At MindTunes, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with Singapore's Personal Data Protection Act 2012 ("PDPA") and other applicable regulations.
By using our app and services ("Service"), you consent to the practices described in this Privacy Policy.
1. Information We Collect
We collect the following types of personal data:
1.1 Information You Provide
- Account Information: Name, email address, date of birth, gender, and profile details
- Wellness Data: Self-reported mood, mental health status, goals, routines, and journal entries
- Communication Data: Messages, feedback, and support requests you send to us
- Payment Information: Billing details and transaction history (processed securely by third-party payment providers)
1.2 Automatically Collected Information
- Device Information: Device type, operating system, unique device identifiers
- Usage Data: Features accessed, time spent, interaction patterns, and in-app behavior
- Location Data: Approximate location based on IP address (with your consent for precise location)
- Cookies & Tracking: We use cookies and similar technologies to enhance user experience
2. How We Use Your Information
We use your personal data for the following purposes:
- Service Delivery: To provide, personalize, and improve our mental wellness features
- AI-Powered Support: To train and operate our AI wellness coach and recommendation systems
- Communication: To send you updates, notifications, newsletters, and respond to inquiries
- Analytics: To analyze usage patterns, improve app functionality, and enhance user experience
- Security: To detect, prevent, and address fraud, security issues, or technical problems
- Legal Compliance: To comply with legal obligations, enforce our Terms & Conditions, and protect our rights
- Marketing: To send promotional content (with your consent, which you may withdraw anytime)
3. Legal Basis for Processing (PDPA Compliance)
Under Singapore's PDPA, we process your personal data based on:
- Consent: You have provided explicit consent for specific purposes
- Contractual Necessity: Processing is necessary to fulfill our service agreement with you
- Legitimate Interests: For business operations, fraud prevention, and service improvement
- Legal Obligations: To comply with Singapore laws and regulations
4. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
4.1 Service Providers
- Cloud hosting providers (e.g., AWS, Google Cloud)
- Payment processors (e.g., Stripe, PayPal)
- Analytics platforms (e.g., Google Analytics, Mixpanel)
- Customer support tools (e.g., Zendesk, Intercom)
4.2 Professional Partners
- Licensed mental health professionals (only when you request referrals or consultations)
- Content creators and wellness experts who contribute to our platform
4.3 Legal Requirements
- To comply with court orders, legal processes, or government requests
- To protect the rights, property, and safety of MindTunes, our users, or the public
- In connection with a merger, acquisition, or sale of assets (with notice to you)
5. Data Retention
- We retain your personal data for as long as your account is active or as needed to provide services
- Wellness data and journals are retained while your account exists, unless you request deletion
- After account closure, we may retain certain data for legal, tax, or regulatory compliance (typically 7 years)
- Anonymized or aggregated data may be retained indefinitely for analytics purposes
6. Your Rights Under Singapore PDPA
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Withdrawal of Consent: Withdraw consent for specific data processing activities
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Data Portability: Request transfer of your data in a structured, machine-readable format
- Objection: Object to data processing for direct marketing purposes
To exercise these rights, please contact us at admin@yourmindtune.com. We will respond within 30 days as required by PDPA.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Access controls and authentication mechanisms
- Regular security audits and vulnerability assessments
- Employee training on data protection best practices
- Secure data centers with physical and digital safeguards
However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. International Data Transfers
Your data may be transferred to and processed in countries outside Singapore where our service providers operate. When we transfer data internationally, we ensure:
- Adequate level of data protection comparable to Singapore's PDPA
- Use of standard contractual clauses or other approved mechanisms
- Compliance with cross-border data transfer regulations
9. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we discover that a child has provided us with personal data, we will promptly delete it.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Remember your preferences and settings
- Analyze usage patterns and improve our Service
- Provide personalized content and recommendations
- Deliver targeted advertising (with your consent)
You can manage cookie preferences through your browser settings. Note that disabling cookies may affect certain features of our Service.
11. Third-Party Links
Our Service may contain links to external websites or services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- Posting the updated policy in the app with a new "Last Updated" date
- Sending you an email or in-app notification
- Requesting your consent for material changes affecting your rights
Your continued use of the Service after such updates indicates acceptance of the revised Privacy Policy.
13. Contact Us & Data Protection Officer
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
14. Complaints to Regulatory Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with: