Legal
Privacy Policy
Effective August 24, 2026
MindGraph is a product operated by Syed Shan-E-Haider Rizvi, an individual based in New York ("MindGraph," "we," "us," or "our").
This Privacy Policy explains how MindGraph collects, uses, discloses, and protects personal information when you visit our websites or use our hosted service, APIs, integrations, and related services (collectively, the Services).
1. Scope and our role
This Policy applies to information MindGraph handles for its own purposes, such as website, account, billing, support, security, and marketing information. For that information, MindGraph acts as a controller or business under applicable privacy law.
When a business customer submits personal information in documents, databases, messages, or other Customer Content, MindGraph generally processes that information on the customer's behalf. The customer controls the content and is responsible for its privacy notices and instructions. If your information was submitted by a MindGraph customer, direct your request to that customer first; we will assist the customer as required by law and our agreement.
This Policy does not govern third-party services you choose to connect to MindGraph or third-party sites linked from the Services.
2. Information we collect
Depending on how you use the Services, we collect:
- Account and profile information, such as name, email address, authentication provider identifiers, organization, role, and preferences. Password authentication is handled by our authentication provider; MindGraph does not receive your plaintext password.
- Customer Content, such as documents, text, URLs, database metadata and selected records, messages, prompts, AI outputs, knowledge-graph records, citations, agent instructions and activity, connected-service data, support submissions, and feedback.
- Organization and collaboration information, such as memberships, invitations, roles, grants, API-key metadata, integration configurations, and audit or activity records.
- Transaction information, such as plan, credit balance, purchases, billing status, and transaction history. Our payment processor collects payment-card details directly; we do not store full card numbers.
- Communications, including support requests, research or design-partner inquiries, survey responses, email preferences, and messages we exchange with you.
- Usage and technical information, such as IP address, browser and device type, operating system, referring pages, pages viewed, feature activity, API requests, timestamps, error reports, approximate location derived from IP address, and security or diagnostic logs.
- Cookie and analytics information, including authentication cookies, local preferences, and interactions measured by analytics and marketing technologies described below.
Please do not submit payment-card data, government identifiers, protected health information, or other specially regulated information unless your plan and a written agreement with us expressly permit it.
3. Sources of information
We collect information directly from you; automatically from your browser, device, and use of the Services; from organization administrators and other users who invite or collaborate with you; from services you connect or authorize, including Google sign-in and configured data sources; and from service providers such as payment, analytics, and marketing partners. We may also receive business contact information from public sources or partners when you ask to hear from us.
4. How we use information
We use personal information to:
- create and secure accounts, authenticate users, and administer organizations, permissions, subscriptions, and credits;
- provide requested features, including ingestion, parsing, extraction, retrieval, AI chat, agent workflows, integrations, exports, and support;
- process Customer Content according to customer instructions and configurations;
- maintain, troubleshoot, analyze, and improve the safety, reliability, usability, and performance of the Services;
- measure usage, enforce limits, prevent fraud and abuse, and protect users, MindGraph, and third parties;
- send transactional messages, service notices, invitations, requested briefings, and support responses;
- send product or marketing communications where permitted, measure campaign performance, and honor opt-out choices;
- comply with law, enforce our agreements, and establish, exercise, or defend legal claims; and
- create aggregated or de-identified information that does not reasonably identify an individual.
5. AI processing
To provide AI features, we may send your prompts, relevant Customer Content, and attached files to AI infrastructure and model providers. Depending on the feature, this may include OpenRouter and model providers available through it, or other providers identified in the Services. We may also use specialized providers to parse documents or retrieve webpage content at your request.
MindGraph does not use Customer Content to train its own generalized AI models unless you separately and expressly agree. Third-party providers process information under their contracts, privacy terms, and the configurations applicable to our account. Avoid placing information in a prompt or connected source that you are not authorized to disclose.
6. How we disclose information
We may disclose personal information to:
- Infrastructure and operations providers, including Supabase for authentication and hosted data services, Vercel for the website and analytics, and Fly.io for cloud application hosting;
- AI and content-processing providers, including OpenRouter and selected model providers, LlamaParse for document parsing, and Firecrawl for webpage retrieval when those features are used;
- Business service providers, including Stripe for payment processing and Resend for email delivery;
- Analytics and marketing partners, including LinkedIn, to measure website use and signup campaigns;
- Your organization and integrations, including organization owners, administrators, members, agents, MCP servers, and third-party services you direct us to connect;
- Professional advisers and authorities when reasonably necessary for professional advice, legal compliance, safety, fraud prevention, or enforcement; and
- Transaction participants in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality protections.
We do not sell personal information for money. Our disclosure of identifiers and internet or network activity to analytics or marketing partners may be considered a "sale," "sharing," or targeted advertising under some laws. You may contact us to opt out where that right applies. We do not knowingly sell or share the personal information of anyone under 18.
7. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, maintain security, remember preferences, understand use of the Services, and measure marketing. Strictly necessary technologies are required for account and security functions. Analytics and marketing technologies may collect device identifiers, IP address, page views, and interactions.
You can control cookies through your browser and, where available, device or platform settings. Blocking necessary cookies may prevent sign-in or other features from working. We honor legally required opt-out requests; browser "Do Not Track" signals are not yet interpreted consistently across the industry.
8. Legal bases for European users
If European data-protection law applies, we process personal information under these legal bases:
- Contract to create your account, provide requested Services, process payments, and support you;
- Legitimate interests to secure and improve the Services, understand usage, communicate about the product, prevent abuse, and operate our business, where those interests are not overridden by your rights;
- Consent for activities where consent is required, such as certain marketing or non-essential tracking; you may withdraw consent prospectively; and
- Legal obligation and legal claims to comply with law and protect rights, safety, and property.
When we process Customer Content for a business customer, that customer determines the legal basis and we process the content on its documented instructions.
9. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including while your account or organization is active, and as needed for security, dispute resolution, legal compliance, tax and accounting duties, and enforcement. Retention varies by data type, sensitivity, customer configuration, and legal requirements.
Customer Content is generally retained until you or an authorized organization administrator deletes it or closes the applicable account, subject to reasonable backup cycles and legal holds. Security, billing, consent, and audit records may be kept longer when needed for legitimate business or legal purposes. We delete or de-identify information when it is no longer required.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authentication, encryption in transit, tenant and organization scoping, monitoring, and credential lifecycle controls where applicable. No internet service is completely secure, and we cannot guarantee absolute security. Protect your credentials and notify us promptly if you suspect unauthorized access.
11. Your rights and choices
Depending on where you live, you may have rights to know or access, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of targeted advertising, sale, or sharing; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
You can update some information in the Services, unsubscribe using the link in marketing emails, and delete graph content using available controls. To exercise another right, emailhello@mindgraph.cloud. Describe your request and the account or organization involved. We may verify your identity and authority, and may deny or limit a request where permitted by law. An authorized agent may submit a request where applicable, subject to verification.
If we process your information for a customer, contact that customer. If you are in the EEA, United Kingdom, or Switzerland, you may complain to your local data-protection authority. You may contact us first so we have an opportunity to address the concern.
12. International transfers
MindGraph and its providers operate in the United States and other countries. Your information may be transferred to and processed in countries whose laws differ from those where you live. Where required, we use recognized safeguards for international transfers, such as adequacy decisions or contractual protections.
13. Children
The Services are not directed to people under 18, and we do not knowingly collect personal information from them. If you believe a minor has provided personal information in violation of this Policy, contact us and we will take appropriate steps.
14. Changes to this Policy
We may update this Policy as our Services or legal obligations change. We will post the revised Policy and change the effective date. If a change materially affects how we use personal information, we will provide additional notice or obtain consent when required by law.
15. Contact us
The controller for account, website, billing, support, security, and marketing information is Syed Shan-E-Haider Rizvi. For privacy questions or requests, email hello@mindgraph.cloud. For the terms governing the Services, see our Terms of Use.