Privacy policy
Last updated: August 2026.
Courtesy translation. In case of any discrepancy, the Spanish version prevails.
Who we are
MindHaOS (“the app”) is a personal organisation application. Contact: [email protected] · 55 1013 2542.
What data we collect
- Account: your email address and an encrypted password, managed by Supabase (our backend provider).
- App data: whatever you record in your rooms (routines, meals, finances, notes, photos…). It lives on your device first and, with sync on, is synchronised encrypted in transit with our servers so that your house follows you between devices.
- Payments: processed by RevenueCat and Stripe. We never see or store your card; we only receive the status of your purchase and your subscription.
- AI usage: counters of credits consumed (not the content of your conversations, which is sent to the AI providers solely to generate each reply and is not used for training).
- Camera and microphone: only when you turn them on (AR mask, chat photo, voice dictation). The mask is processed on your device; the dictation audio and the photos you attach to the chat are sent to the AI providers solely to generate that reply.
- Health and wellbeing data: whatever you record about exercise, meals, medications, medical appointments or cycle is stored for you like any other app data; it is never sold or used for advertising.
Scope of the health features
MindHaOS is a personal planner, not a medical application. Its health features are a log you write yourself plus a few reminders: the app does not diagnose, does not interpret symptoms, does not recommend doses or treatments, does not check drug interactions and is no substitute for consulting a health professional. Cycle estimates are derived only from the data you enter and are indicative. It is not a health product or a medical device, and it does not connect to medical records, insurers or healthcare providers.
What we use it for
- Giving you access to your account, your purchase and your subscription.
- Syncing your data between devices and backing it up.
- Running the AI features against your credit allowance.
- We do not sell your data or share it with third parties for advertising.
Storage on your device
The app stores information on your own device and reads it to work: a local database (IndexedDB) with your house data and your files, and the local storage of your browser with your preferences — language, theme, welcome state — and the session token that keeps you signed in. We do not use our own cookies or similar technologies for advertising, analytics or tracking. You can erase all of it from your browser settings or by uninstalling the app.
The services we integrate may store or read information on your device when you use them: Google when you sign in and when you authorise YouTube API Services (see the Google cookie policy), and likewise TikTok and Meta when you connect those accounts. That information is handled by them under their own policies.
Connected social media accounts
If you connect your YouTube, TikTok, Facebook or Instagram account, we store the access tokens that network gives us, encrypted on our server, together with the name and picture of the account or Page you choose. We use them only to publish to your own account the videos you decide to publish from the video editor, at the moment you tap Publish. We do not read your videos, posts, comments, messages or any other data from those accounts, and we never post anything on our own. The tokens are kept until you disconnect the account in Settings → Connected accounts or delete your MindHaOS account; you can also revoke access in each network’s security settings (Google: myaccount.google.com/permissions).
For YouTube, the app uses YouTube API Services; by connecting your account you agree to the YouTube Terms of Service, and the Google Privacy Policy applies.
How we protect your data
Everything that travels between the app and our servers is encrypted in transit with HTTPS/TLS, and the data you sync is encrypted at rest on the Supabase infrastructure. Your password is never stored in the clear: Supabase Auth keeps only its hash. Every account is isolated from the rest — the tables have row-level isolation enabled and only the server functions, after checking your session, can read or write what is yours — administrative access is limited to the people who operate the service, and nobody reviews the contents of your house. Your data is not sold, is not used for advertising and is not used to train AI models.
The tokens of the social accounts you connect get extra protection because they are sensitive data: before being stored they are encrypted with 256-bit AES-GCM using a key that exists only as a server secret, is not in the code, never travels to your device and cannot be read from the database. The app never receives a token: when it asks for your connected accounts it only gets the name, the picture and the expiry date. The token is decrypted inside the server, at the moment of publishing the video you asked for, and is used for nothing else. It is deleted as soon as you disconnect the account or delete yours, and a daily process reviews idle connections and removes the ones that are no longer valid.
If you cancel your subscription
Your local data stays on your devices. Synced data remains stored (inaccessible until you renew) and you can delete it for good by deleting your account.
How to delete your account and your data
From the app: Editor → Settings → Account. Deletion removes your user, your synced data and your files from our servers; only the billing records the law requires us to keep are retained.
Providers
- Supabase (database, authentication and files).
- RevenueCat and Stripe (purchases, subscriptions and payments).
- Anthropic and Google (AI replies and images, on demand).
- OpenAI (voice transcription and AI image fallback, on demand).
Changes
If this policy changes, we will publish the new version here with its date. Questions are answered at the contact address.