
MindyCards:
Privacy Policy
MindyWorld OÜ (MindyCore)
Privacy PolicyTerms of Service
Effective date: this version applies from the date MindyCards is published on the Apple App Store or Google Play.
1. Data controller
MindyWorld OÜ is the data controller for the data processed in connection with MindyCards.
Registered address: Jõe tn 3-315, 10151 Tallinn, Estonia
Registry number: 17339961
Contact: core@mindycore.com
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee/en
2. Summary
MindyCards offers two ways to use the App: anonymously (without an account) or with an account that enables progress synchronization and a Premium subscription that removes advertising. The data we process depends on which option you choose.
In the free tier, the App is supported by non-personalized advertising. Personalized advertising is not used in MindyCards.
We collect only the minimum personal data needed to provide the App, process Premium subscriptions, and operate the account features.
3.1 If you use MindyCards without an account
Device model and operating system version.
App version and crash reports.
Anonymized session metrics (game starts, game completions, time in app, screens visited).
Language and locale preferences.
Approximate region derived from IP address (country level only).
Non-personalized advertising data (see Section 7).
3.2 If you create an account in MindyCards
Additional data processed:
Account identifier (Keycloak subject identifier, Sign in with Apple identifier, Google account identifier, or email address used for registration).
Username or display name chosen by you.
Profile image, if you choose to upload one.
Game progress, achievements, virtual currency, and customization choices synchronized across your devices.
App preferences and accessibility settings linked to your account (when you opt-in to sync them across devices).
3.3 If you subscribe to MindyCards Premium
Subscription status (active, paused, cancelled) and renewal date.
Country of the app store account used to purchase the subscription.
Transaction identifier associated with your purchase.
Full payment details (card number, security code, billing address) are never accessible to MindyCore. They are handled directly by Apple, Google, or our payment processor, depending on the purchase method you use. See Section 8.
3.4 Data we do NOT collect
We do not collect biometric data.
We do not collect real-time precise location data.
We do not collect your contacts, photos, or files outside the App.
We do not collect information about your neurodivergent profile, diagnosis, or health condition. Accessibility settings, even when synchronized via account, are stored as user preferences and are not interpreted, inferred, or analyzed as health data.
We do not sell personal data.
4. Why we process this data (purposes)
Operate the App, maintain your account, and synchronize your progress across devices.
Process and verify Premium subscriptions.
Display non-personalized advertising in the free tier (Premium users do not see ads).
Detect, diagnose, and fix crashes and bugs.
Analyze aggregated, anonymized usage patterns to improve gameplay and accessibility.
Communicate with you about your account, subscription, or material changes to the App.
Protect against fraud, abuse, and policy violations.
Comply with legal obligations applicable to us, including tax law and consumer protection.
5. Legal basis (GDPR)
Performance of a contract (Art. 6(1)(b)): to provide the App, maintain your account, and operate the Premium subscription.
Legitimate interest (Art. 6(1)(f)): to detect crashes, analyze aggregated metrics, and prevent fraud, balanced against your rights and freedoms.
Consent (Art. 6(1)(a)): for tracking technologies that require consent under EU ePrivacy rules and for any optional features (e.g., marketing communications, if introduced).
Legal obligation (Art. 6(1)(c)): to comply with laws and regulations applicable to us, including taxation.
6. Account creation and authentication
Authentication in MindyCards is managed through Keycloak, an identity and access management system operated by MindyWorld OÜ on infrastructure hosted in the European Union, in combination with Firebase Authentication. Your credentials and identity tokens are handled by these systems.
To create an account in MindyCards you may use one of these methods:
Sign in with Apple: Apple shares with us a stable identifier and, at your option, your email (or a private relay email). Your Apple ID password is never shared with us.
Sign in with Google: Google shares with us a stable identifier and your email address. Your Google password is never shared with us.
Email and password registration: we ask for an email address and a password. Passwords are stored using industry-standard cryptographic hashing and are never stored in plain text.
You may delete your MindyCards account at any time from the Settings menu inside the App, or by writing to core@mindycore.com. Upon deletion, your personal data is removed within 30 days, except for records we are legally required to retain (such as transactional records under Estonian and EU tax law, retained for up to 7 years).
7. Advertising and consent
The free tier of MindyCards shows only non-personalized advertising. The Premium subscription removes all advertising.
Where required by EU and UK law, we use Google’s User Messaging Platform (UMP) to request your consent for the use of advertising identifiers, before any ad is shown. You may change your consent decision at any time from the privacy options available in the App settings.
On iOS, Apple’s App Tracking Transparency (ATT) applies. Since MindyCards does not use cross-app tracking, the ATT prompt is not shown.
On Android, the Android Advertising ID may be used in a limited way for fraud prevention and frequency capping, as described in Google AdMob’s policies for non-personalized advertising.
8. Premium subscriptions and payments
Premium subscriptions purchased inside the App are billed through Apple’s In-App Purchase or Google Play Billing, in accordance with their respective rules. Payment data for these purchases is processed by Apple or Google directly.
We use RevenueCat as a subscription management service. RevenueCat receives the transaction identifier, your app user identifier, subscription status, product identifier, platform, and renewal or expiry dates. It does not receive your payment card details. RevenueCat acts as a data processor on our behalf under a data processing agreement.
For purchases made outside the app stores, where offered, payments are processed by Stripe. Stripe receives the payment details necessary to complete the transaction and acts as an independent controller for the payment data it processes, in addition to being our processor for transaction records. MindyCore does not store your full card details at any time.
Subscriptions renew automatically until cancelled. You can manage or cancel your subscription at any time from your Apple ID or Google Play account settings, or through the mechanism indicated at the time of purchase. Refund requests for app store purchases are handled by the relevant app store.
9. Children and minors
MindyCards is intended for users aged 13 years or older, as set out in our Terms of Service.
If you are between 13 and the digital consent age in your country (16 by default under EU GDPR, with national variations), you confirm that you have explicit consent from a parent or legal guardian to create an account and use the App.
We do not knowingly collect personal data from children under 13. If we become aware that a user is under 13, we will close the account and delete the associated personal data without undue delay. If you are a parent or legal guardian and you believe your child under 13 has created an account, please contact us at core@mindycore.com.
Parental controls in the operating system (Apple Screen Time, Google Family Link, or equivalent) remain the primary mechanism for parents to supervise their child’s use of digital services. MindyCore offers the technical and contractual framework, but parental supervision is the responsibility of the parent or legal guardian.
For all users, regardless of age, we apply strong privacy defaults in MindyCards: only non-personalized advertising, no marketing communications without explicit opt-in, and minimal data collection by design.
10. Sharing data with third parties
We do not sell your personal data. We share limited data with the service providers listed below, each under contracts requiring GDPR-equivalent protection. Some of these services are already in use; others are integrated and will become active in upcoming versions of the App, and are listed here for transparency.
Identity and authentication
Keycloak: identity and access management, operated by MindyWorld OÜ on infrastructure hosted in the European Union.
Hostinger International Ltd: hosting provider for the infrastructure running our authentication services.
Firebase Authentication: Google Ireland Limited and Google LLC.
Sign in with Apple: Apple Inc.
Sign in with Google: Google Ireland Limited and Google LLC.
Data storage and backend
Firebase Cloud Firestore: storage of game progress and account preferences. Google Ireland Limited and Google LLC.
Firebase Storage: storage of user-uploaded content such as profile images. Google Ireland Limited and Google LLC.
Firebase Cloud Functions: server-side processing of application logic, including subscription events. Google Ireland Limited and Google LLC.
Analytics and diagnostics
Firebase Analytics: aggregated usage analytics, where consent is given where required. Google Ireland Limited and Google LLC.
Advertising
Google AdMob: non-personalized advertising in the free tier. Google Ireland Limited and Google LLC.
Payments and subscriptions
Apple App Store: distribution, billing and subscriptions. Apple Inc.
Google Play: distribution, billing and subscriptions. Google LLC.
RevenueCat, Inc.: subscription management and entitlement verification.
Stripe Payments Europe, Ltd.: payment processing for purchases made outside the app stores, where offered.
Communications
Brevo (Sendinblue SAS): transactional and newsletter email delivery, where applicable.
Zoho Corporation B.V.: email services.
Each of these services has its own privacy policy. Links can be requested at core@mindycore.com.
We may also disclose data when required by law, a court order, or a binding request from a competent authority, or to protect our rights or the rights of others.
11. International data transfers
Some of our service providers process data outside the European Economic Area (EEA), including the United States. When data is transferred internationally, we ensure adequate protection through:
Standard Contractual Clauses approved by the European Commission, where applicable.
The EU-US Data Privacy Framework (DPF), where the recipient is certified.
Other equivalent legal mechanisms recognized under GDPR.
Our authentication infrastructure is hosted within the European Union. Game progress and account data stored in Firebase Cloud Firestore may be hosted in regions outside the EEA; where this is the case, the safeguards described above apply.
12. Retention
Active accounts: data is retained while your account is in use.
Inactive accounts: accounts with no activity for 24 consecutive months may be deleted, with prior notice by email where we hold a valid address.
After account deletion: personal data is deleted within 30 days, except for records we are legally required to retain.
Transactional records (Premium subscriptions): retained for up to 7 years, as required by Estonian and EU tax law.
Crash logs and diagnostic data: retained for up to 90 days.
Aggregated and anonymized analytics: may be retained indefinitely for statistical purposes.
13. Your rights
Under the EU GDPR and similar laws, you have the following rights:
Right of access: to know what personal data we process.
Right to rectification: to correct inaccurate or incomplete personal data.
Right to erasure (right to be forgotten): you may delete your account from the Settings menu in the App, or by contacting us.
Right to restriction: to limit how we process your personal data.
Right to object: to object to processing based on legitimate interest.
Right to data portability: to receive your data in a structured, commonly used, machine-readable format.
Right to withdraw consent: at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint with a data protection authority: particularly in the EU Member State of your habitual residence.
To exercise these rights, please contact us at core@mindycore.com. We respond within 30 days, with a possible extension of 60 additional days for complex requests.
14. US residents (CCPA / CPRA)
If you are a resident of California, USA, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights, including:
Right to know what categories of personal information have been collected.
Right to delete personal information that we have collected.
Right to opt out of any “sale” or “sharing” of personal information. We do not sell or share personal information as defined under California law.
Right to correct inaccurate personal information.
Right to non-discrimination for exercising your rights.
To exercise California-specific rights, please contact us at core@mindycore.com. Similar rights may apply if you are a resident of other US states with comparable laws, and we honor them on request.
15. Security
We protect data with industry-standard security measures: encryption in transit (TLS), encryption at rest where applicable, password hashing with industry-standard algorithms, access controls based on least privilege, secure cloud infrastructure, and regular security reviews.
In the event of a personal data breach that may affect your rights, we will notify the competent data protection authority within 72 hours, and, where required by law, we will also notify affected users without undue delay.
16. Device identifiers and similar technologies
Although MindyCards is a mobile app and does not use cookies in the technical sense, it relies on similar technologies on your device, in particular:
Local device storage to remember accessibility settings, gameplay progress, login state, and consent preferences.
Authentication tokens to keep you signed in across sessions.
Advertising identifiers (IDFA on iOS, Android Advertising ID on Android) used in a limited way by Google AdMob in the free tier for fraud prevention and frequency capping in non-personalized advertising.
Anonymized session identifiers used by Firebase Analytics, where consent is given where required.
You can reset advertising identifiers, disable advertising tracking, or configure tracking permissions in your device system settings (iOS Privacy → Tracking; Android Settings → Privacy → Ads).
17. Automated decision-making
MindyCards does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Significant changes will be announced through the App, by email (for account holders), and on mindycore.com at least 30 days in advance, where reasonably possible. The version date at the top of this Policy will be updated to reflect each change.
19. Contact and complaints
For questions, requests about your data, or complaints related to this Privacy Policy, contact us at: core@mindycore.com.
If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee/en) or with your local data protection authority.