ClearMind AI Logo

    Privacy Policy

    Last Updated: January 7, 2025

    This Privacy Policy describes how ClearMind AI ("we," "us," or "our") collects, uses, and protects your information when you use our AI-powered business planning platform and services.

    1. Information We Collect

    Personal Information

    When you create an account or use our services, we may collect the following personal information:

    • Name and email address
    • Company name and business information
    • Payment and billing information (processed securely through Stripe)
    • Communication preferences and account settings

    Business Information

    • Business ideas, plans, and strategic information you input
    • Financial projections and market research data
    • Generated business plans and documents
    • AI chat conversations and coaching sessions

    Technical Information

    • Device information, browser type, and operating system
    • IP address and general location information
    • Usage patterns, feature interactions, and session data
    • Cookies and similar tracking technologies

    2. How We Use Your Information

    Primary Uses

    • Generate personalized business plans and strategic documents
    • Provide AI-powered coaching and business guidance
    • Process payments and manage your subscription
    • Communicate with you about your account and our services
    • Provide customer support and technical assistance

    Service Improvement

    • Analyze usage patterns to improve our platform
    • Develop new features and enhance existing ones
    • Train and improve our AI models (using anonymized data)
    • Conduct research and analytics for business insights

    Legal and Security

    • Comply with legal obligations and regulatory requirements
    • Protect against fraud, abuse, and security threats
    • Enforce our terms of service and platform policies
    • Respond to legal requests and court orders

    3. AI Services and Data Processing

    Third-Party AI Providers

    We use third-party AI services to power our business planning features:

    • OpenAI: For advanced language processing and content generation
    • Anthropic (Claude): For business analysis and strategic planning
    • Google AI: For market research and data analysis

    Data Sharing with AI Providers

    • Business information is shared only for processing your requests
    • Data is transmitted securely and used solely for service provision
    • We do not retain copies of data sent to AI providers longer than necessary
    • AI providers may have their own data retention and privacy policies

    Data Protection Measures

    • All data transmissions are encrypted using industry-standard protocols
    • We implement access controls and authentication for AI service connections
    • Regular security audits and monitoring of data processing activities
    • Immediate deletion of sensitive data after processing completion

    4. Information Sharing and Disclosure

    We Do Not Sell Your Information

    We do not sell, rent, or trade your personal information or business data to third parties for marketing purposes.

    Limited Sharing Scenarios

    • AI Service Providers: As described above, for content generation
    • Payment Processing: Billing information with Stripe for subscription management
    • Legal Compliance: When required by law, court order, or legal process
    • Business Transfers: In case of merger, acquisition, or asset sale

    Anonymized Data Usage

    • We may use anonymized, aggregated data for research and analytics
    • No personally identifiable information is included in anonymized datasets
    • This data helps us improve our services and develop new features
    • You can opt out of anonymized data usage by contacting us

    5. Data Security

    Security Measures

    • End-to-end encryption for data transmission and storage
    • Regular security audits and penetration testing
    • Access controls and multi-factor authentication for our systems
    • Employee training on data protection and privacy practices
    • Incident response procedures for potential security breaches

    Data Storage

    • Data is stored on secure, encrypted servers hosted by Supabase
    • Regular backups and disaster recovery procedures
    • Geographic data replication for redundancy and performance
    • Compliance with industry-standard security certifications

    Breach Notification

    • Immediate investigation and containment of any security incidents
    • Notification to affected users within 72 hours of discovery
    • Coordination with law enforcement and regulatory authorities as required
    • Transparent communication about the nature and scope of any breach

    6. Your Rights and Choices

    Data Access and Control

    • Access: Request a copy of all personal data we have about you
    • Correction: Update or correct inaccurate personal information
    • Deletion: Request deletion of your personal data and account
    • Portability: Export your business plans and data in standard formats

    Communication Preferences

    • Opt out of marketing communications at any time
    • Customize notification settings in your account preferences
    • Unsubscribe from newsletters and promotional emails
    • Control frequency of product updates and announcements

    Account Management

    • Deactivate or delete your account through account settings
    • Control data sharing preferences for AI processing
    • Manage third-party integrations and data access
    • Set privacy preferences for collaboration features

    7. Cookies and Tracking Technologies

    Types of Cookies We Use

    • Essential Cookies: Required for basic platform functionality
    • Performance Cookies: Help us understand how you use our platform
    • Functional Cookies: Remember your preferences and settings
    • Analytics Cookies: Provide insights into user behavior and platform performance

    Third-Party Tracking

    • Google Analytics for website traffic and user behavior analysis
    • Payment processor cookies for secure transaction processing
    • Customer support tools for chat and help desk functionality
    • Social media plugins for content sharing features

    Managing Cookies

    • Control cookie preferences through your browser settings
    • Opt out of non-essential cookies through our cookie banner
    • Clear existing cookies and reset tracking preferences
    • Use private browsing mode to limit cookie storage

    8. Data Retention

    Retention Periods

    • Account Data: Retained while your account is active
    • Business Plans: Kept for the duration of your subscription plus 30 days
    • Payment Information: Retained for 7 years for tax and accounting purposes
    • Usage Logs: Deleted after 2 years unless needed for security or legal reasons

    Account Deletion

    • 30-day grace period after account deletion request
    • Permanent deletion of all personal data after grace period
    • Anonymization of any data used for analytics or research
    • Immediate cessation of all marketing communications

    Legal Holds

    • Data may be retained longer if subject to legal proceedings
    • Compliance with law enforcement requests and court orders
    • Protection of our legal rights and interests
    • Investigation of potential fraud or abuse

    9. International Data Transfers

    Data Processing Locations

    Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers.

    Transfer Safeguards

    • Standard Contractual Clauses (SCCs) with international partners
    • Adequacy decisions for transfers to countries with adequate protection
    • Binding Corporate Rules for intra-group transfers
    • Certification schemes and codes of conduct compliance

    Your Rights for International Transfers

    • Right to be informed about international transfers
    • Access to copies of transfer safeguards
    • Right to object to transfers in certain circumstances
    • Complaint rights with data protection authorities

    10. Children's Privacy

    Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16.

    Age Verification

    • Account registration requires age confirmation
    • Immediate deletion of accounts found to belong to minors
    • Parental notification procedures if minor accounts are discovered
    • Compliance with COPPA and similar international regulations

    Parental Rights

    • Parents can request deletion of their child's information
    • Right to review information collected from children
    • Ability to refuse further collection or use of child's information
    • Direct contact with our privacy team for child-related concerns

    11. Changes to This Privacy Policy

    Update Rights

    We reserve the right to update, modify, or change this Privacy Policy at any time without prior notice. Changes will be effective immediately upon posting on our website. Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.

    Update Process

    • Updated privacy policy will be posted on our website with revision date
    • Material changes may be communicated via email or platform notifications
    • Version history maintained for transparency when possible
    • Users are encouraged to review this policy periodically

    Your Options

    • Continue using our services under the updated policy
    • Contact us with questions about specific changes
    • Delete your account if you disagree with changes
    • Export your data before account deletion

    12. Intellectual Property Protection

    Whitelabeling Prohibition

    ⚠️ IMPORTANT LEGAL NOTICE

    Whitelabeling, rebranding, or unauthorized redistribution of ClearMind AI's platform, technology, or services is strictly prohibited.

    If we discover any whitelabeling or unauthorized use of our intellectual property, you will be held fully accountable for all damages, including but not limited to our lost revenue, time, effort, and business opportunities. We reserve the right to pursue all available legal remedies, including injunctive relief and monetary damages.

    Legal Enforcement

    • Immediate cease and desist actions for unauthorized use
    • Recovery of all damages, lost profits, and legal fees
    • Injunctive relief to prevent continued infringement
    • Criminal prosecution where applicable under intellectual property laws

    Monitoring and Detection

    • We actively monitor for unauthorized use of our technology
    • Regular audits and investigations of suspected violations
    • Cooperation with law enforcement agencies when necessary
    • Reward programs for reporting unauthorized use or whitelabeling

    13. Contact Us

    If you have questions about this Privacy Policy or our data practices, please contact us:

    Privacy Officer: privacy@clearmind-ai.com

    General Support: support@clearmind-ai.com

    Legal Matters: legal@clearmind-ai.com

    Address: ClearMind AI Privacy Team

    456 Business Boulevard

    Richmond, VA 23219

    Response Timeframes

    • Privacy inquiries: Within 3-5 business days
    • Data access requests: Within 30 days
    • Data deletion requests: Within 7 business days
    • Urgent privacy concerns: Within 24 hours
    • Legal matters: Within 5-7 business days