Privacy Policy
Last updated: 14 August 2026
Mindex is a free, local-first desktop app for keeping notes and working with an AI agent over a local Markdown vault, operated by AAV Advisory Services LLC (mkr. Vostok-5, dom 17, kv. 58, Sverdlovskiy rayon, Bishkek, Kyrgyzstan), the data controller. This policy covers both the app and this website (mindex.live). The short version: your vault stays on your computer and is not uploaded to Mindex servers. Mindex does process limited account, access, device, activity, diagnostic, and website data described below.
1. Account & sign-in
Mindex requires an account during the private beta. You can sign up with email or sign in through Google or GitHub. Authentication is handled by Supabase and, for social sign-in, the provider you choose. Mindex does not receive your Google or GitHub password; Supabase processes authentication credentials and sessions.
We store your account id, email address, name, avatar URL, linked sign-in methods, account status, beta-access status, tester id, plan field, profile changes, and active sessions. Supabase authentication logs may include technical data such as an IP address, user agent, provider, and sign-in time. Your vault is not part of your account.
2. Your notes & vault
Your notes live as plain files in a folder on your own computer (local-first). Mindex never uploads the vault to Mindex servers. The search index, folder-context files, chat history, settings, and version history used by the desktop app are stored locally. The AI exception is explained in §3.
3. AI features
AI features run through an agent CLI installed on your own machine — Claude Code (Anthropic), Codex (OpenAI), or Gemini CLI (Google) — under your own account or subscription with that vendor. When you use AI, your prompt and any vault content that Mindex includes or that the selected CLI reads while completing the request may be sent directly to that vendor. Their handling of that content is governed by their privacy policy: Anthropic, OpenAI, or Google. Mindex servers do not proxy or retain that AI content; it travels between the CLI on your device and the selected vendor.
4. Desktop app diagnostics & activity
The desktop app uses one pseudonymous install id. This id is not your name or email, but the same id is also used for a signed-in device row, so it can be associated with your account while you are signed in. The app sends the following separate data streams:
- Install record (always on, Supabase) — install id, operating system, app version, first-seen time, and last-seen time. This is used to count active installations.
- Usage analytics (on by default, optional) via PostHog — app opened (OS, CPU architecture, first-run flag), app closed (session duration), vault opened (note count), note created (note type), search used, and app version. Search queries, prompts, note text, titles, file names, folder structure, and vault paths are not included.
- Crash and error reporting (always on) via Sentry — error details, stack traces, app version, environment, and install id. Performance tracing and default PII collection are disabled. Mindex scrubs file paths, OS usernames, and text fields before a report is sent.
- Signed-in activity (Supabase) — device label and OS, last-seen time, onboarding timestamps, and daily counts of note saves and AI-written files. These counts do not include note contents, titles, or file names.
- Bug reports (only when you submit one) — category, title, description, optional reply email, app version, OS, and install id, stored via Supabase.
You can turn PostHog usage analytics off in Settings → Diagnostics; the change takes effect immediately. The install record and scrubbed crash reports are always on.
5. Website, account & beta data
The website and account area may store:
- Beta access — request status, an optional request note, tester id, and whether you have seen the welcome message.
- Downloads and onboarding — platform, app version, download time, and timestamps for downloaded, signed in, first vault, and optional GitHub identity steps.
- Account activity — the daily note-save and AI-write counts described in §4, shown in your account heatmap.
- Beta feedback — satisfaction score, optional comments, requested improvement, recommendation score, app version, and submission time when you send the survey.
- Newsletter or Advanced waitlist — if you submit your email, it is stored via Supabase with the source of the signup so we can send product updates.
- Website analytics after cookie consent via PostHog: page views and exits, clicks and taps, download and CTA events, heatmaps, and session replay. Standard form inputs are masked by PostHog by default, but visible non-input page text can appear in a replay. PostHog is loaded only after you accept cookies and stores identifiers in cookies and local storage. Declining does not block the site.
6. Data deletion & contact
You can delete your account from the account area, unsubscribe from product email in your profile, or contact dvolynov@gmail.com for access, correction, export, or deletion requests. Deleting your local vault is separate: the files are on your computer and remain under your control.
7. Third parties
Mindex uses Anthropic, OpenAI, or Google for AI requests you initiate; Supabase for authentication, account and beta data, install counts, activity, feedback, and email lists; PostHog for optional app analytics and consent-based website analytics; Sentry for app crash reporting; and Cloudflare to serve installers. Each provider processes data under its own terms and privacy policy.
8. Changes
We may update this policy as the beta changes. Material changes will be reflected by the “last updated” date above.