MindDuck Privacy Policy
Version 4 of 10/6/2026
This is a translation. The German version is legally binding. Read the German version
MindDuck Privacy Policy
Version 1 of 5 October 2026
Controller. The controller responsible for processing personal data on the MindDuck website and in the MindDuck services is Dmitriy Klein, Untere Alte Poststr. 235, 95485 Warmensteinach, Germany (further details in the Imprint). Please send questions and requests about your data to privacy@mindduck.app.
Website and account data
Visiting the website.
When you visit the website, our hosting provider Vercel Inc. processes your IP address, the date and time of the request, the page requested, technical information about your browser and the result of the request. This is necessary to deliver the page, fix errors and protect the service. The legal basis is our legitimate interest in secure and functional operation of the website, Art. 6(1)(f) GDPR. These log data are deleted after no more than 30 days unless they are needed longer to investigate a specific security incident.
Login and account. We store your email address, chosen language and technical account data. For one-time-code login, we process information about the code issued, its expiry and verification attempts. For the session, we store a technical identifier, browser information and the times of creation, expiry and use. This lets you sign in and use your account; the legal basis is Art. 6(1)(b) GDPR.
The one-time code is valid for 15 minutes. A website session lasts up to 30 days unless you sign out earlier. Expired entries are deleted during regular clean-up. We keep account data until you close your account; they are then deleted within 30 days unless statutory retention obligations apply. After you sign in, the website uses the necessary cookie “md_session” (see below).
Abuse prevention.
To limit frequent login attempts and other requests, we may process the IP address, the time of the request and a related identifier such as email address or account. The legal basis is Art. 6(1)(f) GDPR; our interest is protecting accounts and keeping the service running. These data are deleted after no more than 30 days.
Beta, licences and devices. We store the status of your application, your place in the beta or on the waiting list, redeemed vouchers, licence type, start, end and expiry dates and device limits. For each device we store the installation ID, device name, platform, app version, access checks and deactivations. We use these data to grant access and manage devices (Art. 6(1)(b) GDPR) and to investigate breaches of the access terms (Art. 6(1)(f) GDPR). They are kept for as long as the account exists.
The access check service receives only these technical data, not the content of your notes and chats. Access is determined automatically from licence status, term and the number of active devices; your content is not assessed. Questions about access check errors can be sent to support@mindduck.app.
Accepted terms. We store which version of the contract terms you accepted and when. This is necessary to perform and evidence the contract. For consents, we store their content, when they were given and, where applicable, when they were withdrawn. Depending on the purpose, the legal basis is Art. 6(1)(b) and (f) GDPR (contract and legal claims) or Art. 6(1)(c) GDPR (legal obligation to demonstrate consent). We keep these records for the duration of the contract and then until the three-year statutory limitation period expires.
Emails.
We send login codes, account security notices, access confirmations and replies to your requests. For this we pass your email address and the content of the message to our email delivery provider Resend (Plus Five Five, Inc.). Incoming emails to mindduck.app addresses are routed via Cloudflare, Inc. The legal basis is Art. 6(1)(b) GDPR and, for security notices, Art. 6(1)(f) GDPR. We send marketing emails and purchase offers only with your separate consent, Art. 6(1)(a) GDPR. Unsubscribing from marketing does not stop messages required under your contract.
Feedback and support.
We process the category and text of your request, your contact details, the attachments you select and technical information about the problem. Where processing is necessary to perform a contract or take pre-contractual steps you requested, the legal basis is Art. 6(1)(b) GDPR. For other requests, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is handling the request and defending related claims. We delete support requests no later than three years after the case is closed.
Diagnostic files are transmitted only if you attach them yourself and are used only as far as necessary to handle the report, on the same legal basis. Before sending, passwords, API keys, recovery codes and personal data not relevant to the problem are removed. Any use for other purposes requires its own legal basis and appropriate notice; special categories of personal data also require a basis under Art. 9 GDPR.
Purchases (once sales open). Payments are handled by Paddle.com Market Ltd, which acts as reseller (Merchant of Record) and is your contractual partner for the purchase. We receive the information needed to issue your licence and handle refunds: customer and order IDs, product, amount, currency, and the time and status of the payment or refund. We do not receive full card details. The legal bases are performance of the contract (Art. 6(1)(b) GDPR), statutory commercial and tax retention obligations (Art. 6(1)(c) GDPR) and fraud prevention (Art. 6(1)(f) GDPR). We keep accounting-relevant data for up to ten years. Paddle also processes data under its own privacy policy.
Gift access to noon.land.
At your separate request and with your consent, your email address, language and gift details are passed to noon.land, a service also operated by Dmitriy Klein; the legal basis is Art. 6(1)(a) GDPR. Registration and accounts on that platform are subject to its own terms. No content from the app is transferred with the gift request. Withdrawing consent in MindDuck does not close a noon.land account that has already been created.
Personal content in the app
Chats, notes, documents, attachments and the app’s search database are stored on your devices. For ordinary licence management we do not receive the content of your workspace. Content may reach external services when you use features you have connected, or reach us when you send it to support yourself.
The app encrypts content and uses the operating system’s secure key storage. Some technical metadata may remain unencrypted in local files. Encryption does not protect against programs that have access to a device that is already unlocked. Do not share recovery codes with others. If you lose all the necessary keys and devices, we cannot promise to recover your content.
AI providers.
When you use AI, your request, the necessary conversation history, the selected context and the relevant attachments are sent to the provider you chose. Besides the latest message, the request may include context found by the memory feature. Background features, once enabled, may create additional requests. With OpenRouter, recipients may be OpenRouter and the provider that actually runs the request.
Retention periods, use for training, processing locations and costs depend on the chosen provider and its settings. MindDuck cannot guarantee that providers will not store requests or use them for training. Check the provider’s terms before connecting it. Using your own API key does not remove the need for a legal basis to send other people’s personal data.
Web search, audio and images.
With external search, the chosen search service receives your query, and servers you visit can see the technical connection data. With external transcription, the chosen service receives the recorded audio. With image recognition or a model request containing an image, the relevant provider receives the selected image and the instructions. Connected external tools receive the data and permissions needed for the chosen action; review them before granting access to files and accounts.
Google Drive.
When sync is turned on, the app uploads encrypted packages to a dedicated app folder in your Google Drive. Google also receives technical connection data such as IP address, time and data volume. Turning sync off stops further transfers; data already uploaded and Google permissions already granted must be deleted or revoked separately. Sync does not give us an unencrypted copy of your workspace. Google Drive is subject to Google’s terms.
Updates and downloads.
When checking for a new version and downloading a build, the server delivering the files sees your IP address and technical request details. For protected downloads, the website may also check your licence and record the download. Local storage therefore does not mean the app never goes online.
Apple TestFlight.
If you get builds via TestFlight, Apple processes installation and usage data, crash reports and feedback sent via TestFlight. As the developer, we may receive technical reports, messages you send, screenshots and your tester information. We use these data only to improve the app; the legal basis is Art. 6(1)(f) GDPR. Apple provides its own privacy information, see “TestFlight and Member Data”.
Cookies and analytics
Necessary cookie.
The cookie “md_session” is necessary to keep you signed in. It contains a random session ID, is set after you sign in and lasts up to 30 days or until you sign out. The legal basis for accessing your device is § 25(2) no. 2 TDDDG; for processing the session data, Art. 6(1)(b) GDPR.
Optional analytics.
Only with your separate consent do we use Vercel Web Analytics for visitor statistics. It may process the time of the visit, the page path, the referrer, technical information about browser and device, approximate location and a temporary visit identifier. The legal basis is Art. 6(1)(a) GDPR and, for accessing your device, § 25(1) TDDDG. According to Vercel’s documentation, the visit identifier is discarded after 24 hours; aggregated statistics may be kept longer. Details are available in Vercel’s documentation.
Recipients and third countries
We use the following service providers as processors: Vercel Inc. (hosting and analytics), Supabase, Inc. (database), Resend (Plus Five Five, Inc.; email delivery) and Cloudflare, Inc. (email routing). Paddle, Apple and Google process data as independent controllers in the cases described above. AI, search and other services you connect yourself receive data at your instruction.
Some of these providers are based in the USA or process data outside the European Economic Area. Such transfers are based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
Obligation to provide data and your rights
Your email address, licence and device data are required for the account and the related access; without them these features are not available. Feedback, additional diagnostic files, marketing emails, analytics and noon.land gifts are optional.
Subject to the statutory conditions, you have the right to access and obtain a copy of your data, rectification, erasure, restriction of processing and data portability. You can withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing before the withdrawal. Send requests to privacy@mindduck.app; we may verify your identity if necessary.
Right to object.
You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. You may object at any time, without giving reasons, to the use of your data for direct marketing.
Right to lodge a complaint.
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.