18. If we learn we have collected data from a child under 18, we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify users of material changes through the app or by email. The "Last updated" date at the top indicates when this policy was last modified.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. In Germany, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI).
We encourage you to contact us first at hello@mindflex.world so we can address your concern directly.
Mindflex UG (haftungsbeschränkt)
Mariendorfer Damm 85
12109 Berlin, Germany
Email: hello@mindflex.world
Website: https://mindflex.world