Privacy Policy
How we protect and handle your data
Effective Date: July 24, 2025
Last Updated: July 24, 2025
StillMind is operated by Prioritised OÜ (Registration number: 16530243, VAT ID: EE102588297), located at Sepapaja tn 6, 15551 Tallinn, Harju County, Estonia.
This Privacy Policy applies to the StillMind mobile application (iOS and Android) and the StillMind Chrome browser extension. When we refer to "the service" or "StillMind," we mean both platforms collectively.
1. Information Collection
Account & Contact Data
We collect email addresses, usernames, encrypted passwords, names, and contact information when provided by users.
Payment Handling
StillMind does not process or store payment-card or bank details. All purchases are handled through Apple App Store or Google Play Billing.
Technical Information
We collect device type, operating system, browser information (including browser type and version for Chrome extension users), device identifiers, IP addresses, usage patterns, feature interactions, and performance metrics via Firebase Crashlytics.
Location Data
StillMind does not request or collect precise location. Our analytics providers may derive coarse city- or country-level region from IP addresses.
Meditation & Mood Data
Users can log mindfulness sessions, reflections, mood ratings, and goals. We do not collect sensitive medical or biometric health data.
AI Insights
With your explicit opt-in, we process your Meditation & Mood Data using cloud-hosted large-language-model (LLM) services. Users can disable this feature in Settings at any time.
2. Data Usage
We use collected information for:
- Service provision and personalization
 - Customer support and communications
 - Analytics and feature improvement
 - Legal compliance and fraud prevention
 - Marketing communications (with consent)
 
3. Legal Basis (GDPR)
For EEA users, we process data under these grounds:
- Explicit user consent
 - Contract performance
 - Legitimate business interests
 - Legal obligations
 - Protection of vital interests
 
4. Data Sharing and Disclosure
Service Providers
We share data with trusted service providers who assist with hosting, analytics, customer support, and payment processing. All providers are bound by data protection agreements.
AI Processing
When AI Insights are enabled, your meditation data is sent to cloud-based LLM providers for processing. We do not share personal identifying information with these services.
Legal Requirements
We may disclose information when required by law, to enforce our terms, or to protect rights and safety.
Business Transfers
In the event of a merger, acquisition, or asset sale, user data may be transferred with advance notice to users.
5. Data Security
We implement industry-standard security measures including encryption at rest and in transit, secure authentication, regular security audits, and access controls. However, no system is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, we remove or anonymize your data within 90 days, except where retention is required by law.
7. Your Rights
Depending on your location, you have rights to:
- Access: Request copies of your personal data
 - Correction: Update inaccurate information
 - Deletion: Request removal of your data
 - Data Portability: Receive your data in a portable format
 - Withdraw Consent: Revoke previously given consent
 - Object to Processing: Object to certain data processing activities
 - Lodge Complaints: File complaints with data protection authorities
 
To exercise your rights, contact us at [email protected].
8. Children's Privacy
StillMind is not intended for users under 18. We do not knowingly collect information from children. If we learn we have collected data from a child, we will delete it promptly.
9. International Data Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place, including standard contractual clauses and compliance with applicable data protection laws.
10. Cookies and Tracking
We use essential cookies for authentication and preferences. Analytics cookies help us understand usage patterns. You can control cookie preferences through your browser settings. The Chrome extension uses browser local storage to maintain your session and sync preferences with the mobile app.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
12. Contact Us
For questions about this Privacy Policy or to exercise your data rights, contact us at:
 Email: [email protected]
 Address: Prioritised OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia