# Minds > Minds is web-informed synthetic research: create AI personas and panels powered by Minds PRISM™, our proprietary source-modelling technology for public signals and research materials where enabled. Canonical Origin: https://getminds.ai ## LLM Resources - [Full Content](https://getminds.ai/llms-full.txt) Complete page content in markdown format. ## Pages ### Terms of Service for Minds | Minds Source: https://getminds.ai/legal/terms Description: Last Updated: June 24, 2026 Minds June 24, 2026·Minds Team h1. **Terms of Service for Minds** Last Updated: June 24, 2026 **Last Updated: June 24, 2026** By creating an account or using the services, the user agrees to these Terms of Service ("Terms"). If the user does not agree, the services should not be used. h2. 1. Who We Are We are **Art of X UG (haftungsbeschränkt)**, Köpenicker Straße 145, 10997 Berlin, Germany. h2. 2. The Services We provide tools for creativity and AI-assisted workflows. **All content generated by Minds and AI assistants on our platform is produced by artificial intelligence. Minds are not real people, and their outputs do not represent genuine communications from any natural person.** Core features include: - **User Accounts**: For managing personal data, preferences, and content. - **Flows**: Collaborative workspaces where users can organize ideas and work with AI assistants on creative tasks. - **Minds**: A gallery of AI creative companions with unique personalities and skills, including system, premium, and community-shared Minds. All Mind interactions are AI-generated. (Earlier versions of the platform referred to these companions as "Sparks"; the term "Minds" supersedes "Sparks" in these Terms and across the platform.) - **My Minds**: Tools for users to create, train, and share their own personal AI models. - **Teams and Organizations**: Team accounts, shared Minds/Flows, roles/seats, and team billing. - **Groups & Group Grounding**: Tools to assemble multiple Minds into synthetic groups, panels, or audiences, optionally grounded in publicly available statistical and demographic distribution data (see Section 4, "Group Grounding"). - **Content Uploads and Source Collection**: The ability to upload or submit voice, text, images, files, URLs, public web sources, and social/video sources for use in Flows and AI workflows. - **Voice, Video, Messaging, and Phone Features**: Optional voice mode, live audio/video/avatar conversations, SMS, WhatsApp, phone number, and voice-call features where enabled. - **Integrations**: Optional integrations such as Google Calendar, mobile push notifications, in-app purchases, and third-party authentication. - **API, MCP, Browser Extension, and Widgets**: Programmatic access, MCP tools, widgets, and browser-extension features for connecting Minds to approved external clients and workflows. - **Sharing**: Features to share Minds, outputs, and content with others. A more detailed description of the services is available in our [user guide](https://getminds.ai/guide/flows). The services may change or be discontinued at any time. h3. Accessibility We aim to make consumer-facing website, checkout, account, and support flows accessible in line with applicable accessibility requirements. Accessibility barriers can be reported to [accessibility@getminds.ai](https://getminds.ai/mailto:accessibility@getminds.ai) or [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai). Please include the affected page or feature, device/browser, assistive technology if any, and a short description of the issue. h2. 3. Eligibility & Accounts - Users must be at least 18 years old. - The user is responsible for their account and for keeping credentials confidential. - We may suspend or terminate accounts for violations of these Terms or applicable law. h2. 4. Acceptable Use The user will not: (a) violate law or third-party rights; (b) upload illegal, harmful, or infringing content; (c) attempt to gain unauthorized access or disrupt the services; (d) reverse engineer or misuse the services or APIs; (e) spam or abuse sharing features. When using automated collection features (including auto setup for Minds), the user confirms they have all necessary rights and permissions to collect, process, and reuse information about each submitted person or entity. The user must only submit: (i) information they have the right to use; (ii) links or content that are publicly available or otherwise authorized for such use; and (iii) must not submit unlawful, sensitive (e.g., health, political views), or data about minors. Art of X UG only provides tooling that processes publicly available information; the user remains solely responsible and liable for the data they choose to collect, store, or process through the services. h3. Voice Synthesis and Cloning Restrictions The user must not upload or use voice recordings, audio samples, video links (including YouTube videos), phone-call audio, or other audio/video source material to create synthetic voices of individuals without their explicit, documented consent. Creating voice clones for impersonation, fraud, deception, or any non-consensual purpose is strictly prohibited. The user represents and warrants that they have obtained all necessary rights and consents from any individual whose voice, likeness, or recording is used to train a Mind or generate synthetic speech. Violations may result in immediate account termination and may be reported to relevant authorities. h3. AI-Generated Image Restrictions The user must not use image generation features to create: (a) images depicting real, identifiable individuals without their explicit consent; (b) images depicting minors in any context; (c) non-consensual intimate or sexual imagery; (d) content that infringes trademarks, copyrights, or other intellectual property rights; (e) images intended to deceive, defraud, or spread misinformation (including deepfakes); (f) violent, hateful, or illegal content. The user is solely responsible for ensuring compliance with all applicable laws regarding AI-generated imagery. h3. Group Grounding and Public Distribution Data When creating a Group or using Group-level features (such as Group Grounding, group covers, panels, or synthetic-audience tools), the platform may incorporate publicly available statistical, demographic, and market-research distribution data — for example, census-style population aggregates, labour-market statistics, industry benchmarks, or results retrieved from public web sources — to ground synthetic groups in plausible real-world distributions. The user acknowledges and agrees that: (a) Distribution data is processed in **aggregate, statistical form** and is not used to identify, profile, target, or simulate any specific identifiable natural person. (b) Where the user supplies inputs to drive Group Grounding (including links, search queries, demographic targets, seed personas, or biographical details), the user warrants they have all rights necessary to submit those inputs under applicable data-protection, image, intellectual-property, and other laws, and that the inputs do not concern minors or special categories of personal data (Art. 9 GDPR) without a valid legal basis and documented consent. (c) Group-grounded outputs are AI-generated synthetic content within the meaning of Art. 50(4) of the EU AI Act and must not be represented as the views, statements, decisions, or actions of any real, identifiable individual or organisation. (d) Art of X UG provides only the tooling that processes publicly available aggregate information; the user remains solely responsible and liable for the inputs they choose to submit, for compliance with applicable law in their jurisdiction, and for any downstream use of group-grounded outputs. For details on the categories of distribution data ingested, the legal bases relied upon, and retention periods, see Section 4 of our Privacy Notice. h3. Content Moderation, Notices, and Redress Where the services host, store, display, or share User Content, we may review, restrict, remove, disable access to, or demote content, Minds, Flows, Groups, accounts, API clients, or integrations that we reasonably believe are illegal, infringe rights, violate these Terms, threaten service security, or create abuse risk. Users and third parties can report suspected illegal or infringing content to [legal@getminds.ai](https://getminds.ai/mailto:legal@getminds.ai) or [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai). A notice should include the relevant URL or content identifier, a clear explanation of the issue and legal basis, supporting information, contact details, and a good-faith statement that the notice is accurate. Where required by applicable law, including the EU Digital Services Act for covered features, we will process notices, provide reasons for moderation decisions, and offer a way to contest decisions. Appeals or objections can be sent to [legal@getminds.ai](https://getminds.ai/mailto:legal@getminds.ai) within six months after the decision notice, unless a different period is stated in the notice. We may use automated systems to assist moderation, but contested decisions are eligible for human review where required by law. h2. 5. User Content and License - The user retains ownership of content uploaded or created ("User Content"). - The user grants us a worldwide, non-exclusive, transferable, sublicensable, royalty-free license to host, store, copy, modify, process, analyze, display, and distribute User Content as necessary to provide, improve, secure, and operate the services (including backups, content moderation, embeddings, and model evaluation), and to comply with law. - If content is shared publicly or with others, the user grants us the rights necessary to deliver that sharing. - The user represents that they have all rights to grant the foregoing and that their User Content does not infringe rights or violate law. h2. 6. AI Features and Model Training - We use third-party AI, voice, source-extraction, messaging, and infrastructure providers (including providers listed in our Privacy Notice and Subprocessors page) to process prompts, generate outputs, create embeddings, transcribe/synthesize voice, generate images, extract user-submitted sources, route messages/calls, and operate integrations. Use of these features may be subject to those providers' terms and policies. - User interactions (including prompts, files, metadata) may be used for model quality, safety, and evaluation in accordance with our Privacy Notice and these Terms. - Users can opt-in to contribute their User Content to improve generalized datasets and models. If a user does not opt in, their User Content will not be included in generalized model training. Content created within a team account or shared in team-specific Flows is automatically excluded from training general models. - Outputs are generated content; they may be inaccurate or inappropriate. The user is responsible for evaluating and using outputs. h3. Ownership of AI-Generated Outputs Subject to compliance with these Terms, users retain rights to AI-generated outputs (including text, images, and audio) created through their use of the services. We make no claim to ownership of such outputs. However, the user acknowledges that: (a) similar outputs may be generated for other users; (b) outputs may be subject to third-party AI provider terms; (c) the user is solely responsible for ensuring their use of outputs complies with applicable laws and does not infringe third-party rights. h2. 6A. EU Artificial Intelligence Act Transparency This section addresses our transparency obligations and your obligations when you use or distribute AI-generated output under Regulation (EU) 2024/1689 (the "EU AI Act"). Article 50 transparency obligations apply from 2 August 2026; until that date, this section describes the platform's current disclosures, contractual user obligations, and readiness measures. h3. 6A.1 AI System Disclosure Minds is an AI-powered platform. All Minds, AI assistants, panels, synthetic audiences, and automated content generators on the platform are artificial intelligence systems. No Mind is a real person, and no Mind output constitutes a genuine communication from the individual whose personality, voice, or communication style a Mind may simulate. We disclose this in the product interface and onboarding, and users must preserve that disclosure when sharing outputs. h3. 6A.2 Labelling and Machine-Readable Marking of AI-Generated Content Minds labels AI-generated outputs in the product interface and stores generation metadata such as content type, timestamp, and model/provider where technically available. We are preparing machine-readable marking and provenance metadata for exported text, audio, and image outputs in line with Art. 50(2) EU AI Act, to the extent technically feasible and supported by the relevant format/provider by 2 August 2026. Users must not remove, alter, or hide any AI labels, metadata, watermarks, or provenance information applied by the platform. h3. 6A.3 Synthetic and Simulated Content (Deep Fakes) Certain Minds may simulate the communication style, voice, likeness, or behaviour of real or fictional persons, and group-grounded panels or synthetic audiences may generate aggregate-style outputs. These outputs are synthetic and must not be represented as the views, statements, decisions, or actions of any real individual, organisation, or population. If you publish or otherwise distribute such output outside Minds, you are responsible for clearly disclosing that it was artificially generated or manipulated and for preserving any platform-provided provenance information. h3. 6A.4 B2B and Enterprise Use If you use the Services in a business or enterprise context, including Mind panels, group-grounded simulations, AI-generated surveys, API/MCP integrations, or synthetic-audience tools for research, analysis, or decision-making, you acknowledge that: (a) The outputs are AI-generated and do not represent the views or statements of real individuals. (b) You are responsible for your own compliance with the EU AI Act and any other applicable regulations, including human oversight, transparency notices to your own users or stakeholders, and any sector-specific obligations. (c) Minds does not warrant that AI-generated outputs are suitable for regulatory, legal, medical, financial, hiring, credit, insurance, or other high-impact decisions. You should independently verify outputs before relying on them for material decisions. h3. 6A.5 Your Obligations By using the Services, you agree to: (a) Not remove, alter, or circumvent any AI-generated content labels, metadata, watermarks, or provenance information applied by the platform. (b) Maintain AI disclosure labels when sharing content with third parties. (c) Not represent AI-generated content as human-created content or as a genuine statement by the person, organisation, or group being simulated. (d) Comply with all applicable AI, data-protection, consumer-protection, intellectual-property, personality-rights, and platform rules that apply to your use and downstream distribution of outputs. Violation of these obligations may result in suspension or termination of your account in accordance with Section 15 of these Terms. h2. 7. Payment, Plans, and Billing (Stripe, App Stores, and RevenueCat) - We offer free and paid plans, including Individual, Team, and enterprise/custom plans. Plan limits may apply (e.g., flows, Minds, API usage, integrations, seats, or usage credits). - Web subscriptions, invoices, and payment methods are billed or managed via Stripe. Mobile in-app purchases may be billed through the applicable app store (for example, Apple App Store) and managed by RevenueCat. The billing provider shown at checkout controls the payment flow and may apply its own terms. - By subscribing or purchasing through a paid channel, the user authorizes recurring charges until cancellation through the applicable billing portal, app-store subscription settings, or other flow shown at checkout. - Public Marketplace Groups, partner-branded groups, verified groups, data-provider content, or similar add-ons may be offered as separately ordered paid add-ons, including per-seat, per-group, or custom charges. Unless stated otherwise at checkout or in an enterprise order form, such add-ons are not included in free allowances, trials, or base plan usage and may require a Team or enterprise plan. - Prices, taxes, usage limits, credits, and features may change. Users will be notified of material changes as required by law. - Cancellation takes effect at the end of the current billing period; no refunds for partial periods unless required by law. - Paid add-ons (including Marketplace Group access) are charged at the time of purchase and access begins immediately upon your express consent. For EU consumers, this means your right of withdrawal expires once the add-on has been fully performed (see Section 18). - We may offer promotions or trials; additional terms may apply. h3. Marketplace Groups and Partner Add-Ons Public, verified, or partner-branded Marketplace Groups may incorporate content, data, research classifications, segment descriptions, or other materials provided by creators, third-party partners, or data providers. A paid listing does not require a verified badge. A verified badge means that the listing is identified as partner-provided, curated, or validated for marketplace purposes; it does not mean that outputs are legal, financial, medical, regulatory, or other professional advice, nor that AI-generated outputs are guaranteed to be accurate for a specific decision. Unless expressly permitted in writing, the user may access paid or partner Marketplace Groups only through the services during the applicable subscription or add-on term. The user must not copy, export, scrape, extract, reverse engineer, resell, sublicense, train competing models on, or use paid or partner Marketplace Groups to recreate the creator's or partner's underlying data, methodology, classifications, or proprietary materials. Paid or partner Marketplace Groups may be locked against editing, copying, or customization; bespoke versions may require a separate partner or enterprise agreement. We may restrict, suspend, replace, or discontinue access to a paid or partner Marketplace Group or add-on if the relevant creator or partner agreement ends, required rights are no longer available, legal or security concerns arise, or the listing is withdrawn. Where required by law or by the applicable checkout terms, we will provide notice, a reasonable wind-down, refund, or substitute access. h3. Selling in the Marketplace (Partners and Creators) If you list a paid Marketplace Group or add-on as a creator or partner ("Partner"), the following additional terms apply. - **Connect onboarding.** Payouts are processed through Stripe Connect. To receive payouts you must create and complete onboarding for a connected Stripe account and accept the [Stripe Connected Account Agreement](https://stripe.com/connect-account/legal). We may withhold a listing's availability or any payout until your connected account is verified and payouts are enabled. - **Merchant of record; revenue share.** Buyers purchase from us, and we act as the merchant of record for marketplace transactions. For each paid purchase you receive your agreed share of the amount collected and we retain the remainder as a platform fee; the applicable split is shown in your partner settings or an order form. Payouts are made per buyer on the schedule set by us and Stripe, and only for amounts actually collected and not refunded, reversed, or disputed. - **Refunds, chargebacks, and claw-backs.** Because we are the merchant of record, we are responsible to buyers for refunds and chargebacks. Where a purchase you were paid on is later refunded, charged back, or otherwise reversed, your corresponding share is reversed and may be deducted from your connected-account balance or offset against future payouts. You remain responsible for your share of such reversals. - **Your content and rights.** You represent and warrant that you own or have all rights necessary to offer, monetize, and grant access to the Group, its members, data, classifications, and any partner branding, and that your listing does not infringe, misappropriate, or violate any third party's rights or applicable law. You grant us the rights necessary to host, display, market, and deliver your listing to buyers through the services. You will indemnify us for claims arising from your listing or its content as set out in Section 14. - **Taxes.** You are solely responsible for determining, collecting where applicable, reporting, and remitting any taxes due on your payouts. Amounts paid to you are exclusive of any taxes you may owe. - **Suspension and withdrawal.** We may review, decline, delist, suspend, or withhold payouts for a listing that violates these Terms, our policies, or applicable law, that is subject to a rights, fraud, or chargeback concern, or where required by Stripe or by law. h2. 8. Intellectual Property; Feedback - We and our licensors own all rights in the services, software, documentation, and models (excluding User Content). - By providing feedback, the user grants us a perpetual, irrevocable, royalty-free license to use said feedback to improve the services. h2. 9. Privacy and Security - We use Supabase and other providers for authentication and storage. We implement reasonable technical and organizational measures to protect data. No system is 100% secure. - The processing of personal data is described in our Privacy Notice. Our services also use cookies as further detailed in our Privacy Notice. By using the services, the user acknowledges and understands such processing as described in our Privacy Notice. h2. 10. Data Retention, Deletion, and Model Unlearning - A user may request deletion of their account and associated User Content. The data will be deleted from active systems and backups in accordance with our retention schedules and legal obligations. - After deletion, the user's data will not be used for training new generalized models. For existing models, we will take reasonable steps to prevent future use of the data (including retraining or suppression) where technically and commercially feasible. h2. 11. Third-Party Services Third-party services (e.g., Stripe, app stores, RevenueCat, AI/voice providers, source-extraction services, messaging/telecom providers, storage/CDN, analytics, and optional integrations such as Google Calendar) are subject to their own terms and privacy policies. User-selected external clients connected through API/MCP, widgets, or browser-extension features are independent services unless we provide them directly. We are not responsible for third-party services outside our control. h2. 12. Beta, Experimental, and Availability Disclaimer The services are offered on an "AS IS" and "AS AVAILABLE" basis, including experimental or beta features. We do not warrant accuracy, reliability, uptime, or fitness for a particular purpose. h2. 13. Limitation of Liability To the maximum extent permitted by law: (a) we will not be liable for indirect, incidental, special, consequential, punitive, or exemplary damages; and (b) our total liability for any claim will not exceed the amounts paid to us by the user in the 12 months preceding the event giving rise to the claim, or €50 if the user has paid nothing. h2. 14. Indemnity The user will defend and indemnify us against claims arising from their User Content, their use of the services, or their violation of these Terms or law. h2. 15. Suspension and Termination We may suspend or terminate accounts or access for any breach, risk to the services, fraud, or legal requirement. A user may stop using the services at any time. h2. 16. Changes to the Services or Terms We may modify the services and these Terms. If we make material changes, users will be provided notice (e.g., in-app or email). Continued use after changes constitutes acceptance. These Terms may be made available in multiple languages. The language version presented during checkout, account creation, or an enterprise order form controls that transaction. If no controlling language is specified, the English version is the operational reference for interpretation. Mandatory consumer-protection rights and mandatory local-language requirements remain unaffected. h2. 17. Export and Sanctions The user represents they are not prohibited from using the services under applicable export control and sanctions laws and will not use the services in restricted jurisdictions. h2. 18. Right of Withdrawal (EU Consumers) EU consumers have the statutory right to withdraw from contracts within fourteen days without giving any reason. The withdrawal period is fourteen days from the day of contract conclusion. **Withdrawal Instructions:** To exercise your right of withdrawal, you must inform us (Art of X UG (haftungsbeschränkt), Köpenicker Straße 145, 10997 Berlin, Germany, Email: [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai)) of your decision to withdraw from this contract by a clear statement (e.g., a letter sent by post or email). To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired. **Effects of Withdrawal:** If you withdraw from this contract, we shall reimburse to you all payments received from you, including delivery costs (with the exception of supplementary costs resulting from your choice of a type of delivery other than the least expensive type of standard delivery offered by us), without undue delay and in any event not later than 14 days from the day on which we are informed about your decision to withdraw from this contract. **Early Performance:** If you requested to begin the performance of services during the withdrawal period, you shall pay us an amount which is in proportion to what has been provided until you have communicated to us your withdrawal from this contract, in comparison with the full coverage of the contract. **Expiry of Right of Withdrawal:** The right of withdrawal expires in the case of a contract for the provision of services if we have fully performed the service and only began performance after you gave your express consent and at the same time confirmed your knowledge that you will lose your right of withdrawal upon complete performance of the contract by us. h2. 19. Governing Law and Venue These Terms are governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). Exclusive venue is Berlin, Germany, except where mandatory law provides otherwise for consumers. For consumers: Mandatory legal provisions of the country in which the consumer has their habitual residence remain unaffected. h2. 20. Dispute Resolution The European Online Dispute Resolution platform was discontinued on 20 July 2025 and is no longer available for submitting consumer complaints. We are not obligated and generally not willing to participate in dispute resolution proceedings before a consumer arbitration board. We prefer to resolve concerns directly; contact us at [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai). h2. 21. Severability If individual provisions of these Terms are or become invalid or unenforceable, the validity of the remaining provisions shall remain unaffected. h2. 22. Contact Questions: **[hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai)** --- ### Privacy Policy for Minds | Minds Source: https://getminds.ai/legal/dataprivacy Description: Effective Date: July 7, 2026 Minds July 7, 2026·Minds Team h1. **Privacy Policy for Minds** Effective Date: July 7, 2026 **Effective Date: July 7, 2026** This privacy policy provides information about the nature, scope, and purpose of the processing of personal data within the platform operated by **Art of X UG (haftungsbeschränkt)** (hereinafter "we" or "us"). h2. 1. Data Controller The controller within the meaning of the GDPR and other national data protection laws is: **Art of X UG (haftungsbeschränkt)** Köpenicker Straße 145 10997 Berlin Germany Email: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) h2. 2. Data Protection Officer The external Data Protection Officer can be reached as follows: Prof. Dr. Norman Uhlmann h3ko Innovations GmbH Pappelallee 64 16359 Biesenthal Germany Email: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) h2. 3. General Information on Data Processing The subject of data protection is personal data. This refers to all information relating to an identified or identifiable natural person (the "data subject"). Personal data of users is generally only processed to the extent necessary to provide a functional platform and its content and services. h3. Obligation to Provide Data The provision of personal data is neither legally nor contractually required. However, without providing the necessary data (such as email address and name for registration), we cannot offer you access to our services. Data marked as mandatory during registration or use is required for contract fulfillment. Failure to provide this data means the relevant services cannot be used. The provision of optional data is voluntary and does not affect your ability to use core services. h2. 4. What Data is Processed and For What Purpose h3. a. Provision of the Website and Creation of Logfiles (Hosting) Each time the website is accessed, the system automatically collects data and information from the computer system of the accessing computer. This data is stored in the server's logfiles. The following data is collected: - IP address of the requesting computer - Date and time of access - Name and URL of the retrieved file - Website from which access is made (referrer URL) - Browser used and, if applicable, the computer's operating system This data is processed to ensure smooth connection establishment and comfortable use of the website, as well as to evaluate system security and stability. The legal basis for data processing is Art. 6 Para. 1 S. 1 lit. f GDPR. The legitimate interest follows from the purposes for data collection listed above. The services of **DigitalOcean, LLC**, 101 6th Ave, New York, NY 10013, USA, are used for website hosting. Our infrastructure is hosted in the Frankfurt (Germany) region within the EU. A data processing agreement (DPA) has been concluded with DigitalOcean. Through this agreement, DigitalOcean ensures that data is processed in accordance with the GDPR and that the rights of data subjects are guaranteed. Further information can be found in DigitalOcean's privacy policy: https://www.digitalocean.com/legal/privacy-policy. h4. Cloudflare (CDN, DNS & Security) **Cloudflare, Inc.**, 101 Townsend St, San Francisco, CA 94107, USA, is used for content delivery (CDN), DNS management, DDoS protection, and web application security. When you access our website, your requests are routed through Cloudflare's network. In this process, Cloudflare may process your IP address, request headers, and other connection metadata to deliver content, protect against attacks, and optimize performance. The legal basis for this processing is Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in ensuring the security, availability, and performance of our website. A data processing agreement (DPA) has been concluded with Cloudflare. Data transfer to the USA is covered by Cloudflare's participation in the EU-US Data Privacy Framework and supplemented by Standard Contractual Clauses (SCCs). Further information: https://www.cloudflare.com/privacypolicy/. h3. b. Registration and Use of an Account (Authentication & Database) To use the platform, creating a user account is required. The following data is collected: - Name - Email address - Password (stored in encrypted form) This data is necessary to manage the account and enable access to the services. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment). For authentication and user database management, the services of **Supabase Inc.**, 970 Toa Payoh North #07-04, Singapore 318992, are used. Supabase provides the backend infrastructure for the platform. Data storage, including the database, authentication, storage, and AI-related embeddings, takes place in the Northern EU region (Stockholm, `eu-north-1`). A data processing agreement (DPA) has been concluded with Supabase. Further information on data protection at Supabase can be found here: https://supabase.com/privacy. h3. c. AI-Powered Features For the provision of AI-powered features, the following services are used: h4. OpenAI (Text Generation, Embeddings, Image Analysis) **OpenAI OpCo, LLC**, 3180 18th St, San Francisco, CA 94110, USA, is used for text generation, creation of embeddings from user content, voice transcription (Whisper), and image analysis. When these features are used, the relevant data (e.g., text inputs or content to be analyzed) is sent to OpenAI's servers for processing. We do not transmit any personal data to OpenAI beyond what is necessary for the function, and we store the results generated by OpenAI in our system hosted on Supabase (see above). The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as these features are a core component of the services offered. A data processing agreement has been concluded with OpenAI. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information on data protection at OpenAI can be found here: https://openai.com/policies/privacy-policy. h4. Anthropic (Text Generation with Claude Models) **Anthropic PBC**, 548 Market St, PMB 87430, San Francisco, CA 94104, USA, is used for advanced text generation using Claude AI models. When these features are used, your text inputs and prompts are transmitted to Anthropic's servers for processing. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as these features are a core component of the services offered. A data processing agreement has been concluded with Anthropic. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information on data protection at Anthropic can be found here: https://www.anthropic.com/legal/privacy. h4. Google AI (Text Generation with Gemini Models) **Google LLC**, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, is used for text generation and AI-powered features using Gemini models. When these features are used, your text inputs and prompts are transmitted to Google's servers for processing. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as these features are a core component of the services offered. A data processing agreement has been concluded with Google. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information on data protection at Google can be found here: https://policies.google.com/privacy. h4. ElevenLabs (Voice Processing) **ElevenLabs Inc.**, 20-22 Wenlock Road, London, N1 7GU, United Kingdom, is used for voice synthesis (text-to-speech) and voice transcription (Scribe v1). When you use voice features, audio data is transmitted to ElevenLabs for processing. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment). A data processing agreement has been concluded with ElevenLabs. Data transfer to the United Kingdom is covered by the EU Commission's adequacy decision for the UK (Decision 2021/1772), ensuring an adequate level of data protection. Further information: https://elevenlabs.io/privacy. h4. Langfuse (AI Observability & Prompt Management) **Langfuse GmbH**, Residenzstraße 27A, 80333 München, Germany, is used for managing AI prompts, tracking AI interactions, and system observability. This helps us improve service quality and debug issues. Technical metadata about AI interactions is processed. The legal basis for this processing is Art. 6 Para. 1 lit. f GDPR (legitimate interest). Our legitimate interest lies in ensuring service quality, debugging issues, and improving our AI features. As Langfuse is based in Germany, data remains within the EU. A data processing agreement has been concluded with Langfuse. Further information: https://langfuse.com/docs/data-security-privacy. h4. Deepgram (Speech-to-Text) **Deepgram, Inc.**, 548 Market St, Suite 25104, San Francisco, CA 94104, USA, is used for real-time voice transcription (speech-to-text) using the Nova-3 model. When you use voice features, your audio data is streamed to Deepgram's servers for transcription. Deepgram processes audio in real time and does not retain audio recordings after transcription is complete. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as voice transcription is a core component of the voice features offered. A data processing agreement has been concluded with Deepgram. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information: https://deepgram.com/privacy. h4. Fish Audio (Voice Synthesis & Cloning) **Hanabi AI Inc.** (operating as Fish Audio), 131 Continental Dr, Suite 305, Newark, DE 19713, USA, is used for text-to-speech voice synthesis and voice cloning. When you use voice features, text is sent to Fish Audio for speech synthesis. If you create a voice clone, audio samples you provide are transmitted to Fish Audio for voice model training. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as voice synthesis and cloning are core components of the voice features offered. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information: https://fish.audio/privacy. h3. d. Content in Flows and Training of Minds (User Content) The heart of the platform is the processing of content created by users in "Flows" (collaborative workspaces) and shared with "Minds" (AI assistants; previously referred to as "Sparks"). This can include voice recordings, texts, images, or other creative works ("User Content"). This data is processed for the following purposes: - **Training a Personal AI Model ("My Mind"):** User Content is used to create and train a personal AI model based on individual contributions. - **Training General AI Models:** If explicit consent (opt-in) has been given, User Content is also used to be incorporated into our larger, general AI models. These models may be used for commercial purposes and made available to customers. **Important Note for Team Users:** Content created as part of a team account or in shared team flows is fundamentally excluded from this regulation and will under no circumstances be used for training general AI models. The processing of User Content for training personal AI models is based on Art. 6 Para. 1 lit. b GDPR (contract fulfillment). The processing for training general AI models is exclusively based on explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR. h3. d2. Group Grounding and Public Distribution Data For the **Group Grounding** feature and related group-level functionality (synthetic panels, group covers, audience simulation, marketplace groups), the platform ingests and processes publicly available statistical and distribution data to ground synthetic groups of Minds in plausible real-world distributions. The categories of data processed include: - **Aggregate demographic and population statistics** (e.g. age, gender, occupation, education, geography distributions) sourced from public statistical offices, census-style datasets, and comparable open data sources. - **Industry, market, and labour-market benchmarks** sourced from publicly available reports, market-research summaries, and trade publications. - **Public web content** retrieved through our web-search provider (Tavily, see Section 4.g) when you explicitly request grounding from a public source (e.g. a public profile page, company website, or news article that you submit as input). - **Technical metadata** about the grounding request itself (your account identifier, the requested distribution parameters, the timestamp, and the resulting group configuration) so that the configuration is reproducible and auditable. This processing serves the purpose of generating realistic, statistically grounded synthetic groups for research, simulation, and creative work. **No personal data of identifiable natural persons is generated, profiled, targeted, or stored** as part of the distribution data itself; the data is processed in aggregate, statistical form. Where you submit inputs that may contain personal data of third parties (e.g. a link to a public profile), you are responsible for the lawfulness of that submission and warrant that you have all necessary rights and consents (see Section 4 of our Terms of Service). The legal bases for this processing are: - **Art. 6 Para. 1 lit. b GDPR (contract fulfillment)** for processing your account identifier, the grounding configuration, and the search inputs you submit, as these are necessary to deliver the Group Grounding feature you have requested. - **Art. 6 Para. 1 lit. f GDPR (legitimate interest)** for the ingestion and caching of publicly available aggregate statistics. Our legitimate interest lies in providing a robust, reproducible, and statistically meaningful grounding feature; the source data is already public and aggregate, and our interest is not overridden by the rights of data subjects, since no identifiable natural persons are processed. - In addition, processing of aggregate statistics for synthetic-research purposes is supported by **§ 27 BDSG** (processing for scientific or statistical purposes), to the extent applicable. **Retention:** Aggregate distribution datasets are cached for the duration of their usefulness as ground-truth references and are refreshed when source data updates; group configurations are retained for the duration of the user's account plus 30 days after deletion (see Section 5). Inputs submitted to the web-search provider are retained according to that provider's terms (see Section 4.g). **Sub-processors involved in Group Grounding** include the AI providers listed in Section 4.c (for generating grounded outputs), Tavily (Section 4.g, for public web search when used), and our hosting and database providers (Section 4.a–b). h3. e. Payment Processing If paid services are used, payment data is processed for the purpose of contract fulfillment. Processing is based on Art. 6 Para. 1 lit. b GDPR. Payment processing is carried out through the payment service provider **Stripe Payments Europe, Ltd.**, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. No credit card data is stored; it is directly forwarded to Stripe. Stripe is a certified partner and is subject to strict data protection and security standards. A data processing agreement has been concluded with Stripe. Further information on data protection at Stripe can be found at: https://stripe.com/privacy. h3. f. Mobile App Services (iOS/Android) When you use Minds through our mobile applications (iOS/Android), the following additional services and device features are used: h4. Firebase Cloud Messaging (Push Notifications) **Google LLC** (Firebase), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, is used to deliver push notifications to your device. When you enable push notifications, a device token (a unique identifier for your device) is generated and stored on our servers to route notifications. No message content beyond the notification payload is shared with Firebase. The legal basis for this processing is Art. 6 Para. 1 lit. a GDPR (consent), as push notifications are only sent after you explicitly grant permission. You can revoke this consent at any time by disabling notifications in your device settings. A data processing agreement has been concluded with Google. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information: https://firebase.google.com/support/privacy. h4. RevenueCat (In-App Purchases) **RevenueCat, Inc.**, 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, is used to manage in-app purchases and subscriptions on mobile devices. RevenueCat processes an anonymized user identifier, purchase receipts, and subscription status. No personal data such as name or email is shared with RevenueCat. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as in-app purchase management is required to provide paid services. A data processing agreement has been concluded with RevenueCat. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information: https://www.revenuecat.com/privacy. h4. Native Authentication (Apple/Google Sign-In) When you sign in using Apple Sign-In or Google Sign-In on mobile devices, an identity token is issued by Apple or Google and exchanged with our authentication service (Supabase) to create or link your account. We receive only the information you authorize (typically name and email address). No credentials are stored on our servers; authentication is handled via secure token exchange. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment). h4. Device Permissions The mobile app may request access to the following device capabilities: - **Microphone:** Required for voice mode (real-time conversations). Audio is streamed to Deepgram for transcription and is not stored on our servers. - **Camera:** Used for capturing images to upload as content for AI analysis. Images are processed only when you explicitly initiate a capture. - **Photo Library:** Used to select existing images or files for upload. Only files you explicitly select are accessed and uploaded. Each permission is requested only when you first use the relevant feature. You can revoke any permission at any time through your device settings. The legal basis for this processing is Art. 6 Para. 1 lit. a GDPR (consent). h3. g. Additional Data Processing Services The platform uses additional specialized services to enhance functionality. These services process only the inputs needed for the feature you request. h4. Tavily (Web Search) **Tavily AI**, services via api.tavily.com, is used to provide web search capabilities within the platform. When you use search features, search queries, submitted URLs, and public page snippets may be transmitted to Tavily for processing. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment), as web search is a feature of the services offered. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information: https://tavily.com/privacy. h4. Firecrawl (Web Extraction and Screenshots) **Firecrawl**, operated by SideGuide Technologies, Inc., is used to retrieve, extract, and in some cases visually analyze public web pages or screenshots when you submit links or request web/source analysis. Processed data may include submitted URLs, page content, screenshots, and technical metadata. The legal basis is Art. 6 Para. 1 lit. b GDPR for requested source analysis and Art. 6 Para. 1 lit. f GDPR for source quality, security, and debugging. Data transfer to the USA is based on standard contractual clauses. Further information: https://www.firecrawl.dev/privacy-policy. h4. Apify (Social and Video Source Extraction) **Apify Technologies s.r.o.**, Czech Republic, is used for public social-media, web, and video transcript/content extraction when you provide a URL or request source collection for a Mind. Processed data may include submitted URLs, public profile/post/video metadata, transcripts, and extraction logs. The legal basis is Art. 6 Para. 1 lit. b GDPR (contract fulfillment). The legal basis is Art. 6 Para. 1 lit. b GDPR. Data transfer to third countries is based on standard contractual clauses where required. h4. Public API, MCP, Browser Extension, and External Clients When you use our public API, MCP server, browser extension, widgets, or third-party clients that connect to Minds (for example ChatGPT, Claude, OpenRouter, Open WebUI, or LibreChat), we process API keys, OAuth authorization codes/access tokens, scopes, request metadata, tool calls, prompts, content, widget/session identifiers, and audit logs required to authenticate, route, secure, and deliver the integration. The legal basis is Art. 6 Para. 1 lit. b GDPR and Art. 6 Para. 1 lit. f GDPR for security and audit logging. Third-party clients chosen by you may independently process your data under their own terms. h4. Google Calendar Integration If you connect Google Calendar, we use the Google Calendar API to sync calendar events and related metadata. We request the calendar.events scope, store access/refresh tokens, create webhook channels, read future event metadata and attendees, create related Minds, and may update event descriptions with Mind links when enabled. Data includes calendar IDs, event IDs, titles/descriptions/times, attendee names/emails, webhook identifiers, token scopes/expiry, and sync status. The legal basis is Art. 6 Para. 1 lit. a GDPR (consent) and Art. 6 Para. 1 lit. b GDPR (contract fulfillment). You may disconnect the integration in settings; tokens, webhook channels, and synced events are deleted subject to backup retention. h4. Twilio (SMS, WhatsApp, and Voice Calls) Optional messaging and phone features use **Twilio Inc.** for SMS, WhatsApp sender management, phone number provisioning, and voice call media streams. Data may include assigned phone numbers, caller/sender numbers, message metadata/content, call metadata, and call audio streams. Voice calls may also be processed by Deepgram and Fish Audio as described above. The legal basis is Art. 6 Para. 1 lit. b GDPR; where consent is required for call recording, voice cloning, or similar features, Art. 6 Para. 1 lit. a GDPR applies. h3. h. Communication via Email For sending platform-related emails (e.g., registration confirmations, password resets), the service **Resend** is used, offered by Resend Inc., 548 Market St PMB 95453, San Francisco, CA 94104-5401, USA. Resend processes the email address on our behalf. The legal basis for this processing is Art. 6 Para. 1 lit. b GDPR (contract fulfillment) for transactional emails. A data processing agreement (DPA) has been concluded with Resend. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Further information can be found in Resend's privacy policy: https://resend.com/legal/privacy-policy. h3. i. Cookies Cookies, local storage, and similar technologies are used on the website and in the app. Necessary storage is used for login, security, language, consent, session, and core app functions. Non-essential analytics or marketing cookies and comparable device storage are used only with consent. For users in Germany, access to or storage of information on the end device is based on § 25 TDDDG where applicable. The related personal-data processing is based on Art. 6 Para. 1 lit. a GDPR for consent-based analytics and marketing, and on Art. 6 Para. 1 lit. f GDPR for strictly necessary security, fraud-prevention, and service functions. You can change or revoke consent at any time through our cookie settings. The browser can also be configured to reject or delete cookies, although some core functions may then be unavailable. h3. j. Web Analytics with Google Analytics This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies that enable analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. The storage of Google Analytics cookies and the use of this analytics tool is based on your consent according to Art. 6 Para. 1 lit. a GDPR. You can change or revoke this consent at any time through our cookie settings. We have activated IP anonymization on this website. As a result, your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. We have concluded a data processing agreement with Google. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/. More information on Google Analytics' handling of user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245. h3. k. Product Analytics with PostHog We use the product analytics service **PostHog**, provided by PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. PostHog helps us understand how users interact with our platform and may include session replay. Persistent analytics cookies, localStorage persistence, analytics user identification, and session replay are used only with analytics consent. Without analytics consent, PostHog is configured without persistent analytics cookies; limited cookieless or in-memory events may be processed for product reliability, abuse prevention, and aggregated service improvement where lawful. The legal basis for consent-based analytics is Art. 6 Para. 1 lit. a GDPR. For limited security, reliability, and abuse-prevention processing that is strictly necessary for the service, the legal basis is Art. 6 Para. 1 lit. f GDPR. You can change or revoke consent in cookie settings. We have concluded a data processing agreement with PostHog. Data is processed in the EU region. Further information can be found in PostHog's privacy policy: https://posthog.com/privacy. h3. l. Conversion Tracking with TikTok Pixel We use the **TikTok Pixel**, a conversion tracking tool provided by TikTok Information Technologies UK Limited and TikTok Technology Limited ("TikTok"). The TikTok Pixel allows us to track user actions and measure the effectiveness of our advertising campaigns on TikTok. The TikTok Pixel collects data about your interactions with our website (e.g., page views, registrations) and transmits it to TikTok. The TikTok Pixel is **only activated with your explicit consent** for marketing cookies (Art. 6 Para. 1 lit. a GDPR). You can revoke your consent at any time. Data transfer to third countries is secured by the EU Commission's standard contractual clauses. More information on TikTok's data processing: https://www.tiktok.com/legal/page/eea/privacy-policy/en. h3. m. Conversion Tracking with X Pixel We use the **X Pixel** (formerly Twitter Pixel), a conversion tracking tool provided by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA ("X"). This tool helps us measure the success of our advertising on X. The X Pixel tracks actions on our website and transmits them to X. The X Pixel is **only activated with your explicit consent** for marketing cookies (Art. 6 Para. 1 lit. a GDPR). You can revoke your consent at any time. Data transfer to the USA is secured by the EU Commission's standard contractual clauses. More information on X's data processing: https://twitter.com/en/privacy. h2. 5. Storage Duration and Data Deletion Personal data is stored for the following periods: | Data Category | Retention Period | Reason | | --- | --- | --- | | Account data (name, email) | Duration of account + 30 days after deletion | Contract fulfillment and account recovery | | User Content (Flows, Minds) | Duration of account + 30 days after deletion | Contract fulfillment | | Group Grounding configurations and inputs | Duration of account + 30 days after deletion | Contract fulfillment | | Aggregate distribution datasets (no personal data) | Refreshed periodically; cached as long as required for the feature | Legitimate interest / statistical purpose | | Server logfiles | 90 days | Security and debugging | | Payment records | 10 years after transaction | German tax law (§ 147 AO) | | Consent records | 3 years after withdrawal | Proof of consent (Art. 7 GDPR) | | Content moderation, illegal-content notices, appeals, and decision records | Up to 3 years; longer where required for legal claims | Legal compliance, abuse prevention, rights enforcement | | Analytics data | 14 months | Service improvement | | AI interaction logs | 90 days | Quality assurance and debugging | | API keys, OAuth/MCP tokens, and integration audit logs | Duration of account or until revoked; audit/security logs up to 3 years | Contract fulfillment, security, abuse prevention | | Google Calendar tokens, webhook channels, and synced event metadata | Until disconnect or account deletion + 30 days | Consent / contract fulfillment | | SMS/WhatsApp/voice metadata and assigned phone numbers | Duration of feature use/account + 30 days; provider records per provider/legal retention | Contract fulfillment, abuse prevention | | Submitted URLs, web extraction results, screenshots, and source-search metadata | Duration of related Mind/Flow/Group + 30 days unless cached as non-personal aggregate source data | Contract fulfillment and reproducibility | | Backup data | 30 days after deletion from active systems | Disaster recovery | **Right to Deletion:** The deletion of the account and all associated data can be requested at any time. This can be done directly in the settings under [/settings/preferences](https://getminds.ai/settings/preferences). After such a request, personal data and user content are permanently removed from active systems within 30 days. Backup data is purged according to our backup retention schedule. The data will no longer be used for training new models, and all reasonable technical steps will be taken to remove it from existing models as well. h2. 6. Automated Decision-Making and Profiling Our platform uses AI-powered features that may involve automated processing of your data: h3. AI-Assisted Features When you use our AI features (Flows, Minds, Group Grounding), your inputs are processed by AI models to generate outputs. This processing: - **Does not constitute automated decision-making** with legal or similarly significant effects under Art. 22 GDPR - Is used solely to provide the creative and conversational services you request - Does not result in decisions that produce legal effects or significantly affect you - Remains under your control—you decide how to use any AI-generated outputs h3. Personalization If you create a personal AI model ("My Mind"), the system analyzes your uploaded content to create a personalized AI assistant. This is based on your explicit request and consent (Art. 6 Para. 1 lit. a and b GDPR). You can delete your personal model at any time. h3. Content Moderation, Notices, and Appeals We may use automated systems and human review to detect content that violates our Terms of Service or applicable law, including harmful, illegal, infringing, abusive, or security-risk content. Flagged content may be reviewed by our team. When users or third parties submit illegal-content notices, rights complaints, moderation appeals, or objections, we process the information needed to assess and document the request. This can include reporter contact details, account identifiers, URLs/content IDs, submitted reasons and evidence, moderation decision records, timestamps, and follow-up communications. The legal basis is Art. 6 Para. 1 lit. c GDPR where processing is required by law, Art. 6 Para. 1 lit. f GDPR for service integrity, abuse prevention, legal defense, and rights enforcement, and Art. 6 Para. 1 lit. b GDPR where moderation is necessary to perform or enforce the user agreement. Moderation and notice records are generally retained for up to 3 years unless a longer period is required to establish, exercise, or defend legal claims. h3. Your Rights Regarding Automated Processing You have the right to: - Obtain human intervention in decisions that significantly affect you - Express your point of view and contest decisions - Request information about the logic involved in automated processing - Opt out of non-essential automated processing To exercise these rights, contact us at [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai). h2. 7. EU AI Act Transparency and AI-Generated Content h3. 7.1 AI System Disclosure The Minds platform is an AI-powered platform within the scope of Regulation (EU) 2024/1689 (the "EU AI Act"). Article 50 transparency obligations apply from 2 August 2026. Until that date, this section describes our current disclosures, contractual obligations, and readiness measures for AI transparency. h3. 7.2 Notification of AI Interaction Before or at the time of your first interaction with any Mind or AI assistant, we inform you that you are interacting with an AI system, not a natural person. This notification is provided through in-app disclosures, onboarding screens, and labelling within the user interface. We process your account identifier, interaction timestamp, and acknowledgement metadata where needed to document that this notification has been delivered. h3. 7.3 Labelling and Machine-Readable Marking Minds labels AI-generated outputs in the product interface and stores generation metadata such as content type, creation timestamp, model/provider identifier where technically available, and output context. We are preparing machine-readable marking and provenance metadata for exported text, audio, and image outputs in line with Art. 50(2) EU AI Act, to the extent technically feasible and supported by the relevant format/provider by 2 August 2026. We do not use this metadata for profiling or marketing. It is used to disclose AI origin, support auditability, preserve context for shared/exported outputs, and respond to user or regulatory transparency requests. h3. 7.4 Synthetic Content Disclosure Where Minds simulate the communication style, voice, likeness, or behaviour of real or fictional persons, or where group-grounded panels generate aggregate-style outputs, the resulting output is synthetic. We disclose the artificial origin of such content through visible labels and, where technically feasible, metadata/provenance information. To support this disclosure, we process Mind configuration data, group-grounding configuration, generation logs, and output metadata. h3. 7.5 Legal Basis Until the relevant EU AI Act transparency obligations apply on 2 August 2026, transparency and provenance-readiness processing is based on Art. 6 Para. 1 lit. b GDPR where needed to provide the service and Art. 6 Para. 1 lit. f GDPR for accountability, security, and misuse prevention. From 2 August 2026, where processing is required to comply with Art. 50 EU AI Act, the legal basis will be Art. 6 Para. 1 lit. c GDPR. h3. 7.6 Data Processed for AI Transparency Purposes | Data Category | Purpose | Retention | | --- | --- | --- | | AI interaction notification records | Proof that AI-system disclosure was provided | Duration of account plus 3 years | | Generation metadata and available provenance data | AI-origin labelling, export context, and auditability | As long as the content exists on the platform, plus 1 year | | Mind persona/configuration data | Synthetic-content disclosure and misuse prevention | Duration of account plus 3 years | | Group-grounding configuration (distribution parameters, sources used) | Synthetic-output disclosure for group-grounded outputs | Duration of account plus 3 years | | Content generation logs (model, timestamp, type) | Auditability, debugging, and regulatory accountability | 3 years from content creation | h3. 7.7 Your Rights In addition to your GDPR rights (see Section 8), you may request confirmation of whether a specific output was generated by AI and what generation/provenance metadata is available. Where transparency processing relies on legitimate interests, you may object under Art. 21 GDPR. Processing that is legally required after the EU AI Act obligations apply cannot be opted out of. h2. 8. Rights of the Data Subject Data subjects have the following rights regarding their personal data: - **Right to Access** (Art. 15 GDPR) - **Right to Rectification** (Art. 16 GDPR) - **Right to Erasure** ("Right to be Forgotten") (Art. 17 GDPR) - **Right to Restriction of Processing** (Art. 18 GDPR) - **Right to Data Portability** (Art. 20 GDPR) - **Right to Object** (Art. 21 GDPR) There is also the right to **withdraw** consent at any time with effect for the future (Art. 7 Para. 3 GDPR). The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. To exercise these rights, the contact address mentioned above can be contacted. h2. 9. Right to Lodge a Complaint with a Supervisory Authority Without prejudice to any other administrative or judicial remedy, there is the right to lodge a complaint with a supervisory authority, in particular in the Member State of residence, place of work, or place of the alleged infringement, if it is believed that the processing of personal data violates the GDPR (Art. 77 GDPR). The supervisory authority responsible for us is: **Berliner Beauftragte für Datenschutz und Informationsfreiheit** Friedrichstr. 219 10969 Berlin Germany Phone: +49 30 13889-0 Email: [mailbox@datenschutz-berlin.de](https://getminds.ai/mailto:mailbox@datenschutz-berlin.de) Website: https://www.datenschutz-berlin.de h2. 10. Data Security All necessary technical and organizational security measures are taken to protect personal data from loss and misuse. Data is stored in a secure operating environment that is not accessible to the public. Data transmission is encrypted using SSL technology. h2. 11. Changes to This Privacy Policy We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to services in the privacy policy, e.g., when introducing new services. The new privacy policy will then apply to future visits. --- ### Data Processing Agreement (DPA) | Minds Source: https://getminds.ai/legal/dpa Description: Last Updated: May 30, 2026 Minds May 30, 2026·Minds Team h1. **Data Processing Agreement (DPA)** Last Updated: May 30, 2026 **Last Updated: May 30, 2026** This Data Processing Agreement ("DPA") pursuant to Art. 28 GDPR forms part of the Agreement between Art of X UG (haftungsbeschränkt) ("Processor", "we", "us") and the Customer ("Controller", "you") for the use of our services (the "Main Agreement"). h2. 1. Definitions - **Personal Data**: Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR). - **Processing**: Any operation performed on Personal Data, including collection, storage, use, and deletion (Art. 4(2) GDPR). - **Sub-processor**: Any third party engaged by the Processor to process Personal Data. - **GDPR**: Regulation (EU) 2016/679 (General Data Protection Regulation). - **Data Breach**: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (Art. 4(12) GDPR). h2. 2. Scope and Duration of Processing 2.1 This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the services. 2.2 The Processor shall process Personal Data only for the purposes of providing the services as described in the Main Agreement and in accordance with the Controller's documented instructions. 2.3 The duration of the Processing corresponds to the term of the Main Agreement, unless further obligations arise from the provisions of this DPA. h2. 3. Data Processing Details | Category | Description | | --- | --- | | **Subject Matter** | Provision of the AI-powered platform "Minds", including AI assistants, synthetic panels, group-grounded simulations, API/MCP access, browser-extension and widget workflows, integrations, voice/messaging features, and related services | | **Duration** | For the term of the Main Agreement | | **Nature and Purpose** | Hosting, authentication, storage, retrieval, analysis, simulation, and generation of outputs from Controller-provided data; operation of optional integrations such as Google Calendar, public API/MCP access, source extraction, messaging/voice, and billing. Controller data is not used for training general-purpose models or models accessible to third parties unless the Controller has expressly opted in. AI sub-processors are accessed via API endpoints and contractual no-training/retention controls where available. | | **Types of Personal Data** | Contact data (name, email), access credentials, usage data, content data provided by the Controller (text, images, audio, files, URLs), prompts and outputs, embeddings, API keys, OAuth tokens, calendar event/attendee metadata, phone/message/call metadata and audio where enabled, technical data (IP address, browser, device), payment data (via Stripe), audit and security logs | | **Categories of Data Subjects** | Controller's employees and agents, end users invited by the Controller, individuals whose data is entered into the platform by the Controller, and individuals referenced in submitted content, calendar events, messages, or public sources | h2. 4. Instruction Rights 4.1 The Processor shall process Personal Data only on the basis of documented instructions from the Controller, including the instructions set out in this DPA and the Main Agreement, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information. 4.2 Instructions may be given in writing or in text form (including email). Oral instructions shall be confirmed in text form without undue delay. 4.3 The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes data protection law (Art. 28(3) sentence 3 GDPR). The Processor shall be entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the Controller. h2. 5. Processor Obligations The Processor shall: 5.1 Process Personal Data only within the scope of the Controller's instructions and not for its own purposes. 5.2 Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). 5.3 Implement and maintain appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR throughout the duration of this DPA. The current TOMs are described in **Appendix 1 – Technical and Organizational Measures (TOM)** of this DPA and available at https://getminds.ai/legal/tom. 5.4 Immediately inform the Controller if the Processor becomes aware of any violations of the GDPR or other data protection regulations in connection with the Processing. 5.5 Designate a Data Protection Officer where required by law. The current Data Protection Officer is: Prof. Dr. Norman Uhlmann, h3ko Innovations GmbH, Pappelallee 64, 16359 Biesenthal, Germany. Email: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) h2. 6. Data Subject Rights 6.1 The Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests for exercising the data subjects' rights laid down in Chapter III of the GDPR (access, rectification, erasure, restriction of processing, data portability, objection). 6.2 If a data subject contacts the Processor directly with a request, the Processor shall forward the request to the Controller without undue delay. h2. 7. Assistance with Data Protection Obligations 7.1 The Processor shall assist the Controller, taking into account the nature of the Processing and the information available to the Processor, in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, in particular: - ensuring the security of Processing (Art. 32 GDPR); - notifying Personal Data breaches to the supervisory authority (Art. 33 GDPR) and to data subjects (Art. 34 GDPR); - carrying out Data Protection Impact Assessments (Art. 35 GDPR); - prior consultation with the supervisory authority (Art. 36 GDPR). 7.2 The Processor shall assist the Controller with requests and investigations by data protection supervisory authorities relating to the commissioned Processing. h2. 8. Sub-processors 8.1 The Controller hereby grants the Processor general written authorization to engage Sub-processors pursuant to Art. 28(2) GDPR, subject to the requirements of this section. 8.2 The current Sub-processors at the time of conclusion of this DPA are listed at https://getminds.ai/legal/subprocessors. 8.3 The Processor shall notify the Controller of any intended addition or replacement of Sub-processors at least **14 days** before the planned change, giving the Controller the opportunity to object. 8.4 If the Controller raises objections within the notice period, the parties shall endeavor to reach an amicable solution. If this is not possible, the Controller shall have the right to terminate the Main Agreement with immediate effect. 8.5 The Processor shall contractually ensure that Sub-processors are bound by data protection obligations no less protective than those set out in this DPA (Art. 28(4) GDPR). The Processor shall be liable for the acts and omissions of its Sub-processors as for its own acts and omissions. h2. 9. International Transfers 9.1 Processing of Personal Data in a third country or by an international organization shall only take place where the specific conditions of Articles 44 et seq. GDPR are met. 9.2 For Sub-processors located in the United States, transfers are carried out on the basis of: - The EU-US Data Privacy Framework (DPF), where the Sub-processor is certified - Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914 9.3 For Sub-processors in the United Kingdom, the European Commission's adequacy decision (Decision 2021/1772) applies. 9.4 The Processor monitors the status of applicable adequacy decisions and transfer mechanisms and shall inform the Controller if changes require an adjustment to the transfer basis. 9.5 If the Processor or any of its Sub-processors receives a governmental order for the disclosure of Personal Data (including orders under the US CLOUD Act, FISA, or comparable legislation), the Processor shall inform the Controller without undue delay, to the extent legally permitted. The Processor shall review the legality of the order and pursue reasonable legal remedies before disclosing any Personal Data. h2. 10. Personal Data Breach Notification 10.1 The Processor shall notify the Controller without undue delay, and in any event within **24 hours**, upon becoming aware of a Personal Data breach. 10.2 The notification shall include at a minimum: - a description of the nature of the breach, including where possible the categories and approximate number of data subjects and data records concerned; - the name and contact details of the Data Protection Officer or other point of contact; - a description of the likely consequences of the breach; - a description of the measures taken or proposed to address the breach and to mitigate its effects. 10.3 The Processor shall assist the Controller in fulfilling the notification obligations pursuant to Articles 33 and 34 GDPR. h2. 11. Audit Rights 11.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR. 11.2 The Controller shall be entitled to conduct audits, including inspections, at the Processor's premises or have them conducted by an appointed auditor. Such audits shall take place upon reasonable notice (at least 14 days) during normal business hours and shall not unreasonably disrupt the Processor's business operations. 11.3 The Processor may present current audit reports, certifications, or extracts thereof to demonstrate compliance. 11.4 Appointed third-party auditors must be bound by confidentiality obligations in advance. Audit costs shall be borne by the Controller, unless a breach by the Processor is established. h2. 12. Deletion and Return of Personal Data 12.1 Upon termination of the Main Agreement, the Processor shall delete all Personal Data processed on behalf of the Controller within **30 days**, unless the Controller requests the return of the data in a common, machine-readable format. 12.2 Deletion shall be carried out in accordance with the current state of the art and shall be confirmed to the Controller in writing upon request. 12.3 Where retention is required under Union or Member State law, the Processor shall inform the Controller of the retention obligation and the data concerned. h2. 13. Liability 13.1 The parties' liability shall be governed by Art. 82 GDPR. 13.2 The Processor shall be liable to the Controller for damages attributable to Processing that does not comply with the GDPR or the Controller's instructions. 13.3 The Processor shall be liable for the acts and omissions of its Sub-processors as for its own acts and omissions. 13.4 Unless otherwise agreed in the Main Agreement, the Processor's aggregate liability shall be limited to the fees paid to the Processor in the 12 months preceding the event giving rise to the claim. This limitation shall not apply to claims arising from intentional misconduct or gross negligence, nor to claims whose limitation is impermissible under the mandatory provisions of the GDPR. h2. 14. Amendments to this DPA 14.1 The Processor may amend this DPA with at least 30 days' notice before the amendment takes effect, where such amendment is necessary due to changes in law, regulatory orders, technical developments, or changes to the processing activities. 14.2 The Controller shall be notified of amendments by email to the address associated with their account. The amended version shall be published at https://getminds.ai/legal/dpa. 14.3 If the Controller does not object to the amendments within 30 days of receipt of the notification, the amendments shall be deemed accepted. The Processor shall draw attention to this legal consequence in the amendment notification. 14.4 If the Controller objects, the parties shall endeavor to reach an amicable solution. If this is not possible, the Controller shall have the right to terminate the Main Agreement with immediate effect. h2. 15. Final Provisions 15.1 This DPA shall be governed by the laws of the Federal Republic of Germany. 15.2 The exclusive place of jurisdiction for all disputes arising from or in connection with this DPA shall be Berlin, to the extent legally permissible. 15.3 Amendments and supplements to this DPA must be made in text form, unless otherwise provided in Section 14. 15.4 Should any provision of this DPA be or become invalid, the validity of the remaining provisions shall not be affected. 15.5 In the event of conflicts between this DPA and the Main Agreement, this DPA shall prevail with respect to the protection of Personal Data. --- **Art of X UG (haftungsbeschränkt)** Köpenicker Straße 145, 10997 Berlin, Germany Managing Directors: Friedrich von Borries and Alexander Doudkin For questions regarding this DPA, contact: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) --- h2. Appendix 1: Technical and Organizational Measures (TOM) **Last Updated: May 30, 2026** Art of X UG (haftungsbeschränkt) ("Minds") implements the following technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk involved in the processing of personal data. --- h2. 1. Access Control h3. Physical Access Control Minds infrastructure is hosted exclusively with certified cloud providers: - **DigitalOcean** – Frankfurt, Germany data center (EU). Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018. - **Supabase** – Stockholm, Sweden data center (EU), hosted on AWS. Certifications: SOC 2 Type II. Physical security (biometric access controls, 24/7 surveillance, access logging) is fully managed by the cloud providers. h3. Logical Access Control - Role-based access control (RBAC) for all internal systems and administration interfaces. - Multi-factor authentication (MFA) required for all employee access to production systems. - Individual user accounts – no shared credentials. - Regular review and revocation of access rights following the principle of least privilege. - API keys and credentials are managed in encrypted secrets managers. - OAuth tokens, integration credentials, and API keys are scoped, encrypted at rest, and revocable. --- h2. 2. Encryption h3. Encryption in Transit - All data transmissions are secured via TLS 1.2 or higher. - HSTS (HTTP Strict Transport Security) is enabled for all public endpoints. - Internal service-to-service communication is also encrypted. h3. Encryption at Rest - Databases (Supabase/PostgreSQL) use AES-256 encryption for data at rest. - File storage (DigitalOcean Spaces / Supabase Storage) uses server-side AES-256 encryption. - Backups are stored in encrypted form. --- h2. 3. Data Separation (Tenant Isolation) - Strict logical separation of customer data at the database level through tenant isolation (Row-Level Security in PostgreSQL). - Each customer can only access their own data – enforced at both the database and API level. - Automated tests ensure no cross-tenant data leakage occurs. --- h2. 4. Availability and Resilience h3. Hosting Architecture - Application runs on DigitalOcean App Platform with automatic scaling and health checks. - Database on Supabase with high-availability configuration. h3. Backup and Recovery - Daily automatic database backups with a retention period of at least 7 days. - Point-in-Time Recovery (PITR) for the PostgreSQL database. - Regular testing of recovery procedures. - Recovery Time Objective (RTO): as defined in SLA. - Recovery Point Objective (RPO): maximum 24 hours. --- h2. 5. Incident Response - Documented incident response process for security incidents. - Notification of the Controller (customer) within **24 hours** of becoming aware of a personal data breach, in accordance with the Data Processing Agreement (DPA). - Logging and tracking of all security-relevant incidents. - Regular review and update of the incident response plan. --- h2. 6. Confidentiality and Employee Obligations - All employees and contractors are bound by confidentiality agreements (NDAs). - Regular data protection training for all employees. - Obligation to maintain data secrecy in accordance with GDPR. - Access to personal data is granted only on a need-to-know basis. --- h2. 7. Subprocessor Management - Careful selection of sub-processors based on data protection and security criteria. - Contractual obligation of all sub-processors to GDPR-compliant data processing. - Regular review of sub-processors. - Current list of sub-processors is available at [Subprocessors](https://getminds.ai/legal/subprocessors). - Advance notice to customers of any changes as per the DPA. --- h2. 8. Logging and Monitoring - Centralized logging of system events and access. - Audit logs cover API/MCP access, OAuth and integration changes, calendar sync/webhook events, and security-relevant administrative actions. - **Langfuse** for monitoring and tracing AI model interactions (hosted in the EU). - **PostHog** for product analytics and optional session replay - persistent analytics/session replay only with analytics consent; limited cookieless diagnostics where lawful. - Monitoring of critical system metrics with automated alerts. - Regular review of logs for anomalies. --- h2. 9. Data Minimization and Pseudonymization h3. Data Minimization - Collection and processing of only those personal data that are necessary for the respective processing purpose. - Regular review of processed data categories for necessity. - Automatic deletion of data no longer needed in accordance with defined retention periods. h3. Pseudonymization - Where technically feasible and appropriate, personal data is processed in pseudonymized form. - Internal processing primarily uses UUIDs rather than real names. - Analytical evaluations are performed on an aggregated or pseudonymized basis. --- h2. 10. Regular Review and Assessment - Regular security assessments of infrastructure and applications. - Dependencies are regularly checked for known vulnerabilities (dependency scanning). - Review and update of these TOMs at least annually or upon significant changes to processing activities. - Continuous improvement of security measures based on current threat landscape. --- h2. 11. Additional Measures h3. Input Control - Logging of changes to personal data (audit trail). - Traceability of who entered, modified, or deleted which data and when. h3. Transfer Control - Data transfers are exclusively encrypted. - No transfer of personal data to third countries without an adequate level of protection (adequacy decision or Standard Contractual Clauses). h3. Processing Control - Processing of personal data exclusively in accordance with the Controller's instructions. - Contractual regulation of commissioned processing in the DPA. --- _These technical and organizational measures are reviewed regularly and updated as necessary to ensure a level of protection consistent with the current state of the art._ --- ### Service Level Agreement (SLA) | Minds Source: https://getminds.ai/legal/sla Description: Last Updated: May 30, 2026 Minds May 30, 2026·Minds Team h1. **Service Level Agreement (SLA)** Last Updated: May 30, 2026 **Last Updated: May 30, 2026** This Service Level Agreement ("SLA") is part of the Agreement between Art of X UG (haftungsbeschränkt) ("Provider", "we", "us") and the Customer ("you") and describes the service levels for our platform and API services. h2. 1. Service Availability h3. 1.1 Uptime Commitment | Service | Monthly Uptime Target | | --- | --- | | Web Platform | 99.5% | | API Services | 99.5% | | ChatGPT/MCP Integration | 99.0% | h3. 1.2 Uptime Calculation - **Uptime %** = ((Total Minutes in Month - Downtime Minutes) / Total Minutes in Month) × 100 - **Downtime** excludes scheduled maintenance and force majeure events. h3. 1.3 Scheduled Maintenance - Scheduled maintenance windows: Sundays 02:00-06:00 CET - We will provide at least 48 hours notice for planned maintenance - Emergency maintenance may occur without notice if required for security or stability h2. 2. Support Services h3. 2.1 Support Channels | Channel | Availability | | --- | --- | | Email ([support@getminds.ai](https://getminds.ai/mailto:support@getminds.ai)) | 24/7 (response within SLA) | | In-App Chat | Business hours (Mon-Fri, 09:00-18:00 CET) | | Documentation | 24/7 self-service | h3. 2.2 Response Times | Priority | Description | Initial Response | Resolution Target | | --- | --- | --- | --- | | **Critical** | Service completely unavailable | 2 hours | 8 hours | | **High** | Major feature unavailable, no workaround | 4 hours | 24 hours | | **Medium** | Feature impaired, workaround available | 8 business hours | 72 hours | | **Low** | Minor issue, questions, feature requests | 24 business hours | Best effort | h3. 2.3 Priority Definitions - **Critical**: Complete service outage affecting all users or data loss/security breach - **High**: Major functionality unavailable affecting business operations - **Medium**: Partial functionality loss with available workaround - **Low**: Minor issues, cosmetic bugs, general inquiries h2. 3. Performance Standards h3. 3.1 API Performance | Metric | Target | | --- | --- | | API Response Time (p95) | < 2 seconds | | Panel Query Response (p95) | < 10 seconds | | Throughput | 100 requests/minute per customer | h3. 3.2 Data Processing | Metric | Target | | --- | --- | | Self-service Mind/Panel Creation | Processing begins immediately after user request; target completion within 24 hours under normal load | | Custom/Enterprise Imports | As agreed in the applicable order form or statement of work | | Panel Updates | Within 7 days of request for custom/managed work; self-service updates normally begin immediately | | Data Export | Within 24 hours of request | Third-party AI, calendar, telecom, voice, payment, app-store, and source-extraction services may add latency or temporary unavailability outside our direct control. h2. 4. Service Credits h3. 4.1 Credit Eligibility If monthly uptime falls below the committed level, you may be eligible for service credits: | Monthly Uptime | Service Credit | | --- | --- | | 99.0% - 99.5% | 10% of monthly fee | | 95.0% - 99.0% | 25% of monthly fee | | < 95.0% | 50% of monthly fee | h3. 4.2 Credit Request Process 1. Submit credit request within 30 days of the incident 2. Include dates, times, and description of the outage 3. Credits are applied to future invoices (not refundable as cash) h3. 4.3 Credit Exclusions Service credits do not apply to: - Scheduled maintenance - Force majeure events - Issues caused by customer actions or third-party services - Beta or preview features - Free tier usage - Third-party AI providers, payment processors, calendar APIs, telecom/voice/messaging providers, app-store services, source-extraction services, or customer-selected external clients h2. 5. Data Protection h3. 5.1 Backup and Recovery | Metric | Commitment | | --- | --- | | Backup Frequency | Daily | | Backup Retention | 30 days | | Recovery Point Objective (RPO) | 24 hours | | Recovery Time Objective (RTO) | 8 hours | h3. 5.2 Data Location - Primary data storage: European Union (Germany) - Backups: European Union h2. 6. Security h3. 6.1 Security Measures - Encryption in transit (TLS 1.2+) - Encryption at rest (AES-256) - Regular security assessments and penetration testing - SOC 2 Type II compliance (in progress) h3. 6.2 Incident Response - Security incidents are treated as Critical priority - Affected customers notified within 24 hours of confirmed breach - Post-incident report provided within 14 days h2. 7. Reporting h3. 7.1 Status Page Real-time service status available at: https://status.getminds.ai h3. 7.2 Monthly Reports Upon request, we provide monthly reports including: - Uptime statistics - Incident summaries - Performance metrics h2. 8. SLA Modifications We may update this SLA from time to time. Material changes will be communicated with at least 30 days notice. Continued use of the services constitutes acceptance of the updated SLA. --- **Art of X UG (haftungsbeschränkt)** Köpenicker Straße 145, 10997 Berlin, Germany For SLA-related inquiries: [support@getminds.ai](https://getminds.ai/mailto:support@getminds.ai) --- ### Sub-processors | Minds Source: https://getminds.ai/legal/subprocessors Description: Last Updated: July 7, 2026 Minds July 7, 2026·Minds Team h1. **Sub-processors** Last Updated: July 7, 2026 **Last Updated: July 7, 2026** Art of X UG (haftungsbeschränkt) uses the following sub-processors to provide our services. This list is updated when changes occur. h2. Current Sub-processors | Sub-processor | Purpose | Location | | --- | --- | --- | | **Cloudflare** | CDN, DNS, DDoS protection, web security | USA (global edge network) | | **DigitalOcean** | Cloud infrastructure, hosting | Germany (Frankfurt) | | **Supabase** | Database, authentication | EU (Stockholm) | | **OpenAI** | LLM API for AI processing, embeddings, transcription | USA | | **Anthropic** | LLM API for AI processing | USA | | **Google AI (Gemini / Vertex AI)** | LLM API for AI processing and AI image generation | USA (global) | | **ElevenLabs** | Text-to-speech voice generation | UK | | **Tavily** | Web search and content retrieval | USA | | **Firecrawl (SideGuide Technologies)** | Web content extraction, visual page analysis | USA | | **Langfuse** | LLM observability and tracing | Germany | | **Resend** | Transactional email delivery | USA | | **Stripe** | Payment processing | Ireland (EU data) | | **PostHog** | Product analytics | EU | | **Google Analytics** | Web analytics | USA | | **TikTok** | Conversion tracking via TikTok Pixel (marketing consent required) | Ireland/USA | | **X (Twitter)** | Conversion tracking via X Pixel (marketing consent required) | USA | | **Twilio** | SMS, WhatsApp messaging, voice calls, phone number provisioning | USA | | **Deepgram** | Speech-to-text transcription | USA | | **Fish Audio (Hanabi AI Inc.)** | Voice cloning, text-to-speech | USA | | **Apify** | Web content extraction, social media scraping | Czech Republic (EU) | | **Google Firebase (FCM)** | Push notifications | USA | | **RevenueCat** | In-app purchase management (iOS) | USA | | **Slack (Salesforce)** | Internal notifications (webhooks) | USA | | **Google Calendar API** | Calendar integration | USA | | **Google Drive API** | File attachments from Google Drive (user-selected files) | USA | | **Microsoft Graph API (OneDrive)** | File attachments from OneDrive (user-selected files) | USA | | **Figma API** | Design attachments from Figma (user-selected files, rendered to images) | USA | h2. User-selected external clients External clients chosen by the user to connect to Minds (for example ChatGPT, Claude, OpenRouter, Open WebUI, LibreChat, or similar tools) are independent services. They are not Art of X sub-processors unless Art of X engages them to process data on its behalf. Their processing is governed by their own terms and privacy notices. h2. Data Transfer Safeguards For sub-processors located outside the European Economic Area (EEA), the applicable transfer mechanism and contractual measures are assessed for each vendor and processing activity. The legal requirement for processor terms does not depend on whether a vendor makes its preferred contract available. Depending on the transfer, safeguards may include: - **Standard Contractual Clauses (SCCs)** where required - **EU-US Data Privacy Framework** certification where applicable - **Data Processing Agreements or equivalent contractual terms** where legally required If legally required processor terms or transfer safeguards cannot be put in place, the affected processing must not begin or must be suspended until the gap is resolved. Additional technical and organizational measures, including data minimization, may be required by the assessment. h2. Changes to Sub-processors We will notify customers of any intended changes to sub-processors with at least 14 days notice before the change takes effect. Notifications are sent to the email address associated with your account. To object to a new sub-processor, contact us at [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) within 14 days of notification. h2. Questions For questions about our sub-processors, contact: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) --- **Art of X UG (haftungsbeschränkt)** Köpenicker Straße 145, 10997 Berlin, Germany --- ### Provider identification according to § 5 DDG | Minds Source: https://getminds.ai/legal/imprint Description: Last Updated: May 31, 2026 Minds May 31, 2026·Minds Team h1. **Provider identification according to § 5 DDG** Last Updated: May 31, 2026 **Last Updated: May 31, 2026** Art of X UG (haftungsbeschränkt) Köpenicker Straße 145 10997 Berlin represented by the managing directors Friedrich von Borries and Alexander Doudkin h2. Responsible for the content according to § 18 Abs. 2 MStV Art of X UG (haftungsbeschränkt) Köpenicker Straße 145 10997 Berlin Contact E-Mail: [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai) Phone: +1 628 2369184 h2. Digital Services Act Point of Contact For notices concerning illegal content, content-moderation decisions, or communications under the EU Digital Services Act, contact [legal@getminds.ai](https://getminds.ai/mailto:legal@getminds.ai). Communications in English or German are accepted. h2. Commercial Register Entry in the Charlottenburg Commercial Register Register court: Amtsgericht Charlottenburg Register number: HRB 266185 B VAT Identification Number (§ 27a UStG): DE410421417 h2. Web-Design The website concept was created by [Tim Ballaschke](https://timballaschke.com/) for Minds. h2. Out-of-court dispute resolution The European Online Dispute Resolution platform was discontinued on 20 July 2025 and is no longer available for submitting consumer complaints. We are not willing or obliged to participate in dispute resolution proceedings before a consumer arbitration board. We prefer to resolve disputes directly. Please contact us at [hello@getminds.ai](https://getminds.ai/mailto:hello@getminds.ai). h2. Liability for content All information and data have been compiled to the best of our knowledge, but no guarantee is given for their completeness and accuracy. As a service provider, we are responsible for our own content on these pages in accordance with § 7 (1) DDG (German Digital Services Act) and general laws. According to §§ 8 to 10 DDG, however, we as a service provider are not obliged to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information in accordance with general legislation remain unaffected by this. However, liability in this respect is only possible from the time of knowledge of a specific infringement. As soon as we become aware of such infringements, we will remove this content immediately. h2. Liability for links Our website contains links to external third-party websites over whose content we have no influence. Therefore, we cannot accept any liability for this third-party content. The respective provider or operator of the pages is always responsible for the content of the linked pages. The linked pages were checked for possible legal violations at the time of linking. Illegal contents were not recognizable at the time of linking. We therefore hereby expressly distance ourselves from all content on all linked pages. However, permanent monitoring of the content of the linked pages is not reasonable without concrete evidence of an infringement. If we become aware of any legal infringements, we will remove such links immediately. h2. Copyright All contributions published on this website are protected by copyright. The content and works created by the site operators on these pages are subject to German copyright law. Duplication, processing, distribution and any kind of exploitation outside the limits of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use. However, offers and general terms and conditions may be printed out for orders. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is marked as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. If we become aware of any infringements, we will remove such content immediately. --- ### Technical and Organizational Measures (TOM) | Minds Source: https://getminds.ai/legal/tom Description: Last Updated: May 30, 2026 Minds May 30, 2026·Minds Team h1. **Technical and Organizational Measures (TOM)** Last Updated: May 30, 2026 **Last Updated: May 30, 2026** Art of X UG (haftungsbeschränkt) ("Minds") implements the following technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk involved in the processing of personal data. --- h2. 1. Access Control h3. Physical Access Control Minds infrastructure is hosted exclusively with certified cloud providers: - **DigitalOcean** – Frankfurt, Germany data center (EU). Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018. - **Supabase** – Stockholm, Sweden data center (EU), hosted on AWS. Certifications: SOC 2 Type II. Physical security (biometric access controls, 24/7 surveillance, access logging) is fully managed by the cloud providers. h3. Logical Access Control - Role-based access control (RBAC) for all internal systems and administration interfaces. - Multi-factor authentication (MFA) required for all employee access to production systems. - Individual user accounts – no shared credentials. - Regular review and revocation of access rights following the principle of least privilege. - API keys and credentials are managed in encrypted secrets managers. - OAuth tokens, integration credentials, and API keys are scoped, encrypted at rest, and revocable. --- h2. 2. Encryption h3. Encryption in Transit - All data transmissions are secured via TLS 1.2 or higher. - HSTS (HTTP Strict Transport Security) is enabled for all public endpoints. - Internal service-to-service communication is also encrypted. h3. Encryption at Rest - Databases (Supabase/PostgreSQL) use AES-256 encryption for data at rest. - File storage (DigitalOcean Spaces / Supabase Storage) uses server-side AES-256 encryption. - Backups are stored in encrypted form. --- h2. 3. Data Separation (Tenant Isolation) - Strict logical separation of customer data at the database level through tenant isolation (Row-Level Security in PostgreSQL). - Each customer can only access their own data – enforced at both the database and API level. - Automated tests ensure no cross-tenant data leakage occurs. --- h2. 4. Availability and Resilience h3. Hosting Architecture - Application runs on DigitalOcean App Platform with automatic scaling and health checks. - Database on Supabase with high-availability configuration. h3. Backup and Recovery - Daily automatic database backups with a retention period of at least 7 days. - Point-in-Time Recovery (PITR) for the PostgreSQL database. - Regular testing of recovery procedures. - Recovery Time Objective (RTO): as defined in SLA. - Recovery Point Objective (RPO): maximum 24 hours. --- h2. 5. Incident Response - Documented incident response process for security incidents. - Notification of the Controller (customer) within **24 hours** of becoming aware of a personal data breach, in accordance with the Data Processing Agreement (DPA). - Logging and tracking of all security-relevant incidents. - Regular review and update of the incident response plan. --- h2. 6. Confidentiality and Employee Obligations - All employees and contractors are bound by confidentiality agreements (NDAs). - Regular data protection training for all employees. - Obligation to maintain data secrecy in accordance with GDPR. - Access to personal data is granted only on a need-to-know basis. --- h2. 7. Subprocessor Management - Careful selection of sub-processors based on data protection and security criteria. - Contractual obligation of all sub-processors to GDPR-compliant data processing. - Regular review of sub-processors. - Current list of sub-processors is available at [Subprocessors](https://getminds.ai/legal/subprocessors). - Advance notice to customers of any changes as per the DPA. --- h2. 8. Logging and Monitoring - Centralized logging of system events and access. - Audit logs cover API/MCP access, OAuth and integration changes, calendar sync/webhook events, and security-relevant administrative actions. - **Langfuse** for monitoring and tracing AI model interactions (hosted in the EU). - **PostHog** for product analytics and optional session replay - persistent analytics/session replay only with analytics consent; limited cookieless diagnostics where lawful. - Monitoring of critical system metrics with automated alerts. - Regular review of logs for anomalies. --- h2. 9. Data Minimization and Pseudonymization h3. Data Minimization - Collection and processing of only those personal data that are necessary for the respective processing purpose. - Regular review of processed data categories for necessity. - Automatic deletion of data no longer needed in accordance with defined retention periods. h3. Pseudonymization - Where technically feasible and appropriate, personal data is processed in pseudonymized form. - Internal processing primarily uses UUIDs rather than real names. - Analytical evaluations are performed on an aggregated or pseudonymized basis. --- h2. 10. Regular Review and Assessment - Regular security assessments of infrastructure and applications. - Dependencies are regularly checked for known vulnerabilities (dependency scanning). - Review and update of these TOMs at least annually or upon significant changes to processing activities. - Continuous improvement of security measures based on current threat landscape. --- h2. 11. Additional Measures h3. Input Control - Logging of changes to personal data (audit trail). - Traceability of who entered, modified, or deleted which data and when. h3. Transfer Control - Data transfers are exclusively encrypted. - No transfer of personal data to third countries without an adequate level of protection (adequacy decision or Standard Contractual Clauses). h3. Processing Control - Processing of personal data exclusively in accordance with the Controller's instructions. - Contractual regulation of commissioned processing in the DPA. --- _These technical and organizational measures are reviewed regularly and updated as necessary to ensure a level of protection consistent with the current state of the art._ **Art of X UG (haftungsbeschränkt)** Managing Directors: Friedrich von Borries and Alexander Doudkin ---