Privacy Policy
This Policy explains how we collect, use, and share information when you use SecondMind.
1. Data we collect
- Account data: email, name, password hash (we never store plaintext passwords).
- Billing data: handled by Stripe (customer ID, subscription status). We do not store full card numbers.
- Customer Content: notes, inbox captures, skills, settings you create in the Service.
- Usage / technical: IP address, user agent, timestamps, login attempt logs for security.
2. How we use data
- Provide, secure, and improve the Service
- Authenticate users and prevent abuse
- Process subscriptions and communicate about billing
- Run LLM features you invoke (sending relevant content to configured model endpoints)
- Comply with law and enforce our Terms
3. Processors
We use infrastructure and subprocessors such as: hosting/VPS providers, Stripe (payments), and any LLM API you configure (or our self-hosted Ollama instance when enabled). Their processing is governed by their terms and our agreements with them.
4. Sharing
We do not sell personal information. We share data with processors needed to run the Service, when required by law, or to protect rights and safety.
5. Retention
Account and Customer Content are retained while your account is active. After deletion or prolonged inactivity we remove or anonymize data within a reasonable period, except where retention is required for legal, security, or billing records (e.g. invoices).
6. Security
We use HTTPS, hashed passwords (bcrypt), HTTP-only session cookies, CSRF protections on authenticated mutating requests, and access controls. No method of transmission or storage is 100% secure.
7. Your rights
Depending on your location (e.g. GDPR/CCPA), you may request access, correction, export, or deletion of personal data by emailing privacy@controlgrp.com. You may also cancel your account via support.
8. Children
The Service is not directed to children under 16. We do not knowingly collect their data.
9. International transfers
Data may be processed in the United States or other countries where we or our processors operate. Where required, we use appropriate safeguards.
10. Changes
We may update this Policy and will post the new effective date here.
11. Contact
privacy@controlgrp.com
This document is a practical baseline, not formal legal advice. Have counsel review before public launch if you need jurisdiction-specific compliance.