Miindy

Version 2026-09-21

Privacy Policy

How Miindy handles account identity, collaboration, recipient access, optional public information, and evidence of authority. This policy shares the Terms of Service's version and staged availability boundaries.

Account and service information

We keep your email, chosen account name and avatar, verified-email status, password hash, and session and second-factor information needed to secure your account. Service records include sign-in and action times, network and browser information, Workspace and Task relationships, invitations, access grants, owner policies, and relationship changes.

We use this information to authenticate you, apply permissions, deliver verification and access messages, run available collaboration features, investigate abuse, diagnose errors, and understand product use. Account creation and email verification are recorded across ordinary registration, Task and Workspace invitation, and recipient entry. An invitation creates only the relationship it offers.

One identity, with contextual audiences

You have one account name and avatar. Your Profile starts private, and reserving a handle does not publish it. You may use a pseudonym. Optional biography and self-described affiliation become public through your intentional publication choice. Public Task ownership identifies its owning person or Workspace even without a published Profile, using permitted name, handle and, for a person, avatar; it does not publish optional Profile details or unrelated affiliations. An email-like account name is withheld from public display.

Your own settings show your account information. Workspace co-members can see your account name, email and avatar. Task-only collaborators see permitted name, avatar and any established public handle, without private email, the Workspace directory, unrelated affiliations, or other private Tasks. Public views disclose only permitted public identity and work. Private, unknown, and nonredirecting retired addresses do not identify a private holder. Handle availability reveals availability without identifying the holder.

User and Workspace handles share one unique namespace. Previous handles remain reserved permanently and redirect to public destinations only by deliberate choice. Account and Workspace deletion preserve reservations. Current hosted attribution follows the permitted current name while stable authorship remains recorded. Earlier names are not automatically published as a history; copies saved by others can contain them.

Ownership and private work

Workspace Owners can inspect every Task their Workspace owns. Other Task access follows current named grants or an explicitly selected all-members audience. A personal Task stays under its personal owner's authority when collaborators join. Access to one Task does not open the owner's other private resources or authorize combining material from separate client or research contexts.

Personal library contents, private affiliations, and unrelated activity retain their own audiences. Joining a Workspace or inviting a Task collaborator does not make a Personal library public. Personal libraries and Task content workflows are unavailable in this release; their intake requires the applicable release, source, and audience controls. Ordinary private use grants no model-training or evaluation-corpus permission.

Recipients and departure

A recipient grant records addressed email, the identified account when known at issue, a hash of the link secret, issuer and authority, expiry, claim, revocation and reissue, and commenting and downloading permissions. Unclaimed grants expire after 30 days; expiry is an access state, not a promise of deletion that day. Claim binds access to the verified intended account. Claimed access survives the unclaimed-link expiry and follows the account through email changes without passing to a new holder of the former address.

The authorized publisher can inspect recipient addresses and management states. The declared common audience sees recognizable names, avatars and relationships within the share, without automatic public-Profile links, private emails or affiliations. A recipient grant creates neither Workspace membership nor private Task access. Current share pages show access state and audience; publication content, evidence, comments, and downloads are unavailable in this release.

Workspace departure ends inherited and direct working Task access by default. An Owner removing another Member can retain selected Tasks as outside grants. Recipient access survives by default and is shown separately; that Owner can revoke selected or all applicable recipient grants from the same Workspace. Voluntary departure ends working grants and keeps recipient grants. Other owners' grants and personal work retain their own rules. Readmission applies current audiences and new admission authority without reviving ended direct Task grants.

Attribution and Standing records

Attribution permissions record your versioned choice at broad, Workspace, or Task scope, including denials and revocations. An authorized publication checks applicable permission without exposing unrelated relationships or choices. Identity disclosure permission is separate from access, editorial authority, and material rights. Earlier uses retain their permission evidence; later uses follow current choices.

Standing statements retain scoped claims, their basis, and immutable revisions. Optional credential records include your claimed credential, issuer, record reference, subject as stated, scope, evidence description, stated validity, recording time, withdrawal, and checking records. Recording leaves the credential's association with you unconfirmed; currency follows your stated dates. Issuer correspondence checking is unavailable, and a supplied reference does not verify a credential.

Publishing a Standing statement supported by a credential discloses the credential's claim, issuer, record reference, scope, evidence description, stated validity, recording time, withdrawal, and checks with that statement. The separate subject-name field remains private; identifying details you put in other published fields can still be visible. Credentials are optional and create no role or expert status. Withdrawal remains a distinct recorded state. Erasure removes existing identifying records under the removal rules below.

Agreement and processing acceptance

We record the Agreement version you affirmatively accept and when, with authority evidence for re-acceptance. Joining a Workspace or Task, claiming a share, and continued use do not accept another Agreement version. A notice offers review and acceptance without blocking unrelated covered work.

For expanded processing such as credential evidence, we retain the capability, immutable offered text, version, digest, accepting account, time, and actual scope. The affected action validates the offered version and records acceptance together with the authorized action. Covered later actions reuse that acceptance. A changed offer requires its own acceptance; declining affects only the uncovered use. Retained catalogue versions preserve what earlier acceptances meant.

Authority, enforcement, and retention

Minimal authority records identify the actor, relevant User, Workspace or Task scope, action, subject, authority and policy basis, applicable Agreement and permission or assent references, outcome, and time. Inspection follows that scope. Ordinary membership does not expose restricted Task activity through a Workspace audit log. Review-independence assessments retain their relationship basis privately; public results do not disclose private affiliation reasons.

The authority ledger is automatically purged after its 365-day retention period unless a recorded preservation basis and future end date apply. After erasure, only permission and assent evidence needed by retained authority records remains for restricted legal and security inspection; it contains no Standing statements, credential details, or public identity text. This evidence is deleted when supporting authority retention ends, with extension only for a recorded preservation obligation. Preservation supplies no ordinary publication or processing permission.

The ledger's 365-day period does not describe every account, relationship, provenance, enforcement, or recovery record, or a provider's telemetry. Stable relationship and authorship histories support retained references and authority assessments. Erasure and deletion records support removal and recovery enforcement. Their continued retention requires its applicable purpose and lawful basis; they do not justify retaining removed identifying credential or Standing content.

Suspensions, security holds, contests, and restorations retain their reasons and outcomes within authorized inspection. A public suspension limits specified public rights while preserving otherwise authorized private and recipient access. A security hold ends sessions and refuses ordinary entry. A contest is available through the account or verified email-based hold route. Restoration does not silently reinstate ended grants or earlier review eligibility.

Providers and diagnostics

Service providers host the application and database, deliver account and invitation email, run background work and abuse protection, measure usage, and report errors. They receive information for those functions. Using a hosted provider does not establish a particular processing location or data-residency guarantee.

Analytics can associate usage with your account identifier, name, email, and Workspace identifier and name. Browser storage and cookies support sessions and measurement. Diagnostics include request, browser, network, performance and error data, and sampled browser-session replay. These internal tools are distinct from public Profile disclosure. The authority ledger's retention period is not a verified provider-wide deletion deadline.

Removal, deletion, and restore

Unused, unverified account records older than seven days are eligible for automatic cleanup only when they have no reserved handles, Memberships, or authority records. Ordinary registration reserves a permanent handle, so leaving an account unverified does not itself erase it. Account settings let you change identity and security information. Where available, attribution erasure permanently unlinks public identity and removes published details and links, existing Standing statements including private statements and versions, credential records and checks, attribution permissions and related assents, subject to the minimal retained evidence above. Handles retire without redirects and remain reserved. Lawful references can use neutral anonymous attribution. Login, private account name and avatar, Memberships, Tasks and grants remain; later private Standing and credentials are possible, but public identity cannot be reestablished.

Account deletion previews ownership and access effects. Personal Tasks awaiting disposition and final-Owner responsibilities prevent completion. Task transfer and deletion needed to resolve personal ownership are unavailable in this release. Once responsibilities are resolved, deletion removes login credentials, sessions and second-factor data, ends Memberships and Task grants, revokes claimed recipient grants, applies erasure, and replaces account name, email and avatar with a tombstone and deletion time. A new account at the former email inherits none of the former account's identity, ownership, Memberships, grants, or attribution.

Workspace work and independently authorized copies retain their ownership and conditions. Other recipients' grants can survive deletion of their personal publisher, who can no longer manage them. Hosted removal cannot recall downloads. Task and Personal library content-removal workflows are unavailable in this release. Recovery must reapply recorded erasure, deletion, and current restrictions before restored data serves requests. This operation does not certify provider backup expiry or complete removal from external systems; those obligations require qualification before affected content features are released.

Changes to this policy

This policy is versioned with the Terms of Service. Material changes are offered for explicit acceptance of the version shown. Continued use or joining a Task or Workspace supplies no new acceptance. Unrelated covered work continues while an uncovered use waits for its applicable acceptance.