Privacy Policy

Version 2026-05-10 · Effective May 10, 2026

1. What data we collect

MindMap collects information you explicitly enter, including daily wellness check-ins (mood, sleep, anxiety, depression, mania, focus, productivity, HRV, migraines, body sensations, notes), journal entries, medication schedules and adherence, routines, goals, therapy session records, reminders, and triggers. We also collect your account email, authentication identifiers, and basic diagnostic logs.

2. Why we collect it

Your data powers the in-app dashboards, trends, reminders, and self-tracking insights. We do not sell your data. We do not use it for advertising.

3. How we use it

Data is processed to (a) render your own dashboards and exports, (b) compute pattern-detection insights you can review, (c) send the notifications you have opted into, and (d) fulfill your explicit sharing choices.

4. Sharing with providers

Sharing your data with a clinician, coach, or supporter is opt-in. You choose which categories, what date range, and what detail level. You can revoke any share at any time from Settings. Every provider read is logged in your audit trail.

5. Analytics & crash reporting

Analytics and crash reporting are off by default. You can enable them under Settings → Privacy. We use Vercel Analytics for aggregated, anonymous page views when enabled.

6. Push notifications

Push notifications require your explicit permission on iOS, Android, and the web. Notification content is limited to the reminders you have configured.

7. Data export

You can request an export of all your data at any time from Settings. Exports are produced in CSV, JSON, or PDF and made available through a private, expiring download link.

8. Data deletion

You can request deletion of your account or specific data categories at any time from Data Deletion. Soft-deletion is immediate; hard-deletion follows our retention window.

9. Security

Data is stored in Supabase Postgres with row-level security enforced on every health-related table. All traffic is encrypted in transit (TLS 1.2+). Journal entries you write are encrypted at the application level using envelope encryption (AES-256-GCM): each account has its own data-encryption key, wrapped by a master key we hold on the server. This protects the journal body in database backups and dumps; it does not hide journal content from our own systems when features you have opted into (AI reflection, AI reports) send that content to our AI provider on your behalf.

10. Children

MindMap is not directed at children under 13 and we do not knowingly collect data from them.

11. Contact

For privacy questions, contact privacy@heartwire.com.