Privacy Policy
Last updated: March 29, 2026
1. Who are we?
We are MindNavigator (mindnavigator.io), based in the Netherlands (Chamber of Commerce number: pending). We are committed to protecting your privacy. This policy describes how we collect, use, and protect your personal information.
MindNavigator is an online platform for personal development of neurodivergent young people. We are not a medical institution and do not provide diagnoses.
2. What information do we collect?
We may collect the following types of information:
- Personal Identification Information: Name, email address, date of birth.
- Account Data: Username, password (encrypted), profile information.
- Assessment Data: Responses to questionnaires and self-assessments.
- Technical Data: IP address, browser type, operating system, device information.
- Usage Data: Information about how you use our site, such as pages viewed and features used.
- AI Chat Data: Conversations with our AI expert (Dr. Florentine Forest) are processed in real-time but not permanently stored. Token usage is tracked anonymously for cost management.
- Beta Program Data: During our beta phase, we collect registration details, verification status, and feedback (including optional screenshots) from beta testers.
3. How do we use your information?
Your information is used to:
- Deliver and personalize our services.
- Manage and secure your account.
- Generate personalized insights and reports.
- Communicate with you about your account and our services.
- Improve and secure our site.
- Comply with legal obligations.
4. With whom do we share your information?
We never sell your personal data. We may share your data with:
- Service Providers: Companies that help us deliver our services (see section 5 for details about hosting and storage).
- Coaches: Coaches and tutors on our platform only receive the information necessary for their services, with your consent.
- Parents/Guardians: For minors, we share certain progress information with parents, depending on the user's age (see our Terms of Service).
- Legal Authorities: When legally required or in acute safety situations (in accordance with the reporting code).
For payment processing (when active after beta phase), we use Mollie. You can find their privacy policy here: Mollie Privacy Policy
Other service providers:
- Anthropic (Claude AI): For AI analysis and report generation. Pseudonymized data only (no names/emails). Data is NOT used for model training. Located in the US, with Standard Contractual Clauses.
- Resend: For transactional emails (verification, notifications, password reset). Located in the US, with SCC's.
- Google Analytics (Consent Mode v2): For anonymized usage statistics. Only active after your explicit consent. IP anonymization enabled. Do Not Track respected. Minors (<16) are automatically excluded.
- Sentry: For technical error monitoring. Located in the EU (Germany). Only technical error information is shared, no personal user data.
5. Where is your data stored?
Your personal data remains within the European Union.
- Database (Firestore): Your personal data, account information, and assessment results are stored on servers in the Netherlands (europe-west4).
- Application (App Hosting): Our application runs on servers in the Netherlands (europe-west4).
- Media Files (Cloud Storage): Videos and images are stored on servers in the United States (us-central1). This does not concern personal data but educational content.
We use Google Firebase and Google Cloud Platform. Google LLC is certified under the EU-US Data Privacy Framework (DPF), which the European Commission has recognized as providing adequate protection. More information can be found in the Google Cloud Privacy Policy
6. How do we protect your information?
We take the security of your data seriously:
- Encryption: All data is encrypted at rest and transmitted via secure connections (HTTPS/TLS).
- Authentication: Passwords are hashed and never stored in plain text.
- Access Control: Only authorized personnel have access to personal data, on a need-to-know basis.
- Monitoring: We monitor our systems for suspicious activities.
Despite these measures, no security method is 100% foolproof. In case of a data breach, we will inform you and the relevant authorities in accordance with legal requirements.
7. Your rights under GDPR
You have the following rights regarding your personal data:
- Right of Access: You can request what data we have about you.
- Right to Rectification: You can have incorrect data corrected.
- Right to Erasure: You can request deletion of your data.
- Right to Restriction: You can have the processing of your data restricted.
- Right to Data Portability: You can receive your data in a standard format.
- Right to Object: You can object to certain processing activities.
To exercise these rights, contact us at privacy@mindnavigator.io. We will respond to your request within 30 days.
8. Cookies and tracking
We use cookies to deliver and improve our services. For more information, see our Cookie Policy.
9. Retention periods
We do not retain your data longer than necessary:
- Account Data: As long as your account is active, plus a maximum of 2 years after deletion for administrative purposes.
- Assessment Results: As long as your account is active. After deletion, these are anonymized or deleted.
- Technical Logs: Maximum 90 days for security purposes.
10. Minors
MindNavigator is aimed at young people from 6 years old. We apply age-appropriate privacy protections:
- Children 6-11: Parental consent always required. The parent creates and manages the account. Full parental control and visibility. No community features, messaging, or coach connections.
- Children 12-15: Parental consent required for data processing. Children can manage their own privacy settings (what parents see) but cannot delete all data.
- Youth 16-17: Can give their own consent and manage their privacy. Can delete their own data with a 7-day reflection period and parental notification.
- Adults 18+: Full autonomous control over all data.
11. Changes to this policy
We may update this privacy policy from time to time. For significant changes, we will inform you via email or a notification on our platform. The date at the top of this document indicates when the policy was last updated.
12. Contact
Do you have questions about this privacy policy or how we handle your data? Please contact us:
- Email: privacy@mindnavigator.io
- Website: mindnavigator.io
You also have the right to file a complaint with the Dutch Data Protection Authority .