Privacy policy
Last updated 24 July 2026
This policy explains what data we collect when you use the Mentalità Blindata app and the mentalitablindata.com website, why we process it and what rights you can exercise. It is written under Regulation (EU) 2016/679 (GDPR) and Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018, LGPD).
To be completed before publication. The controller's identifying details, registered address and the name of the representative in the European Union must be filled in below. While these still read as placeholders, this policy does not meet Article 13 of the GDPR.
1. Who processes your data
The controller is Jacopo Artefice, CNPJ 46.099.053/0001-02, registered at [ADDRESS: street, number, city, state, postcode], Brazil.
You can contact the controller and the data protection officer (encarregado, under Article 41 LGPD) at privacy@mentalitablindata.com.
Because the controller is not established in the European Union but offers the app to users located in the Union, Article 3(2) of the GDPR applies. The representative in the Union designated under Article 27 GDPR is [EU REPRESENTATIVE: name and address].
2. What data we process
2.1 Data that stays on your device only
Most of what you write in the app never reaches us. The following stays in your phone's storage:
- the vice you chose to work on, clean days, your streak, completed missions and experience points;
- the text of the Pact you write on day one;
- your journal and daily check-ins, including mood;
- weight, height, age, goal and the inputs used to generate your workout and diet;
- transformation photos;
- language, theme and reminder preferences.
This data is stored locally and is not sent to our servers, unless you create an account: in that case section 2.6 on cloud backup applies, and a copy is kept on our side.
2.2 Online account data
The account is optional: the app works without one. If you create one to use the leaderboard, the community board or sync, we process:
- email address and user identifier;
- the display name you choose;
- if you sign in with Google or Apple, the identifier returned by that provider;
- creation date and last sign-in;
- subscription status (active or not).
2.3 Health data
If you grant permission, the app reads steps, weight and sleep from Health Connect (Android) or Apple Health, and shows them inside the app. This is special category data under Article 9 GDPR and sensitive data under Article 5, II, LGPD. We never write anything back to those platforms, and you can withdraw the permission in your system settings at any time.
It stays on your device until you turn on the two features that send it out: the coach, which receives steps, sleep and weight along with your message (section 2.4), and cloud backup, which keeps a copy if you have an account (section 2.6).
The vice you are working on, your clean days and the craving level you report are health-related data too. The same two exceptions apply: the coach receives them with your message, and they end up in the backup if you have an account.
2.4 Coach conversations
The coach is a Premium subscription feature. When you write to it, your message and a summary of your path are sent to a server of ours, which forwards them to Anthropic's language model to generate the reply. We do not use these conversations to train models and we do not sell them.
That summary is not generic: it contains the vice you are working on and its severity, your clean days and personal record, today's mood and craving level, steps, sleep, water, weight, level, active challenge and the days you are most at risk. It is what lets the coach talk about your actual situation rather than in the abstract.
On top of that, if you ask it to, the coach can read other content in the app to answer you: diet, workout plan, check-ins, relapses, risk map, reminders and the text of your Pact. Whatever it reads at that moment is sent to Anthropic along with the conversation. That is why the coach is a feature you switch on yourself: if you would rather this data stayed on your phone, do not use it.
Conversations stay on your device. We keep no archive of your chats on our servers: the server only relays them, and stores the technical counters needed to prevent abuse for at most 24 hours.
2.5 Purchase data
Purchases happen inside the App Store or Google Play. We never see your card number. From the subscription service provider we receive an anonymous identifier and the entitlement status, which is what we need to unlock Premium features.
2.6 Cloud backup
If you have an active account, the app keeps a backup of your path on our servers, refreshed automatically no more than once every three days. It exists so you do not start from scratch when you change phone.
The backup contains everything listed in section 2.1, including journal notes, the text of your Pact, logged relapses and transformation photos. Each user can only reach their own.
If you would rather this did not happen, do not sign in: with no account nothing leaves the device, and the app remains fully usable. If you already have an account and want the copy removed, delete your account from the app or write to privacy@mentalitablindata.com.
2.7 Crash reports
If the app closes because of an error, we send the technical crash report to Sentry so we can fix it: error type, point in the code, device model and operating system version. The feature is configured not to attach your IP address or personal identifiers, and it does not record what you were writing.
2.8 Website data
The mentalitablindata.com website is made of static pages. We use no profiling cookies, no traffic analytics and no embedded third-party content. The hosting provider records IP addresses in technical logs for security and service operation. See the cookie policy.
3. Why we process data, and on what legal basis
- Running the app and your account. Legal basis: performance of a contract, Art. 6(1)(b) GDPR; Art. 7, V LGPD.
- Managing subscriptions and the related tax obligations. Legal basis: contract and legal obligation, Art. 6(1)(b) and 6(1)(c) GDPR; Art. 7, II and V LGPD.
- Reading health data from your phone and displaying it in the app. Legal basis: your explicit consent, Art. 9(2)(a) GDPR; Art. 11, I LGPD. That consent is the permission you grant the operating system, and you can withdraw it whenever you want.
- Answering your support requests. Legal basis: legitimate interest in providing support, Art. 6(1)(f) GDPR; Art. 7, IX LGPD.
- Preventing abuse and protecting the service. Legal basis: legitimate interest, Art. 6(1)(f) GDPR; Art. 7, IX LGPD.
- Keeping a backup of the path of users who have an account. Legal basis: performance of a contract, Art. 6(1)(b) GDPR; Art. 7, V LGPD.
- Fixing app crashes. Legal basis: legitimate interest in keeping the service working, Art. 6(1)(f) GDPR; Art. 7, IX LGPD.
We do no advertising profiling and we make no automated decisions producing legal effects on you.
4. Who we share data with
We rely on providers that process data on our behalf, as processors:
- Supabase (US company): authentication, account database, cloud backup and server functions. Our project's data is hosted on servers in the European Union (Frankfurt).
- RevenueCat Inc. (United States): technical subscription management.
- Anthropic PBC (United States): generating the coach's replies.
- Resend (US company): sending service emails such as the password reset code. Our account is configured on servers in the European Union (Ireland).
- Sentry: collecting technical crash reports, on servers in the European Union.
- Apple Inc. and Google LLC: app distribution, account sign-in and payment collection. For those activities Apple and Google act as independent controllers under their own policies.
- The website hosting provider.
We do not sell personal data and we do not pass it to advertising intermediaries.
5. Transfers outside the European Union and outside Brazil
The providers listed above are in the United States and the controller is in Brazil. Transfers from the European Economic Area rely on the standard contractual clauses adopted by the European Commission under Article 46 GDPR, or on an adequacy decision where one applies. The European Commission has not adopted an adequacy decision for Brazil, so those transfers rely on the standard contractual clauses. You can request a copy of the safeguards by writing to privacy@mentalitablindata.com.
6. How long we keep data
- Data on your device: for as long as the app is installed. Uninstalling deletes it, so export a backup first if you need it.
- Online account: until you delete it. After a deletion request, data is removed within 30 days, except what must be kept for tax or accounting obligations.
- Coach conversations: they stay on your device until you delete them. We keep no copy on our servers; at Anthropic the retention set by our API contract applies.
- Cloud backup: for as long as you keep the account. It is deleted when you delete the account.
- Crash reports: according to Sentry's retention plan, normally 90 days.
- Technical anti-abuse counters for the coach: 24 hours.
- Support requests: 24 months after the request is closed.
- Billing records: for the period required by the applicable tax law.
7. Your rights
Under Articles 15 to 22 GDPR and Article 18 LGPD you can ask at any time to:
- know whether we process data about you and get a copy of it;
- correct data that is inaccurate or incomplete;
- have data deleted, where we have no obligation to keep it;
- restrict processing, or object to processing based on legitimate interest;
- receive your data in a machine-readable format and move it to another controller;
- withdraw consent, without affecting the lawfulness of what was done before;
- know who we shared your data with.
Write to privacy@mentalitablindata.com. We reply within one month, extendable by two months for complex requests. To delete your account you do not need to write to us: you can do it straight from the app, under Account, and the deletion also takes away your cloud backup and anything you published. The procedure is described on the account deletion page.
If you believe the processing breaches the law, you can lodge a complaint with a supervisory authority:
- in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it);
- in Brazil, the Autoridade Nacional de Proteção de Dados (www.gov.br/anpd);
- or with the authority of the EU member state where you live.
8. Minors
The app is intended for adults and is rated for an adult audience, because it deals with addiction and substances. We do not knowingly collect data from anyone under 18. If we find that we have, we delete it. If you are a parent or guardian and believe your child has given us data, write to privacy@mentalitablindata.com.
9. Security
Communication with our servers uses TLS. Database access is governed by row level security rules, so each user can only read and write their own data. The app can be locked with your phone's biometric lock. No system is invulnerable: if a breach occurs that poses a high risk to your rights, we will notify you under Article 34 GDPR and Article 48 LGPD.
10. Changes to this policy
If we change how we handle data, we update this page and the date at the top. When a change is significant we also flag it inside the app.
11. Contact
For anything about personal data: privacy@mentalitablindata.com. For help using the app: see the support page.