Last updated: January 2025
This Data Policy provides detailed information about how Mindstage collects, processes, stores, and protects your data. It supplements our Privacy Policy with technical details about our data practices.
Key Principle: We believe in data minimization - we only collect what we need to provide and improve the Service.
Data Type | When Collected | Purpose |
---|---|---|
Account Data | Registration | User authentication and identification |
Content Data | Creating scenarios/characters | Service functionality |
Interaction Data | Using AI features | Personalization and improvement |
Media Assets | Uploading/generating images | Visual content for scenarios |
Important: Your personal conversations with AI characters are NOT used to train our models without explicit consent. We use aggregated and anonymized interaction patterns to improve the Service.
We process content to:
We analyze aggregated data to understand:
In case of a data breach:
Service Type | Data Shared | Purpose |
---|---|---|
AI Providers | Prompts and content (anonymized) | Generate AI responses |
CDN Provider | Public media assets | Content delivery |
Email Service | Email addresses, names | Account notifications |
Analytics | Anonymized usage data | Service improvement |
Currently, we do not provide public API access to user data. Any future API development will include:
You can access your data through:
Export your data in standard formats:
Deletion is Permanent: When you request data deletion, we permanently remove your data from our active systems within 30 days. Some data may remain in backups for up to 90 days but will not be restored.
What gets deleted:
What may be retained:
Data Category | Active Retention | Post-Deletion |
---|---|---|
Account Data | Until account deletion | 30 days |
User Content | Until manually deleted | 30 days |
Session Data | 30 days | Immediate |
Analytics Data | 2 years (anonymized) | N/A |
Security Logs | 1 year | N/A |
Backup Data | 30 days rolling | 90 days max |
Primary data storage is in the United States. For users outside the US:
We use automated systems for:
You have the right to:
We will notify you of significant changes through:
We publish annual transparency reports including:
Data Protection Officer
Email: [email protected]
Response time: Within 2 business days
Privacy Team
Email: [email protected]
Security Issues
Email: [email protected]
PGP key available upon request