MindDeserves← Back to site

Privacy Policy

Last updated: July 2026

1. Who we are

MindDeserves ("we", "us") is a mental-health software platform. We provide standardised assessment and screening tools, non-clinical wellbeing support, and the infrastructure through which independent licensed professionals, schools, and organisations deliver their own services. For any question about your data or this policy, contact us at [email protected].

For your personal account and use of the platform, we are the data controller of your data. Where a licensed professional, healthcare organisation, or school uses MindDeserves to serve their own patients or students, that professional or organisation is the controller of the care they deliver, and we additionally act as their data processor (or, for US healthcare organisations covered by HIPAA, their business associate) under a signed agreement.

2. What we collect

Account information: name, email address, phone number, date of birth, gender, country, and (for professionals) qualifications and registration details.

Health information: your responses to clinical assessments and their scores, performance data from game-based cognitive assessments, clinical notes and case history written by your professional, prescriptions, appointment and video-session records, and safety-relevant responses (see Section 4). This is sensitive health data and receives our strongest protections, including strong, industry-standard encryption in transit and at rest.

Guardian and child information: where a parent or guardian creates or consents to an account for a person under 18, we record the guardian's identity, the relationship, and the consent itself.

Payment information: we issue invoices and you pay them by bank transfer to the account printed on the invoice; we record the invoice, the amount and the payment reference. We never see or store card numbers or online-banking credentials. If we introduce a card payment provider we will name it here first.

Technical information: login times, IP address, and security logs. We do not use advertising trackers or analytics cookies, the only cookies we set are the essential, httpOnly session cookies that keep you signed in.

Anonymous screening: the free public screening tools can be used without an account. Those responses are scored in memory and are not stored at all.

3. How we use your data

  • To deliver the service: administer and score assessments, generate reports, schedule appointments, host video consultations, and maintain your health record.
  • To share your results and records with the professional(s) treating you (Section 5).
  • To protect your safety (Section 4).
  • To send service notifications (appointment reminders, assessment assignments, results availability).
  • To bill for services, issue tax invoices, and meet our accounting and tax obligations.
  • To build assessment norms: we use de-identified, aggregated assessment and game-performance statistics to calibrate scoring norms. This data cannot be linked back to you and is never shared in identifiable form.
  • To secure the platform: access control, audit logging, and abuse prevention.

Where GDPR applies, our legal bases are: performance of our contract with you (service delivery and billing), your explicit consent for processing health data (Article 9(2)(a), collected at registration and withdrawable at any time), our legitimate interests (security, de-identified norming), and legal obligation (tax records, safety duties).

We do not sell your data. We do not use your health data for advertising. We do not use your data to train third-party AI models.

4. Safety: an important limit on confidentiality

If your answers to certain assessment questions indicate a risk of serious harm to yourself or others (for example, questions about suicidal thoughts or plans), the platform automatically alerts your treating professional, or, if you have no assigned professional, the platform's clinical safety team, so that a human can follow up with you. This is a deliberate safety feature, and by using the clinical assessments you accept this limited disclosure. Professionals may also have legal duties in their jurisdiction to act on risk of harm, abuse, or court orders.

5. Who we share data with

  • Your professional(s): the provider(s) you are connected with see your assessment results, records, and safety alerts.
  • Your guardian: for users under 18, the consenting guardian can access results as permitted by law.
  • Your school or organisation: sees only anonymous, aggregated statistics. An organisation is shown an individual student's clinical results only when the student's guardian has explicitly granted consent through the platform, and that consent can be withdrawn at any time.
  • The categories of service providers (sub-processors) who process data on our behalf under contract:
Sub-processorPurposeData involvedLawful basisProcessing location
Oracle Cloud Infrastructure (oracle.com)Cloud hosting & infrastructure: runs the platform and stores data securelyAll platform data (encrypted at rest)Performance of contractIndia (Hyderabad region)
Cloudflare (cloudflare.com)Content delivery, security filtering, and encrypted backup storageNetwork traffic (in transit); encrypted backup archivesPerformance of contract / legitimate interest (security)Global edge network; backups in Asia-Pacific region
LiveKit (livekit.io)Video infrastructure: powers live video consultationsReal-time audio/video (encrypted in transit; not recorded or stored)Performance of contractGlobal edge (transit only)
Our banking providers (the account named on your invoice)Receiving bank-transfer payments against invoicesPayer name, amount and payment reference as shown on your bank transferPerformance of contractIndia, United States, United Kingdom (depending on the invoice currency)
Google Firebase (firebase.google.com)Authentication: secure sign-in (Google, phone)Authentication identifiersPerformance of contractUnited States
Resend (resend.com)Email delivery: account and notification emailsEmail address and message content; our emails contain no health resultsPerformance of contractEuropean Union (Ireland) / United Kingdom

Questions about our sub-processors can be sent to [email protected]. Organisation customers additionally receive this list in the data processing agreement we sign with them, and are notified of changes to it.

  • Legal requirements: we disclose data where required by law, court order, or to protect life, and we document every such disclosure.

6. International transfers

We operate internationally, so your data may be processed or stored in countries other than your own. Where data of UK or EU users is transferred outside their jurisdiction, we rely on the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses respectively, together with the encryption measures described above. Organisation customers receive these as part of our data processing agreement.

If we relocate our hosting infrastructure to a different country, or change the countries from which our staff or sub-processors can access customer data, we will notify organisation customers in advance of the change taking effect.

7. Security

  • Your data is encrypted both in transit and at rest using strong, industry-standard encryption.
  • Access is restricted by role-based permissions; professionals can only access patients they have an active care relationship with.
  • Every access to health data is recorded in an audit log.
  • Backups are encrypted and stored securely off-site.

8. Retention

  • Health records: retained for 7 years after your last activity, in line with medical record-keeping requirements, then deleted.
  • Account deletion: you can request deletion at any time from your privacy settings. After a 30-day grace period (during which you can cancel the request), your personal data is erased. Access-audit logs and tax/invoice records are retained where the law requires it, with your identifiers removed wherever possible.
  • Backups: encrypted backups are retained for up to 30 days on a rolling basis, plus a small number of encrypted archival snapshots (monthly copies kept for 12 months, and yearly copies kept for the legally required record-keeping period) maintained solely for disaster recovery and data-integrity purposes. Data erased from the live system leaves rolling backups within 30 days and archival snapshots as they rotate.
  • Anonymous screening: never stored.

9. Your rights

Depending on where you live (UK GDPR, EU GDPR, and other applicable data-protection laws), you have the right to:

  • Access your data and receive a copy (available self-serve in your privacy settings);
  • Correct inaccurate information;
  • Delete your account and data (self-serve, with the grace period above);
  • Export your data in a portable format (self-serve);
  • Object to or restrict certain processing, and withdraw consent at any time without affecting prior processing;
  • Complain to your supervisory authority, the ICO (UK) or your national data protection authority (EU).

To exercise any right that isn't self-serve, contact us at [email protected]. We respond within the timelines required by your jurisdiction (one month under GDPR).

If you are a US resident, you have the rights granted by any applicable US state privacy law, including to know what personal information we hold and to access, correct, or delete it, which you can exercise the same way. We do not sell your personal information.

10. Children

Users under 18 may only use MindDeserves with verifiable parent/guardian consent, recorded on the platform. School screening programmes additionally require guardian consent before any individual result is shown to the school. Guardians can withdraw consent at any time, which immediately stops the associated disclosure.

11. Breach notification

If a data breach affects your personal data, we will notify the relevant authorities and affected users within the timelines required by applicable law: for example, within 72 hours to the supervisory authority under GDPR, and, for US users of our consumer health tools, to affected individuals and the US Federal Trade Commission as required by the Health Breach Notification Rule. Our notice explains what happened, what data was involved, and what we are doing about it.

12. Changes

We will post any changes to this policy here and update the date above. For material changes affecting health data, we will notify you in the app or by email before they take effect.

13. Contact

Privacy & data protection: [email protected]
General support: [email protected]