LoveMindGrow

Privacy policy

Last updated October 7, 2026

LoveMindGrow is a journaling app. This policy explains which personal data it processes, why, where the data is stored, how long it is kept, and what you can ask of us. It describes the app as it works today. Before we add something new, such as AI reflections, we update this policy.

The short version

  • Your journal entries, moods and answers to the first questions are encrypted with a key that belongs to your account alone.
  • If you speak instead of typing, AssemblyAI turns your speech into text in its EU data centers and keeps neither the audio nor the text afterwards. We don’t keep the audio either.
  • Our server is in the USA and run by Hostinger. Our emails go out through Resend, and our mailbox is at Spaceship, both in the USA. The EU Standard Contractual Clauses cover these transfers.
  • We never use what you write to train AI models, and we never sell your data or use it for advertising.
  • No analytics, no ad trackers, no third-party cookies. The only cookie keeps you signed in.
  • You can delete any entry, download everything, withdraw your consent or delete your account at any time, in the app under Settings.

Who is responsible

The controller responsible for your data under the EU General Data Protection Regulation (GDPR) is:

Masiar IghaniAugenbroicher Str. 10453879 EuskirchenGermanyEmail: data@lovemindgrow.com

LoveMindGrow is run by this person as a sole trader. In this policy, “we” and “us” mean the operator named above. Write to this address with any question about your data or to use any of your rights.

What we process and why

We process only what the app needs. For each kind of data: what it is, what it’s for, the legal basis under the GDPR, and how long we keep it.

Your account

What
Your email address and password, whether you have confirmed the address, and when the account was created and last changed. The password is stored only as a salted hash (scrypt), so nobody can read it, us included.
Why
To create your account, sign you in and help you back in if you forget your password.
Legal basis
Our contract with you (Art. 6(1)(b) GDPR).
Kept
Until you delete your account.

Signing in

What
A cookie in your browser with a random session token, and on our server a matching session record: the token, your account ID, and when the session started, was last renewed and ends. We don’t store your IP address or browser with it. While the app is open, your browser also holds an access token with your email address; it expires after 15 minutes and is never saved on your device.
Why
To keep you signed in and make sure only you reach your journal.
Legal basis
Our contract with you (Art. 6(1)(b) GDPR). The cookie is strictly necessary for the service you asked for, so it needs no consent (§ 25(2) no. 2 TDDDG).
Kept
A session ends when you sign out or after about a week without use. Signing out deletes the session record; records of sessions that simply expired are deleted with your account.

Emails we send you

What
Your email address and the email itself. We send only what your account needs: a link to confirm your address when you sign up, a sign-in link when you ask for one, a link to choose a new password when you ask for one, and a short note if someone tries to sign up with an address that already has an account. Each link contains a code; sign-in and password links work only once. Our server stores the codes of sign-in and password links only as hashes, together with the email address you entered (sign-in links, also when there is no account for it) or your account ID (password links). Confirmation links are not stored. No newsletters or marketing, and nothing in our emails tracks whether you open them or click a link.
Why
To make sure the address is yours, to sign you in, and to let you reset a forgotten password.
Legal basis
Our contract with you (Art. 6(1)(b) GDPR); for the note about an existing account, our legitimate interest in keeping accounts secure (Art. 6(1)(f) GDPR).
Kept
Sign-in links expire after 10 minutes, the other links after an hour. Our server deletes a link’s code once the link is used; an expired code is deleted the next time someone opens a sign-in or password link. Our email service Resend keeps each email, with its link, and its delivery record for 30 days (see where your data is stored); by then the link no longer works.

Running the server safely

What
Your IP address, which your device sends with every request, as with any website. If something fails on our server, a technical error report.
Why
To deliver the app to your device, to slow down repeated sign-in attempts and email requests (protection against password guessing and floods of email), and to find and fix faults.
Legal basis
Our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR).
Kept
Your IP address is used only in the server’s working memory for these checks and never written to a database or log; our web server keeps no access logs. Error reports may contain your account ID or email address and, in rare cases, sign-in data such as a session token; they leave out what you write in your journal and your answers. They are overwritten automatically once newer reports fill their space (about 30 MB per service).

Your journal

What
The text of your entries, the mood you pick (optional), when each entry was created and last changed, and how often it was edited. What you write may include information about your health, which the GDPR protects as a special category of data (Art. 9 GDPR).
Why
To save your journal and show it back to you. No feature analyzes your entries yet; before one does, we update this policy and tell you in the app.
Legal basis
Your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), given on the “Before we start” screen. You can withdraw it at any time.
Kept
Until you delete the entry, withdraw your consent or delete your account. A deleted entry is removed from our database immediately.

When you speak instead of typing

What
When you choose “Speak instead”: the audio of what you say while the microphone is on, and the text made from it, which becomes your entry or answer. What you say may include information about your health (Art. 9 GDPR).
Why
To turn what you say into text while you speak.
Legal basis
Your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), given on the “Before we start” screen. You can withdraw it at any time.
Kept
The text is kept like typed text (see “Your journal” and “Your answers to the first questions”). The audio is not stored: your browser holds at most the last minute in memory, to send it again if the connection drops, and discards it when you stop. AssemblyAI, which makes the text, keeps neither the audio nor the text once it has sent the text back (see “Where your data is stored”).

Your answers to the first questions

What
What you tell us after sign-up: what to call you, your life right now, what brings you here, how life is going and what weighs on you most, what you want to be different in three months, how much you journaled before, how the app should talk with you, and whether and when you want a daily reminder, with your time zone. We also store when you finished the questions and when your answers last changed. You can skip every question. Your answers may include information about your health (Art. 9 GDPR).
Why
To choose the guide the app suggests first, how it talks with you, and when it reminds you. No feature uses your answers yet; before one does, we update this policy and tell you in the app.
Legal basis
Your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), given on the “Before we start” screen. You can withdraw it at any time.
Kept
Until you withdraw your consent or delete your account.

When you download or import your data

What
When you choose “Download everything”, we put your entries, your answers, your consent record and your email address into one ZIP file at that moment and send it to your browser. When you import a file (a LoveMindGrow export, or an export from the journaling app Mindsera), we read it in memory and save its entries like ones you write, skipping entries that are already in your account, and its answers only for questions you haven’t answered yet. From a Mindsera export we take your text and Mindsera’s questions to you; we leave out Mindsera’s summaries and analyses.
Why
So you can take your data with you (Art. 20 GDPR) and bring your journal from another app.
Legal basis
Download: our legal obligation to give you your data (Art. 6(1)(c) with Art. 15 and 20 GDPR). Import: your explicit consent, as for your journal (Art. 9(2)(a) and Art. 6(1)(a) GDPR); you can withdraw it at any time.
Kept
We keep neither the download nor the uploaded file. What you import is kept like your journal and your answers.

Your consent record

What
That you agreed, which version of the consent text you agreed to, and when.
Why
We have to be able to show that you consented (Art. 7(1) GDPR).
Legal basis
Our legal obligation (Art. 6(1)(c) GDPR).
Kept
Until you withdraw your consent or delete your account.

When you email us

What
Your email address, your message and our reply.
Why
To answer you and carry out your request.
Legal basis
Our contract with you, or our legal obligation for requests about your rights (Art. 6(1)(b) and (c) GDPR); for other messages, our legitimate interest in answering (Art. 6(1)(f) GDPR).
Kept
Until your request is settled, unless the law requires us to keep it longer. Copies can remain in our mail provider’s backups for up to four more weeks.

What we don’t do

  • We never use your entries or answers to train AI models, ours or anyone else’s.
  • We don’t sell your data, share it for advertising or build ad profiles.
  • We use no analytics or tracking tools, no third-party cookies and no social media plug-ins.
  • Fonts come from our own server, so your browser contacts no font service such as Google Fonts.
  • We make no decisions about you based solely on automated processing (Art. 22 GDPR).

Where your data is stored

The app runs on a virtual private server rented from Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. The server is in a data center in Boston, USA. Hostinger processes the data only on our behalf and on our instructions, under a data processing agreement (Art. 28 GDPR), and may not use it for its own purposes.

Because the server is in the USA, your data is transferred outside the European Union. Under US law, authorities there may be able to demand access to data stored in the USA. We protect this transfer with the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are part of Hostinger’s data processing agreement (Art. 46(2)(c) GDPR). You can ask us for a copy.

When you speak an entry or answer, your browser sends the audio directly to AssemblyAI (AssemblyAI Inc., 169 Madison Ave STE 38365, New York, NY 10016, USA). AssemblyAI turns it into text in its EU data zone (data centers in the EU) and sends the text back while you speak. It also receives your IP address, as with any connection. It processes this data only on our behalf under a data processing agreement (Art. 28 GDPR), does not use it to train its models, and keeps neither the audio nor the text after the transcription; it keeps only technical details for billing, such as how long you spoke. AssemblyAI is a US company, so access from the USA can’t be ruled out; the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses in its data processing agreement cover this (Art. 45 and 46(2)(c) GDPR).

The emails we send you (see above) go out through Resend, run by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Resend sends them from its data center in Ireland but stores them in the USA, together with delivery records (your address, the time, and whether the email was delivered), and deletes both after 30 days. It processes this data only on our behalf under a data processing agreement (Art. 28 GDPR) and uses it only to provide its service to us. The EU Standard Contractual Clauses in that agreement cover the transfer to the USA (Art. 46(2)(c) GDPR).

When you email us, your message is stored in our mailbox at Spacemail, run by Spaceship, Inc., 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA, in the USA. Spaceship processes it only on our behalf under a data processing agreement (Art. 28 GDPR) that includes the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). It checks mail that is not end-to-end encrypted automatically for spam, malware and illegal content and may have parts of a message checked for abuse by OpenAI’s moderation service, which keeps such checks for at most 30 days and doesn’t use them for training. Spaceship keeps backups of the mailbox for up to four weeks.

We pass your data to no one else, unless the law obliges us to.

How we protect it

Every connection to the app is encrypted (HTTPS), including the one that streams your voice for transcription. Your entries, moods and answers are encrypted (AES-256-GCM) before they are stored, with a key that belongs to your account alone. That key is itself stored only in encrypted form, locked by a master key kept outside the database. If the database or a copy of it were exposed, your entries and answers would stay unreadable.

This is not end-to-end encryption: our server decrypts your entries and answers to show them to you. Passwords are stored only as salted hashes, and access tokens expire after 15 minutes.

How long we keep it

Each kind of data above says how long we keep it. When your account is deleted, we delete your account data, sessions, consent record, your answers and every entry, and destroy your account’s key. Your journal entries and answers in any copy that might remain somewhere, for example in a backup, become unreadable at that moment, because nothing can decrypt them without the key. Your other account data, such as your email address, is not encrypted with that key and can remain in backups until they are replaced.

You can delete your account in the app under Settings; you confirm it with your password. If you can’t sign in, email us and we delete it promptly, at the latest within one month.

Your rights

Under the GDPR you have the right to:

  • get a copy of your data and information about how we process it (Art. 15);
  • have incorrect data corrected (Art. 16);
  • have your data deleted (Art. 17);
  • have the processing restricted (Art. 18);
  • receive the data you gave us in a common, machine-readable format, or have it sent to someone else (Art. 20);
  • object to processing based on our legitimate interests, for reasons arising from your situation (Art. 21);
  • withdraw your consent at any time (Art. 7(3)).

You can download all your data at any time in the app under Settings, as Markdown and JSON in one ZIP file. To use any of these rights, email us. It’s free, and we answer within one month.

Complaints

You can complain to a data protection supervisory authority, in particular in the EU country where you live or work, or where you think the infringement happened (Art. 77 GDPR). The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–440213 DüsseldorfGermanywww.ldi.nrw.de

We’d welcome the chance to sort out any concern first, so feel free to write to us.

What you must provide

To create an account we need your email address, which you confirm through a link we email you, and a password. To use the journal we need your consent. Everything else, such as your mood, your answers to the first questions or speaking instead of typing, is optional.

Changes to this policy

We update this policy whenever the app changes in a way that affects your data, for example when we add a feature or a service provider. The date at the top shows the latest version. If a change affects what you consented to, we ask you again in the app before it applies.