DRAFT — This document requires review by legal counsel before being linked from the live application.
Privacy Policy
Effective: March 2026
Myndura is operated by Mynda Tech Solutions ("we", "us", or "our"). This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data when you use Myndura ("the Platform").
By creating an account or using the Platform, you agree to the practices described in this policy.
1. Who We Are
Myndura is an interactive psychiatric education platform designed for mental health professionals and trainees. It is operated by Mynda Tech Solutions.
If you have questions about this policy, contact us at privacy@myndura.com.
2. Data We Collect
2.1 Account Data
When you register, we collect:
- Email address
- Display name
This data is managed through Firebase Authentication (Google Cloud).
2.2 Profile Data
During onboarding and via your profile settings, we collect:
- Professional role (e.g., psychiatry resident, consultant, medical student)
- Learning goals
- Preferred learning domains
This data is used to personalise your experience.
2.3 Learning Data
As you use the Platform, we record:
- Lab progress and completion status
- Practice quiz scores
- Streak data (daily activity)
- Spaced Repetition System (SRS) scheduling data (due dates, ease factors, review history)
- Knowledge map mastery levels per domain
This data is core to the Platform's function and is stored in Firebase Cloud Firestore.
2.4 AI Tutor Conversation Data
When you interact with the AI tutor, your messages and the tutor's responses are:
- Transmitted to Anthropic's Claude API for processing and response generation
- Stored in your session as conversation context
See Section 5 (AI Tutor) and Section 4 (Third-Party Services) for important details.
2.5 Usage and Analytics Data
We collect aggregate usage data through Firebase Analytics, including:
- Page views and feature usage
- Session duration
- Navigation patterns
2.6 Device Data
Firebase Analytics automatically collects:
- Browser type and version
- Screen size and resolution
- Operating system
This data is used in aggregate form to improve platform performance and compatibility.
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Personalise learning content and recommendations | Profile data, learning history |
| Schedule spaced repetition reviews | SRS data, practice scores |
| Display knowledge map and mastery progress | Lab progress, mastery levels |
| Generate AI tutor responses | Conversation messages (sent to Anthropic) |
| Improve content quality and platform features | Aggregate usage analytics |
| Authenticate your account and maintain sessions | Account data, Firebase session cookies |
We do not sell your personal data to third parties. We do not use your data for advertising.
4. Third-Party Services
4.1 Firebase (Google Cloud)
We use Firebase for authentication, data storage, analytics, and hosting. Your data is stored on Google Cloud infrastructure. Google's privacy policy applies to Firebase services: https://policies.google.com/privacy
4.2 Anthropic Claude API
The AI tutor feature transmits your conversation messages to Anthropic's Claude API to generate educational responses. This means:
- Your AI tutor messages leave our servers and are processed by Anthropic
- Anthropic's data practices apply to data transmitted to their API: https://www.anthropic.com/privacy
- We do not control how Anthropic processes or retains API request data on their infrastructure
You must not enter any real patient data, identifiable clinical information, or sensitive personal information into the AI tutor. The AI tutor is for educational purposes only. See Section 5 for full details.
5. AI Tutor — Important Notice
The AI tutor is an educational tool. The following rules apply:
- Do not enter real patient information. The AI tutor must not be used to process, discuss, or store information about real patients. This is a strict requirement.
- Educational context only. The tutor is designed to support learning about psychiatric concepts, not to provide clinical advice or substitute for clinical judgment.
- Conversations are transmitted to Anthropic. Every message you send to the AI tutor is sent to Anthropic's servers for processing. Anthropic may process and retain this data in accordance with their own privacy policy.
- No clinical reliance. The AI tutor's responses should never be used as the basis for clinical decisions.
6. Data Storage and Retention
Your data is stored on Google Cloud (Firebase) servers.
- Data is retained for as long as your account is active.
- If you delete your account, we will delete your personal data within 30 days of receiving your deletion request.
- Aggregate, anonymised analytics data may be retained beyond this period as it cannot be linked to individuals.
To request account deletion, contact privacy@myndura.com.
7. Cookies and Local Storage
Cookies
We use Firebase session cookies to maintain your authenticated session. These are essential for the Platform to function. We do not use third-party advertising or tracking cookies.
Local Storage
Your browser's local storage may be used for:
- Theme preference (light/dark mode)
- Offline caching of content to improve performance
You can clear local storage at any time via your browser settings. This will log you out and reset any locally cached preferences.
8. Your Rights
You have the following rights regarding your personal data:
| Right | How to Exercise |
|---|---|
| Account deletion | Request via privacy@myndura.com or through in-app account settings |
| Data export | Request a copy of your data by emailing privacy@myndura.com |
| Correction | Update profile and account data directly in the app, or contact us |
| Opt-out of analytics | Contact privacy@myndura.com to opt out of Firebase Analytics |
We will respond to rights requests within 30 days.
Depending on your jurisdiction, additional rights may apply (e.g., GDPR rights for users in the European Economic Area). Contact us to exercise any rights not listed here.
9. Children
Myndura is not intended for users under the age of 18. The Platform is designed for medical and mental health professionals and trainees, who are expected to be adults.
We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact us at privacy@myndura.com and we will delete the account promptly.
10. Security
We take reasonable measures to protect your data:
- All data in transit is encrypted via HTTPS/TLS
- Firebase Security Rules restrict access so users can only access their own data
- Passwords are never stored in plain text — authentication is handled entirely by Firebase Authentication
- Access to production systems is restricted to authorised team members
No system is completely secure. If you believe your account has been compromised, contact us immediately at privacy@myndura.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users by email using the address associated with their account.
The "Effective" date at the top of this document reflects when the current version took effect. We encourage you to review this policy periodically.
12. Contact
For privacy-related questions, data requests, or concerns:
Email: privacy@myndura.com
We aim to respond to all enquiries within 5 business days.
Myndura is operated by Mynda Tech Solutions.