Data we collect
Account data (name, email, authentication metadata), profile and onboarding answers, project and brief content, uploaded files, support messages, billing records from our payment providers, and product usage events.
This policy explains what data MindSpring Lab collects, why we collect it, how long we keep it, and the controls you have over it.
Account data (name, email, authentication metadata), profile and onboarding answers, project and brief content, uploaded files, support messages, billing records from our payment providers, and product usage events.
To operate your account, generate AI recommendations from the context you provide, deliver purchased services, meter usage against plan limits, prevent abuse, and communicate about your account and projects.
Content you submit to AI features is processed server-side by our AI provider to produce a response. We do not sell your data, and we do not use your private project content to train third-party public models.
Data is stored in PostgreSQL with row-level security so records are scoped to their owner. Files are stored in access-controlled storage. Passwords are hashed, never stored in plain text, and secret API keys are held server-side only.
Credentials you supply for QA testing are stored through a secure mechanism, restricted to assigned staff, and removed on request or at project close.
You can access, export, correct or delete your data, and object to certain processing. Contact us to exercise these rights; we respond within the timeframes required by applicable law.