Legal
Privacy Policy
Effective date: August 29, 2026
This Privacy Policy explains how MindQot ("MindQot", "we", "us", or "our") collects, uses, and shares information when you use the MindQot mobile application (the "App") and the website at https://mindqot.com. Please read it with our Terms of Service.
MindQot is operated by Anirudh Verma, an individual developer based in India. MindQot is intended for adults aged 18 and over (see section 12). It is offered worldwide, subject to app-store availability and any country-specific restrictions.
This policy has two parts: (1) global disclosures that apply to everyone, and (2) regional supplements (section 16) that add rights and information for people in certain regions.
Part 1 — Global disclosures
1. Who we are
The controller responsible for your personal data is Anirudh Verma. Contact: see section 2.
2. How to contact us about privacy
For any privacy question or request, contact mindqot.support@gmail.com. This is our privacy point of contact. Where a region requires an additional local contact or representative, it is listed in the relevant regional supplement (section 16).
3. Information you provide to us
- Email address — to create and secure your account.
- Display name — optional, shown in the App where applicable.
- Account information — the credentials and profile record for your MindQot account.
- Onboarding goals and preferences — the learning goals you select and your chosen reading depth.
- Notification preferences — whether notifications are enabled, your preferred daily delivery time, and frequency.
3A. The website and the early-access waitlist
This section covers mindqot.com (the website), which is separate from the App. The website sets no cookies, loads no third-party scripts, and serves its own fonts.
If you join the early-access waitlist, we record:
- Your email address, exactly as you typed it (normalized to lower case).
- Your consent to receive MindQot early-access, beta and launch emails — the fact of it, the version of the wording you were shown, and the time you gave it. Submitting the form is that consent; the form says so next to the button. We do not send a confirmation email or ask you to click a link first: you are on the list as soon as you submit.
- How you arrived — the referring page, and any
utm_campaign parameters in the link you followed. - Your optional answers, if you choose to give them after joining: which phone platform you expect to use, and which topics interest you. Neither question is required and neither affects your place on the list.
We do not store your IP address or browser user agent with your waitlist entry. A salted, one-way hash of your IP address is kept in a separate short-lived record for the sole purpose of limiting abusive submissions.
Why: to email you about MindQot's early access, beta and launch, and the follow-ups that belong to that launch. The lawful basis is your consent. We use these addresses for nothing else — this is not a general-purpose newsletter, and there is no advertising, no sale or sharing of the list, and no transfer to any other product.
Withdrawing: every email includes an unsubscribe link, and you can write to mindqot.support@gmail.com at any time to be removed. Removal deletes your waitlist entry, including the optional answer, and the matching contact at our email provider (Resend, section 6). Because we do not ask you to confirm the address first, anyone could in principle type someone else's: if you receive a MindQot email you never asked for, unsubscribe or write to us and we will delete the entry.
Retention: we keep your waitlist entry until you unsubscribe or ask to be removed, and in any case no longer than 24 months after MindQot launches.
Website measurement: we record a small set of non-identifying events about the page itself — that the page was viewed, that the signup form came into view, that a submission was made, whether it succeeded, failed or was already on the list, and which optional answer was chosen. These carry no email address and no IP address. To group the events of a single visit, your browser holds two random tokens in session storage for the length of that visit; they are erased when you close the tab and are never linked to your identity. The events are written to our own server logs and, where a measurement stream is configured, to Google Analytics 4.
If you arrive through a creator or campaign link — a
MindQot link containing a ref code, for example from a
creator's video or bio — your browser keeps that code, and the time it
was used, in local storage for about
30 days. The code is a random reference to the link
itself. It holds no name, email address, IP address or browsing
history, and it is not readable by anyone else: only our own site
script uses it, and it is never sent to an advertising network or any
other third party. We use it for one thing — so that if you later join
the waitlist or become a Founding Member, we can credit the creator
whose link brought you. We keep the first link you arrived through and
the most recent one. This is still not a cookie, and moving between
pages on mindqot.com does not create or change it. You can remove it at
any time by clearing site data for mindqot.com in your browser; doing
so affects nothing except that credit.
4. Information generated through your use of the App
- Learning progress — active path, current day, completed days.
- Daily briefing activity — the daily card assigned to you and its status (scheduled, opened, completed).
- Card interactions — when you open a card, the depth selected, and when you complete an "Apply Today" action.
- Streak and progress state — streak count and total completed briefings.
- Timezone — your device timezone (e.g.
Asia/Kolkata), to schedule your briefing at your chosen local time.
5. Device and notification information
- Push notification token (FCM registration token) — lets us deliver your daily briefing.
- Platform and device registration data — device platform, whether notifications are enabled on that device, and last token-refresh/last-seen times.
Your push token is stored only in your own device records, is never shared publicly, and is removed automatically if it becomes invalid.
6. Service providers we use
MindQot is built on Google Firebase, with two providers that are not part of Google Firebase and are marked as such below. The services active in the current production App are: Google provides these Firebase services and processes data in connection with them under Google's own applicable terms and privacy documentation (including Firebase Privacy and Security). Google's role can vary by service and region.
- Resend (resend.com) — sends the early-access, beta and launch emails described in section 3A. Resend receives only the address you submitted and its subscription state, so that unsubscribes, bounces and suppression are honoured. It receives nothing from the App: no account data, no reflections, no activity. If you ask us to remove your waitlist entry, the contact is deleted from Resend too.
- Firebase Authentication — manages sign-in; stores your email and a secure credential; may process technical data (e.g. IP address, user agent) to secure sign-in and prevent abuse.
- Firestore — stores the account, preference, and activity data in sections 3–5 in Google's cloud.
- Firebase Cloud Messaging — delivers push notifications using the token in section 5.
- Firebase Crashlytics — collects crash and diagnostic data (stack traces, error state) and device/app information required for diagnostics (device model, OS version, app version, memory/storage, a Crashlytics installation identifier). Per Google's current documentation, Crashlytics keeps this data for 90 days, after which Google begins removing it from its live and backup systems.
- Firebase App Check (Google Play Integrity) — protects our backend from abuse; on supported Android release builds it uses the Google Play Integrity API, which evaluates app/device integrity signals through Google.
- Firebase Remote Config — manages feature configuration; may process a Firebase installation identifier.
- Google Analytics for Firebase (Firebase Analytics) — measures how the App is used so we can improve it. We record product events only — for example that a briefing was opened, which reading depth was chosen, that a learning-path day was completed, or that a card was saved — together with non-identifying details such as the content or path identifier, the day number, and whether the account is on the free or premium tier. Firebase also automatically collects standard app and device information (app version, device model, OS version, country/region, coarse session and screen data) and a Firebase-generated app-instance identifier. We never send your name, email address, phone number, the goals you select, your reflections, or any text you write into the App, and we do not set your account identifier in Analytics.
- PostHog (posthog.com) — product analytics, not a Google service. PostHog records the same product events as Firebase Analytics above, with the same non-identifying details (the content or path identifier, the day number, the reading depth, where an action started from, saved-card counts, and whether the account is on the free or premium tier), so that we can read one set of usage numbers rather than two. PostHog additionally records standard app and device information — app name and version, device model and manufacturer, device type, operating system and version, screen size, language, time zone, mobile network carrier, and an approximate location derived from your IP address — and a PostHog-generated anonymous device identifier. We do not identify you to PostHog: we never call PostHog's user-identification feature, no PostHog person profile is created for you, and your account identifier is never sent. We never send your name, email address, phone number, the goals you select, your reflections, any text you write into the App, or your notification token. Session recording/replay, surveys, feature flags, experiments, error tracking and push notifications are all disabled in our PostHog configuration. When you log out, delete your account, or your session expires, we reset your PostHog identity: the anonymous identifier is rotated and the stored free/premium property is cleared, so nothing from one account carries over to the next person using that device. PostHog processes this data on PostHog Cloud US (United States).
We do not use any analytics or crash-reporting service other than the Google Firebase services and PostHog listed above. We do not sell your personal data, do not share it for cross-context behavioural advertising, and do not use it for targeted advertising. Firebase Analytics and PostHog are used for first-party product measurement only; we do not enable Google Analytics advertising features, do not collect an advertising identifier, and do not build advertising audiences or profiles.
7. Payments and subscriptions (not currently active)
MindQot may offer paid subscriptions in the future. The App contains integration groundwork for the subscription providers RevenueCat and Superwall, but these are not enabled in the current production configuration and do not currently process user data. If paid subscriptions become available, we will update this policy first, and purchases will be handled through your app store (e.g. Google Play), whose terms and privacy practices will apply.
8. Why we process your information
To create/secure/operate your account; deliver your daily briefing at your chosen time and depth; track and display progress and streaks; send notifications you enable; keep the App stable and secure (crash diagnostics, abuse prevention); and respond to support and privacy requests. The legal bases that apply in the EEA/UK are described in section 16.
9. Data security
We use technical and organisational safeguards appropriate to the nature of the information we process, relying on the security features of the Google Firebase platform. Data in transit between the App and our backend is protected using encryption supported by that platform, and account credentials are handled by Firebase Authentication and are not stored by us in plain text. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data retention
We retain your account and activity data for as long as your account exists. When you delete your account (section 11), we delete the associated data listed in 11.1. Some data processed through the Firebase services is retained and removed on Google's own schedules, which we do not control (for example, Crashlytics data is kept for 90 days as described in section 6). Except where an official service-provider source states a specific period, we do not state fixed retention periods in this policy.
11. Account deletion
Delete your account and its data any time:
- In the App: Settings → Delete Account.
- From the web: follow https://mindqot.com/delete-account (no need to reinstall or open the App).
11.1 What deleting your account removes
The current implementation removes: your Firebase Authentication account; your user profile and all subcollections, including device and push-token records; your daily briefing records; your learning-path progress; your card interactions; your notification logs; and any subscription mirror / subscription-webhook records, where present. Shared, non-personal content (wisdom cards, learning-path definitions) is not deleted, as it is not your personal data.
11.2 What may remain after deletion
- Crash/diagnostic data already collected by Crashlytics is kept by Google for 90 days before Google begins removing it (section 6).
- Records held by Google as part of the Firebase services (e.g. authentication and messaging records) are retained and removed on Google's own schedules; we do not control those schedules and do not represent that all such records are removed on a fixed timeline following your deletion.
- Operational and security logs may be kept for a period to run the Service reliably and prevent abuse; some entries may include identifiers such as your account identifier. These are separate from the account record deleted above.
12. Children and intended audience
MindQot is intended for users aged 18 and over, is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 provided us data, contact mindqot.support@gmail.com.
13. Automated decision-making and personalization
MindQot selects and personalizes the learning content you see (for example, based on the goals you choose). This is a straightforward content-recommendation feature. We do not make decisions producing legal or similarly significant effects about you solely by automated means (no automated decision-making of the kind addressed by GDPR Article 22).
14. Your choices
You can edit many details in the App, delete your account (section 11), and control notifications through your device settings. Region-specific rights are in section 16. Contact mindqot.support@gmail.com to make a request; we may need to verify your identity first.
15. Changes to this policy
We may update this policy. We will revise the "Effective date" and, for material changes, provide notice through the App or by other appropriate means. Where applicable law requires your consent for a change, we will seek it before that change applies to you, and we will not treat your continued use of the App, by itself, as acceptance of a materially changed privacy practice where the law requires consent.
Part 2 — Regional supplements (section 16)
These apply in addition to Part 1 for people in the regions named. Where MindQot is not actually made available in a region, that supplement may not be relevant.
16.1 EEA / European Union
- Controller: Anirudh Verma.
- Legal bases (GDPR Art. 6): performance of your contract (providing the account, progress, briefings, notifications); our legitimate interests (security, stability, abuse prevention, crash diagnostics); legal obligation (handling rights requests); and your consent where required (e.g. device-notification permission).
- Your rights: access, rectification, erasure, restriction, objection, data portability, and to withdraw consent where processing is based on consent. You may lodge a complaint with your local supervisory authority (the data-protection authority in your EU/EEA country).
- International transfers: your data may be processed by Google and accessed by the operator in India, which does not have an EU adequacy decision. Transfers of this kind require an appropriate safeguard (such as the European Commission's Standard Contractual Clauses); we will put the applicable transfer mechanism in place and confirm it before MindQot is offered in the EEA.
- To exercise rights: mindqot.support@gmail.com.
16.2 United Kingdom
- Same rights and bases as 16.1 under the UK GDPR and Data Protection Act 2018.
- You may complain to the Information Commissioner's Office (ICO). Transfers to India require an appropriate UK transfer mechanism (such as the UK IDTA or Addendum); we will confirm the applicable mechanism before MindQot is offered in the UK.
16.3 United States
We do not sell or share your personal information, and do not use it for targeted advertising. Where a US state privacy law grants you rights (such as access, deletion, or correction) and applies to us, we will honor those rights. Contact mindqot.support@gmail.com.
16.4 Canada
We handle personal information under applicable Canadian privacy law (including PIPEDA and, for Quebec residents, Law 25). You may request access or correction and may contact our privacy contact; Quebec residents may contact the person responsible for privacy at mindqot.support@gmail.com.
16.5 Australia / New Zealand
We handle personal information consistent with the Australian Privacy Principles / the New Zealand Privacy Act 2020 where they apply, including limits on overseas disclosure. You may request access/correction via mindqot.support@gmail.com and complain to the OAIC (Australia) or the Office of the Privacy Commissioner (New Zealand).
16.6 Brazil
We process personal data consistent with the LGPD where it applies, on an applicable legal basis, and honor data-subject rights. Contact: mindqot.support@gmail.com.
16.7 India
We process personal data consistent with the Digital Personal Data Protection Act, 2023 and its Rules as their provisions come into force. You may contact mindqot.support@gmail.com regarding your personal data.
16.8 Other regions
Where another region's law applies to MindQot, we will honor the rights it grants. Contact mindqot.support@gmail.com.