Back to home

Privacy Policy

Last updated: September 7, 2026

Your wellness data belongs to you. This policy explains, in plain language, what MindMate collects, how it is protected, who can see it, and the control you have over it.

1. Who we are and what this policy covers

MindMate ("MindMate", "we", "us") operates the MindMate wellness platform, including the website, web and mobile apps, AI chat companion, wellness check-ins, coping toolkit, therapist directory, and the dashboards used by therapists, schools, workplaces, and crisis / emergency teams (together, the "Service").

This Privacy Policy explains what information we collect, how we use it, who can see it, and the choices you have. It applies to everyone who uses the Service: individuals, students, employees, licensed clinicians, institution and enterprise administrators, and crisis team members.

2. Information we collect

We collect only what is needed to run the Service and keep you safe.

  • Account information: name, email address, password (hashed), language, appearance preferences, and the role(s) you hold on the platform.
  • Wellness data you enter: check-ins across mood, stress, sleep, energy, motivation, and connection; journal entries; coping tool usage; goals and streaks; wellness plans; small wins.
  • Conversations: messages you send to the AI chat companion and secure messages exchanged with linked therapists or crisis teams.
  • Clinical and safety data: safety-check answers, risk levels, crisis alerts, therapist notes, session notes, assignments, shared resources, and clinical reports generated for your care team.
  • Care connections: join codes you enter, the therapists, schools, workplaces, or crisis teams you link to, and your emergency / trusted contacts and outpatient providers.
  • Professional verification (clinicians, school and enterprise administrators): license or employment documents, photo ID, headshot, and practice details, stored in private storage and visible only to MindMate administrators.
  • Billing information: plan, seats, and order identifiers. Card details are handled by our payment processor and are never stored by MindMate.
  • Support and usage data: support tickets, device and browser type, pages visited, and estimated AI usage so we can enforce fair-use limits.

3. How we use your information

We use information to:

  • Provide the Service, including personalized insights, the MEII™ wellness score, tool and goal suggestions, and wellness plans.
  • Power the AI chat companion and generate clinical summaries or reports. AI features run on our servers through approved model providers; prompts are limited to what the feature needs and are never used to train third-party models.
  • Detect risk. When language or check-in patterns suggest someone may be in crisis, we may run a safety check and notify the care team you have linked, in this order: your emergency contacts, outpatient providers, your assigned therapist, and any crisis team linked to your account.
  • Send reminders and notifications you have turned on, such as check-in nudges, plan reminders, appointment updates, and announcements.
  • Verify professional credentials, manage billing, respond to support requests, and keep the platform secure.
  • Produce aggregated, de-identified analytics for schools and workplaces.

4. Who can see your data

Your wellness data is private by default. No therapist, school, workplace, or crisis team can see anything about you unless you link them yourself using a join code, or a clinician you are already linked to assigns a crisis team to your care.

  • Therapists you link see your check-ins, trends, wellness orb, goals, assignments, shared resources, secure messages, safety assessments, and crisis alerts.
  • Crisis / emergency teams linked to your account see crisis alerts, safety-check responses, escalation history, and can message your therapist about your care. They do not see your journal or general chat history.
  • Schools and workplaces see aggregated, cohort-level trends and risk distribution. Individual student or employee data is shown only with privacy safeguards and never includes journal entries or chat transcripts.
  • MindMate administrators can access records to verify professionals, respond to support tickets, investigate safety events, and maintain the platform. Access is logged and restricted to what is necessary.
  • Service providers who host, email, process payments, or run AI models for us, under contracts that restrict their use of your data.
  • Authorities, when required by law or to prevent imminent harm to you or someone else.

5. We never sell your data

MindMate does not sell, rent, or trade personal information, and we do not show advertising based on your wellness data. Formal wellness reports shared with clinicians contain aggregated clinical insights only and never include raw chat transcripts.

6. Security

Data is encrypted in transit and at rest. Every record is protected by row-level access rules so users only see records they own or are explicitly linked to. All AI calls run server-side behind access checks, sensitive documents live in private storage accessible only through short-lived signed links, and the app is protected against embedding in other sites. No system is perfectly secure, so please use a strong, unique password.

7. HIPAA, FERPA, and other laws

When MindMate handles protected health information on behalf of a covered entity such as a licensed therapist, we act as a business associate and apply HIPAA safeguards. When we handle student education records on behalf of a school, we follow FERPA requirements and act only on the school's instructions. Where state or international privacy laws (for example GDPR or CCPA) apply, you have the rights described in the "Your choices" section below.

8. Children and students

MindMate is designed for people aged 13 and older. Students under 18 use MindMate through a school program or with a parent or guardian's consent. We do not knowingly collect data from children under 13; if you believe a child has created an account, contact us and we will delete it.

9. Data retention

We keep your data while your account is active. If you delete your account from Settings, your personal wellness data, conversations, and links to care teams are deleted. Clinical records that a licensed therapist or crisis team is legally required to retain may be kept by them in de-identified or archived form. Demo data created in Demo Mode is removed automatically when the demo ends.

10. Your choices and rights

  • Access, correct, export, or delete your data from Settings, or by contacting support.
  • Unlink a therapist, school, workplace, or crisis team at any time from My Therapist or Settings.
  • Turn reminders and notifications on or off in Settings.
  • Use Simple Reading Mode, dark mode, and 13 languages without affecting your privacy.
  • Request a copy of your data or object to processing where local law gives you that right.

11. Changes to this policy

We may update this policy as the Service evolves. We will post the new version here with a new "last updated" date and, for material changes, notify you in the app.

12. Contact

Questions about privacy? Open a ticket from Support & Tutorial inside the app, or use the Support page linked in the footer. If you are in crisis, do not use support channels: call or text 988 (US) or your local emergency number.