mindora

Privacy Policy

Last Updated: April 14, 2026

1. Introduction

Mindora ("we", "us", or "Company") is a clinical management platform designed for therapists. We are committed to protecting the privacy of our users and their clients. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights.

By using Mindora, you agree to this policy. If you do not agree, please do not use the platform.

2. Data Controller

Company: Mindora
Website: usemindora.com
Contact: support@usemindora.com

3. Information We Collect

3.1. Account Data

When you register and manage your account, we collect:

  • First name, last name, and professional title
  • Email address
  • Phone number
  • Country and timezone
  • Profile photo
  • Language preference

3.2. Client Data

Data entered by therapists about their clients:

  • Name, email, phone number
  • Date of birth, gender, occupation
  • Address and emergency contact information
  • Referral source
  • National ID number (encrypted with AES-256-GCM; used only for e-SMM invoice issuance in Turkey)

3.3. Clinical Data (Sensitive Health Information)

The following health data is entered by therapists within their professional capacity:

  • Session notes and clinical notes
  • Therapy goals and progress records
  • Mental state assessments
  • Tasks and reminders
  • Clinical connections and breakthroughs

3.4. Financial Data

  • Session fees and currency
  • Payment status and history
  • Invoice/receipt information

Payments for your Mindora subscription are processed through Paddle (Merchant of Record), which handles international VAT/tax management.

For client collections: Online collection on Business and Platform plans works by you connecting your own Stripe (international), iyzico (Turkey, PayTR coming soon) account to Mindora. Payments flow directly into your own account; Mindora never touches your funds and takes no commission. Mindora's role is to create payment links, track their status, and initiate refunds when needed. Account settings and receipts are always managed in your provider's own dashboard.

Credit card information is never stored by Mindora at any stage.

3.5. Technical Data

  • IP address and approximate geolocation
  • Browser and device information (user agent)
  • Session data and cookies
  • Login attempts and security logs

4. How We Use Your Information

  • Providing and improving platform services
  • Account creation, authentication, and security
  • Session scheduling and Google Calendar synchronization
  • Payment processing and invoicing
  • Email notifications (session reminders, payment confirmations, etc.)
  • Responding to support requests
  • Compliance with legal obligations

5. Third-Party Services

Mindora works with the following third-party providers to deliver our services:

ServiceProviderPurposeData Shared
AuthenticationGoogle OAuth 2.0Sign in with GoogleEmail, name, profile info
Calendar syncGoogle Calendar APIBidirectional session syncEvent titles, date/time data
Video meetingsGoogle MeetOnline session linksMeeting links
Mindora subscription billingPaddle (Merchant of Record)Subscription payments, international VAT/tax managementPayment amount, transaction reference
Client payment links (therapist-connected account)Stripe, iyzico (PayTR coming soon)Therapist's own connected account for payment link creation and status trackingAmount, transaction reference; funds flow to therapist's account, not Mindora
Email deliveryResendNotification and transactional emailsRecipient email, email content
File storageSupabaseProfile photos, receiptsUploaded files
AccountingParasute-SMM invoice issuance (Turkey)Client name, national ID, invoice amount
MessagingWhatsAppPayment confirmations, receipts, and remindersRecipient phone number, message content

6. Cookies

Mindora uses the following cookies:

CookiePurposeDurationType
access_tokenSession authentication15 minutesEssential (HttpOnly)
refresh_tokenSession renewal7 daysEssential (HttpOnly)
csrf_tokenCSRF protection7 daysEssential

Mindora does not use third-party analytics or advertising cookies.

7. Data Security

We implement comprehensive security measures to protect your data:

  • Sensitive data is protected with AES-256-GCM encryption; encryption keys are versioned and rotated periodically (key rotation).
  • HTTP security headers (Helmet.js) protect against clickjacking, MIME sniffing, and protocol downgrade attacks.
  • Multi-factor authentication (MFA) support is available.
  • Login attempts are rate-limited (5 attempts per 15 minutes, followed by temporary lockout).
  • Clinical notes and blog content are protected against XSS attacks through server-side HTML sanitization.
  • All security events and data access are recorded in audit logs.
  • Multi-tenant architecture provides organization-level data isolation.
  • Payment webhook notifications are protected against replay attacks.
  • Registration and password reset processes do not reveal email address existence (anti-enumeration).

For detailed information about our security practices, please visit our Security page.

8. Data Retention

  • Account data: Retained while the account is active.
  • Deleted client data: Permanently deleted after 30 days.
  • Audit logs: Retained for 365 days.
  • Account deletion: 30-day cancellation period after deletion request, then permanent deletion.
  • Note edit history: Previous versions of clinical notes are retained while the account is active.

9. Your Rights

You have the following rights regarding your personal data:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to data processing
  • Request data portability

To exercise your rights, contact us at support@usemindora.com.

10. Data Storage Location and International Transfers

All client and clinical data is hosted at the AWS Frankfurt (Germany, EU region) data center. This region offers adequate protection under both KVKK and GDPR frameworks.

Some of our third-party service providers (Google, Paddle, Stripe, iyzico, Resend, Supabase) may process data in their own regions. These transfers are conducted with appropriate safeguards in compliance with applicable data protection laws.

11. Children's Privacy

Mindora is not intended for use by individuals under the age of 18. Only licensed therapists may use the platform.

12. Google API Services User Data Policy

Mindora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only request access to Google Calendar data necessary for session synchronization.
  • We do not use Google user data for advertising purposes.
  • We do not sell Google user data to third parties.
  • Google Calendar data is used solely to sync therapy sessions and personal calendar events between Mindora and your Google Calendar.

13. Public Booking Form

Therapists can create a public booking page for clients to schedule appointments online. Data collected through this form (name, contact information, booking note) is processed solely for appointment creation. Booking notes are encrypted with AES-256-GCM.

14. Therapist Website

Therapists can create a personal website through Mindora (e.g., dr-ayse.usemindora.com). This site may include the therapist's biography, areas of expertise, certificates, and blog posts. Therapists may optionally add a Google Analytics tracking code to their website; in this case, Google Analytics' own privacy policy applies.

15. Support Requests

Registered or guest users can submit support requests. During this process, name, email address, and request content are collected and used solely for support purposes.

16. WhatsApp Communication

Therapists can send payment confirmations, receipts, and session reminders to their clients via WhatsApp. In this case, the relevant information is transmitted through WhatsApp's infrastructure and WhatsApp's own privacy policy applies.

17. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email. The current version is always available on this page.

18. Contact

For privacy-related questions:
Email: support@usemindora.com
Website: usemindora.com