Privacy Policy

Last updated July 17, 2026. This policy explains what data ProjectMind collects, how it is used, and the choices you have.

1. Overview

ProjectMind (“ProjectMind”, “we”, “us”) provides a long-term memory and context layer for LLM applications. This Privacy Policy describes how we handle information when you use our website, application, API, and MCP (Model Context Protocol) server.

2. Information we collect

  • Account data. Email address and authentication credentials managed through our identity provider (Supabase Auth).
  • Content you store. Projects, buckets, tasks, notes, context files, repositories, teams, and any text or documents you send to ProjectMind through the app, API, or MCP tools.
  • API & MCP keys. Keys you generate to authenticate programmatic access. We store hashed or scoped representations needed to validate requests.
  • Usage & audit logs. Records of API/MCP calls, activity logs, and access events used for security, debugging, and the in-app audit trail.
  • Technical data. IP address, browser/client type, and timestamps associated with requests.

3. How we use information

  • Provide, operate, and maintain the service and its retrieval features.
  • Authenticate requests and enforce project- and tenant-level access control.
  • Generate embeddings and indexes so stored context can be searched and retrieved.
  • Maintain audit logs, detect abuse, and secure the platform.
  • Communicate service, security, and account notices.

4. Storage and security

Data is stored in managed Postgres (Supabase) with row-level security to isolate tenants, plus encryption in transit and at rest. Access to production data is limited to what is required to operate the service. If you self-host, your data remains on infrastructure you control.

5. Third-party services

We rely on service providers to deliver ProjectMind, including Supabase (authentication, database, storage) and LLM/embedding providers (such as OpenAI) used to process and index content you submit. Optional integrations you configure — such as Jira or Confluence sync — exchange data with those services on your behalf.

6. Data retention

We retain your content for as long as your account is active or as needed to provide the service. You can delete tasks, context, projects, and other content at any time; deleted content is removed from active systems and purged from backups on a rolling basis.

7. Your rights

You may access, correct, export, or delete your data through the app or by contacting us. Depending on your jurisdiction, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, additional notice.

9. Contact

Questions about this policy or your data? Contact us at privacy@projectm.dev.