
Privacy
The Mindset Operating System Ltd ("MindsetOS", "we", "our", or "us") provides digital and AI tools that help individuals and teams build psychological awareness, develop healthier performance habits, and strengthen their mindset at work and in life.
Company details:
We are the Data Controller for the personal data of individual users, whether they access MindsetOS directly or through their employer. Where access is provided through an organisation, that organisation is a separate, independent controller only for the limited data it determines, such as the employee list it provides and the aggregated, de-identified insights it receives.
We collect only the data necessary to provide, personalise, and improve the MindsetOS experience.
MindsetOS does not collect or process health records, medical information, or any data intended for clinical or diagnostic use. All data shared within the app relates to mindset, habits, and personal growth, not to medical or therapeutic evaluation.
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following lawful bases to process personal data:
| Purpose | Type of data | Lawful basis | GDPR article |
|---|---|---|---|
| Account creation and delivery of services | Account and contact data | Necessary for performance of a contract (to deliver app functionality). | Art. 6(1)(b) |
| User reflections, assessments, and AI coaching interactions | Self-reported mindset and behavioural information (non-clinical) | Consent: users choose to share this data to receive personalised insights. | Art. 6(1)(a) |
| Platform improvement and analytics | Technical and aggregated usage data | Legitimate interests in maintaining and improving the service (balanced against user rights). | Art. 6(1)(f) |
| Aggregate analysis of coaching themes | Coaching conversation content, analysed automatically to produce anonymised theme-level statistics | Legitimate interests in understanding and improving the product, and in describing how MindsetOS is used in our marketing and public communications (balanced against user rights). | Art. 6(1)(f) |
| Taking payment and managing subscriptions | Billing data (subscription status, plan, payment provider identifiers) | Necessary for performance of a contract (to provide the subscription you purchased), and to comply with tax and accounting obligations. | Art. 6(1)(b), Art. 6(1)(c) |
| Marketing communications (optional) | Contact data (email) | Consent (users can withdraw at any time). | Art. 6(1)(a) |
Important: MindsetOS does not collect or process medical, clinical, or therapeutic information. The data you provide through assessments or reflections relates to personal development and mindset awareness, not to health status or diagnosis. Our tools are designed for self-awareness and behavioural insight, not for medical or psychological evaluation.
We use data to:
Aggregate insights. We also analyse coaching activity in aggregate to understand the themes people bring to the coach. We use what we learn to improve the product and in our marketing and public communications, for example to describe what people use MindsetOS for. This analysis is automated and based on conversation summaries, never the conversation detail. It produces only anonymised statistics at theme level, for example the share of conversations about focus or confidence. We never publish figures for groups small enough to identify anyone, and we never publish themes that touch on health, neurodiversity, bereavement or other special category data. Individual conversations are not read by our team for this purpose, and no client organisation is named without its agreement. We rely on our legitimate interest in understanding, improving and promoting the product.
We do not sell or rent your personal data.
When MindsetOS provides services through an employer or organisation:
Data is securely hosted and processed using GDPR-compliant partners, including:
All personal data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is limited to authorised personnel and protected by authentication controls. MindsetOS is Cyber Essentials certified, meeting UK government-backed standards for cyber security. MindsetOS remains responsible for ensuring lawful and secure processing by all partners.
Where third parties (such as Convex, OpenAI, or Kit) process data outside the UK/EU, Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) ensure equivalent safeguards and compliance with UK GDPR.
Under UK GDPR, you have the right to access, correct, delete, restrict, or object to processing; withdraw consent; and request data portability.
To exercise your rights, contact admin@themindsetos.com.
If you are unsatisfied with our response, you can lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
MindsetOS uses local storage and session tokens to maintain secure sessions, save progress, and enable offline functionality.
Product analytics (provided by PostHog) are used to understand general usage patterns and improve the platform. Analytics are on by default under our legitimate interest in improving the product, and we tell you about this the first time you visit. PostHog stores this data in the European Union. Analytics data is anonymised or aggregated and is never used for advertising or cross-app tracking. You can opt out at any time from the consent prompt or in your account settings, and you can request deletion of your analytics data along with your account.
You can delete local data at any time by logging out or deleting your account within the app.
We may update this policy periodically. The latest version will always be available within the app and on our website.
For organisations using MindsetOS under a business agreement, data protection terms are set out in our standard Data Protection Agreement (available on request).