Privacy Policy

Privacy

Privacy Policy

Effective 13 August 2026

This policy explains what personal data Myndora processes, why we process it, and the choices and rights available to you.

1. Controller and contact details

Sam Buwalda, trading as Myndora, is the controller responsible for the personal data described in this policy.

  • Establishment address: Groene Hilledijk 469 H, 3075 EA Rotterdam, The Netherlands
  • KVK number: 42003061
  • VAT identification number: NL005426052B61
  • Privacy contact: support@myndora.app
  • Telephone: +31 6 81 95 30 83

2. Data we collect

Account and authentication data

We process your email address, internal user identifier, account creation date, authentication records, settings, and login/session information. Authentication is provided through Supabase.

Living Profile data

We process the answers you submit, question and session records, profile signals, scores, progress, coverage, recalibration state, history, and other derived information needed to build and update your Living Profile. These are private account features and are not posted publicly through Myndora.

Myndora is not intended to collect medical records, diagnoses, or other legally protected special-category data. Please do not include unnecessary health information or sensitive information about other people in free-text fields or Ask Your Profile prompts.

Share & Compare

If you use Share & Compare, we process your preferred first name, the relationship context you select, private invitation and consent records, the matched profile-item references, connection status, and a comparison across all 26 Areas derived from profile signals currently available for both people. An unclaimed invitation shows only the inviter-approved three-tendency preview. It does not reveal individual answers, email addresses, or the inviter’s separate profile.

Both participants can view the shared comparison after the invited person explicitly consents and completes any questions needed to cover the 26 comparison Areas. Either participant can disconnect at any time, which removes access to the comparison without deleting either person’s own profile answers. An inviter can permanently delete a revoked invitation from Share & Compare. Private invitation paths and tokens are excluded from PostHog page-view capture.

Product feedback

If you submit feedback about an assessment question or a Profile Fit card, we store your user id, the selected rating or issue reasons, any explanation you provide, timestamps, and the question, card, score, profile-evidence, or other technical snapshot needed to understand what you saw. Authorized Myndora administrators can review the feedback, add internal notes, and mark it resolved. This feedback is included in your data export and is deleted when you delete your account.

Ask Your Profile

When you use Ask Your Profile, your prompt and relevant Living Profile context are sent to OpenAI so the requested response can be generated. Myndora disables Responses API application-state storage for these requests. Chats, prompts, and generated responses are not saved in your Myndora account or chat history unless you deliberately submit a specific response as Not helpful feedback. Myndora’s operational logs store metadata such as your user id, timestamp, model, latency, usage, and error state, but not the prompt or generated response.

Helpful feedback stores only your user id, a response id, timestamp, model, prompt version, and a fingerprint of the system prompt; it does not store the question or response. If you submit Not helpful feedback, Myndora stores the latest question that triggered the response, that generated response, your selected reasons, and any optional explanation so authorized Myndora administrators can investigate it. This feedback is account-linked, remains separate from anonymous Ask research, is included in your data export, and is deleted when you delete your account.

When anonymous Ask research is active, a separate classifier processes only your newest prompt by default so we can understand, in aggregate, what people need help with. Before that call, Myndora applies a local privacy screen intended to exclude direct identifiers, address and contact details, identifier-heavy text, protected or special-category data, criminal information, and identifiable details about other people. Unsafe or uncertain prompts are excluded. You can turn this research processing off for all future prompts in Settings → Privacy choices without losing access to Ask Your Profile.

For an eligible prompt, OpenAI returns only controlled topic, intent, canonical-concept, confidence, and safety codes. Myndora then creates a generalized summary locally from the approved labels. The anonymous research record contains only a random submission UUID, UTC week-start date, generalized summary, topic codes, intent codes, canonical concept codes, taxonomy version, classifier model and version, and confidence level. It contains no user id, email, account tier, exact timestamp, original or sanitized prompt, reply, Living Profile context, or free-form model text. The classifier call uses application-state storage disabled. PostHog remains separate and receives neither prompts nor these classifications.

OpenAI processes the transmitted content as our service provider under its applicable data-processing terms. Its abuse-monitoring logs may contain prompts and responses and are normally retained for up to 30 days. OpenAI may retain them longer where legally required or reasonably necessary to protect its services or third parties. Zero or modified retention applies only where OpenAI has approved and the relevant project has enabled those controls. See OpenAI’s data-control documentation.

Payments and subscriptions

Stripe processes payments and stores payment-method information. Myndora receives and stores identifiers, subscription tier and status, renewal/cancellation state, and billing-period dates needed to provide paid access. If you submit an online withdrawal, we also record the name, purchase email, contract reference, statement, submission date and time, deadline basis, processing result, and confirmation-delivery status needed to honour the request and demonstrate compliance with consumer law. We do not receive or store your complete card number.

Support and communications

We process messages and contact details you submit through support. We may retain records from the former contribution-application programme, including submitted application details and review status, where needed to preserve an earlier access decision or resolve a dispute. If you separately opt into product news, we process your email address and subscription status for that purpose.

Usage and device data

Essential technical logs may contain timestamps, request information, IP-derived security information, browser/device information, and errors. If you allow analytics, PostHog also receives page paths, limited referrer and campaign parameters, device/browser data, your Myndora user ID and account creation date after login, and product events such as the profile stage reached or feature opened. These events do not include your email address, assessment answers, profile content, or Ask Your Profile questions and replies. We do not activate optional PostHog analytics before you make that choice. Limited server-side subscription events may also be recorded to measure confirmed upgrades and support billing reliability and fraud prevention without reading or writing to your device. These may include your Myndora user ID, plan, billing interval, amount, currency, and subscription status, but not payment-card details.

3. Why we use personal data and our legal bases

  • Performing our contract: creating your account; providing, personalising, and maintaining your Living Profile; generating requested Ask Your Profile responses; providing support; and administering subscriptions.
  • Legitimate interests: securing Myndora, preventing misuse, diagnosing failures, maintaining service reliability, answering non-contractual enquiries, and—when anonymous Ask research is active—understanding aggregate user needs through privacy-minimized classifications. You can object by switching off future Ask research in Settings.
  • Consent: sending optional product news and running optional analytics where consent is required. You may withdraw consent at any time.
  • Legal obligations: retaining required tax/accounting records, responding to lawful requests, and complying with consumer and data-protection law.
  • Legal claims: establishing, exercising, or defending legal claims when necessary.

4. Service providers and recipients

We use a limited set of providers to operate Myndora:

  • Supabase: authentication and database infrastructure.
  • Vercel: website, application, and serverless hosting.
  • OpenAI: generating Ask Your Profile responses from the prompt and profile context you submit and, when anonymous Ask research is active, classifying only the newest prompt with application-state storage disabled.
  • Stripe: checkout, recurring billing, refunds, and the customer billing portal.
  • PostHog: optional browser product analytics after your analytics choice, plus limited server-side subscription events used for billing reliability and fraud prevention.
  • Resend: transactional email, support notifications, data exports, withdrawal confirmations, and product news when requested.

Providers may process data only for the relevant service and under applicable contractual and legal safeguards. We may also disclose limited information where required by law, to protect rights or safety, or in connection with a genuine business reorganisation subject to appropriate confidentiality and data-protection requirements.

We do not sell personal data or use Living Profile data for third-party advertising.

5. International data transfers

Myndora is established in the Netherlands, while some providers or their sub-processors may process data in the United States or other countries outside the European Economic Area. Where an adequacy decision does not apply, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and relevant provider data-processing agreements, together with supplementary measures where required. You may contact us for more information about the safeguard relevant to a particular transfer.

6. Retention

  • Account and Living Profile data: generally retained while your account exists and deleted or anonymised after account deletion, subject to limited legal exceptions.
  • Individual answers: retained until you delete them, delete your account, or they are no longer needed for the profile feature.
  • Share & Compare records: retained while needed to provide and manage invitations and comparisons. An inviter can permanently delete a revoked invitation; account deletion removes the participant’s comparison records subject to limited legal exceptions.
  • Billing and transaction records: retained for the period required by tax, accounting, fraud-prevention, and dispute rules. Stripe may retain its own legally required records.
  • Withdrawal records: retained as long as reasonably needed to process the request and meet consumer-law, accounting, and legal-claims obligations.
  • Support and historical application records: retained only as long as reasonably needed to handle the request, preserve an earlier access decision, maintain a decision record, or resolve a dispute.
  • Assessment-question and Profile Fit feedback: retained while needed to investigate and improve the relevant question or result, and deleted when you delete your account.
  • Operational logs and quota records: retained for the shortest period reasonably needed for security, reliability, abuse prevention, and cost control.
  • Ask Your Profile content: original prompts, replies, and Living Profile context are not saved in your Myndora account, chat history, Myndora operational logs, or Myndora research records unless you deliberately submit the latest question and response as Not helpful feedback. Submitted feedback is retained until account deletion. OpenAI may retain transmitted content in abuse-monitoring logs as described above.
  • Anonymous Ask research insights: retained indefinitely while useful for aggregate product research, with an annual re-identification-risk and taxonomy review. Turning research off stops future processing. Because completed records contain no account link, Myndora cannot identify or selectively delete an earlier anonymous insight.
  • Analytics and newsletter records: retained according to our provider configuration until no longer needed or until you withdraw consent, subject to limited suppression records needed to respect an unsubscribe choice.

7. Cookies and local storage

Myndora uses essential authentication and security storage to keep accounts signed in and operate requested features. We store your analytics choice in the browser. If you select “Yes, help improve Myndora”, we also store limited acquisition information and activate PostHog analytics. You can reopen Cookie settings from the website footer or Account Settings and change your choice at any time. Withdrawing stops future optional browser analytics and removes PostHog and acquisition storage from that browser. See the complete cookie and browser-storage list for names, providers, purposes, data, and lifetimes.

8. Security

We use reasonable technical and organisational measures appropriate to the nature of the data, including encrypted transport, managed encrypted storage, authentication, access controls, and restricted production access. No online system can guarantee absolute security. Please use a unique password and tell us promptly if you suspect unauthorised account access.

9. Your data-protection rights

Depending on the law that applies to you, you may have the right to:

  • access personal data and receive information about its processing;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • receive portable data in a structured, commonly used format;
  • object to processing based on legitimate interests;
  • withdraw consent without affecting earlier lawful processing; and
  • complain to a supervisory authority.

You can export data and delete your account from Settings. You can object to future anonymous Ask research directly in Settings; doing so takes effect for later submissions and does not change Ask Your Profile access. Completed anonymous records cannot be connected back to your account for access or deletion. For another request, email support@myndora.app. We may need to verify your identity. You may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the competent authority where you live or work.

10. Children

Myndora is intended only for people aged 18 or older. We do not knowingly offer accounts to children. Contact us if you believe a person under 18 has provided personal data through an account.

11. Changes to this policy

We will update this policy when our processing changes. For a material change, we will provide registered users with advance notice where required and show a new effective date. If we want to use previously collected data for a materially different purpose, we will provide the information and obtain any consent required before doing so.

12. Contact

Questions, objections, complaints, and rights requests can be sent to support@myndora.app. You can also use the Help page.

Get Myndora Updates

Get product updates, new features, and occasional Myndora news in your inbox.