Legal

Privacy Policy

Last updated: July 23, 2026 · Version 1.0.0-beta

1. Our Approach

Mindscape is designed to be private by default. Sessions are anonymous to other users, only first names are shared. This Privacy Policy explains what we collect, why, how it is protected, who can see it, and how long we keep it.

2. Information We Collect

We collect only what we need to run Mindscape safely:

  • Account information: email, first and last name, age, education level, languages, and role (participant or volunteer).
  • Google authentication information: when you sign in with Google, we receive your Google email and basic profile info to create or match your account.
  • Profile data: optional avatar image and language preferences.
  • Volunteer training data: which training modules and video versions you completed and when.
  • Volunteer applications: answers you provide when applying to become a listener, and approval status.
  • Session metadata: start/end times, participants, language, and consent timestamps, not the content of chat messages, and no audio or video recordings.
  • Volunteer notes: written observations volunteers may save after a session about a participant, used to help future matched volunteers offer continuity of support.
  • Reports and appeals: in-session user reports, footer bug reports, and moderation appeals you submit.
  • Uploaded files: images optionally attached to bug reports, and admin-uploaded training videos.
  • Bug reports: what you describe, the page/context, and optional screenshots.
  • Analytics: aggregate, non-identifying usage stats used to improve reliability and matching.

3. What We Do Not Collect

  • We do not store the content of chat messages after a session ends.
  • We do not record audio or video sessions.
  • We do not sell, rent, or trade your personal data.
  • We do not use your data to train third-party advertising models.

4. Why We Collect Each Type

  • Account & Google info: to authenticate you and prevent duplicate or abusive accounts.
  • Profile & languages: to match participants with volunteers who share a common language.
  • Training data: to ensure only volunteers who completed required training can take sessions.
  • Session metadata: to operate the matching queue, enforce safety, and support moderation.
  • Volunteer notes: to give future matched volunteers helpful context so participants don't have to repeat themselves.
  • Reports, appeals, bug reports: to keep the platform safe and improve reliability.
  • Analytics: to understand usage patterns in aggregate, never to profile you personally.

5. Who Can See What

  • Other users see only your first name, avatar (if any), and the languages you've enabled.
  • Volunteers see the same, they do not see your email, age, or full identity.
  • Volunteer notes are visible only to volunteers who are currently matched with the same participant. They are never visible to participants.
  • Moderators may review reports, appeals, session metadata, and volunteer notes to keep the platform safe.
  • Administrator access is restricted to a small number of approved accounts and protected by role-based access control.

6. How We Protect Your Data

  • Encryption in transit (HTTPS) for all connections.
  • Authentication handled by a trusted cloud provider, with Google OAuth as the recommended sign-in method.
  • Row-level security rules on the database so users can only read and write their own data.
  • Administrator access gated by server-side role checks, not client-side flags.
  • Private storage buckets with signed URLs for training videos and uploaded files.
  • Moderation systems for reports, appeals, and volunteer-note abuse.

7. Data Retention and Deletion

  • Account data is kept while your account is active.
  • Session metadata and reports may be retained for up to 24 months to support moderation and safety reviews.
  • Volunteer notes are retained while relevant to ongoing participant support and may be removed when moderation determines they are no longer appropriate.
  • Bug reports and analytics may be retained in aggregate for platform improvement.
  • You can request deletion of your account by contacting support@mindscapeproject.com. Some information may be retained where required by law or for legitimate safety purposes.

8. Age Requirement

You must be at least 12 years old to use Mindscape. Where local law requires parental or guardian consent for minors, it is your responsibility to obtain it.

9. Legal Compliance

Mindscape operates in the United States and the Commonwealth of Puerto Rico and follows applicable U.S. privacy principles and Puerto Rico laws relevant to online services. Mindscape is a peer-support platform, not a covered healthcare entity, and therefore is not subject to HIPAA. We do not claim any certification or regulatory status we do not actually hold.

10. Your Choices

  • Update your profile picture and language preferences at any time.
  • Sign out or stop using Mindscape at any time.
  • Request account deletion by emailing support@mindscapeproject.com.

11. Changes to This Policy

We may update this policy as the platform evolves. The "Last updated" date and version above will change when we do. We'll surface meaningful changes inside Mindscape.

See also: Terms and Conditions · Community Guidelines · Safety & Trust