Privacy policy
In short: MindMate knows no name and no email address until you request an appointment. Your transcript stays on the device. Everything server-side is visible in the app and deleted with one tap.
Last updated: 2026-09-05
1. Controller
Colopoint GmbH, Lindleystraße 12, 60314 Frankfurt am Main, Germany, email hello@lynk.run.
2. What the app stores – and where
| Data | Where | Purpose | Legal basis |
|---|---|---|---|
| Anonymous device id (random string, no link to a person or the hardware) | Device + our server | Find your data again without keeping an account | Art. 6(1)(b) GDPR |
| Profile: first name (free choice), goals, voice, language | Our server | Noa addresses you and knows your topics | Art. 6(1)(b), Art. 9(2)(a) GDPR (consent before the first conversation) |
| Conversation transcript with Noa | Your device only | Sent with each message to be answered, never stored | Art. 9(2)(a) GDPR |
| Summary per conversation (title, themes, insights, next step), time, message count, mood before/after, safety level | Our server | Noa's memory across conversations; your review under “History” | Art. 9(2)(a) GDPR |
| Mood check-ins (1–5, optional note) | Our server | 30-day history | Art. 9(2)(a) GDPR |
| Appointment request: name, email, requested slot, note, whether summaries may be shared | Our server | Passing the request to the therapist | Art. 6(1)(b) GDPR |
| Help form: topic, message, optional contact, app version | Our server | Answering your request | Art. 6(1)(b) and (f) GDPR |
| Safety event: level and detector – never the wording | Our server | Checking how often the crisis protocol fires | Art. 6(1)(f) GDPR |
| Usage events (e.g. “app opened”) without device id | Our server | Counting, not recognising | Art. 6(1)(f) GDPR |
3. Artificial intelligence – who reads your words
Noa's answers are produced by language models from Anthropic and OpenAI, which we reach through the intermediary OpenRouter, Inc. (USA). For text, safety checks and summaries we choose endpoints with zero data retention (the provider stores neither request nor answer and does not train on them) and prefer data centres in the EU. Each request carries the recent messages of the conversation, your first name, your goals, your latest mood and your last three summaries.
Exception – voice output: when you talk to Noa, an OpenAI audio model generates the spoken answer. No zero-data-retention endpoint exists for that model yet; the provider's own retention applies (per OpenAI up to 30 days for abuse monitoring, no training). If you would rather avoid that, use text mode – dictation runs independently through your phone's speech recognition.
Transfers to the USA rest on the providers' standard contractual clauses (Art. 46(2)(c) GDPR). There is no automated decision-making in the sense of Art. 22 GDPR; Noa takes no decisions with legal effect.
Noa is labelled as an AI (Art. 50 EU AI Act). She makes no diagnoses and replaces no treatment.
4. Crisis protocol
Before each answer your message is checked for signs of acute distress – first by patterns on our server, in parallel by a small language model. When the protocol fires, Noa changes tone and the app shows help lines. Only level and source are stored, never the sentence. Nothing is forwarded to third parties automatically.
5. Hosting and recipients
- Servers: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland (Rechenzentrum Nürnberg/Falkenstein). Processing under Art. 28 GDPR.
- OpenRouter, Inc. (USA) as intermediary to Anthropic PBC and OpenAI, L.L.C. – see section 3.
- Therapists receive your appointment request (name, email, slot, note) and – only if you tick the box – your summaries.
- Crash reports: when enabled, the app reports crashes to Sentry (Functional Software, Inc., USA) – without conversation content and without device id.
- This website sets no cookies and loads no external scripts or fonts. The admin area uses Google Sign-in for staff.
6. Retention
All server-side data stays until you delete it. “Delete my data” in Settings removes profile, moods, conversations, appointment requests, help requests and safety events for your device id immediately and gives the app a fresh id. The transcript on the device is removed when you uninstall the app. Id-free usage events are aggregated after 90 days.
7. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) and withdrawal of consent with effect for the future (Art. 7(3) GDPR). Access and portability are built into the app: “Export my data” hands you everything stored for your device id as JSON. Because we keep no names, we can answer email requests only if you tell us the device id from Settings.
Complaints go to the supervisory authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden, Germany.
8. Changes
This policy covers the current version of the app and is updated with every change to a data flow. The current version lives here; the date above shows its state.