Privacy Notice (EU)
Privacy Notice (EU / GDPR)
Details on how Mindex processes data under GDPR.
Last updated: 4 June 2026 · Version 2026-06-04
1. Controller
Mindex (pinedapps) (Owner: Diego Felipe Pineda Leiva)
c/o MDC Management#4996
Welserstraße 3
87463 Dietmannsried, Germany
Email: datenschutz@pinedapps.de
2. Privacy Contact
No Data Protection Officer has currently been appointed. Please send privacy requests to datenschutz@pinedapps.de.
3. Purpose & Legal Basis
We process personal data to operate the web and mobile apps, administer accounts, store and sync private user content, fulfil contracts, respond to support requests, improve the product, and ensure security, quota enforcement, fraud prevention, and abuse prevention. Legal bases: Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (legal duties), Art. 6(1)(f) GDPR (legitimate interest in a safe, functional platform), and Art. 6(1)(a) GDPR (consent for optional analytics or marketing).
4. Categories of Data
- Registration: name, email address, password hash, language, and consent status.
- Usage and private user content: bookmarks/URLs, link metadata, text, notes, files, images, PDFs, profile photos, folders/tags, spaces/projects, search and interaction data, import/share-intent metadata, AI categorisation metadata, device data, and log files (IP, timestamps, user agent).
- Billing and entitlement data when paid plans or add-ons are used: plan status, product identifiers, transaction/receipt references, renewal or cancellation status, payment-provider metadata, and support records. Full card or payment details are handled by the payment provider and are not stored by Mindex.
- Support: ticket contents, chat transcripts, feedback.
5. Retention
Data is retained while an account remains active plus as required for statutory retention (e.g., 6 or 10 years) or legitimate interests (claim defence). Log files are anonymised or deleted after ~30 days.
6. Recipients & Transfers
We rely on processors such as Firebase/Google Cloud for authentication, hosting, database, storage, security logs, and App Check, plus Google GenAI/Gemini through Genkit for optional AI features. AI requests may include content, URLs, PDFs, or metadata that users submit for analysis. For paid Pro plans in the mobile apps, we use App Store / Play Store billing and RevenueCat for entitlement management. The web app does not sell Pro directly for now. Processing is covered by Art. 28 GDPR agreements, EU Standard Contractual Clauses, and supplementary safeguards for international transfers.
7. Cookies, Local Storage & Analytics
We use technically necessary cookies and local storage for sign-in, security, language, consent records, app functionality, and entitlement status where needed. Optional analytics, marketing, or tracking technologies only run with prior consent. Mindex does not sell personal data or share personal data for behavioural advertising.
8. Export, Deletion & Your Rights
You can export your data and request account deletion. Account, profile, Firestore, and Storage data are deleted unless limited retention is required for legal duties, security records, or claim defence. Under GDPR you may request access, rectification, erasure, restriction, portability, and object to processing under Art. 6(1)(e)/(f) GDPR. Consent can be withdrawn at any time. Complaints may be lodged with a supervisory authority, including the Bavarian Data Protection Authority: https://www.lda.bayern.de/.
9. International Rights Notice
Depending on where you live, you may have additional rights under laws such as the UK GDPR, California CCPA/CPRA, Brazil LGPD, Canada PIPEDA, or the Australian Privacy Act. These may include rights to access, correct, delete, port, object/opt out, restrict processing, or complain. Mindex does not sell personal data or use it for targeted advertising. Send requests to datenschutz@pinedapps.de.
10. AI, Profiling and Automated Decisions
We do not use solely automated decision-making with legal or similarly significant effects. AI suggestions in the Knowledge Map are for private organisation only, may be inaccurate, incomplete, or unsuitable, and should be reviewed before users rely on or save them. Mindex does not provide medical, legal, financial, tax, safety, or other professional advice.
11. Security
Data is protected via TLS encryption, access controls, encrypted storage (Firebase), monitoring, and routine audits.
12. Updates
Date: 4 June 2026. We publish updates whenever processing activities or legal requirements change.