Mindroll — Privacy Policy

Last updated 17 September 2026

This policy explains what Mindroll collects, why, who else sees it, and what you can do about it. It is written to be read, not to be survived.

The short version: Mindroll collects what it needs to give you a personalised reading plan and to remember your progress. Usage analytics are off unless you turn them on. We do not sell your data, and we do not show you advertising.


1. Who is responsible for your data

Mindroll is operated by a sole trader based in the United Kingdom, trading as Mindroll, who is the data controller for the information described here.

Contact: teammindroll@gmail.com

2. What we collect, and why

Your account. If you create an account: your email address, a display name and handle, and — if you sign in with Apple or Google — the identifier they give us. We need this to keep your library on your account rather than on one phone.

Your onboarding answers. The name you give us, what you want to achieve, what gets in your way, the topics you pick, the books you keep and the daily goal you set. These shape what the app shows you, and the name is used to address you in the app.

What you read and keep. Your reading and listening progress, saved ideas, collections, notes, reflections, review answers, streaks and daily goals. This is the product: without it there is no library and no progress.

Search and content requests. Searches you make in the app, and any request you send asking for particular content.

Your subscription status. Whether you are on the free plan or Pro, which plan, and whether a trial is running. Our payment provider tells us this. We never see your card details — Apple and Google handle payment and do not give them to us.

Usage analytics — only if you agree. If you turn analytics on, we record events such as screens viewed, sessions finished and features used, to understand what works. Analytics are off by default, you can turn them off again at any time in Settings, and turning them off discards anything waiting to be sent.

Diagnostics. If the app crashes or hits an error, we may receive a technical report — what went wrong, the device model and the app version — so we can fix it.

Links and books you submit. When you paste a link or scan a barcode, the link or the ISBN is sent to the services described below to produce a breakdown. When you scan, the camera is used only while that screen is open and no image is uploaded or stored — the barcode is read on your device.

On your device only. Downloads for offline reading, your reminder settings and your theme preferences stay on your phone. Reminders are scheduled locally on your device, so we do not hold a push token for you.

Under UK and EU data protection law we rely on:

  • Performing our contract with you — running your account, your library, your progress and your subscription.
  • Our legitimate interests — keeping the app secure, preventing abuse, fixing faults, and understanding overall usage in a way that does not override your rights.
  • Your consent — usage analytics, and notifications if you enable them. You can withdraw either at any time.
  • Legal obligations — keeping records we are required to keep.

4. Who else sees your data

We use a small number of service providers, who process data on our instructions and are not allowed to use it for their own purposes:

WhoWhat they doWhat they see
SupabaseHosting, database and sign-inYour account, library, progress and notes
RevenueCatSubscription managementYour subscription status and an app-specific identifier
Apple / GooglePayment and app distributionYour purchase, under their own privacy policies
PostHog (EU hosting)Usage analytics, only if you agreeThe events described above
SentryCrash and error reportsTechnical details of a fault
ExpoApp delivery and updatesTechnical details needed to deliver updates
Open LibraryBook covers and book detailsA request for a cover or an ISBN, including your IP address

When you paste a link or scan a book, the request is handled by our own server and is not sent to any third party. [ADD BEFORE SHIPPING AI BREAKDOWNS: the moment that server calls an AI provider to generate a breakdown, that provider becomes a processor and must be named in the table above, with what it receives. Today it is not listed because it does not exist — the generation step is still a stub.]

We also share information when the law requires it, or to protect someone's safety or our legal rights.

We do not sell your personal data, and we do not use it for advertising.

5. Where your data is stored

Your reading history, your library and the answers you gave during setup are held on your device. If you create an account so that they follow you to another device, they are also stored in our database, hosted in the United Kingdom or the European Economic Area. Analytics, if you turn them on, are processed on European servers.

Where data is transferred outside the UK or the European Economic Area, we rely on the safeguards approved for such transfers, such as the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.

6. How long we keep it

  • Your account and library: until you delete your account.
  • After you delete your account: removed from our live systems promptly and from backups within 30 days.
  • Analytics events: kept for up to 24 months, then deleted.
  • Crash reports: kept for up to 90 days.
  • Support emails: kept for up to 24 months so we have the history of your question.

You can delete your account at any time in Settings → Delete account. It asks you to confirm, and then removes your profile, library, progress and notes.

7. Your rights

You have the right to ask us to:

  • give you a copy of the data we hold about you;
  • correct anything that is wrong;
  • delete your data;
  • restrict or object to how we use it;
  • send your data to another service in a portable form;
  • withdraw consent you have given, at any time.

Email teammindroll@gmail.com and we will respond within one month. It costs nothing to ask.

If you think we have handled your data badly, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection authority where you live. We would appreciate the chance to put it right first.

8. Children

Mindroll is for people aged 13 and over. We do not knowingly collect data about children under 13. If you believe a child under 13 has given us their data, email us and we will delete it.

9. Security

Data is encrypted in transit. Access to our systems is limited to the people who need it, protected by strong authentication, and our database enforces rules so one reader cannot see another's library. No service can promise perfect security, but if a breach affects you we will tell you and the regulator as the law requires.

10. Changes to this policy

If we change this policy in a way that affects you, we will tell you in the app or by email before it takes effect. The date at the top always shows the current version.

11. Contact

teammindroll@gmail.com