Privacy Policy

Last updated: August 8, 2026

The short version. What you write is encrypted on your device before it is stored, and we do not hold the key that decrypts it, so our database only ever holds ciphertext we cannot open. When you choose to use an AI feature, your device decrypts what that request needs and sends it through our AI proxy to our AI provider. We do not store that plaintext, and our provider does not train on it, though it may hold it briefly. Section 5 says exactly how long. We do not sell your information, we do not advertise to you, and we use no advertising networks or cross-site tracking. We do keep a small amount of information we can read, such as your email address, cookieless measurements of which pages get visited and how fast they load, and records of which features get used. Section 4 describes what that is.

1. Introduction and Scope

KindMind Labs LLC (“Company,” “we,” “us,” or “our”) operates KindMind, BookPath, and other websites and applications that link to this policy (each, and together, the “Service”). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use the Service. It applies to every product we operate under it, whether or not that product is named here.

2. How This Policy Stays Accurate As the Product Changes

The Service is actively developed, and features are added, renamed, and removed over time. So this policy describes categories of information and processing rather than a fixed list of features. Where a feature is named below, it is an example, not a limit.

Two commitments make that workable, and they hold regardless of what we ship next:

  • The private-content rule. We store the substance of what you write, your journal entries, your conversations with AI features, your responses inside guided programs, the summaries built from them, and your display name, only in client-side encrypted form. There are two exceptions, and both are described before you use them: things you deliberately send us to read, such as a support message, a testimonial, or product feedback; and the temporary plaintext processing that happens when you choose a feature that requires it, such as an AI feature, described in Section 5.
  • Readable information stays in stated categories. Section 4.2 lists the categories of information we currently hold in a form we can read. We will update this policy before we start collecting a materially different category, or using readable information for a materially different purpose, and where the change is material we will tell you by email before it takes effect. Where the law requires your consent for a new category or purpose, we will ask for it first.

3. Information We Collect

3.1 Information you provide

  • Account information: your email address, password, and display name.
  • Content you create: everything you write inside the Service, such as journal entries, conversations with AI features, responses within guided programs, and anything the Service summarizes from them on your behalf.
  • Content you send to us on purpose: support and contact messages, product feedback, and testimonials you choose to submit. These are addressed to us, so they are not encrypted from us.
  • Payment information: collected and processed directly by our payment processor. We do not store card numbers, bank details, or other payment instrument information.
  • Referral, invite, and promotional codes you share or redeem, and the fact that they were used.
  • Settings and preferences, such as whether AI features are on, whether your journal entries may inform AI memory, and which optional emails you want.

3.2 Information collected automatically

  • Authentication cookies: session tokens managed by our authentication provider to keep you logged in.
  • Product usage events: our own first-party records of what happened in the app, described in Section 6.
  • Technical request data: our hosting and infrastructure providers process ordinary web request metadata, including IP addresses, for delivery, reliability, abuse prevention, and security. We do not use it to build profiles, to track you across sites, or for advertising.
  • Time zone: your browser’s time zone name, recorded when you sign up and when you sign in, so that dates, streaks, and scheduled emails line up with your day. A time zone is approximate location information, so we are naming it here rather than filing it under settings.
  • Page performance and traffic measurement: our hosting provider measures page views and page load performance for the site. See Section 3.3 for what this does and does not include.
  • Local preferences: theme, font settings, and dismissed prompts stored in your browser. These stay on your device.

3.3 Measurement, and what we do not collect

We use the built-in page analytics and page speed measurement offered by Vercel, who host the site. Between them they record which page was viewed, how quickly it loaded, the site you arrived from, and general device and browser type and country.

What makes this different from ordinary web analytics, and the reason we were willing to keep it: it sets no cookies, it does not follow you to other websites, it does not build an advertising profile, and it is never joined to your account. Neither measurement ever receives anything you write.

We also rewrite the address before either measurement is sent. Pages inside the app are reported as the section you were in and nothing more, so that you opened a guided program is measured, while which one is not. Public pages, like this one or a blog post, report their full address, because that address is the same for everyone reading it and says nothing about you. The query string is dropped entirely, so an address that happened to carry your email address never leaves your browser. Anything we add later is treated as part of the app, and therefore trimmed, until we decide otherwise.

Beyond that, we use no advertising networks, no tracking pixels, no session recorders, and no cross-site tracking technology of any kind. We do not collect device fingerprints, browsing history, contacts, or precise location. We do not buy personal information from data brokers. We never send anything you write to any analytics provider.

4. What We Can and Cannot Read

4.1 Encrypted content, which we cannot read where it is stored

Content you create inside the Service is encrypted with AES-256-GCM on your device, before it is transmitted to our servers. This covers your journal entries, your conversations with AI features, your responses inside guided programs, the summaries the Service builds from them, your display name, and any equivalent content in features we add later.

Your device generates a random key that encrypts your content. That key is itself locked with a second key derived from your password, and only the locked version is ever sent to us. To be precise about the password: the one you use to sign in does travel, over an encrypted connection, to the service that authenticates you, exactly as it would on any site. What never leaves your device is the key derived from it and the unlocked key it protects, which is why we cannot decrypt the content we store. This is commonly called zero-knowledge encryption. Two honest notes about the limits of that. First, because the locked key we hold is unlocked by your password, the protection is only as strong as the password you choose. Second, this describes content as we store it. When you choose a feature that needs to work with your words, such as an AI feature, your device unlocks what that request needs and sends it through the path described in Section 5.

A recovery key is generated when you create your account so you can regain access if you forget your password. That recovery key is the key to your content, not a code we can look up, so treat it like the content itself and do not share it. You are solely responsible for storing it. If you lose both your password and your recovery key, your encrypted content cannot be recovered by anyone, including us.

4.2 Information we can read

A limited set of information is stored in a form we can read, because the Service cannot function otherwise or because you sent it to us deliberately. These are the categories we currently hold:

  • Account and billing data: your email address, account identifiers, subscription and plan status, trial dates, promotional and referral code usage, and timestamps. Your email address and sign-in details are held by our authentication provider.
  • Settings and preferences: whether AI features are on, whether your journal entries may inform AI memory and when you decided that, which optional emails you want, which prompts you have dismissed, backup reminders, and similar choices we need in order to apply them.
  • Structural metadata: how many items you have, when they were created or updated, how long an entry is, which guided program you selected, which day you are on, and similar non-content details needed to render the app. To keep that category from quietly growing: structural metadata never includes the substance of what you write, and it never includes a new readable conclusion we have drawn about your health, beliefs, sexuality, or other sensitive subject. If we ever start storing a readable inference of that kind, it gets its own entry in this list before we begin, and your consent first where the law requires it.
  • Which guided program you chose. Guided programs are named, and the name is stored in a form we can read, so we can tell that an account is working through a program on, for example, grief or sobriety. What you write inside it stays encrypted. If that matters to you, the whole catalog is browsable without starting anything.
  • Product usage events: see Section 6.
  • Automated safety records: see Section 5.
  • Records of automated decisions: a content-safe record of what the Service decided to show or send you, and why, as described in Section 7.
  • Messages you address to us: support and contact messages, product feedback replies, and testimonials. These are plaintext by design. We can read them, which is the point of them. Please do not include anything in them you would not want us to see.
  • Saved catalog selections: where a feature lets you save an item from a public catalog, such as a book or a guided program, we store which catalog item you saved.
  • Support identifier: a code derived from your account ID that you can safely paste into an email so support can find your account without you sharing anything you wrote. It cannot be turned back into your account ID by anyone who only has the code, but we can match it to your account.
  • Request and infrastructure metadata: the ordinary web request data described in Section 3.2, handled by our providers for delivery, reliability, and security.

5. AI Features and the Automated Safety Check

When you use an AI feature, your browser decrypts the content that request needs and sends it over an encrypted connection through an AI proxy we operate, on to a third-party AI provider, which generates a response. That content is never stored by us, and it never reaches our application servers or our database. The proxy is ours, it does run on our infrastructure, and it necessarily handles your words in the clear for the moment it takes to pass them along. It keeps no database, writes no message bodies to its logs, and retains nothing between requests.

Our AI provider handles that content under its commercial API terms. It does not use it to train its models. Under the retention practices that apply to our account, it may keep the request and the response for up to 30 days, subject to its own stated exceptions for safety, abuse prevention, and law. We do not have a zero-retention arrangement with it, and we would rather say so than let you assume otherwise. For speed, a short-lived cache at the provider may also hold the repeated opening portion of a conversation for a few minutes so it does not have to be re-sent with every message.

Before you have an account. If you answer the questions on our signup flow, those answers are sent through the same AI proxy so the flow can respond to them. That happens before an account or an encryption key exists, so those answers are not encrypted on the way. They are not stored in that form. If you go on to create an account, they are encrypted on your device and saved as part of your account. If you do not, nothing about you is kept beyond the safety record described below, which carries no account identifier.

Some AI features also periodically summarize your recent content so the AI can be useful over time. Summarization runs through the same path, and the resulting summary is re-encrypted on your device before it is saved. Whether your journal entries may be included is a setting you control, and it is off until you turn it on. You can turn AI features off entirely, and you can clear the stored summaries, in your account settings.

Automated safety check. Messages you send to certain AI features, including the signup questions above, pass through an automated check intended to recognize signs of crisis or risk so the Service can show supportive resources. The check is a separate automated call to an AI model under the same terms. Two kinds of record can result, and neither ever contains your words:

  • If the check flags a concern, or if the check itself fails to run, we store a record linked to your account containing the category, a severity level, the action taken, for example “crisis resources shown,” and related technical details such as which feature it came from and how confident the check was. We never store the message content or the check’s reasoning.
  • Separately, we keep operational records of each time the check runs, noting the category it saw and how long it took, so we can confirm the check is working. These carry no account identifier of any kind. We avoid calling them anonymous, because one is written at the same moment as the account-linked record above, and we could in principle line the two up by their timestamps. We do not do that, and we do not keep them beyond 90 days.

This check is not a monitoring service. No person reviews your content. It is not infallible, and it can be wrong in both directions: it will miss things, and it can also offer you crisis resources when you were not in crisis, or set aside a reply it misjudged. If it misreads you, tell it so and carry on. Please see Section 4 of our Terms of Service, and never rely on the Service in an emergency.

A fuller technical description is on our How AI Works page.

6. Product Usage Events

We keep our own first-party record of what happens in the app: which feature was opened, which action succeeded or failed, which route an error came from, and similar operational facts, along with your account identifier and a timestamp. We use these to keep the Service working, to diagnose errors, and to understand which parts of the product are useful.

These records are designed never to contain the content you write, and we review them against a list of what is allowed in them. They are stored on our own infrastructure. They are not sold, and they are not sent to any advertiser or data broker. When you delete your account, we permanently remove your account identifier from these records. The rows themselves remain, with nothing in them pointing back to you, and we use them only to understand how the product behaves in aggregate. We do not try to re-attach them to anyone.

7. Automated Decisions

The Service decides automatically what to show you and when. It may decide to display a prompt or supportive message, to send you an optional email, or to grant an account benefit such as a trial extension. These decisions use account and usage signals and, in some cases, AI. Where a decision draws on what you have written, your browser unlocks that content and sends it along the same AI path described in Section 5, and the record we keep of the outcome is redacted in your browser before it reaches us, so that what we store notes only that content was involved. Some of these records hold the wording the AI chose to show you.

These decisions affect only what appears in the app, which optional emails you receive, and whether you receive an optional benefit. They do not produce legal effects or similarly significant effects on you, and they are never used to deny you access, set your price, or assess you in any way. You can turn AI features off and unsubscribe from optional emails at any time, and you may contact us to ask a person to review any automated decision that affects you.

8. How We Use Your Information

We use your information to:

  • Provide, operate, maintain, and improve the Service.
  • Authenticate you and secure your account.
  • Store and return your encrypted content to you.
  • Route content you submit to an AI feature to our AI provider, including the automated safety check described in Section 5.
  • Process subscription payments, trials, promotions, and referrals.
  • Send you the emails described in Section 9.
  • Detect, investigate, and prevent fraud, abuse, and security incidents, and enforce our Terms.
  • Respond to your support requests.
  • Comply with legal obligations.

We do not use your personal information for advertising, for behavioral profiling, for training AI models, or for any purpose other than operating the Service.

9. Emails We Send

We send two kinds of email, and you can always tell them apart by whether they have an unsubscribe link.

  • Account emails, which you cannot unsubscribe from while you have an account: welcome and verification, password and security notices, billing and trial notices, and legal or policy notices.
  • Optional emails, which every message links to unsubscribe from: occasional suggestions, encouragement, tips, offers, and product news. Whether and when you receive one may be decided automatically as described in Section 7. Unsubscribing costs you nothing and never limits your access.

Optional emails are composed from account and usage signals only. They are not based on the content of your writing, and the process that decides them has no access to it. That decision is made by an AI model, so a summary of those signals, together with an account identifier that is not your email address or your name, is sent to our AI provider once a day. Nothing you have written is included.

10. Service Providers and Sharing

We use a small number of third-party providers, solely as necessary to operate the Service, in the following categories: application hosting and page measurement; database and authentication; AI processing; edge request routing; payment processing; transactional email; and rate limiting and abuse prevention. Providers receive only what they need for their function, and are bound by contract to use it only to provide services to us.

Our AI provider is Anthropic PBC. Because AI processing is the one place your unencrypted words leave your device, we name that provider here rather than describing it only by category. If we ever change it, we will update this policy before a different provider begins handling your content. A current list of all the providers we use is available on request at hello@kindmind.com.

We may change, add, or remove other providers as needed to operate the Service, and we will update this policy to reflect material changes.

We may also disclose information if required by law, subpoena, or valid legal process, to protect our rights, safety, or property or those of others, or in connection with a merger, acquisition, or sale of assets, in which case the successor remains bound by this policy or gives you notice before changing it. Because your stored content is encrypted with a key we do not hold, we cannot produce it in readable form in response to any legal request. What we could produce is the readable information in Section 4.2, which includes the automated safety records described in Section 5.

We will never sell, rent, trade, or share your personal information for advertising or cross-context behavioral advertising. We do not share your data with advertisers or data brokers, and we never send anything you write to an analytics provider.

11. Cookies and Local Storage

We use only essential cookies required for authentication, session management, and security. We do not use tracking cookies, advertising cookies, or any non-essential cookies. Our page measurement sets no cookies at all. Your browser’s local storage holds your visual preferences and dismissed prompts, and your encryption key is held in your browser’s session storage only for the duration of your session and is never transmitted to us. In our mobile app, your key is held in the device’s secure keychain, protected by your device unlock, so that it survives closing the app. It is removed when you sign out or delete your account.

Do Not Track.Some browsers can send a “Do Not Track” signal. There is no consistent standard for what a site should do with it. We do not track you across other websites in the first place, so there is nothing for the signal to switch off, and our behavior is the same whether you send it or not.

12. Data Retention and Deletion

We retain your information for as long as your account is active or as needed to provide the Service.

Deleting one item. You may delete individual items through the Service. Deleting one removes it from our live database outright. Two things do not go with it: a copy may remain in an encrypted backup until that backup expires, and if an AI feature had already drawn a memory from that item, the memory is a separate record that you delete separately in your account settings.

Deleting your account. You may delete your entire account from your account settings. Deletion is immediate and permanent, and there is no recovery period. Please export anything you want to keep before you delete. Your content, memories, safety records, support messages, feedback, and testimonials are removed. Your product usage records are stripped of your account identifier and kept in the de-linked form described in Section 6. Encrypted backups expire on our provider’s backup cycle. You may also request deletion at hello@kindmind.com.

Deleting your account cancels an active subscription, but it does not by itself erase the billing history your payment processor keeps, which they retain for the period tax and accounting law requires. If you have a subscription, cancel or check it in the billing portal as well.

How long we keep things. Encrypted content, until you delete it or your account. Account and settings data, while your account is active. Automated safety records linked to your account, while your account is active. Safety operational records carrying no account identifier, no more than 90 days. Support messages, feedback, and testimonials, until you delete your account or ask us to remove them. Billing and tax records, for the period required by law, held by our payment processor. Product usage records, indefinitely, de-linked from you once your account is deleted.

13. Security and Breach Notification

We use layered technical and organizational safeguards suited to how sensitive the information is. These include client-side AES-256-GCM encryption of your content, database access controls that keep one account’s rows from being readable by another, encrypted transport, scoped service credentials, and rate limiting on sensitive endpoints. These measures reduce risk. No system can promise absolute security.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident triggers a notification obligation under applicable law, we will notify you and any required regulator within the time that law requires. We may also tell you about an incident when we think you should know, even where no law requires it. You are responsible for maintaining the security of your credentials and recovery key, and because the strength of your encryption depends on your password, please choose a strong one.

14. Your Rights

Depending on where you live, you may have the right to:

  • Access: request a copy of the personal information we hold about you.
  • Correction: update your display name, email address, or password in your account settings.
  • Deletion: delete individual items or your whole account, at any time, yourself.
  • Portability: export your data in a machine-readable format, at any time and on any plan. The export covers your profile, your encryption key material, your journal entries, your AI memories, your Guide threads and messages, and your Paths with their messages and day plans. Encrypted content comes out encrypted, because we hold no key that could produce it otherwise, and your password or recovery key unlocks it.
  • Objection or restriction: object to or request restriction of certain processing.
  • Withdraw consent: where processing relies on your consent, withdraw it at any time.
  • Non-discrimination: exercise these rights without being charged more or given a lesser service.

Contact hello@kindmind.com to exercise any right. We will respond without undue delay and within the period the applicable law allows, and we will tell you if we need more time where the law permits it. We may need to verify your identity through the email address on your account. You may use an authorized agent where law permits. If we decline a request, we will tell you why and how to appeal.

We cannot access, correct, or produce your encrypted content in readable form, because we do not hold the key. You can already do all of those things yourself inside the Service.

15. United States State Privacy Rights

We make the rights in Section 14 available to you as described there, whether or not a particular state privacy statute applies to us or to your account. Where a state law gives you additional rights that apply to us, we will honor those too. That includes the right to appeal a denied request by replying to our response. This section is written with residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Washington, and Nevada particularly in mind.

Notice at collection. The categories of personal information we collect are identifiers (email address, account and support identifiers), commercial information (subscription and payment status), internet activity and device information (the product usage events in Section 6, the page measurement in Section 3.3, and ordinary request metadata), approximate location (your time zone, and the country the page measurement in Section 3.3 derives), your settings and the choices you have made, the guided programs and catalog items you select, the automated safety records in Section 5, communications you send us, and the content you create, which we hold only in encrypted form. We collect them for the purposes in Section 8, from you and from your use of the Service. We retain them as described in Section 12.

Sensitive personal information. What you write may touch on health, beliefs, sexuality, or other sensitive subjects, and we hold it only in encrypted form, so we cannot read what we store. We never use sensitive information to infer characteristics about you for advertising, pricing, eligibility, employment, housing, insurance, credit, or any other consequential decision, and we do not sell or share it.

There are two places where automated processing does derive something limited from what you write, and we would rather name them than hide behind the encryption. The automated safety check in Section 5 classifies a message by risk category and severity so the Service can decide whether to show supportive resources. And when you choose a guided program, the program you chose and the approach the AI selected for it are stored in a form we can read. Both exist only to provide the feature you asked for.

We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 18. We do not use or disclose personal information for cross-context behavioral advertising or targeted advertising, and we do not profile you in furtherance of decisions producing legal or similarly significant effects. No provision of our Terms or of this policy waives or limits any right that a state privacy law makes non-waivable.

Washington and Nevada consumer health data. KindMind is not a medical, mental health, therapeutic, or clinical service, and we do not present it as one. Washington and Nevada nonetheless define “consumer health data” broadly enough to include information a service derives about you using an algorithm, and the automated safety check in Section 5 does derive a risk category from a message. So some of what we hold may fall under those laws even though the product is a journal. We have published a separate Consumer Health Data Privacy Policy covering what that includes, why we process it, who it goes to, and how to exercise the rights those laws give you.

16. European Economic Area, United Kingdom, and Switzerland

KindMind Labs LLC is the controller of your personal information. Our legal bases for processing are: performance of a contract (operating the Service, your account, and your subscription); legitimate interests (security, fraud prevention, keeping the Service working, and understanding which features are used, balanced against your rights); consent (optional AI features that use your journal entries, and optional emails, each of which you can withdraw at any time); and legal obligation (tax, accounting, and responding to lawful requests).

Special categories. Content you choose to send to an AI feature may contain information treated as a special category of personal data, such as information about health, beliefs, political opinions, or sexuality. Where an Article 9 condition is needed for that optional processing, we rely on your explicit consent, given when you turn the feature on. You can withdraw it by turning AI features off in your account settings. Withdrawing does not affect processing that was lawful before you withdrew.

What we need in order to provide the Service. We need an email address, a password, and the account and subscription information required to run your account. Without those we cannot provide the Service at all. AI features, journal-informed AI memory, and optional emails are all genuinely optional, and declining them costs you nothing but those features.

Where your data goes. Our service providers may store or process personal information in the United States and in other countries where they operate. Our AI proxy runs on a global edge network, so an AI request is handled at the location nearest you, which outside the US means outside the US. Requests sent to our AI provider may be kept by that provider for the period described in Section 5, so that leg is not only transit.

Where European, UK, or Swiss law requires a transfer mechanism, we rely on the appropriate one for that transfer, which may include the European Commission’s Standard Contractual Clauses for transfers under the EU GDPR, the UK International Data Transfer Agreement or UK Addendum for transfers under the UK GDPR, and any Swiss adaptations required. Your stored content travels already encrypted with a key we do not hold, which is a safeguard beyond those clauses. You may contact us for more detail about the safeguards that apply to you.

You have the rights listed in Section 14, and the right to lodge a complaint with your local supervisory authority. Regarding automated decision-making under Article 22, please see Section 7: the automated decisions we make do not produce legal effects or similarly significant effects, you can switch them off, and you may request human review.

17. Children’s Privacy

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe someone under 18 has provided us with personal information, please contact us at hello@kindmind.com.

18. Importing Data From an Earlier Version

If you move an account from an earlier version of KindMind, the import works differently from everything else described above, and only during the import itself. With your authorization, content from the older service is transferred to your browser, encrypted there with your new key, and then stored. During that transfer the content is protected in transit by encryption, but it is briefly readable to the migration process on our server so it can be handed to your browser. It is never written to our database and never logged. Once the import finishes, the content is subject to Section 4 like everything else, and the import path is retired once migration closes on September 1, 2026.

Importing is entirely optional, and you can start a new account instead.

19. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy here with a revised “Last updated” date. Changes apply going forward, from their effective date. Where the law requires your consent to a change, or where we would begin processing a materially new category of information about you, we will ask before the change applies to you. If you do not accept a change, you may delete your account.

20. Contact Us

KindMind Labs LLC
Email: hello@kindmind.com