1. Who we are
MindWell is an AI support companion built by a team of students in India as an academic project. It is not a medical device and does not provide diagnosis, treatment or medication advice. In this policy, "we" means the MindWell project team, and "you" means anyone who uses the website or the app.
We act as the "Data Fiduciary" for the personal data described here, in the sense of India's Digital Personal Data Protection Act, 2023 (DPDP Act). Your use of MindWell is also covered by our Terms of use.
2. What we collect
We only store what the app needs to work for you. Free text that could reveal something personal is encrypted before it is saved.
| Data | Why | Stored as |
|---|---|---|
| Anonymous account ID, a fingerprint (hash) of your access token, account creation date | To keep your conversations separate from everyone else's | Plain (contains nothing about you) |
| Country and language you choose; consent date | To show the right helplines and reply in your language | Plain |
| Your messages and MindWell's replies | To continue the conversation and give relevant support | Encrypted |
| Text read from files you share (screenshots, chats, documents, voice notes) | To understand what you shared. The original file is discarded right away | Encrypted |
| Mood notes, journal entries, safety plan, self-check answers (PHQ-9, GAD-7) | Your own wellbeing tools | Encrypted (scores stored plain, so trends can be shown) |
| Labels the app works out: emotional state (e.g. "worrying thoughts"), risk level, exercises tried and how helpful you rated them | To choose how to respond, keep you safe within a conversation, and remember what helped | Plain labels, no message text |
| Your answers to "did I read you right?" | To improve how the app recognises feelings (only the label, never your words) | Plain |
| Count of AI replies used today | To apply the fair daily limit | Plain, deleted after 7 days |
| Optional: typing rhythm and speaking speed summary (off by default) | Only if you switch it on, to gently notice when you may be tense | Plain numbers, never keystrokes or audio |
3. What we don't collect
- Your name, email address, phone number, photos of you, contacts or precise location.
- The files you upload. Only the extracted text is kept; the file itself is deleted immediately.
- Voice recordings. Voice notes are turned into text and the audio is not stored.
- Advertising or analytics trackers. There are none on the website or in the app.
4. How we use your data
- To support you: write replies, offer exercises, and show your history, moods and journal back to you.
- To keep you safe: check messages for signs of risk and show helplines when needed. These checks are automatic.
- To keep the service running and fair: rate limits, the daily AI limit, and preventing abuse.
- To improve MindWell: only with anonymous labels and counts (for example, how often the emotion reading was right). We do not use your conversations to train AI models, and nobody on the team reads your chats.
We never sell your data, share it for advertising, or use it to build a profile of you for anyone else.
5. AI providers
MindWell uses third-party AI services to understand your messages and write replies. When the AI is online, your latest message, recent conversation history, and some context (your chosen language, the app's reading of your mood, relevant tips, and the text of files you shared in that conversation) are sent to one of these providers:
- Groq (main chat models, voice-note transcription, and an automatic check for attempts to misuse the AI). Groq's privacy policy.
- Google Gemini (Hindi and Kannada conversations, reading photos and screenshots, and as a backup). Gemini API terms and Google's privacy policy.
These providers process data on their own servers, which may be outside India. MindWell uses their free tiers. Under some free-tier terms a provider may keep submitted content for a period and use it to improve its services, possibly including review by people. Please read their terms, and avoid sharing details that identify you or others (full names, phone numbers, addresses).
If you add your own Gemini API key in Settings, it is kept in your browser and sent with your requests so they run on your own key. We do not store it on our server.
When the AI is unavailable, or after your daily AI limit, MindWell replies from its built-in offline engine, which runs entirely on our server. A short automatic safety check may still use an AI provider.
6. Other services
- Fonts and libraries: the website loads fonts from Google Fonts, and the app loads a few open-source libraries from public content networks (unpkg and jsDelivr). Like any website, these services can see your IP address when your browser downloads the files.
- Hosting: MindWell runs on a cloud server rented by the project team. The hosting provider stores the server's disks, including the encrypted database; the encryption key is managed by the project team.
7. Security
- Personal free text is encrypted at rest (Fernet: AES with an integrity check). The key is kept separately from the database on the server.
- Connections to MindWell use HTTPS.
- Your access token is never stored on the server, only a one-way fingerprint of it. Every request is checked so one account can never read another's data.
- The site sends strict security headers and allows no third-party trackers.
To be honest about the limits: this is not end-to-end encryption. The server has to decrypt your messages to reply to you and to send them to the AI provider. Anyone who has your device and your browser's saved access token can open your conversations, so use the Exit button or a private window on shared devices.
The server's technical logs may briefly record IP addresses and request times, for security and troubleshooting. They are not linked to your conversations and are cleared regularly.
8. How long we keep it
Your data stays until you delete it. There is currently no automatic expiry, so if you stop using MindWell and want your data gone, please delete it from Settings first. The daily AI-use counter is deleted after 7 days. Temporary rate-limit information is kept only in memory and disappears within a day.
If the project ends, we will delete the database and the encryption key.
9. Your rights
Under the DPDP Act, 2023, you have the right to:
- Access a summary of your data: Settings → Download my data gives you a full copy.
- Correct it: change your country, language and other preferences any time in Settings.
- Erase it: Settings → Delete everything permanently removes your account and all conversations, moods, journal entries, plans and files. This cannot be undone.
- Withdraw consent: stop using MindWell and delete your data. Optional features, like typing rhythm, can be switched off at any time.
- Raise a grievance: contact us using the details below, and you may approach the Data Protection Board of India if you're not satisfied.
Because accounts are anonymous, we can't identify you by name. Requests are handled from inside the app, where your device proves which account is yours.
10. Safety and emergencies
If something you write suggests you or someone else may be in danger, MindWell shows crisis helplines and checks in with you. We do not monitor conversations in real time, we do not contact anyone on your behalf, and we do not share your data with family, your college, or the police. We would only disclose data if required by Indian law, and even then only what we actually hold, which cannot identify you by name.
If you are in immediate danger, call 112, or Tele-MANAS on 14416 (free, 24/7).
11. Age
MindWell is designed for college students aged 18 and over. If you are under 18, please use it only with the knowledge of a parent, guardian or another adult you trust. We do not knowingly collect data from children for any purpose other than providing support.
12. On your device
MindWell does not use tracking cookies. Your browser's local storage keeps your anonymous access token, your language, theme and text-size choices, and your own API key if you add one. Installing MindWell as an app stores the app's files and a public list of helplines so the emergency page works offline. Clearing your browser data removes all of this from your device (but not from our server; use Delete everything for that).
13. Changes to this policy
If we change how we handle data, we'll update this page and its effective date. For any significant change, such as a new AI provider, we'll also show a notice in the app.
14. Contact
Questions, requests or complaints about privacy: [project contact email]. We aim to reply within 7 days.
MindWell is a student project. If you represent an institution and want to deploy it, please contact us first: a real deployment needs clinical oversight and ethics approval.