Who we are
MindMap AI is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For the purposes of the GDPR and equivalent laws, we are the data controller for the personal data described here.
[If you are required to appoint one, name your Data Protection Officer and their contact details. If you are not established in the EU/UK but offer the Service there, you may need an Article 27 representative.]
What we collect
Account data. Your name, email address, and password hash. If you sign in with Google, we receive your name, email, and Google account identifier — we never receive your Google password.
Content you upload. The documents, PDFs, and notes you give us, plus everything we derive from them: extracted claims, vector embeddings, graph nodes and edges, and your traversal history.
Usage data. Which features you use, when, and how — including queries you ask the tutor and quizzes you take.
Technical data. IP address, browser and device type, and log data.
[Confirm this list is exhaustive and accurate against what your app actually logs. An under-disclosed category is a regulatory problem; an over-disclosed one erodes trust unnecessarily. Also: do you use analytics or error-tracking SDKs? Those belong here.]
How we use it
- To run the Service: parse your uploads, generate embeddings, build your graph, answer your questions, and schedule your recall.
- To maintain your account: authenticate you, process payments, and provide support.
- To keep the Service safe: detect abuse, prevent fraud, and enforce our Terms.
- To improve the Service:understand aggregate usage patterns and fix what's broken.
[THE CENTRAL QUESTION: is customer-uploaded content ever used to train, fine-tune, or evaluate models — yours or a third party's? Answer unambiguously here. If the answer is no, state it plainly; it is the single most reassuring sentence on this page. If it is yes-with-opt-out, the opt-out must be genuinely accessible and disclosed at signup, not buried.]
Legal basis for processing
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve it, balanced against your rights.
- Consent — where required, for example for optional analytics or marketing email.
- Legal obligation — where we must retain or disclose data by law.
[Map each processing purpose in the section above to exactly one legal basis. A regulator will ask for this mapping. If you rely on legitimate interests, you should have a documented Legitimate Interests Assessment on file.]
Who we share it with
We do not sell your personal data. We share it only with service providers who help us run MindMap AI, and only to the extent they need it.
[LIST YOUR SUBPROCESSORS. At minimum this likely includes: your model/inference provider, your hosting and database provider, your authentication provider, your payment processor, and any error-tracking or analytics vendor. For each, name the vendor, what it does, and where it processes data. This list must be accurate and kept current — under GDPR you may also owe customers notice before adding a new subprocessor.]
We may also disclose data where required by law, or to protect our rights, safety, or property.
International transfers
[Where is your data physically processed and stored? If personal data leaves the EEA/UK, you must name the transfer mechanism — Standard Contractual Clauses, an adequacy decision, or the EU–US Data Privacy Framework — and say so here. This section cannot be left vague.]
How long we keep it
[SPECIFY CONCRETE PERIODS. For each of: account data; uploaded documents; derived embeddings and graph structures; usage logs; backups. “As long as necessary” is not a sufficient answer under GDPR.]
When you delete a document, we remove it and the nodes derived from it from your active graph. Copies may persist in encrypted backups for up to [BACKUP RETENTION WINDOW] before being overwritten.
When you close your account, we delete your data within [DELETION SLA], except where we must retain records to comply with law.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Where we rely on consent, you can withdraw it at any time.
To exercise any of these, contact [privacy@yourdomain.com]. We'll respond within [RESPONSE SLA — GDPR default is one month].
If you're in the EEA or UK, you also have the right to lodge a complaint with your supervisory authority.
[If you have users in California, Virginia, Colorado, or other US states with comprehensive privacy laws, add the specific disclosures those statutes require — including a “Do Not Sell or Share” mechanism if applicable.]
Security
We use technical and organizational measures to protect your data, including [encryption in transit and at rest? access controls? audit logging? state what you actually do — do not claim controls you have not implemented].
No system is perfectly secure. If a breach affects your personal data, we'll notify you and the relevant regulator where the law requires it.
Children
The Service is not directed at children under [AGE — must be consistent with the eligibility age in the Terms]. We do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy. If changes are material, we'll notify you by [MECHANISM]before they take effect. The “last updated” date at the top always reflects the current version.
Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[privacy@yourdomain.com]