Privacy Policy
Last updated: March 18, 2026
At Mimap, your privacy matters. This policy explains what data we collect, how we use it, and the choices you have.
1. Information We Collect
When you sign in with Google, we receive your email address and display name. As you use the app, we store the mind maps you create and your subscription status.
We also collect technical data automatically when you use the service:
- IP address and approximate location (country/region)
- Browser type, version, and operating system
- Pages visited, time spent, and referring URLs
- Device type and screen resolution
This data is collected via Vercel Analytics and Google Analytics, and is used solely for performance monitoring and improving the service.
2. How We Use Your Data
Your data is used exclusively to operate Mimap:
- Provide and maintain the service
- Process AI-generated mind maps
- Manage your subscription and billing
- Send essential service notifications
3. AI & Your Content
When you generate a mind map, your input is sent to OpenAI for processing. We do not use your content to train any AI models. OpenAI's API data usage policy also prohibits using API inputs for model training.
4. Data Sharing & Disclosure
We share data with a limited set of trusted service providers, strictly to operate Mimap. We never sell your data or share it with advertisers.
- Supabase — database and authentication (data stored in their secure infrastructure)
- OpenAI — processes your prompts to generate mind maps (not used for model training)
- Polar — handles subscription billing and payment processing
- Vercel — hosts the application and provides analytics
- Google Analytics — aggregated, anonymized usage statistics
We may disclose data if required by law, court order, or to protect the rights and safety of our users.
5. What We Don't Do
- We do not sell your data to third parties
- We do not share data with advertisers
- We do not use tracking pixels or ad trackers
- We do not build marketing profiles
6. Data Storage & Security
Your data is stored on Supabase with row-level security (RLS) enabled. Only you can access your mind maps unless you explicitly share them via a public link.
8. Cookies
We use essential cookies only for authentication and session management. No advertising or marketing cookies are used.
9. Your Rights (GDPR & CCPA)
Depending on where you live, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate data
- Erasure — request deletion of your account and all associated data
- Portability — receive your mind map data in a structured, exportable format
- Opt-out (CCPA) — California residents may opt out of any sale of personal data. We do not sell personal data.
To exercise any of these rights, contact us. We will respond within 30 days.
10. Data Deletion
You can delete individual mind maps at any time from your dashboard. To delete your entire account and all associated data, contact us. We will remove everything within 30 days — no backups are retained.
11. Changes to This Policy
We may update this policy from time to time. Registered users will be notified of significant changes via email.
12. Contact
Questions about this policy? Visit our contact page.