Privacy Policy
Your privacy matters to us. Here is everything you need to know.
1. Introduction
Welcome to MindEase, a mental wellness application developed and maintained by Code Crafters IT Innovation ("we," "our," or "us"). We are committed to protecting and respecting your privacy in a manner consistent with applicable data protection laws and the highest industry standards for healthcare technology.
This Privacy Policy explains what personal and sensitive information we collect when you use the MindEase application and related services (collectively, the "Service"), how we collect it, why we collect it, how we store and protect it, with whom we share it, and the rights and choices available to you.
Because MindEase processes health-related and emotionally sensitive information — including mood entries, mental health assessments, audio and facial emotion signals, and biometric indicators — we take our obligations to you very seriously. We have designed this Policy to be transparent, readable, and comprehensive so that you can make informed decisions about using our Service.
Please read this Privacy Policy carefully. If you have any questions or concerns, you may contact us at any time using the details provided in Section 21.
2. Acceptance of Policy
By downloading, installing, accessing, or using MindEase, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and our Terms of Service. If you do not agree to the terms set forth herein, you must discontinue use of the application immediately.
This Privacy Policy applies to all users of the Service worldwide, including visitors, registered users, and premium subscribers. Your continued use of the Service following any update to this Policy constitutes your acceptance of the revised terms.
3. Information We Collect
We collect different categories of information to provide, improve, and personalize the Service. The types of information we collect depend on how you interact with MindEase and the features you enable.
3.1 Personal Information
- Profile Information: Your name, display name, and optional profile photograph when you create or update your account.
- Email Address: Used for account creation, authentication, and service communications.
- Authentication Information: Login credentials, or federated identity information from Google Sign-In, Facebook Login, or phone number/OTP verification. Passwords you create directly with us are stored using industry-standard one-way hashing, never in plaintext.
- Date of Birth: Collected optionally to personalize wellness recommendations and apply age-appropriate safeguards.
3.2 Mental Health and Wellness Data
- Mood Entries: Daily or periodic mood ratings, emotional journal entries, and associated notes that you voluntarily submit.
- PHQ-9 Responses: Responses to the Patient Health Questionnaire-9 depression screening tool when you complete an assessment.
- Audio Analysis Data: Two short (approximately 5-second) audio clips are recorded and uploaded to our servers to detect emotional characteristics in your voice tone and cadence.
- Facial Emotion Analysis Data: A photo captured from your device camera is uploaded to our servers and analyzed to infer emotional states.
3.3 Biometric and Health Data
- Heart Rate Data: Heart rate readings streamed over a Bluetooth Low Energy (BLE) connection from a compatible heart-rate wearable that you pair with the app. MindEase does not read heart rate from a phone's own sensors; a connected wearable device is required for this feature.
- Activity Data: Daily physical activity levels recognized using your device's on-device activity-recognition sensor, together with any activity details you log manually within the Daily Log feature.
- Sleep Data: Sleep duration and timing that you log manually within the Daily Log feature. MindEase does not currently read sleep data automatically from a health platform or wearable.
3.4 Technical and Usage Data
- App Usage Analytics: Feature interactions, session duration, navigation patterns, and in-app events used to understand how users engage with the Service.
- Crash Reports: Diagnostic data transmitted automatically when the application encounters an error, including device state information at the time of the crash.
- Device Information: Device model, operating system version, unique device identifiers, screen resolution, language settings, and time zone.
- IP Address: Collected automatically when you connect to our servers; used for security monitoring, fraud prevention, and approximate geographic region identification.
- Cookies and Similar Technologies: See Section 14 for a detailed explanation of our use of cookies, local storage, and tracking technologies.
3.5 Device Permissions
Certain features of MindEase require access to device hardware and system resources. We request only the permissions necessary for each feature, and we request your explicit consent before activating them:
| Permission | Feature | Required? |
|---|---|---|
| Camera | Facial emotion analysis | Optional |
| Microphone | Audio emotion analysis | Optional |
| Bluetooth (Scan / Connect) | Pairing with and reading data from a heart-rate wearable | Optional |
| Activity Recognition | Daily activity monitoring | Optional |
| Notifications | Wellness reminders, check-in prompts | Optional |
| Storage/Files | Local data caching and backup | Recommended |
| Internet | Syncing your data with our servers so your account, reports, and AI-generated insights work | Required |
You may revoke any permission at any time through your device's system settings. Revoking a permission will disable the associated feature but will not affect your access to other parts of the Service.
4. How We Use Your Information
We use the information we collect for the following purposes, always in accordance with applicable laws and our commitments to you:
- Providing the Service: Processing your wellness entries, generating mental health insights, delivering personalized recommendations, and maintaining your account.
- Improving the Service: Analyzing aggregated, anonymized usage data to understand which features are most valuable and to identify opportunities for improvement.
- Safety and Crisis Detection: Identifying signals that may indicate acute distress and presenting crisis resources where appropriate. This does not constitute clinical intervention.
- Service Communications: Sending you account-related notifications, policy updates, and, with your consent, wellness tips or promotional communications.
- Security and Fraud Prevention: Monitoring for unauthorized access, suspicious activity, and technical vulnerabilities to protect your data and the integrity of the Service.
- Legal Compliance: Fulfilling obligations under applicable law, responding to lawful requests from public authorities, and enforcing our Terms of Service.
- Research (Aggregated and Anonymized Only): Contributing to the broader field of mental wellness research using de-identified, aggregated datasets. Your individually identifiable information is never shared for research purposes without your explicit, separate consent.
We do not sell, rent, or trade your personal or health information to any third party for marketing purposes. We do not use your mental health data to serve targeted advertising.
5. AI Processing
Some features of MindEase are powered by artificial intelligence and machine learning models. These models analyze the information you submit — such as mood entries, PHQ-9 responses, audio characteristics, and facial expression features — to generate mental wellness insights, trend visualizations, and personalized recommendations.
Our AI models are designed to surface patterns and trends in the data you provide. They do not make autonomous decisions that significantly affect your legal rights or produce legal effects. You retain full control over your data through your in-app settings and account preferences.
Our facial emotion and voice analysis models are built using established emotion-recognition datasets. AI-generated outputs are probabilistic in nature and may be incomplete or inaccurate for any given individual; they should be treated as informational signals rather than validated conclusions.
6. Facial Emotion Analysis Disclaimer
MindEase offers an optional feature that uses your device camera to analyze facial expressions and estimate emotional states. We want to be fully transparent about how this feature works and what it does not do:
- Emotional feature extraction only: Our system analyzes facial landmark positions and expression patterns to infer general emotional states (e.g., happiness, sadness, surprise). It does not identify you as an individual.
- No biometric identification: We do not use facial analysis to identify, authenticate, or verify your identity. No facial recognition database is created or maintained.
- Image is uploaded for processing: When you use this feature, the captured image is uploaded from your device to our servers so that it can be processed and analyzed. The image is stored on our servers as part of your account data; see Sections 11 and 18 for storage and retention details.
- No third-party biometric sharing: Facial feature data is never sold, licensed, or shared with any third party for identification, surveillance, or commercial purposes.
7. Audio Analysis Disclaimer
MindEase provides an optional audio check-in feature that analyzes your voice to detect emotional characteristics such as tone, pitch variation, speech pace, and energy levels. These acoustic features are used to supplement your self-reported mood data with an objective signal.
- Acoustic emotion analysis only: Audio is processed to detect emotional characteristics (e.g., elevated stress indicators, low-energy vocal patterns). The system does not use the semantic content of what you say to identify you.
- No voice identity recognition: Our audio processing system does not create voiceprints, speaker embeddings, or any biometric voice profile that could be used to identify you. No voice identification database is maintained.
- Recordings are uploaded for processing: When you use this feature, short audio clips recorded on your device are uploaded to our servers so they can be processed and analyzed. The audio files are stored on our servers as part of your account data; see Sections 11 and 18 for storage and retention details.
- Consent required: Microphone access requires your explicit permission and can be revoked at any time through your device settings.
8. PHQ-9 Assessment
The Patient Health Questionnaire-9 (PHQ-9) is a clinically validated, nine-item self-report screening instrument widely used in primary care and mental health settings to assess the presence and severity of depressive symptoms. MindEase incorporates the PHQ-9 as one of several wellness monitoring tools.
Scoring
Each of the nine items is scored 0–3 (Not at all = 0, Several days = 1, More than half the days = 2, Nearly every day = 3), yielding a total score of 0–27. Score ranges correspond to broadly recognized severity thresholds: Minimal (0–4), Mild (5–9), Moderate (10–14), Moderately Severe (15–19), and Severe (20–27).
Purpose within MindEase
PHQ-9 results within the application are used to: (a) help you track changes in self-reported depressive symptoms over time; (b) inform the personalization of wellness content and suggestions; and (c) provide context for AI-generated trend analysis.
9. Heart Rate Analysis
With your permission, MindEase connects to a compatible heart-rate wearable over Bluetooth Low Energy (BLE) to read heart rate data and provide a physiological dimension to your mental wellness insights. This feature requires a paired wearable device; your phone's own hardware is not used to measure heart rate.
Purpose
Heart rate data is used to: (a) contextualize mood and stress self-reports with an objective physiological signal; (b) identify patterns that may indicate elevated autonomic arousal or physiological stress; and (c) contribute to holistic wellness trend tracking over time.
Limitations
Heart rate data as processed by MindEase is not a medical-grade measurement. Consumer wearable sensors may exhibit variability and should not be relied upon for clinical decision-making. Insights derived from heart rate data within the app are informational only and do not constitute a diagnosis of any cardiac or psychological condition. Always consult a healthcare professional regarding any health-related concerns.
10. Activity Monitoring
Research consistently demonstrates strong relationships between physical activity, sleep quality, screen time, and mental well-being. MindEase incorporates the following behavioral data into your wellness picture through its Daily Log feature and your device's on-device activity-recognition sensor, with your permission:
- Sleep: Duration and timing that you log manually each day. Disrupted sleep is a key indicator in multiple mental health conditions.
- Exercise and Physical Activity: Activity levels recognized using your device's activity-recognition sensor, together with any exercise details you log manually.
- Screen Time: Daily screen-time information that you log manually within the Daily Log feature.
- Daily Habits: Logged routines such as water intake, meal timing, and mindfulness practice duration when you manually enter them.
This data is provided directly by you or derived from the Activity Recognition permission on your device, and is not currently sourced from Apple HealthKit, Google Fit, or similar third-party health platforms. You may withdraw the Activity Recognition permission at any time without affecting your core wellness tracking features.
11. Data Storage
Your data, including uploaded facial images, audio recordings, PHQ-9 responses, and activity data, is stored on servers operated by Code Crafters IT Innovation, organized into a dedicated, access-controlled folder for each user account. Firebase (Google LLC) is used only for the sign-in options described in Section 13; it is not used to store your wellness or health data.
Encryption
Data submitted to the Service is transmitted over HTTPS. We are actively working to strengthen encryption of data at rest and to harden our network configuration so that only encrypted connections are ever accepted, and we will update this section as those improvements are completed.
Retention
We retain your data for as long as your account remains active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods vary by data category (see Section 18 for details).
Backups
Backups of certain data may be maintained to support data resilience. We are working to ensure backup data is subject to access controls and encryption standards consistent with primary data.
12. Security
We take reasonable steps to protect the information we process, commensurate with the sensitivity of the health data involved, and we are continuously working to improve our security practices. Our current measures include:
- Encryption in Transit: Data submitted to the Service is transmitted over HTTPS.
- Authentication: User accounts are authenticated using your login credentials or federated sign-in options such as Google Sign-In, Facebook Login, or phone/OTP verification.
- Access Control: Internal access to user data is limited to personnel who need it to operate and support the Service.
- Ongoing Improvement: Security is an active area of investment for us. We regularly review our practices and are working through a roadmap of hardening measures, including strengthening encryption at rest, tightening server-side session validation, and enforcing encrypted connections at the network configuration level.
Notwithstanding these measures, no security system is impenetrable. In the event of a data breach affecting your rights and freedoms, we will notify you and applicable regulatory authorities as required by law, within the legally specified timeframes.
13. Third-Party Services
MindEase integrates with a limited set of trusted third-party service providers to deliver and support the Service. Each provider is carefully selected and bound by data processing agreements that require them to protect your data in accordance with applicable laws and our standards.
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase | Google LLC | Authentication and related app services | Account data, app data |
| Google Sign-In | Google LLC | Federated authentication | Email, name, profile picture (optional) |
| Facebook Login | Meta Platforms, Inc. | Federated authentication | Email, name, profile picture (optional) |
| Phone/OTP Verification | Google LLC (Firebase Authentication) | Phone number sign-in and verification | Phone number |
We do not share personally identifiable health data with any third-party provider beyond what is strictly necessary to deliver the Service. We are not responsible for the independent privacy practices of third parties when you interact with their services outside of MindEase.
14. Cookies and Tracking Technologies
When you access MindEase via a web browser, we and our service providers may use cookies, local storage, session tokens, and similar technologies to support the functioning of the Service, maintain your session, remember your preferences, and gather anonymized analytics.
- Strictly Necessary Cookies: Required for the Service to function (e.g., session tokens, authentication cookies). These cannot be disabled.
- Functional Cookies: Used to remember your preferences, language settings, and personalization choices.
- Analytics Cookies: If enabled, used to collect aggregated, anonymized data about how users interact with the Service. These can be disabled via your browser settings or our cookie preference manager.
We do not use advertising cookies or cross-site tracking technologies. You may manage or delete cookies through your browser settings at any time. Disabling strictly necessary cookies will impair the functionality of the Service.
15. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data. We are committed to honoring these rights without undue delay:
- Right of Access: You may request a copy of the personal data we hold about you, including its category, source, purpose, and recipients.
- Right to Correction: You may request correction of inaccurate or incomplete personal data. You may update many details directly through your in-app profile settings.
- Right to Deletion ("Right to Be Forgotten"): You may request deletion of your personal data, subject to our legal retention obligations. Account deletion triggers a scheduled purge of your data from our systems.
- Right to Data Portability: You may request an export of your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
- Right to Object: You may object to processing based on our legitimate interests, and you may opt out of direct marketing communications at any time.
- Right to Restrict Processing: In certain circumstances, you may request that we restrict how we use your data while a dispute is being resolved.
To exercise any of these rights, please contact us at codecraftersitinnovation@gmail.com. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request.
16. Children's Privacy
MindEase is intended for users who are at least 16 years of age (or the minimum age of digital consent in their jurisdiction, whichever is higher). We do not knowingly collect personal data from children under this age without verifiable parental or guardian consent.
If we discover that we have inadvertently collected personal information from a child under the applicable age threshold without appropriate consent, we will promptly delete such data from our systems. If you believe we have collected information from a child without proper consent, please contact us immediately at codecraftersitinnovation@gmail.com.
Where MindEase is made available to users under 18 (e.g., in a supervised therapeutic context with guardian consent), we apply enhanced data minimization and additional access controls appropriate to the sensitivity of minors' health data.
17. International Users
MindEase is available globally. By using the Service, you acknowledge that your information may be transferred to, stored in, and processed in countries other than your country of residence, including countries whose data protection laws may differ from those in your jurisdiction.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, such transfers are conducted in accordance with applicable data transfer mechanisms, including Standard Contractual Clauses (SCCs) approved by relevant data protection authorities, ensuring your data receives an adequate level of protection.
We comply with applicable data protection regulations in the jurisdictions where we operate, including the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the California Consumer Privacy Act (CCPA) where applicable. If you have questions about international transfers, please contact our Privacy Team at codecraftersitinnovation@gmail.com.
18. Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by applicable law. Upon account deletion, we initiate a data purge process within 30 days for most data types, subject to legal hold obligations. Key retention periods:
| Data Category | Retention Period |
|---|---|
| Account and Profile Data | Duration of account + 30 days post-deletion |
| Mood Entries and Journal Data | Duration of account + 30 days post-deletion |
| PHQ-9 Assessment Results | Duration of account + 90 days post-deletion |
| Uploaded Audio Recordings | Duration of account + 30 days post-deletion |
| Uploaded Facial Images | Duration of account + 30 days post-deletion |
| Heart Rate / Activity / Sleep | Duration of account + 30 days post-deletion |
| App Usage Analytics (anonymized) | Up to 26 months from collection |
| Crash Logs | Up to 90 days from collection |
| Financial / Transaction Records | 7 years (legal and tax obligation) |
19. Data Deletion
You may delete your MindEase account and request deletion of your associated data at any time through the following methods:
- In-App: Navigate to Settings → Account → Delete Account. This action is irreversible and will initiate the deletion process.
- By Email: Send a deletion request to codecraftersitinnovation@gmail.com from your registered email address, including your account username or associated email.
Upon receiving a valid deletion request, we will: (a) deactivate your account immediately; (b) initiate deletion of personal data, including your PHQ-9 assessment records, from our active systems within 30 days; (c) purge data from backups within 90 days; and (d) confirm completion of the deletion process to your registered email address.
Please note that certain data may be retained where required by law (e.g., financial transaction records), but such retained data will be isolated and not used for any operational purpose.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will:
- Post the updated Policy within the application and on our website with an updated "Effective Date."
- Send an in-app notification and, where appropriate, an email notification to your registered address.
- For material changes affecting your rights or the way we process sensitive health data, seek your renewed consent before the changes take effect.
Your continued use of MindEase following the effective date of any update constitutes your acceptance of the revised Policy. We encourage you to review this page periodically.
21. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact our Privacy Team:
- Email: codecraftersitinnovation@gmail.com
- Application: MindEase
- Company: Code Crafters IT Innovation
- Response Time: We aim to respond to all privacy-related inquiries within 5 business days and within any legally mandated timeframe for formal rights requests.
For general support inquiries unrelated to privacy, please use the Support section within the MindEase application.
22. Legal Disclaimer
MindEase and Code Crafters IT Innovation make no representations or warranties of any kind, express or implied, regarding the completeness, accuracy, reliability, suitability, or availability of the Service or the information contained herein for any particular purpose. The Service is provided on an "as is" and "as available" basis.
To the maximum extent permitted by applicable law, Code Crafters IT Innovation and its directors, officers, employees, agents, and service providers shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of or inability to use the Service, including but not limited to loss of data, loss of profits, or personal injury, even if we have been advised of the possibility of such damages.
Nothing in this Privacy Policy shall be construed to limit our liability for death or personal injury caused by our negligence, fraud, or fraudulent misrepresentation, or any other liability that cannot be excluded by law.
23. Medical Disclaimer
The content, features, tools, assessments, and AI-generated insights within MindEase are intended for general mental wellness support and informational purposes only. They are not a substitute for professional medical advice, psychiatric assessment, psychological counseling, or any other form of licensed healthcare service.
Always seek the guidance of a qualified physician, psychiatrist, psychologist, or other licensed healthcare professional with any questions you may have regarding a mental or physical health condition. Never disregard professional medical advice or delay seeking it because of something you have read or experienced in MindEase.
If you are experiencing a mental health emergency, suicidal ideation, thoughts of self-harm, or any other psychiatric emergency — contact your local emergency services (911 in the US, 999 in the UK, 112 in the EU) or a crisis helpline immediately. MindEase is not equipped to provide crisis intervention.
24. AI Disclaimer
Artificial intelligence and machine learning form the backbone of several MindEase features. Users should understand the following about AI-generated content within the application:
- AI-generated insights, suggestions, and content are probabilistic outputs based on pattern recognition across your submitted data and model training data. They are not deterministic or infallible.
- AI models may produce outputs that are incomplete, inaccurate, or not fully applicable to your unique situation. Always apply your own judgment.
- Our AI models are not licensed mental health practitioners and cannot replicate the nuanced judgment, empathy, or professional responsibility of a qualified clinician.
- We continuously work to improve model quality and reduce inaccuracy; however, no AI system achieves perfect outcomes across all populations or contexts.
- If any suggestion feels inappropriate or inaccurate, please use the in-app feedback mechanism to report it.
25. Consent
Certain categories of processing — particularly processing of special category health data (including mental health, biometric, and physiological data) — require your explicit, freely given, specific, informed, and unambiguous consent. We obtain this consent by requesting the relevant device permission (e.g., camera, microphone, health platform access) before the associated feature is activated, and you can decline or revoke that permission at any time.
You may withdraw consent at any time by: (a) adjusting your data preferences in Settings; (b) disabling specific device permissions; or (c) contacting us directly. Withdrawal of consent does not affect the lawfulness of any processing that occurred prior to withdrawal.
Where processing is based on legitimate interests (e.g., security monitoring, fraud prevention, service improvement using anonymized data), you retain the right to object. Where processing is necessary to fulfill our contractual obligations to you (e.g., delivering the core Service), we may not be able to continue providing certain features if the necessary processing cannot be performed.
26. Governing Law
This Privacy Policy and any disputes arising from or relating to it shall be governed by and construed in accordance with the laws of the jurisdiction in which Code Crafters IT Innovation is registered, without regard to its conflict of law principles, and subject to the mandatory data protection laws of the user's jurisdiction.
For users in the EEA or UK, the applicable supervisory authority for data protection complaints is the data protection authority of your country of residence. We encourage you to raise concerns with us directly in the first instance; however, you are always entitled to lodge a complaint with your supervisory authority.
Any legal action arising out of this Privacy Policy that is not resolved through our internal complaint process shall be subject to the exclusive jurisdiction of the courts of the governing jurisdiction, unless mandatory consumer protection laws in your country require otherwise.




