Privacy Policy

Last updated: October 2026

This Privacy Policy explains how MindMessage UG (haftungsbeschränkt) processes personal data when you visit the public website www.mindmessage.app, sign up to receive information by email, or contact us. A separate Privacy Policy applies to the use of the MindMessage app.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is: MindMessage UG (haftungsbeschränkt), Raintalerstraße 16, 81539 Munich, Germany. Email: felicitas@mindmessage.app.

2. Scope and Principles of Data Processing

Personal data is information relating to an identified or identifiable natural person. We process personal data only to the extent necessary to securely provide the website, respond to your enquiries, send you information by email, or where you have consented to additional processing.

2.1 Legal Bases

Depending on the purpose, we rely in particular on the following legal bases for processing:

  • Art. 6(1)(a) GDPR, where you have given us your consent;

  • Art. 6(1)(b) GDPR, where processing is necessary in order to take steps prior to entering into a contract or to perform a contract;

  • Art. 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;

  • Art. 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party and your interests or fundamental rights do not override those interests.

Section 25 TDDDG additionally applies to the storage of information on your device or access to information already stored on your device. Where such access is strictly necessary to provide a digital service expressly requested by you, access is based on Section 25(2) No. 2 TDDDG. In all other cases, we obtain your prior consent in accordance with Section 25(1) TDDDG.

2.2 Recipients and Processing on Our Behalf

We use carefully selected technical service providers. They receive personal data only to the extent necessary to provide the respective service. Where a service provider processes personal data on our behalf, we enter into a data processing agreement pursuant to Art. 28 GDPR. Data may also be disclosed where we are legally required to do so or where you have given your consent.

2.3 Transfers to Third Countries

Some of the providers we use belong to corporate groups based outside the European Union or European Economic Area. Where personal data is transferred to a third country, this takes place only in accordance with Arts. 44 to 49 GDPR. For recipients in the United States, the transfer may be based on an adequacy decision of the European Commission for companies certified under the EU-U.S. Data Privacy Framework. Otherwise, we use in particular the European Commission’s Standard Contractual Clauses and, where necessary, additional safeguards.

2.4 Storage Period

We store personal data only for as long as necessary for the respective purpose. We subsequently delete or anonymise the data unless statutory retention obligations, legitimate interests in retaining evidence, or other legal grounds require further storage. Where a more specific retention period applies to an individual processing activity, this is stated below.

2.5 Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and unauthorised alteration. The website is transmitted using TLS encryption. Please note that data transmission over the internet cannot be completely protected against all access by third parties.

3. Provision and Hosting of the Website

3.1 Framer

The website is created and provided using Framer. The provider is Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands. In connection with the technical provision of the website, IP addresses, device and browser information, requested pages and files, and technical log data may in particular be processed. The processing serves to deliver the website and ensure its security and functionality. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our online services.

Framer processes data on our behalf on the basis of its data processing agreement. Framer uses subprocessors. This may involve processing outside the European Union or European Economic Area. For such processing, Framer provides in particular for adequacy decisions, the EU-U.S. Data Privacy Framework for appropriately certified U.S. recipients, or Standard Contractual Clauses and, where necessary, supplementary safeguards. Information about the subprocessors used is available in Framer’s Trust Center. You may request a copy of the relevant safeguards from us.

Further information is available in Framer’s Data Processing Addendum and Privacy Statement.

3.2 Server Logs

When you access the website, the hosting and security providers may process in particular the following data:

  • IP address of the accessing device;

  • date and time of the request;

  • page or file accessed and amount of data transferred;

  • referrer URL;

  • browser type and browser version, operating system and device type;

  • information concerning the request and security-related events.

Log data is processed for the technical provision of the website, error analysis, stability and protection against attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the security and functionality of the website. The data is deleted as soon as it is no longer required for these purposes, unless a security-related event requires longer retention.

4. Cookies and Similar Technologies

Where cookies or similar technologies are strictly necessary to provide a service expressly requested by you, storage or access takes place on the basis of Section 25(2) No. 2 TDDDG. The associated processing of personal data is based, depending on the purpose, in particular on Art. 6(1)(f) GDPR. For storage or access that is not necessary, we obtain your prior consent pursuant to Section 25(1) TDDDG. According to Framer, its integrated analytics does not use cookies; it is explained in Section 5.

5. Analytics with Framer Analytics

We use Framer’s integrated analytics to evaluate the use of our website in aggregated form and improve our online services. The analytics include, in particular, page views, visitor numbers, visit duration, referring websites, as well as country, device and browser statistics. According to Framer, analytics are performed without cookies and without persistent identifiers used to recognise visitors across multiple days. Individual visitors are measured within a one-day window.

Where personal data is processed in this context, we base the processing on Art. 6(1)(f) GDPR. Our legitimate interest lies in data-minimising analysis and improvement of our online services. Information about the provider and possible transfers to third countries can be found in Section 3.1.

6. Email Sign-Up and Newsletter

6.1 Sign-Up

You can voluntarily sign up to receive information about MindMessage by email. Depending on your selection, you may receive information about the availability of the app, product news, offers or our newsletter. Your email address is required. The specific content of the sign-up is described directly on the respective form. Signing up solely to be notified about the app launch does not automatically subscribe you to a regular newsletter. We use a double opt-in procedure: after signing up, you will receive an email containing a confirmation link. The subscribed information will only be sent once you have confirmed your registration. For the purpose of documenting your consent, we process your email address, the content or version of your consent, the time of registration and confirmation, and the IP address recorded at those times.

The legal basis for sending emails is your consent pursuant to Art. 6(1)(a) GDPR. The registration process is logged in order to comply with our documentation obligations pursuant to Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR. You may withdraw your consent at any time using the unsubscribe link in each message or by contacting us. The lawfulness of processing carried out before the withdrawal of consent remains unaffected.

6.2 Sending Emails via Brevo

We use Brevo, Köpenicker Straße 126, 10179 Berlin, Germany, for registration, administration and sending emails. Brevo processes in particular your email address, consent and confirmation information, sending data and technical delivery information on our behalf. When a registration form provided by Brevo is used, technical data required to deliver and securely transmit the form, in particular your IP address and browser information, may also be transmitted to Brevo. The legal basis for processing in connection with registration and sending emails is your consent pursuant to Art. 6(1)(a) GDPR. For the technical provision and security of the form, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and functional registration process.

We do not use personalised open or click tracking for these emails. In particular, we do not use tracking pixels to record your individual reading behaviour. Technical delivery information, such as failed deliveries or unsubscribes, continues to be processed where necessary to ensure reliable delivery and respect your preferences.

After you unsubscribe, your address is removed from the active mailing list. Where necessary to defend against possible legal claims, we may retain records of consent for up to three years from the end of the calendar year in which consent was withdrawn, on the basis of Art. 6(1)(f) GDPR. Your email address may also be stored on a suppression list in order to respect your withdrawal and prevent further emails from being sent. This is also based on Art. 6(1)(f) GDPR. Storage ends once the respective purpose no longer applies, unless statutory retention obligations require otherwise.

7. Contacting Us

If you contact us by email or telephone, we process the contact details you provide and the content of your enquiry in order to respond to your request and any follow-up questions. Where your enquiry relates to a contract or pre-contractual measures, the legal basis is Art. 6(1)(b) GDPR. In other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in appropriately handling enquiries.

We delete the data once your enquiry has been fully dealt with and no statutory retention obligations or legitimate grounds for further storage apply. Please do not send sensitive health information through general contact channels unless this is necessary for your enquiry.

8. Links to Social Media Services

Our website contains links to our profiles on Instagram and Substack. Simply visiting our website does not result in data being automatically transmitted to these platforms through these links. Only when you click on a link do you leave our website. The respective platform provider is generally responsible for any subsequent processing. Please refer to the respective provider’s privacy policy:

Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland

Substack: Substack, Inc., 111 Sutter Street, 7th Floor, San Francisco, California 94104, USA

9. Your Rights

Where the statutory requirements are met, you have in particular the following rights:

  • access to your personal data processed by us pursuant to Art. 15 GDPR;

  • rectification of inaccurate data or completion of incomplete data pursuant to Art. 16 GDPR;

  • erasure of your personal data pursuant to Art. 17 GDPR;

  • restriction of processing pursuant to Art. 18 GDPR;

  • data portability pursuant to Art. 20 GDPR;

  • objection to processing pursuant to Art. 21 GDPR;

  • withdrawal of consent with effect for the future pursuant to Art. 7(3) GDPR;

  • the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.

9.1 Right to Object

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you may object to such processing at any time on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you may object to such processing at any time without giving reasons.

9.2 Right to Lodge a Complaint

You may lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us in particular is: Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany. Further information is available from the Bavarian State Office for Data Protection Supervision.

10. Changes to this Privacy Policy

We update this Privacy Policy if our website, the services we use or legal requirements change. The version published on this website at the relevant time applies.