·Updated ·Faq·Minds Team

Is Minds GDPR Compliant and Secure?

How Minds handles data protection and security as of October 2026: the DPA, where data is hosted, which AI providers process it, encryption, and no model training on customer data.

Minds provides the documents and controls a GDPR and security review needs: a data processing agreement under Article 28 GDPR, a published subprocessor list with locations, technical and organisational measures, and a privacy policy. As of October 2026, the application is hosted in Frankfurt and the database in Stockholm, while AI processing uses model providers in the USA under the EU Commission's Standard Contractual Clauses. Customer data is not used to train general-purpose or third-party models. Whether your use is compliant depends on the data you upload and your lawful basis, so review these documents with your data protection officer.

Who this security and compliance overview is for

This page is for data protection officers, IT security, legal and procurement teams assessing Minds, and for research leads who need to answer their questions. For the general question of how GDPR applies to synthetic research, read are synthetic respondents GDPR compliant.

What data Minds processes, and where

Minds processes the data you and your team put into it: account and usage data, uploaded files and stimuli, prompts and Study answers, and the sources used to ground Minds and Audiences. According to the subprocessor list:

  • Application hosting runs on DigitalOcean in Frankfurt, Germany.
  • The database and authentication run on Supabase in Stockholm, Sweden.
  • AI processing uses OpenAI, Anthropic and Google Cloud Vertex AI in the USA, with some OpenAI and Anthropic requests routed through Vercel AI Gateway to those providers' own business APIs.
  • Web research for grounding uses providers such as Exa and Firecrawl in the USA.

The privacy policy states the legal basis for each provider and names the EU Commission's Standard Contractual Clauses as the basis for transfers to the USA. If your policy requires that the relevant data never leaves the EU, keep that data out of the platform.

Security measures

According to Minds' technical and organisational measures:

  • Encryption in transit with TLS 1.2 or higher, including internal service traffic.
  • Encryption at rest with AES-256 for the database, file storage and backups.
  • Logical tenant separation in the database with row-level security.
  • Credentials, OAuth tokens and API keys stored encrypted, scoped and revocable.

DigitalOcean and Supabase hold certifications such as SOC 2 Type II and ISO 27001. These are the providers' certifications; Minds itself does not currently hold a SOC 2 report or ISO certification.

Data use and model training

The data processing agreement states that customer data is not used, and subprocessors may not use it, to train, fine-tune or improve general-purpose, foundation, shared or third-party models. A private, customer-specific model is created only on your documented instruction and only for your workspace.

When Minds is the right fit for your organisation

Minds fits when your review accepts the processing described above, including US-based AI model providers under Standard Contractual Clauses, and your team wants to run synthetic research without recruiting participants.

It is not the right fit if your policy forbids any transfer of the relevant data outside the EU, or if you need a vendor that holds its own SOC 2 report or ISO certification. In those cases, use Minds only with public or aggregated data, or choose a different set-up. For a structured vendor review, use the GDPR guide to data security in AI market research.

Frequently asked questions

Is Minds GDPR compliant?

Minds provides what a GDPR review needs: a data processing agreement under Article 28, a published subprocessor list, technical and organisational measures, and a privacy policy. Whether a particular use is compliant depends on the data you put into the platform and your own lawful basis, so Minds does not claim that every use is compliant by default.

Where is Minds data hosted and processed?

As of October 2026, the application runs on DigitalOcean in Frankfurt, Germany, and the database on Supabase in Stockholm, Sweden. AI processing uses model providers in the USA, including OpenAI, Anthropic and Google Cloud Vertex AI; the privacy policy names the EU Commission's Standard Contractual Clauses as the transfer basis. Every subprocessor is listed with its location.

Does Minds use our data to train AI models?

No. Under the DPA, customer data is not used, and subprocessors may not use it, to train, fine-tune or improve general-purpose, foundation or third-party models. A private customer-specific model is created only when you explicitly ask for one.

How does Minds secure uploaded concepts and files?

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, including file storage and backups. Customer data is separated by tenant at the database level. The hosting providers hold certifications such as SOC 2 Type II and ISO 27001; these are provider certifications, and Minds itself does not currently hold a SOC 2 report or ISO certification.

Do we need to upload personal data to use Minds?

No. You can build Audiences from descriptions, published research and aggregated or anonymised survey results. If you upload files that contain personal data, or build a Mind of a named person, that data is processed under the DPA and needs a lawful basis on your side.

How can our security team review Minds?

Start with the DPA, the subprocessor list, the technical and organisational measures and the privacy policy, all published on the Minds legal pages. Enterprise customers can raise further questions during procurement.