Privacy Policy

Privacy Policy

Last Updated: June 11, 2026

MindFlash ("MindFlash", "we", "us", or "our") provides an offline-first Android flashcard and note-taking app with local AI study tools, reminders, export tools, and a web marketing/demo surface. This Privacy Policy explains how information is handled in the current Phase 5 product.

1. Product Stance

MindFlash is designed so ordinary study work stays on your device. For ordinary local AI generation, MindFlash does not upload your notes, decks, cards, files, or prompts to remote AI services.

The current Android app has no account creation, no subscriptions, no in-app purchases, no community sharing, and no remote AI processing by default. Crash diagnostics remain enabled, so the app is not a zero-data or zero-tracking product.

2. Information Handled Locally

MindFlash stores study data locally on your device, including decks, cards, notes, imported text, drawings, review progress, local AI outputs, model readiness state, preferences, reminders, export metadata, and local backup files you create.

You control local study data through device storage controls, app export/backup features, Delete all local data, and Delete local AI model. Local backups or exported files are your responsibility after you save or share them outside the app.

3. Information That May Leave The Device

MindFlash may share or process limited technical information through active third-party providers. You can read their respective privacy practices using the links below:

- Firebase Crashlytics: May process crash logs, device model, OS version, app version, installation identifiers, and diagnostic metadata. (Firebase Privacy Information: https://firebase.google.com/support/privacy)
- Firebase App Check: May process app/device integrity signals to prevent abuse. (Google Privacy Policy: https://policies.google.com/privacy)
- Google Play Services: May process platform and install/update signals. (Google Privacy Policy: https://policies.google.com/privacy)
- Model-Download Host: May receive ordinary download request metadata when you download or redownload a local AI model.
- Support & Feedback: If you contact support or intentionally report AI output, you may send the message, attachments, generated output, prompt context, email address, and technical details needed to respond or investigate.

4. Legal Basis for Processing (EEA/UK Users)

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), we process your technical and diagnostic information under the following legal bases of the General Data Protection Regulation (GDPR):

- Legitimate Interests: We process technical data for crash diagnostics (Firebase Crashlytics) and app integrity checks (Firebase App Check) under our legitimate interests to maintain a secure, stable, and sustainable free app.
- Performance of a Contract: When you contact support or report safety issues, we process your email and messages to fulfill your support request.

5. How Information Is Used

MindFlash uses information to:

- Provide local study, review, note-taking, import/export, and local AI features.
- Save app preferences and local model state.
- Diagnose crashes, protect app integrity, and improve reliability.
- Respond to support, copyright, privacy, and AI safety reports.
- Comply with Google Play Data Safety, AI-generated content, and legal obligations.

6. AI Processing

Local AI features run on supported Android devices after the user downloads a compatible local model. Generated study content can be wrong, incomplete, biased, or unsuitable, and you are responsible for reviewing it before relying on it.

Ordinary local AI generation does not send notes, decks, cards, files, or prompts to remote AI providers. If a future remote AI feature is introduced, it must be opt-in and separately disclosed before use.

7. Retention and Deletion

- Local Data: App-managed local study data and local AI model files remain on your device until you use the "Delete all local data" and "Delete local AI model" options, clear app storage, or uninstall the app.
- Support & Safety Reports: Any support emails or AI safety reports you intentionally submit are retained only for as long as necessary to address your request or safety concern (typically up to 1 year) or as legally required.
- Third-Party Data: Firebase and other providers retain technical logs under their respective data retention policies.

8. Your Regional Privacy Rights (GDPR & US States)

Depending on your location (such as the EEA, UK, or US states like California), you have rights regarding your personal information, including:
- Right to Access/Know: Know what information leaves the device and access it.
- Right to Delete: Request deletion of your support communications or clear local data.
- Right to Correct: Correct inaccurate information in support requests.
- Right to Opt-Out: MindFlash does not sell personal data for money. You can manage notification and personalization controls through your device settings.

You can also manage notifications through your device settings.

To exercise any of these rights, contact us at mindflash.ai.support@gmail.com.

9. Security

MindFlash uses local app storage, platform security features, HTTPS for provider connections, App Check where applicable, and operational safeguards. No app can guarantee perfect security, especially after users export or share local files.

10. International Processing

Firebase Crashlytics, Google Play services, model hosts, and support tools may process technical or support data in regions where they operate (including the United States).

11. Contact

For privacy, deletion, access, correction, copyright, AI safety, or support questions, contact mindflash.ai.support@gmail.com.