Legal
Effective: April 3, 2026 · Last updated: April 3, 2026
MindFrame ("we", "us", or "our") is operated by VaultSpark Studios LLC. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and your rights in relation to that data. By using MindFrame at usemindframe.com you agree to the practices described here.
VaultSpark Studios LLC is the data controller responsible for your personal data.
We collect the minimum data needed to provide MindFrame's services:
Payment details (card numbers, billing address) are processed exclusively by Stripe and are never stored on MindFrame servers. We receive only a Stripe customer ID and subscription status.
mf-theme)mf-cookie-consent)For users in the European Economic Area (EEA), United Kingdom, and Switzerland, our legal basis for processing personal data is:
| Purpose | Legal basis |
|---|---|
| Providing the MindFrame service | Contract (Art. 6(1)(b) GDPR) |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) — only after consent via cookie banner |
| Sending transactional emails (receipts, password resets) | Contract |
| Sending drip / marketing emails | Consent (Art. 6(1)(a)) — you may opt out at any time |
| Legal compliance and fraud prevention | Legal obligation (Art. 6(1)(c)) |
We use the following third-party services to operate MindFrame. Each is bound by its own privacy policy and, where required, a Data Processing Agreement with us:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication and PostgreSQL database | Account data, session data |
| Railway | API server hosting | All server-side data (processed in-transit) |
| Vercel | Web app hosting and edge CDN | Request logs (IP, headers) |
| Anthropic (Claude) | AI scoring, coaching, and daily intention | Challenge answers, reasoning text, session history |
| Stripe | Payment processing | Email, billing address |
| PostHog | Product analytics | Usage events, device info (with your consent) |
| Resend | Transactional and marketing email | Email address, name |
| Upstash (Redis) | Caching and real-time features | Cached AI responses (no PII) |
We do not sell your data to any third party. We do not share your data with advertisers.
Depending on your location, you may have the following rights regarding your personal data:
Right of access
Request a copy of all data we hold about you
Right to rectification
Correct inaccurate data
Right to erasure
Delete your account and all associated data (see below)
Right to restriction
Ask us to limit how we process your data
Right to portability
Receive your data in a structured, machine-readable format
Right to object
Object to processing based on legitimate interests
Right to withdraw consent
Withdraw marketing consent at any time
Right to lodge a complaint
File a complaint with your local data protection authority
To exercise any of these rights, email privacy@usemindframe.com. We will respond within 30 days.
You may delete your account at any time from your profile settings. Upon deletion:
We use cookies and similar technologies. For full details, see our Cookie Policy.
MindFrame is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided personal data, we will delete it promptly. If you believe a child under 13 has registered, please contact privacy@usemindframe.com.
MindFrame is hosted on infrastructure in the United States (Railway, Vercel, Upstash). If you are accessing MindFrame from the EEA, UK, or Switzerland, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to provide adequate protection for such transfers.
We implement appropriate technical and organisational measures to protect your data:
For our full security posture, see our Security Policy.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on the MindFrame website before the change takes effect. The "Last updated" date at the top of this page indicates when the most recent changes were made.