miMind

Privacy Policy

How we collect, use, share and protect your information across the app, cloud sync and AI features.

Last updated: 29 July 2026  ·  Effective: 29 July 2026

This Privacy Policy explains how CryptoBees LLC (“CryptoBees”, “we”, “us”, “our”) collects, uses, discloses and protects information in connection with the miMind mind-mapping application (the “App”) on all platforms it runs on (Windows, macOS, Linux, iOS, Android and the web), our related websites, our cloud sync and account backend, and the miMind AI features (together, the “Services”). By using the Services you agree to the practices described here and in our Terms & Conditions.

The short version

  • You can use core miMind without an account. Maps you create are stored locally on your device unless you choose to sign in and use cloud sync.
  • Cloud sync is optional and your map files are encrypted on your device before they are uploaded to our storage; the encryption keys are held in your account.
  • AI features are optional. When you use them, the relevant content (your prompt, the map outline, and any attachments) is sent to our AI provider, Anthropic, to generate a response. We store usage counts, not the content of your prompts or the AI’s replies.
  • We do not sell your personal information and we do not use your maps or AI prompts to advertise to you.
  • You control your data. You can sign out of all devices, disable cloud/MCP sync, delete files, revoke access tokens, and delete your account and its associated data from within the App.

1. Who we are

The Services are provided by CryptoBees LLC. For all privacy questions, requests and notices, contact us at cryptobees@gmail.com. For the purposes of the EU/UK GDPR, CryptoBees LLC is the “controller” of the personal data described in this policy, except where we act as a processor of the content you create (your maps).

2. Information we collect

What we collect depends on how you use the Services. If you never create an account, we do not collect account or content data in the cloud; your maps stay on your device.

a. Account & identity information

If you create an account or sign in, our authentication provider (Google Firebase Authentication) records the identifiers associated with your sign-in method. We support email/password sign-in and federated sign-in with Google, Apple, Microsoft and Facebook. Depending on the method, this includes: your email address, display name, profile photo URL (if your provider supplies one), the provider’s user identifier, a unique miMind user ID, and whether your email is verified. We do not receive your password when you use a federated provider.

b. Purchase & subscription information

When you buy a Premium, miMind AI or Agentic subscription or upgrade, the purchase is processed by the relevant app store or reseller (see §8). We store the entitlement result linked to your account — which products/features you are entitled to, the product (SKU) purchased, a purchase/transaction token used to verify and re-validate the purchase, verification timestamps, and, for web/desktop purchases, a Paddle customer identifier. We do not store your full card number or bank details; those are handled by the payment processor.

c. Content you create

Your mind maps, notes, node text, images and files you attach, and other content you author are “Content”. Content lives on your device by default. If you enable cloud sync, your map files are stored in our cloud (see §7); if you use AI features, relevant Content is transmitted to our AI provider to fulfill your request (see §4). You retain ownership of your Content.

d. AI usage data

If you use AI features, we record per-account usage metering: counts of AI generations and chat requests, input/output token totals (monthly and daily), agentic-run counters, and the month/day the counters apply to, together with your email for account support and abuse prevention. We do not store the text of your prompts, your map content, your attachments, or the AI’s responses on our AI-gateway servers — those are streamed to the provider and only counted. (Agentic AI results you receive in your in-app inbox are an exception; see §6.)

e. Device, diagnostic & usage data

To operate the App and understand aggregate usage, we collect a limited set of technical data:

  • Run information stored with your account: platform, device model, operating-system version, app version and the time of your most recent run.
  • Analytics: the App includes Google Analytics for Firebase (GA4), which collects standard app-usage and device information (e.g. app opens, platform, approximate region, and a Google-assigned instance identifier). This is used in aggregate to measure active users and does not require you to sign in.
  • IP address for AI region checks: when you make an AI request, your IP address is used transiently to determine your country for the availability check described in §4. We do not store your IP address for this purpose; only the resulting country verdict (allowed/blocked) may be cached to your account.
  • Storage usage: if you use cloud storage, we record how much storage you are using and your quota.

f. Communications

If you email us for support or opt in to product news, we keep your email address and the content of your message so we can respond and, if applicable, send updates you asked for.

3. How we use information

  • To provide, operate and maintain the App, your account and cloud sync.
  • To authenticate you and keep your account secure, including revoking sessions across devices when you ask.
  • To process purchases, validate and re-validate subscriptions and entitlements, and manage renewals and refunds.
  • To provide AI features — sending your request to the AI provider and returning its response — and to meter usage against your plan’s limits.
  • To enforce fair-use limits, detect and prevent abuse or fraud, and apply legal availability restrictions (see §4).
  • To measure aggregate usage and improve the Services.
  • To communicate with you about support requests, important service or security notices, and (where you opted in) product news.
  • To comply with legal obligations and enforce our Terms.

Where required by law, our legal bases for processing are: performance of our contract with you (providing the Services), your consent (e.g. optional analytics, product emails, and using AI features), our legitimate interests (security, abuse prevention, aggregate product analytics), and compliance with legal obligations (including trade-sanctions compliance).

4. AI features & Anthropic

miMind’s AI features (map generation, chat with your map, expansion suggestions, and agentic AI) are optional and are powered by Anthropic’s Claude models. AI requests are routed through our secure cloud gateway to Anthropic; the App does not call Anthropic directly.

What is sent to Anthropic

Only when you invoke an AI feature, and only what your request needs:

  • Map generation: the topic, pasted text, or URL you provide, plus any attachments you add.
  • Chat with your map: your typed message, the outline of the currently open map (node titles and structure) so the assistant has context, an indication of the node you have selected, and recent turns of that conversation.
  • Attachments: images you attach (analyzed with vision), text extracted from files you attach, and links you provide. When you supply a URL or link, Anthropic’s models may fetch that page and may perform web searches to fulfill your request.

What we retain

Our gateway does not persist the content of your prompts, map data, attachments, or the AI’s responses. We retain only the usage counts described in §2(d), and operational logs that contain metadata (such as request type, node counts and token totals) but not the content itself.

How Anthropic handles your data

Anthropic processes the content you send to generate a response. We access Anthropic’s API under commercial terms under which inputs and outputs are not used to train Anthropic’s models. Anthropic may retain data for a limited period for safety and abuse-prevention purposes in accordance with its own policies. Please review Anthropic’s Privacy Policy. You are responsible for the content you choose to submit; avoid sending sensitive personal information you would not want processed by a third-party AI service.

Bring your own key

miMind AI subscribers may supply their own Anthropic API key. That key is stored only on your device, is never uploaded to or stored in our cloud, is used only to authorize your own requests, and is cleared automatically when you sign out or your AI subscription ends. In this mode your requests are billed to your own Anthropic account and are not metered by us, but they still pass through our gateway and are still subject to the availability check below.

Regional availability

Because our AI provider does not serve certain sanctioned jurisdictions, AI features are unavailable in a small number of countries. To enforce this we determine the country of an AI request from network/geo signals or, as a fallback, your device’s locale (and, transiently, your IP address as described in §2(e)). If your location is restricted, the AI request is declined; core (non-AI) miMind features remain available.

5. MCP server & connected agents

The optional miMind MCP server lets you connect external AI agents (such as Claude Code or Claude Desktop) to your maps. If you enable it:

  • Sync is opt-in. Nothing is published until you turn it on. Only map outlines (titles and node text) are published for agents to read — never your attachments or files.
  • Access tokens are hashed. When you generate a personal access token it is shown to you once; we store only a SHA-256 hash of it, along with your user ID, email and a label. You can keep up to five tokens and revoke any of them instantly.
  • Scoped to you. A token only ever reaches the maps of the account that created it. Changes an agent requests are queued and applied by your own copy of miMind, with normal undo.
  • Any external agent or client you connect operates under its own provider’s privacy terms, which apply to what you send through it.

6. Agentic AI & webhooks

If you use Agentic AI, you can mark nodes as directives that run on a schedule, on demand, or when triggered by an inbound webhook. For these you configure and we store: the directive’s title and prompt text, the associated map/node identifiers, schedule, an inbound webhook secret, and any outbound webhook URLs you set up (for example to Zapier, IFTTT or a home-automation service). Results, questions and errors produced by a directive are written to your in-app inbox (truncated), so unlike ordinary AI chat, agentic outputs are stored in your account until you delete them. When a directive calls an outbound webhook you configured, the data in that call is sent to the third-party endpoint you chose; that transfer and the receiving service are your responsibility.

7. Cloud storage & encryption

Cloud sync is optional. When you store maps in the miMind cloud, your map files and images are held in Google Firebase Storage under your account, readable and writable only by you. Your map files are encrypted on your device before upload; the per-file encryption keys are stored in your account so you can access your files from your other devices. You may also connect third-party drives (Google Drive, Dropbox, OneDrive) as alternative storage; content you place there is governed by that provider’s terms.

8. Third-party services we use

We use the following processors and service providers to run the Services. Each receives only the data needed for its function.

ProviderPurposeData involved
Google Firebase (Authentication, Firestore, Storage, Cloud Functions)Accounts, cloud sync, backendAccount identifiers, entitlements, encrypted map files, usage records
Google Analytics for Firebase (GA4)Aggregate usage analyticsApp/device usage events, approximate region, instance identifier
AnthropicAI generation, chat, MCP & agentic featuresYour prompts, map outline, attachments and links (see §4)
Apple App StorePurchases on iOS & macOSPurchase/transaction identifiers
Google PlayPurchases on AndroidPurchase tokens/product identifiers
PaddleMerchant of Record for Windows, Linux & web purchasesBuyer email, account ID, customer/subscription IDs
Optional user-connected drives (Google Drive, Dropbox, OneDrive)Alternative cloud storage you chooseMap files you place there
We do not control, and are not responsible for, the privacy practices of third-party services you choose to connect (payment providers, connected drives, external AI agents, or webhook endpoints you configure). Please review their policies.

9. How we share information

We do not sell your personal information and we do not share it for cross-context behavioral advertising. We disclose information only:

  • to the processors listed in §8, to provide the Services;
  • to the payment processors and app stores needed to complete and verify your purchases;
  • where you direct it — e.g. content you share, drives you connect, or agents/webhooks you enable;
  • to comply with law, enforce our Terms, or protect the rights, safety and security of our users, the public or CryptoBees; and
  • in connection with a merger, acquisition or sale of assets, subject to this policy.

10. Cookies & analytics

Our websites use a minimal set of cookies and similar technologies necessary to run the site and remember your choices. Our store and account pages may use additional cookies described in the applicable cookie notice. In-app analytics are provided by GA4 as described in §2(e). We do not currently serve third-party advertising in the App. If that ever changes, we will update this policy first.

11. Data retention

  • Account data is kept while your account is active and for a reasonable period afterward for legal, accounting and anti-fraud purposes.
  • Purchase/entitlement records are retained after a subscription ends so we can honor prior purchases and meet tax/audit obligations.
  • AI usage counters reset each month; the usage document (with your email) persists for support and abuse prevention.
  • Cloud files remain until you delete them or delete your account.
  • MCP tokens are stored only as hashes and are removed when revoked; transient sign-in tokens are single-use and short-lived.
  • AI prompt/response content is not retained by us (see §4).
  • When you delete your account, we erase the data associated with it as described in §12, except records we are required to keep by law.

12. Your rights & choices

Depending on where you live (including under the EU/UK GDPR and the California Consumer Privacy Act, as amended), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. Because we do not sell or “share” personal information as those terms are defined, there is no sale to opt out of.

You can exercise many choices directly in the App:

  • Sign out of all devices to revoke active sessions.
  • Turn cloud sync and MCP sync on or off, and delete individual cloud files.
  • Revoke MCP access tokens and remove published map outlines.
  • Remove agentic directives and clear inbox items.
  • Update your display name and manage email verification and password reset.

Deleting your account. You can permanently delete your account and its associated data from within the App: open Account, choose Delete account, and follow the prompts. To protect you against accidental or unauthorized deletion, we first re-verify your identity and ask you to type your exact account email to confirm. When you confirm, we delete your account and the personal data associated with it — including your profile, entitlement and usage records, cloud-stored map files and images, encryption keys, MCP tokens and published outlines, and agentic directives and inbox — and sign you out. Some records may be retained where we are required to keep them by law or to resolve disputes or prevent fraud; and deleting your account does not automatically cancel a paid subscription billed by an app store or reseller (Apple, Google Play or Paddle) — cancel that separately through the store where you bought it. If you prefer, you can also request deletion by emailing cryptobees@gmail.com from your account email. To exercise any other right, contact us at the same address; we will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data-protection authority.

13. International data transfers

We and our processors operate in the United States and other countries. Where we transfer personal data across borders, including from the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms offered by our processors.

14. Security

We take reasonable and appropriate technical and organizational measures to protect your information, including encryption of map files on-device before upload, hashing of MCP access tokens, per-user access rules on cloud storage and data, HMAC verification of billing webhooks, and transport encryption. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and any API or access tokens confidential.

15. Children’s privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Some features (such as AI and purchases) may have a higher minimum age under the applicable app store’s or provider’s terms. If you believe a child has provided us personal information, contact us and we will delete it. This is consistent with the U.S. Children’s Online Privacy Protection Act (COPPA).

16. Do Not Track

Some browsers offer a “Do Not Track” signal. There is no common industry standard for how to respond to it, and our websites do not currently respond to DNT signals. We limit tracking as described in this policy regardless.

17. Data-breach notification

If a data breach affecting your personal information occurs, we will notify affected users and any relevant authorities without undue delay and as required by applicable law, describing the nature of the incident and the steps we are taking.

18. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Services, our practices, or legal requirements. When we make material changes we will update the “Last updated” date above and, where appropriate, provide additional notice. Please review this page periodically.

19. Contacting us

If you have questions, requests or concerns about this Privacy Policy or your data, contact us at:
cryptobees@gmail.com
CryptoBees LLC