Privacy Policy
Last updated: 10 September 2026
MindLake (“we”, “us”) is operated from the United Kingdom and is the data controller for the personal data described in this policy. You can reach us any time at hello@mindlake.app. The short version: MindLake is local-first, your notes live on your own device and in your personal iCloud, and we only receive content you explicitly choose to publish.
The apps: your notes stay with you
The MindLake apps for Mac and iPhone record and transcribe meetings entirely on your device, using on-device speech recognition. Audio, transcripts and notes are written to a Markdown vault stored locally and, if you enable sync, in your own iCloud Drive under your Apple account. None of this content is sent to our servers, and we cannot access it. The apps contain no third-party advertising or tracking SDKs and no analytics of any kind. If the app closes unexpectedly it writes a report to a folder on your own machine, which is never uploaded and which you can read or delete yourself.
AI features, and where your words go
Summaries, chat and AI editing are optional, and they are the one part of MindLake that sends your writing anywhere. When you use them, the note or transcript involved goes from your device directly to the AI provider you have connected under your own account, so that it can answer. We never receive it, cannot access it, and store none of it: what happens to it there is governed by that provider’s own terms and privacy policy, and your relationship is with them. Choose a local model instead and nothing leaves your machine at all. None of this is on until you use it, recording and transcription never use it, and the iPhone app has no AI features.
Images a note points at
If a note references an image by web address, displaying that note fetches it from wherever it is hosted, which tells that site your IP address in the way any web request does. Images kept in your own vault are read from disk and involve no network at all.
Recordings and other people
Recordings you make may capture other participants in your meetings. For MindLake, that data never leaves your device, so you (not we) are responsible for it: please make sure you have any consent required in your jurisdiction before recording. See our Terms for more.
Notes you publish
Publishing is a Mac feature and is never automatic. When you publish a note, its title, content and settings are sent to our servers so we can render it at a public web address, and they stay there where we can access them until you take it down. It stays there until you unpublish it, which removes it from the web immediately. If you password-protect a note, the password is stored only as a salted, peppered hash (never in plain text), and the note’s content is withheld until the correct password is entered. Publishing devices are identified by a revocable token, also stored only as a hash.
The waitlist
If you join the waitlist we store the email address you provide, together with which page you signed up from, so we can contact you about access and launch. We do not sell it, share it, or use it for anything else, and we delete it on request.
Security and server logs
To protect the service, our servers keep short-lived rate-limit counters keyed by IP address (pruned within roughly 24 hours) and standard request logs retained briefly by our hosting provider. We use these solely for security and abuse prevention.
Cookies and analytics
The site sets only functional cookies: your theme preference and, after you unlock a password-protected note, a scoped access cookie so you are not asked again for seven days. We use Vercel Analytics, which is cookieless and collects only aggregate, anonymised page statistics. We set no advertising or cross-site tracking cookies, which is why you see no cookie banner.
Who processes data for us
We use two processors: Supabase (database hosting for waitlist entries, published notes and rate-limit counters) and Vercel (site hosting and analytics). Both may process data on servers outside the UK, including in the United States, under standard contractual safeguards.
Legal bases and retention
We rely on consent for the waitlist (withdraw any time by asking to be removed), performance of a contract for publishing (we cannot host your note without its content), and legitimate interests for security measures such as rate limiting. Waitlist entries are kept until launch or until you ask us to delete them; published notes are kept until you unpublish them; security counters expire automatically.
Your rights
Under UK data protection law you can ask us for a copy of your personal data, ask us to correct or delete it, object to or restrict our processing, and ask for it in a portable format. Email hello@mindlake.app and we will respond within one month. If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office (ico.org.uk).
Changes
If we change this policy we will update this page and the date above. If a change meaningfully affects data we already hold about you (for example, waitlist emails), we will email you first.
Contact
Questions about privacy? Email hello@mindlake.app.