Privacy Policy for MindLumos

Last updated: December 4, 2025

Thank you for using MindLumos ("we," "us," or "our"). This Privacy Policy outlines how we collect, use, and protect your personal and non-personal information when you use our website and services (the "Service").

By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree with the practices described in this policy, please do not use the Service.

1. Information We Collect

When you open an account, we ask for your email address and a password. When you upload study materials (such as PDFs, images, or audio files), we store the files and the content extracted from them to provide the service. Our servers also record routine technical data—such as IP address and browser version—so the app can function safely. We do not knowingly collect special-category or children's data, and we never sell or rent any information you provide.

2. Information from Google API Services

When you use Google Sign-In to create an account or log in, we access certain information from your Google Account in compliance with the Google API Services User Data Policy.

  • What we access and why: We request access to your basic profile information (name) and your email address. Your email address is used as a unique identifier for your MindLumos account and for essential service-related communications. Your name is used to personalize your experience within the application.
  • How we use it: The data obtained through Google Sign-In is strictly used to provide and improve our app's core, user-facing features. This data is never used for advertising purposes, nor is it ever sold or transferred to third parties. Our use fully adheres to the Limited Use requirements outlined in Google's policy.
  • How we store it: Your name and email are stored securely alongside your other account data, protected by the security measures outlined in Section 7 of this policy.

3. How We Use Your Information

We use your details to authenticate you, process payments, link each document to your account, generate study tools with AI, send essential service-related emails, and measure the overall performance of the platform. Optional marketing emails are sent only if you have opted-in. Our legal grounds under the EU & UK GDPR are contract performance and legitimate interest in running a secure and effective service.

4. AI Processing and Service Partners

AI Processing: To transform an uploaded document into study tools, we send the file—over an encrypted connection—to our AI service partners, such as Google's AI models. For audio files, we may use third-party transcription services. These providers act as our processors: they may temporarily store encrypted data to generate and return the output, after which it is automatically deleted. They are contractually forbidden from training their models on your content. Because some servers are located in the United States, transfers rely on appropriate data protection frameworks and Standard Contractual Clauses.

Other partners: Uploaded files are held in an encrypted Google Firebase bucket. Stripe processes all payments on their secure pages, never on ours. These providers act under written agreements that require them to protect your data.

Sub-processors

Service ProviderPurposeLocationSafeguards
Google CloudPrimary AI processing and study tool generationUnited StatesEU-US DPF, Standard Contractual Clauses
Audio Transcription ServicesSpeech-to-text for audio filesUnited StatesStandard Contractual Clauses
Google FirebaseFile storage, authentication, and databaseUnited StatesEU-US DPF, Standard Contractual Clauses
StripePayment processingUnited StatesEU-US DPF, Standard Contractual Clauses

5. Storage, Retention, and Deletion

Files for Free users are retained for 30 days, while files for Pro users are retained for 365 days. You may delete any file or your entire account at any time from your dashboard. When you close your account, all remaining personal data will be immediately deleted except where we are legally obliged to keep bookkeeping records.

6. Cookies

Essential cookies keep you signed in and guard against fraud; they load automatically and are necessary for the service to function properly.

7. Security

All traffic is encrypted with TLS and data at rest is protected with AES-256 on Google Cloud. Access to production systems follows least-privilege rules and we review security controls regularly, yet no online service can guarantee absolute security.

8. Data Sharing and Third Parties

We do not sell, share, or disclose your personal information to any third parties for marketing purposes. Your data is kept strictly for use within our product. We do not allow our employees or contractors to read your file contents unless it is required for security purposes (such as investigating abuse), to comply with a legal obligation, or with your explicit consent for support.

9. Your Rights

You have the right to request access to or deletion of your data. To exercise this right, please contact us using the information provided below.

10. Business Transfers

If MindLumos is ever sold, merged, or otherwise transferred, user data may move to the new owner under the same commitments set out in this notice.

11. Changes to this Policy

We may update this document occasionally. Material changes will be announced by email at least fourteen days before they take effect, and the "last updated" date will change accordingly.

12. Contact

MindLumos is operated by The MindLumos Team. For any privacy questions or to exercise your rights, email privacy@mindlumos.com.