Legal

Privacy Policy

Effective date: June 6, 2026

EternalMind Labs ("EternalMind Labs," "we," "us," or "our") operates Mindleaf, a journaling and self-reflection app (the "App"). This Privacy Policy explains what information we collect when you use the App, how we use it, who we share it with, and the choices you have. By using Mindleaf, you agree to the practices described here.

1. Information we collect

Account information. When you create an account, we collect your email address, display name, and password (handled securely by our authentication provider — we never see or store your raw password). If you sign in with Apple or Google, we receive your name, email address, and an authentication token from that provider. You may optionally add a profile photo.

Journal content. Mindleaf is built around the things you write, say, and reflect on — journal entries, conversations with Bud (our in-app AI companion), voice reflections and their transcripts/summaries, "deep dive" exercises, personality test results, and the weekly life summaries the App generates for you. We refer to all of this as "Your Content."

Usage and device information. We collect basic product-analytics data — such as which screens and features you use, how often you journal, and your streak and milestone progress — so we can understand how the App is used and improve it.

Permissions you grant. If you enable them, we may access your microphone (for voice reflections and audio attachments), your photo library (to save milestone images you choose to export), notifications (for journaling reminders), and limited Health data such as sleep schedules (used only to time reminders more thoughtfully — this stays on your device and is never uploaded).

Onboarding survey. If you choose to complete our optional onboarding survey, we collect the answers you provide (such as your name, email, age range, what brings you to journaling, and how you heard about us) so we can better understand and support new users.

2. How Your Content is protected

Journal entries, AI conversations, deep dive sessions, personality test results, and weekly life summaries are encrypted on your device (AES‑256‑GCM) before they ever leave it. That means this content is unreadable to us in storage — only you, signed into your account, can decrypt and read it. Account metadata (like your display name or profile photo) and app usage statistics are not end‑to‑end encrypted, since we need them to operate basic account features.

3. How we use your information

  • To provide the core App experience — saving and syncing your entries, generating reflections, summaries, and insights, and powering conversations with Bud.
  • To maintain your account, including authentication, sign‑in, and account recovery.
  • To process payments and manage subscriptions and in‑app purchases through Apple's App Store.
  • To send you reminders and notifications you've opted into.
  • To understand how people use Mindleaf so we can fix problems and build a better product.
  • To respond to support requests and communicate with you about your account.
  • To detect, investigate, and prevent fraud, abuse, and security issues.

We do not sell your personal information, run advertising, or use Your Content (journal entries, AI conversations, voice reflections, etc.) to train third‑party AI models. We also do not "track" you — meaning we never combine your data with data from other companies to target ads to you, on Mindleaf or anywhere else.

4. AI processing

When you chat with Bud, generate a journal entry, or request a summary or insight, the relevant text is sent — through our own backend, never directly from your device to a third party — to a third‑party AI model provider for processing, and the response is returned to you. This content is transmitted securely and is not used by us or our AI provider to train models on other users' behalf.

5. Who we share information with

We work with a small number of service providers who process data on our behalf, under appropriate confidentiality and security obligations:

  • Supabase — our backend infrastructure provider, used for authentication, database storage, file storage (e.g., audio and images you attach), and serverless processing.
  • Apple and Google — for Sign in with Apple / Sign in with Google, and for processing payments and subscriptions through the App Store.
  • PostHog — a product analytics provider that helps us understand feature usage and improve the App.
  • Our AI processing provider — used solely to generate the AI features described above.
  • Google Sheets / Google Apps Script — used only to record responses to our optional onboarding survey, if you choose to complete it.

We may also disclose information if required by law, to protect the rights, property, or safety of Mindleaf, our users, or others, or in connection with a merger, acquisition, or sale of assets (in which case we'll make reasonable efforts to notify you).

6. Your choices and rights

  • Access and export. You can export your journal entries from within the App at any time.
  • Deletion. You can permanently delete your account and all associated data — including journal entries, AI conversations, voice reflections, personality results, and media — directly from Settings in the App. This action is irreversible.
  • Notifications. You can turn reminders and notifications on or off at any time in Settings or at the system level.
  • Permissions. You can grant or revoke microphone, photo library, notification, and Health permissions at any time through your device's system settings.

Depending on where you live, you may have additional rights over your personal information, such as the right to request a copy of the data we hold about you or to ask us to correct it. You can exercise any of these rights by contacting us at the email below.

7. Data retention

We retain your information for as long as your account is active, or as needed to provide you the App. If you delete your account, we delete Your Content and associated personal information from our active systems; residual copies may briefly persist in backups before being purged on our standard backup rotation schedule.

8. Children's privacy

Mindleaf is intended for users who are 17 years of age or older. We do not knowingly collect personal information from anyone under 17. If you believe a minor under 17 has provided us with personal information, please contact us so we can remove it.

9. Security

We use industry-standard safeguards — including encryption in transit (HTTPS/TLS) and, for your most sensitive content, on-device encryption before it ever reaches our servers — to protect your information. No system is perfectly secure, but protecting your reflections is central to how we've built Mindleaf.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you in the App or by email before the changes take effect. The "Effective date" at the top of this page reflects the most recent revision.

11. Contact us

If you have questions about this Privacy Policy or how we handle your information, reach us at support@eternalmindlabs.xyz.