MINDFOCUS · PUBLIC INFORMATION
Privacy policy
Last updated: 18/07/2026
1. Scope
This policy describes how MindFocus collects, uses, and protects data when you visit the website, create an account, create or save a community deck, study vocabulary, upgrade to Pro/B2B, or request support.
2. Data we collect
- Account data: email, internal username, display name, password hash, optional country, account type, role, language, and theme.
- User-created content: deck names, descriptions, vocabulary, meanings, pronunciation, context, and Public/Teacher/Share settings.
- Community data: deck ID, author, clone provenance, and whether an account has saved a source deck.
- Learning data: sessions, rounds, CORRECT/WRONG/SKIP/REPAIR, answer length, stage, scheduling reason, and aggregate statistics. Version 0.1.6 does not use response time to judge memory.
- Operational data: page views, aggregate active time, social-link clicks, and completed sessions.
- Technical/abuse-prevention data: IPs in server logs; HMAC hashes of IP, a random device identifier, and User-Agent; session cookies and access times.
- Payment data: order code, plan, B2B contact email, amount, status, and transaction reference when a banking webhook is connected. MindFocus never asks for online-banking passwords or OTP codes.
3. How data is used
Data supports learning, Community, saved progress, statistics, account security, spam prevention, customer support, payments, and product improvement. Developer access is never granted from a display name alone.
4. Community decks
When Share is enabled, the author's display name, deck name/description, and learning content may appear in Community. Saving creates an independent snapshot with attribution. Removing the source from Community does not automatically delete snapshots already saved by other users.
5. Excel files
Excel files are read to extract content and are not retained as personal documents on the server. Extracted rows enter the database only after the user confirms deck creation or update.
6. Cookies, analytics, and advertising
MindFocus uses essential cookies for login, CSRF, language, theme, and a random device identifier used to deter mass registration. Internal analytics records MindFocus operational events without requiring a third-party advertising identifier. Future Google AdSense code will load only after the required configuration and consent process are enabled.
7. Data sharing
MindFocus does not sell personal data. Data may be shared with infrastructure, payment, and abuse-prevention providers, or competent authorities where necessary to operate the service or comply with law.
8. Storage and security
Passwords are one-way hashed. Ownership and edit rights are checked by the backend. The system uses CSRF protection, rate limiting, ORM, secure-cookie controls, and browser security headers. Technical hashes are pseudonymous rather than absolutely anonymous. No system is perfectly secure; MindFocus will respond to incidents and provide notices where legally required.
9. Your choices
You may request access, correction, or deletion by emailing mindfocus.support@gmail.com from the registered address. See Account and data deletion.
10. Young users and contact
Where a user is not old enough to consent under local law, a parent or guardian should review use of the service. Do not place sensitive personal data in display names or community decks. Privacy questions: mindfocus.support@gmail.com.