Effective date: September 1, 2025
Mindbit ("we", "us") helps you read less and learn more. This policy explains what we collect, why we collect it, how we use it, and the choices you have. It applies to our mobile apps (iOS and Android) and our website at www.mindbit.app/privacy.
Controller: Marcin Dukaczewski, KEN 51, Warsaw, Poland.
How to reach us: privacy@mindbit.app for any privacy questions or requests.
Mindbit is for a general audience aged 16+. We don’t knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we’ll delete it.
Third-party sign-in options:
You may link multiple sign-in methods to the same Mindbit account (your choice).
We use only essential cookies necessary to run the site. If we add analytics or non-essential cookies later, we’ll update this policy and ask for consent where required.
If we rely on consent, you can withdraw it anytime in the app/website or by emailing us; withdrawal won’t affect prior lawful processing.
We use Google Firebase as our primary processor:
We configure Firebase data location to europe-west where the product supports it. Some processing by Firebase/Google may still occur outside your country (e.g., for resilience). When data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and comparable safeguards.
We may use an email service provider to send marketing emails strictly as our processor.
We do not disclose personal data to third parties for their own marketing. We may disclose to:
We do not sell personal information and do not “share” it for cross-context behavioral advertising as defined by US state laws.
Depending on where you live, you may have rights to:
Email privacy@mindbit.app from the address associated with your account. We may need to verify your identity.
Delete your account: from in-app settings or by emailing privacy@mindbit.app. Deletion triggers a 30-day grace period (in case you change your mind); after that, we delete active records, with backups purged on their normal cycle.
Export your data: request via email and we’ll provide a portable file of your content where technically feasible.
We use industry-standard measures, including TLS encryption in transit, encryption at rest (Firebase), role-based access, least-privilege access controls, App Check to reduce abuse, and periodic access reviews. No method of transmission or storage is 100% secure, but we work to protect your data.
If you access Mindbit from outside the EU/UK, your data may be processed in Poland and other countries where our processors operate. We use appropriate safeguards (e.g., SCCs) for cross-border transfers.
Google / Apple / Facebook provide us only your basic profile and email (as permitted by you). For Apple, if you choose Hide My Email, we receive a relay email and cannot see your real address.
You can link or unlink sign-in methods at any time in the app.
We’ll update this policy as needed. We’ll post the new version with a new "Effective date" and, if changes are significant, notify you in-app or by email.
Category | Examples | Purpose(s) | Shared? |
---|---|---|---|
Identifiers | Name, email, avatar; third-party user ID | Account creation, authentication, communications | With processors only |
User content | Highlights, bookmarks, points & streaks | Core functionality, sync, personalization | With processors only |
Device/usage | Device model/OS, app version, IP (coarse location), diagnostics | Analytics, performance, security | With processors only |
Push token | FCM token | Deliver push notifications | With processors only |
Marketing contact | Email address | Marketing emails (with consent), product updates | With processors only |
No Ads. No sale or “sharing” for cross-context ads.