Privacy policy

How MindFuel handles information

Last updated 9 October 2026. This policy describes the MindFuel Android app and mindfuellabs.app. It is written for people who use the app, for Google sign-in branding, and for Google Play.

Who is responsible

The data controller is Chris Cleary, an individual in Ireland, operating the MindFuel brand. MindFuel is not a registered company. There is no Data Protection Officer; that role is not required for this service.

Contact: hello@mindfuellabs.app. This inbox receives email. A home address is not published.

This policy is based on the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

This website

mindfuellabs.app is a static site. It does not create accounts, run analytics, or store a contact form on a server. It does not set cookies. Light or dark follows your device setting; the site does not save that choice.

If you email hello@mindfuellabs.app, your email provider and the inbox provider handle that message. The site itself does not receive the contents.

Accounts and sign-in

The Android app requires an account before the main screens open. You can sign in with email and a password, or continue with Google. Authentication is provided by Supabase.

Google sign-in uses the system browser and an authorization-code flow with PKCE. After you approve access, Google returns you to the app at mindfuel://oauth/callback. The Google request in the app also asks for offline access and a consent prompt, so Google and Supabase may hold a refresh token for that sign-in. MindFuel uses the Google account to create and identify your MindFuel account (name and email). It does not use that sign-in to show ads.

After Supabase signs you in, the app sends the Supabase access token to the MindFuel API. The API checks it with Supabase and creates or updates a profile. The production API host in the app is mindfuel-production-7632.up.railway.app (Railway). The account record can include a numeric id, a Supabase user id, sign-in provider, name, email, a user or admin role, and created, updated, and last signed-in times.

Passwords are handled by Supabase. They are not stored in MindFuel’s account table. Providing an email address or Google account is needed to create the account; without it the app cannot open the main screens.

On Android, the MindFuel session is stored in the device’s secure storage (SecureStore) and sent as a Bearer token. That session token is issued with a one-year expiry in code and includes the Supabase user id, the app id mindfuel, and the display name — not the email. A copy of the profile, including email, is also cached in SecureStore. The API can set a cookie named app_session_id; that cookie is for web, not the Android session.

On your device

Wellness activity stays on the phone. The app stores it in local app storage (AsyncStorage), under keys that start with mindfuel:. That includes, in substance:

  • display name, onboarding goal, and language (English or Brazilian Portuguese)
  • theme, streaks, breathing sessions, habits, mood, hydration, sleep logs, journal and reflection text, reset entries, saved quotes, and daily cards
  • notification and wind-down reminder preferences, and the safety acknowledgement
  • a random device id used as one rate-limit subject for guided reflection. It is created in the app. It is not an advertising id
  • session-memory metadata such as feeling, state labels, risk level, timestamps, and a pointer to the encrypted Reset conversation. The current app does not keep chat message bodies in that record
  • a local log of recent AI-usage entries, recent micro-action text, and encrypted snapshots of entitlement status

Reset conversations are stored as encrypted ciphertext on the device. The per-account key is in SecureStore. Continuity summaries of what you typed are encrypted the same way. The full transcript is not written to MindFuel’s account database. When you use guided reflection, a bounded slice of recent turns is sent through the API to Google Gemini, as described below.

Emergency Assistance contacts are bundled in the app. The country you pick is stored on the device. Looking up a number does not send that lookup to the API. Reminders are scheduled on the device; the app code reviewed for this policy does not register a remote push token. Sleep sounds are files inside the app. The Android config describes the app as playback-only and does not request microphone recording.

Profile → Reset app data clears local wellness storage on that phone and reloads it. It does not sign you out. It does not clear SecureStore, so the session, cached profile, and encryption keys can remain. It does not delete the Supabase user, the MindFuel account row, or a Google Play purchase. Sign out is separate: it ends the MindFuel session, signs out of Supabase, and detaches the RevenueCat identity. Sign out does not wipe on-device wellness data.

Guided reflection

When you use guided reflection (including a personalised micro-action), the app sends the conversation to the MindFuel API. The API forwards that text to Google Gemini (model id gemini-flash-latest). The Gemini key stays on the server. The app does not contain it.

The live request can include your display name and onboarding goal when those are set, your latest message (trimmed on the device), a bounded slice of recent turns, and the random device id used for rate limiting.

The handler returns the assistant text. It does not save the transcript in MindFuel’s account database. Google Gemini still processes the prompt in order to generate a reply. This policy does not claim that Google discards prompts or excludes them from model improvement.

The reflection endpoint is rate-limited. Daily allowance rows are written only if that server switch is turned on; in the current code it defaults to off. Rate-limit counters may be stored in Upstash Redis when that is configured, otherwise in server memory, with short time limits.

The reflection assistant is instructed that it is not a therapist, doctor, or crisis service. Emergency Assistance does not send the conversation to Gemini.

Subscriptions

The app can offer optional Standard and Gold plans through Google Play, with status read through RevenueCat. After you sign in, RevenueCat is identified with the Supabase user id, not your email. Google Play processes the payment. The app does not collect a card number.

Prices, tax, billing frequency, renewal, and any store trial are whatever Google Play shows at purchase. This website does not list a price or trial as a live offer. Signing out, resetting on-device data, uninstalling, or deleting a MindFuel account does not cancel a Google Play subscription. Cancel billing in Google Play.

Under GDPR, processing needs a legal basis. For this product those bases are:

  • Contract (Article 6(1)(b)): creating and running your account, providing the app features you use (including guided reflection when you send a message), and handling a support or deletion request you make.
  • Legitimate interests (Article 6(1)(f)): keeping the service secure and usable — for example rate limits, session tokens, and last-signed-in times. Those interests are in running a working, abuse-resistant app. They are balanced against your right to a private wellness journal, which stays on the device unless you send text to reflection.
  • Legal obligation (Article 6(1)(c)): only where Irish or EU law requires a record to be kept. No extra tax or medical record-keeping is described in the app code.

This website does not use marketing cookies or a consent banner, because it does not set cookies or run advertising. Google sign-in is something you choose in the app; Google then processes that sign-in under Google’s terms.

There is no automated decision-making that produces legal or similarly significant effects about you. Guided reflection is a generated reply you can ignore.

Who else processes it

Services used by the app and API
Provider Role
Supabase Email and Google authentication, and the auth session
Google Google sign-in, Gemini for guided reflection, and Google Play billing
RevenueCat Subscription status, identified after sign-in as the Supabase user id
Railway Hosting for the MindFuel API. May see IP, path, and host logs
The MindFuel account database Account profile (name, email, sign-in provider, timestamps)
Upstash Redis Short-lived rate-limit counters when the server is configured with it

The app dependencies reviewed for this policy do not include a mobile advertising SDK, crash reporter, or product-analytics SDK. There is no feature whose purpose is to sell personal information.

Transfers outside the EEA

Some of the providers above may process information outside the European Economic Area, including the United States (in particular Google, and possibly others depending on how their hosting is set). This policy does not invent a claim that standard contractual clauses or another transfer tool is already signed with each provider. Their own privacy terms apply to what they receive. If you use Google sign-in or guided reflection, you should assume that Google processes that data, including outside the EEA.

Retention and deletion

Retention follows these criteria rather than a made-up number of days:

  • On-device wellness data: until you use Reset app data, clear the app’s storage in Android, or uninstall (what uninstall removes depends on Android).
  • MindFuel account row and Supabase user: until the account is deleted after a valid request.
  • Session material in SecureStore: until you sign out, uninstall, or it expires (one year in the current token code).
  • Rate-limit counters: minutes to a day, by design of those keys.
  • Support email: as long as needed to handle the request, then according to the inbox provider.
  • Host logs, backups, RevenueCat customer records, and Google Gemini: not timed in the MindFuel codebase. Those providers’ own retention applies until a deletion request is completed against what MindFuel can control.

Google Play’s user-data policy requires that an account deletion also delete the user data associated with that account, not merely freeze it. In the app, Profile → Delete account (after two confirmations) calls the MindFuel API. That deletes the Supabase sign-in user and the MindFuel account row, plus related trial or AI-usage rows if those tables exist. The app then clears wellness data on that phone and detaches RevenueCat on the device. Guided reflection text already sent to Gemini is not stored as a transcript in MindFuel’s database, so it cannot be pulled back from there. Google Play billing is not cancelled by account deletion.

You can also email hello@mindfuellabs.app from the address on the account, subject “Delete my MindFuel account”. Full steps, including cancelling Google Play billing first, are on the support page. A turnaround in days is not published here. GDPR still requires a response to a rights request without undue delay and in any event within one month, with a possible extension as that law allows. In-app deletion needs the server service-role key; if that is not configured, use email.

Your rights

You can ask Chris Cleary, as controller, to access the personal data held about you, to correct it, to erase it, to restrict processing, to object to processing based on legitimate interests, and to receive a portable copy of data you provided where GDPR gives a portability right. You can withdraw a consent you gave, without affecting processing that already happened.

Email hello@mindfuellabs.app from the address on the account so the request can be matched to a profile. Wellness history that stays on the device is not in the server profile; use Reset app data on the phone to remove most of it. The app does not upload that history into an export file.

You have the right to lodge a complaint with the Irish Data Protection Commission, which is the lead supervisory authority for this controller: dataprotection.ie. If you live in another EEA country you may also complain to your local authority.

Children

MindFuel is a general wellness app. It is not directed at children. In Ireland the digital age of consent for information society services is 16. The app does not currently ask for a date of birth or block an account by age. Do not create an account for a child under 16.

Security

Measures in the product include HTTPS calls to the API, PKCE for Google sign-in, session material in SecureStore, the Gemini key kept on the server, encryption for durable Reset history on the device, and rate limits on the reflection endpoint. That is not a promise that unauthorised access cannot happen.

Changes

When this policy changes, the date at the top of this page will change.

Contact

Chris Cleary, Ireland. Email hello@mindfuellabs.app. Support: https://mindfuellabs.app/support/.