mindlog.today
EN FR

Privacy policy

This policy describes how the Publisher processes Users' personal data, in accordance with the GDPR (EU 2016/679) and French Act no. 78-17 of 6 January 1978 as amended.

1. Data controller

[À COMPLÉTER : raison sociale]

Data protection contact: milo@mindlog.today.

2. Data collected

  • Profile data: public handle, card attributes (public / contacts / private), tags, profile photo, gallery, calendar events, availability exceptions, relationships between profiles, meeting requests, tasks and projects.
  • Authentication data: hash of the access key, session identifiers (HttpOnly cookie), WebAuthn passkey identifiers (fingerprints only), OAuth tokens (fingerprints only). No secret is stored in the clear.
  • Recovery email (optional): allows access to be recovered if the key is lost.
  • Messages: end-to-end encrypted (X3DH / Double Ratchet). The server only stores encrypted data it cannot read.
  • Technical data: connection IP address (transient), user agent, timestamps.
  • Payment data (for subscriptions): no banking data is transmitted to or stored by the Publisher; payment is delegated entirely to Stripe.

3. Purposes and legal bases

  • Providing the Service (account, calendar, messaging, relationships, tasks) — performance of the contract (art. 6.1.b).
  • Security, fraud and abuse prevention — legitimate interest (art. 6.1.f).
  • Transactional and recovery notifications — performance of the contract (art. 6.1.b).
  • Subscription billing — performance of the contract and legal obligation (art. 6.1.b and c).
  • Responding to judicial requests — legal obligation (art. 6.1.c).
  • MCP connector and AI assistant access — consent (art. 6.1.a), revocable.

4. Retention periods

  • Account data: for as long as the Account is active, then deleted on closure.
  • Ephemeral messages: deleted automatically once their lifetime expires (24 hours by default).
  • Expired sessions and OAuth tokens: purged automatically.
  • Billing records: kept for 10 years from issue (article L123-22 of the French Commercial Code).
  • Technical logs (IP, timestamps): 12 months maximum (article L34-1 of the CPCE).

5. Processors and recipients

No data is sold or transferred. Technical processors may be involved:

  • OVHcloud (France) — hosting, infrastructure and database.
  • Stripe Payments Europe, Ltd. (Ireland) — payment processing.
  • SMTP server (where configured) — transactional email delivery.
  • Cloudflare (where Turnstile is enabled) — bot protection at account creation.

6. Transfers outside the European Union

Data is hosted in France. The only possible transfers outside the European Union concern Stripe (United States), covered by standard contractual clauses and the Data Privacy Framework.

7. Security

End-to-end encryption of messages, hashing of authentication secrets, encryption in transit (TLS), CSRF protection, rate limiting, security logging. Any breach exposing personal data would be notified to the CNIL under articles 33 and 34 of the GDPR.

8. Your rights

Under articles 15 to 22 of the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. An export of your data is available from your account.

These rights may be exercised at milo@mindlog.today. You may also lodge a complaint with the CNIL (cnil.fr).