Privacy policy

Last updated: July 2026

Data controller

The controller of your personal data is Clément Guérin, sole proprietor (micro-enterprise), SIRET: 10028571700011, located at 43 Quai Malakoff, 44000 Nantes, France. For any data-related question: hello@minddy.app

Data collected

When you use minddy, we process the following data:

  • Account data email address, user id, display name and profile picture (via Supabase Auth). If you sign in with Google or GitHub, those services pass us your email, name and profile picture; no password is ever shared with us
  • Work content the projects, issues, plans, comments and attachments you create, stored in our database and in Supabase Storage
  • Usage data pages visited and actions performed in the application (via PostHog, only with your consent), plus aggregated traffic measurement with no cookie and no persistent identifier (Vercel Analytics)
  • Data submitted to AI content sent to the Numo assistant, to dictation and to the coding agent — including the code of the linked repository during an agent run — is transmitted to OpenRouter for processing
  • Git connections access tokens for your GitHub or GitLab repositories are encrypted (AES-256-GCM) before storage. We only reach the repository when you trigger an action that requires it
  • Personal AI keys if you provide your own OpenRouter key, it is encrypted (AES-256-GCM) before storage and decrypted only to run your own requests
  • Billing data handled by Stripe — we do not store your banking details, only the customer id and the subscription status
  • Public board participants email address verified by one-time code, votes and posted feedback. Verification emails are delivered by Resend

Purposes of processing

  • Providing and operating the minddy service
  • Managing your account, subscription and associated quotas
  • Running the AI features you trigger (assistant, dictation, coding agent)
  • Improving the product (analytics, with your consent)
  • Service-related communication (updates, incidents, billing)

Legal bases

  • Performance of the contract processing the data needed to provide the service and to bill for it
  • Legitimate interest service security, abuse prevention and aggregated traffic measurement
  • Consent analytics cookies (PostHog), collected through the consent banner and revocable at any time
  • Legal obligation retention of accounting and invoicing records

Retention periods

  • Account data kept until your account is deleted
  • Work content kept until you delete it or until your account is closed
  • Coding agent runs the execution state (messages exchanged with the model, code excerpts) is kept for the duration of the run and its resumptions; afterwards only the metadata (branch, pull request, status) stays attached to the issue
  • Board participants kept while the board is active, then deleted when the board is closed or at its publisher's request
  • Analytics data 12 months maximum
  • Billing data as required by law (10 years for accounting records)

Transfers and sub-processors

Your data is hosted within the European Union (Supabase EU region, Ireland). The application is hosted by Vercel (a company based in the United States); any transfers to third countries are covered by appropriate safeguards (Standard Contractual Clauses). Data processing agreements (DPAs) are in place with our sub-processors.

Sub-processors involved: Supabase (database, storage, authentication), Vercel (application hosting, agent execution environments, custom domains), Stripe (payment), OpenRouter (AI processing), PostHog (analytics, with consent), Resend (transactional email).

If you choose to sign in with Google or GitHub, those services handle your authentication as independent controllers, under their own policies. If you link a GitHub or GitLab repository, access to that repository happens at your initiative and under your responsibility.

Feedback boards: minddy as a processor

When you open a public feedback board, you become the controller for the data of the people who take part in it, and minddy acts as a processor: we process that data only to provide you with the board, on your instructions.

Categories involved: verified email address, votes, published feedback and related exchanges. We never use them for marketing, nor to train models. You can request their deletion at any time; they are deleted along with the board.

Coding agent: execution environment

When you trigger the coding agent, the linked repository is cloned into an isolated, ephemeral virtual machine provided by Vercel (Sandbox), destroyed at the end of the run. The code needed for the task is sent to the model through OpenRouter. minddy keeps no copy of the repository beyond the run.

Connected third-party applications

When you authorize a third-party application (an AI assistant over MCP, for example), it receives an access token and can read and modify your account's data within the permissions granted. The list of these applications, and the ability to revoke them, lives in your account settings.

Your rights (GDPR)

Under the GDPR, you have the following rights over your data:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to object
  • Right to restriction of processing
  • Right to lodge a complaint with a supervisory authority

To exercise these rights, write to us at hello@minddy.app. If a dispute remains unresolved, you may refer the matter to the CNIL.

Data breach notification

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, along with the competent supervisory authority (CNIL), in accordance with articles 33 and 34 of the GDPR.