1. Introduction
Mindora ("we", "us", or "Company") is a clinical management platform designed for therapists. We are committed to protecting the privacy of our users and their clients. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights.
By using Mindora, you agree to this policy. If you do not agree, please do not use the platform.
2. Data Controller
Company: Mindora
Website: usemindora.com
Contact: support@usemindora.com
3. Information We Collect
3.1. Account Data
When you register and manage your account, we collect:
- First name, last name, and professional title
- Email address
- Phone number
- Country and timezone
- Profile photo
- Language preference
3.2. Client Data
Data entered by therapists about their clients:
- Name, email, phone number
- Date of birth, gender, occupation
- Address and emergency contact information
- Referral source
- National ID number (encrypted with AES-256-GCM; used only for e-SMM invoice issuance in Turkey)
3.3. Clinical Data (Sensitive Health Information)
The following health data is entered by therapists within their professional capacity:
- Session notes and clinical notes
- Therapy goals and progress records
- Mental state assessments
- Tasks and reminders
- Clinical connections and breakthroughs
3.4. Financial Data
- Session fees and currency
- Payment status and history
- Invoice/receipt information
Payments for your Mindora subscription are processed through Paddle (Merchant of Record), which handles international VAT/tax management.
For client collections: Online collection on Business and Platform plans works by you connecting your own Stripe (international), iyzico (Turkey, PayTR coming soon) account to Mindora. Payments flow directly into your own account; Mindora never touches your funds and takes no commission. Mindora's role is to create payment links, track their status, and initiate refunds when needed. Account settings and receipts are always managed in your provider's own dashboard.
Credit card information is never stored by Mindora at any stage.
3.5. Technical Data
- IP address and approximate geolocation
- Browser and device information (user agent)
- Session data and cookies
- Login attempts and security logs
4. How We Use Your Information
- Providing and improving platform services
- Account creation, authentication, and security
- Session scheduling and Google Calendar synchronization
- Payment processing and invoicing
- Email notifications (session reminders, payment confirmations, etc.)
- Responding to support requests
- Compliance with legal obligations
5. Third-Party Services
Mindora works with the following third-party providers to deliver our services:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Authentication | Google OAuth 2.0 | Sign in with Google | Email, name, profile info |
| Calendar sync | Google Calendar API | Bidirectional session sync | Event titles, date/time data |
| Video meetings | Google Meet | Online session links | Meeting links |
| Mindora subscription billing | Paddle (Merchant of Record) | Subscription payments, international VAT/tax management | Payment amount, transaction reference |
| Client payment links (therapist-connected account) | Stripe, iyzico (PayTR coming soon) | Therapist's own connected account for payment link creation and status tracking | Amount, transaction reference; funds flow to therapist's account, not Mindora |
| Email delivery | Resend | Notification and transactional emails | Recipient email, email content |
| File storage | Supabase | Profile photos, receipts | Uploaded files |
| Accounting | Parasut | e-SMM invoice issuance (Turkey) | Client name, national ID, invoice amount |
| Messaging | Payment confirmations, receipts, and reminders | Recipient phone number, message content |
6. Cookies
Mindora uses the following cookies:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| access_token | Session authentication | 15 minutes | Essential (HttpOnly) |
| refresh_token | Session renewal | 7 days | Essential (HttpOnly) |
| csrf_token | CSRF protection | 7 days | Essential |
Mindora does not use third-party analytics or advertising cookies.
7. Data Security
We implement comprehensive security measures to protect your data:
- Sensitive data is protected with AES-256-GCM encryption; encryption keys are versioned and rotated periodically (key rotation).
- HTTP security headers (Helmet.js) protect against clickjacking, MIME sniffing, and protocol downgrade attacks.
- Multi-factor authentication (MFA) support is available.
- Login attempts are rate-limited (5 attempts per 15 minutes, followed by temporary lockout).
- Clinical notes and blog content are protected against XSS attacks through server-side HTML sanitization.
- All security events and data access are recorded in audit logs.
- Multi-tenant architecture provides organization-level data isolation.
- Payment webhook notifications are protected against replay attacks.
- Registration and password reset processes do not reveal email address existence (anti-enumeration).
For detailed information about our security practices, please visit our Security page.
8. Data Retention
- Account data: Retained while the account is active.
- Deleted client data: Permanently deleted after 30 days.
- Audit logs: Retained for 365 days.
- Account deletion: 30-day cancellation period after deletion request, then permanent deletion.
- Note edit history: Previous versions of clinical notes are retained while the account is active.
9. Your Rights
You have the following rights regarding your personal data:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to data processing
- Request data portability
To exercise your rights, contact us at support@usemindora.com.
10. Data Storage Location and International Transfers
All client and clinical data is hosted at the AWS Frankfurt (Germany, EU region) data center. This region offers adequate protection under both KVKK and GDPR frameworks.
Some of our third-party service providers (Google, Paddle, Stripe, iyzico, Resend, Supabase) may process data in their own regions. These transfers are conducted with appropriate safeguards in compliance with applicable data protection laws.
11. Children's Privacy
Mindora is not intended for use by individuals under the age of 18. Only licensed therapists may use the platform.
12. Google API Services User Data Policy
Mindora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only request access to Google Calendar data necessary for session synchronization.
- We do not use Google user data for advertising purposes.
- We do not sell Google user data to third parties.
- Google Calendar data is used solely to sync therapy sessions and personal calendar events between Mindora and your Google Calendar.
13. Public Booking Form
Therapists can create a public booking page for clients to schedule appointments online. Data collected through this form (name, contact information, booking note) is processed solely for appointment creation. Booking notes are encrypted with AES-256-GCM.
14. Therapist Website
Therapists can create a personal website through Mindora (e.g., dr-ayse.usemindora.com). This site may include the therapist's biography, areas of expertise, certificates, and blog posts. Therapists may optionally add a Google Analytics tracking code to their website; in this case, Google Analytics' own privacy policy applies.
15. Support Requests
Registered or guest users can submit support requests. During this process, name, email address, and request content are collected and used solely for support purposes.
16. WhatsApp Communication
Therapists can send payment confirmations, receipts, and session reminders to their clients via WhatsApp. In this case, the relevant information is transmitted through WhatsApp's infrastructure and WhatsApp's own privacy policy applies.
17. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email. The current version is always available on this page.
18. Contact
For privacy-related questions:
Email: support@usemindora.com
Website: usemindora.com