Русский · English
Privacy Policy
MindfulMe — a mindfulness and self-development journal (Telegram bot, web app and iOS app).
Effective date: 25.06.2026. Last updated: 11.09.2026.
This is an English translation; in case of any discrepancy, the Russian version prevails.
1. Who processes your data
The data controller (operator) is self-employed individual Sergey Konstantinovich Zakharov, INN 784200016164 (the “we”, “Operator”).
Correspondence address: 197022, St. Petersburg, Aptekarsky Ave., 18, lit. A, apt. 375.
Processing is carried out in accordance with Russian Federal Law No. 152-FZ “On Personal Data”.
For any privacy questions, see the contacts in section 13.
By using MindfulMe, you agree to this Policy. If you do not agree, please do not use the service.
2. What data we process
- Account and sign-in data. Depending on your sign-in method: Telegram identifier, name, username and profile photo; email address; the unique Apple identifier and email when using “Sign in with Apple”.
- Profile. What you provide yourself: name/nickname, gender, date of birth, city, occupation, goals, “about me” text, time zone.
- Journal content. Your entries and conversation with the journal, mood check-ins, well-being/symptom notes, and the reports and “memory” (stable facts about you) generated from them.
- Voice input. If you dictate an entry, the audio is sent to our server solely for speech recognition and is converted to text on our own server (no third-party speech recognition services are used). The audio recording is not stored and is discarded immediately after recognition; only the resulting text is kept — as a regular journal entry.
- Payments. When paying for a subscription, your email and transaction data are processed by the payment provider (see section 5). We do not receive or store bank card data.
- Technical data. Push notification tokens, usage events (analytics), technical logs (including IP address and request identifiers) — for operating and securing the service.
3. Why we use it
- To provide the service itself: keep your journal, respond to your entries, generate reports and suggestions, remember context.
- Artificial-intelligence processing. So that the journal can respond meaningfully and produce reports, the text of your entries is transmitted to our AI provider (DeepSeek) for processing. Short summaries are also sent there to build “memory”. We transmit only what is necessary to produce a response.
- To enable sign-in, notifications, subscription payment and support.
- To improve the product through anonymized product analytics.
4. Encryption and access to data
The content of your entries and “memory” is stored encrypted (AES-256-GCM). Honestly, what this means in practice:
- Data is encrypted “at rest” (in the database) and is not accessible via direct storage access without the key.
- In order to show you a response and generate it, the server temporarily decrypts the relevant text and transmits it to the AI provider (section 3). The encryption key is held on the service side.
- Staff access to content is limited and used only to operate the service, provide support upon your request and fix issues.
We do not sell your data and do not use journal content for advertising.
5. With whom we share data (processors)
We engage third-party service providers solely to operate the service:
- DeepSeek — AI text processing (generating responses and reports).
- Prodamus — accepting subscription payments.
- Apple — “Sign in with Apple”, app delivery and notifications.
- Telegram — bot operation, sign-in via Telegram, notifications.
- PostHog — product analytics (events are proxied through our server).
- Hosting provider — hosting of servers and the database.
We transmit to these processors only the data necessary for the relevant function.
6. Cross-border transfer
Some processors (in particular the AI provider DeepSeek) may be located outside the Russian Federation, and processing may take place on servers in other countries. By using the service, you consent to such cross-border transfer to the extent necessary for the functions described above.
7. Retention and deletion
We retain data while your account is active and for as long as necessary for the purposes in section 3. You may request deletion of your account and associated data by contacting us (section 13) — after confirmation we will delete personal data within the period set by 152-FZ (no more than 30 days), except for information we are required to keep by law (e.g., payment data).
8. Your rights
- Obtain information about the processing of your data and a copy of it.
- Correct or complete your profile data (some of it directly in the app).
- Delete your account and data.
- Withdraw consent to processing (this may make using the service impossible).
To exercise your rights, contact us (section 13).
9. Sensitive data
The journal may contain information about your well-being and emotional or mental state. You share it voluntarily. We treat such data with particular care (encryption, limited access) and use it for nothing other than providing the service to you. MindfulMe is a tool for self-reflection and is not a medical service and does not replace professional help.
10. Children
The service is intended for persons who have reached 18 years of age. Persons aged 14 and over may use the service only with the consent of a parent or legal guardian. We do not knowingly collect data of persons under 14.
11. Changes to the policy
We may update this Policy. We will notify you of material changes through the service. The last-updated date is shown at the top.
12. Security
We apply technical and organizational measures to protect data (content encryption, access restriction, secure transmission channels). However, no method of transmission or storage is absolutely secure.
13. Contacts
For privacy questions and to exercise your rights:
© MindfulMe. All rights reserved.