Effective Date: April 29, 2026
Welcome to MindLight,
At MINDLIGHT PROJECT – FZCO («Company», «we», «us», or «our»), we are committed to protecting your privacy and safeguarding your personal information. This Privacy Policy («Policy») explains how we collect, use, process, store, share, and protect your personal information when you use the MindLight service, including our iOS application (available via the Apple App Store), our Android application (available via Google Play), our website at https://www.mindlight.ae/
(«Website»), and all related services, features, and content (collectively, the «Service» or «Services»).
MindLight is a digital wellbeing, self-development, and personal growth platform that provides users with tools for mood tracking, journaling, productivity management, personalized guidance through an AI-powered chat assistant, and optional esoteric features (numerology).
We operate in compliance with the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data («UAE Data Protection Law»), and where applicable, with other
international data protection regulations including the EU General Data Protection Regulation
(GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), and other applicable privacy laws.
By accessing, downloading, installing, or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
Important Note About AI-Powered Wellbeing Services:
When you use MindLight to track your mood, maintain a personal diary, or engage with our AI chat assistant:
If you have any questions about this Privacy Policy or our data practices, please contact us at
This Privacy Policy applies to:
(a) All users of the MindLight Service, including users of our iOS app, Android app, and web
platform;
(b) All visitors to our Website;
(c) All individuals whose personal information we collect in connection with the Service;
(d) All processing of personal data by the Company in connection with the Service.
This Privacy Policy does not apply to:
(a) Information collected by third-party websites, applications, or services that you may access through links on our Service;
(b) Third-party payment processors’ collection and processing of payment card information (subject to their own privacy policies);
(c) Information processed by third-party AI providers solely on our behalf as data processors, except as described in this Policy.
By using the Service, you:
(a) Acknowledge that you have read and understood this Privacy Policy;
(b) Consent to the collection, use, and processing of your personal information as described herein;
(c) Agree to be bound by the terms of this Privacy Policy and our Terms of Service.
Where required by applicable law (including UAE Data Protection Law), we will obtain your separate, explicit consent for specific processing activities, including:
(a) Processing of Mood Data, Diary Entries, and AI Chat Messages (sensitive personal data concerning mental and emotional state);
(b) Processing of Optional Numerology Data (name, date of birth, gender – if you opt in to esoteric features);
(c) Transmission of AI Chat Messages to Third-Party AI Providers;
(d) Marketing communications;
(e) Use of non-essential cookies;
(f) Cross-border data transfers.
Your silence or inaction does not constitute consent.
The data controller responsible for your personal information is:
MINDLIGHT PROJECT – FZCO
Registration Number: 64926
Registered Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates
Email: hello@mindlight-app.com
Website: mindlight.ae
Support: hello@mindlight-app.com
For questions, requests, or complaints regarding data protection, you may contact our Data Protection Officer at:
Email: hello@mindlight-app.com
Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates
All payments for the app are made and processed exclusively through the app stores from which the app is distributed (Apple App Store and Google Play). Such processors act as independent data
controllers for payment card data and transaction processing, subject to their own privacy policies and applicable payment card industry standards (PCI DSS).
For the purposes of this Privacy Policy, the following terms have the meanings assigned below: «Mood Data» or «Wellbeing Data» means your self-reported evaluations of your emotional state, mood, or wellbeing, including historical tracking data and trends.
«Diary Data» or «Journal Data» means text-based personal notes, reflections, thoughts, and journal entries you create and store in the Service, including post-practice reflections.
«AI Chat Data» means your conversational messages, queries, prompts, and dialogue history with the AI-powered chat assistant, including the context and content of your discussions on personal topics, self-development, emotional state, relationships, and life circumstances.
«Life Sphere Diagnostics» means the evaluation and analysis of various areas of your life (such as career, relationships, health, finances, personal growth) based on your self-assessments, resulting in derived insights, scores, and reports.
«Personal Data» or «Personal Information» means any information relating to an identified or identifiable natural person («Data Subject»), including but not limited to name, email address, date of birth, mood ratings, diary entries, AI chat messages, IP address, device identifiers, and any other data that can directly or indirectly identify you, as defined under UAE Data Protection Law.
«Sensitive Personal Data» means personal data revealing emotional state, mental health,
psychological wellbeing, or other categories of special personal data as defined under UAE Federal Decree-Law No. 45 of 2021, GDPR Article 9, and other applicable data protection laws. In the context of MindLight, this includes Mood Data, Diary Data, AI Chat Data, and Life Sphere Diagnostics.
«Processing» means any operation or set of operations performed on personal data, whether
automated or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
«User Content» means any content, including mood ratings, diary entries, AI chat messages, task descriptions, habit names, goal statements, life sphere assessments, queries, prompts, or other
materials, that you input, submit, or otherwise provide to the Service.
«Generated Content» or «AI Responses» means text-based responses, insights, guidance, reflections, life sphere diagnostic reports, or other outputs created by the Service’s AI assistant in response to your inputs.
«Third-Party Data» means personal information (such as names, dates, details, or characteristics) of individuals other than the User, which the User may mention or input into the Service (e.g., in diary entries, AI chat conversations, or compatibility analyses).
«AI Provider» or «Third-Party AI Provider» means external providers of artificial intelligence technology, models, or APIs (including large language models) used by the Company to power the AI Chat Assistant and analytical features.
«Practices» means audio or text-based wellbeing sessions (such as meditations, affirmations,
breathing exercises, or guided reflections) provided through the Service.
«Cookies» means small text files or similar technologies stored on your device when you access the Service, used for authentication, preferences, analytics, and security.
«Cross-Border Data Transfer» means the transfer of personal data from one country or jurisdiction to another, including transfers outside the UAE.
«Data Breach» means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
«Profiling» means any form of automated processing of personal data to evaluate certain personal aspects relating to a natural person, including analyzing or predicting aspects concerning performance, emotional state, behavior, personal preferences, interests, or life sphere assessments.
We collect only the personal information necessary to provide and improve the Service, ensure
security, and fulfill our legal obligations. We collect information directly from you, automatically when you use the Service, and from third parties in limited circumstances.
In accordance with UAE Data Protection Law, we follow the principles of data minimization and purpose limitation – we collect only the data necessary for specific, legitimate purposes.
When you create an account or use the Service, we collect:
When you purchase a subscription or make a payment, we collect:
Important: We do not collect, store, or have access to your full payment card details (card number, CVV, expiration date). Payment processing is handled by third-party payment processors (Apple App Store and Google Play) who are PCI DSS compliant and act as independent data controllers for payment data.
When you use the mood tracking feature, we collect:
Critical Privacy Notice:
Mood Data may reveal information about your mental and emotional state and is considered Sensitive Personal Data under applicable laws. We process this data solely to provide you with tracking,
insights, and historical trends for self-reflection purposes. We do NOT use Mood Data for medical diagnoses, psychiatric assessments, or clinical evaluations. See Section 8 for detailed information.
When you use the personal diary/journal feature, we collect:
Critical Privacy Notice:
Diary Data is unstructured text input and may contain highly Sensitive Personal Data, including:
You input diary content entirely at your own discretion and risk. We strongly advise against including:
We do NOT read, review, or moderate your diary entries. Diary Data is encrypted and accessible only to you. We do NOT use Diary Data to train our AI models. See Section 8 for detailed information.
When you use the AI-powered chat assistant, we collect:
CRITICAL Privacy Notice – AI Chat Processing:
Sensitive Personal Data: AI Chat Data may contain Sensitive Personal Data about your emotional state, mental health, personal struggles, relationships, and life circumstances.
Third-Party Processing: Your AI chat messages are transmitted to third-party AI Providers located outside your country (typically in the United States) for processing via secure APIs.
What We Share with AI Providers:
NOT shared: Your email address, name, User ID, payment information, or unrelated User Content. AI Provider Commitments:
Retention: We retain your AI Chat history for up to 90 days (to provide conversational context). You may delete chat history at any time via app settings.
NOT Medical Advice: The AI chat assistant does NOT provide medical, psychiatric, or professional psychological advice. It is for informational, self-exploration, and entertainment purposes only. See Section 8 for comprehensive details about AI Chat processing.
When you use productivity features, we collect:
When you use the life sphere diagnostics feature, we collect:
Important – Profiling:
Life Sphere Diagnostics involves Profiling – the automated analysis of your inputs to generate insights about your life circumstances, priorities, and areas for improvement. This processing:
See Section 8 for detailed information.
When you use mindfulness practices (meditations, affirmations, breathing exercises), we collect:
If you explicitly opt in to numerology features, we additionally collect:
IMPORTANT – Separate Consent Required:
Numerology features are OPTIONAL and require separate, explicit consent.
By providing this data, you:
You may withdraw this consent at any time by disabling numerology features or deleting your
numerology data via app settings.
Numerology data is processed in accordance with Section 8 (sensitive and identifiable data
protections).
When you access the Service, we automatically collect:
To improve the Service and understand user behavior, we collect:
completed, habits tracked, goals set, practices completed);
This data is collected automatically through cookies, analytics tools (see Section 13), and our own logging systems.
When you contact us for support or send us messages, we collect:
If you consent to receive marketing communications, we may collect:
You can withdraw consent at any time by clicking «Unsubscribe» in marketing emails or updating your preferences in account settings.
In accordance with UAE Data Protection Law and data minimization principles, we do NOT
intentionally collect:
Important: If you voluntarily provide Sensitive Personal Data in your diary, AI chat messages, or other inputs (e.g., discussing health conditions, therapy, medications, spiritual beliefs), you
acknowledge that such data may be processed solely for generating your requested outputs and
providing the Service. We recommend minimizing such disclosures.
We collect personal information through the following methods:
You provide information directly when you:
(a) Register for an account or log in;
(b) Rate your mood or emotional state;
(c) Create diary or journal entries;
(d) Send messages to the AI chat assistant;
(e) Create tasks, set goals, or track habits;
(f) Complete life sphere diagnostic assessments;
(g) Access and use mindfulness practices;
(h) Opt in to numerology features and provide name or date of birth;
(i) Purchase a subscription or make a payment;
(j) Contact customer support or send us inquiries;
(k) Update your profile or account settings;
(l) Participate in surveys, contests, or promotions (if offered);
(m) Consent to receive marketing communications.
We collect information automatically when you use the Service through:
(a) Cookies and similar technologies (see Section 13);
(b) Server logs (recording IP addresses, timestamps, requests);
(c) Analytics tools (Amplitude);
(d) Mobile SDKs (software development kits embedded in our apps);
(e) Error and crash reporting tools (to diagnose technical issues).
We may receive information about you from:
(a) Third-party authentication providers: none. Accounts are created with an email address and a password; the app does not use third-party or social sign-in services.
(b) Payment processors (Apple App Store, Google Play):
(c) Third-party AI Providers (if they return metadata or processing status related to AI chat
responses).
(d) Analytics and advertising partners (aggregated or de-identified usage data).
We require all third parties to process your information lawfully and in accordance with applicable data protection laws.
Under UAE Federal Decree-Law No. 45 of 2021 and other applicable data protection laws, we process your personal information based on the following legal grounds:
We process your personal information to:
(a) Provide the Service you have requested;
(b) Create and manage your account;
(c) Process payments and subscriptions;
(d) Track your mood and provide historical insights;
(e) Store and secure your diary entries;
(f) Process your AI chat queries and provide AI-generated responses;
(g) Manage your tasks, habits, and goals;
(h) Generate life sphere diagnostic reports based on your assessments;
(i) Deliver mindfulness practices and track your usage;
(j) Process optional numerology data (if you opt in);
(k) Provide customer support;
(l) Fulfill our obligations under the Terms of Service.
Data categories: Account data, payment data, Mood Data, Diary Data, AI Chat Data, productivity data (tasks, habits, goals), Life Sphere Diagnostics, Practices data, optional numerology data,
Generated Content, device data, usage data.
We obtain your explicit, informed, and freely given consent to process:
(a) Sensitive Personal Data (Mood Data, Diary Data, AI Chat Data, Life Sphere Diagnostics) –
obtained when you:
(b) AI Chat transmission to Third-Party AI Providers – obtained when you:
(c) Optional Numerology Data (name, date of birth, gender) – obtained when you:
(d) Marketing communications (email);
(e) Non-essential cookies (analytics, marketing cookies);
(f) Cross-border data transfers (where required by law).
You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
We process your information to comply with:
(a) UAE laws and regulations (tax, accounting, anti-money laundering);
(b) Court orders, subpoenas, or lawful requests from authorities;
(c) Data protection laws (reporting data breaches, responding to data subject requests);
(d) Intellectual property laws (responding to copyright infringement notices).
Data categories: Account data, transaction data, communications, usage logs.
We process your information based on our legitimate interests, provided such interests do not override your fundamental rights and freedoms:
(a) Security and fraud prevention:
(b) Service improvement and development:
(c) Business operations:
(d) Legal claims:
Data categories: Usage data, device data, transaction data, communications.
We conduct balancing tests to ensure our legitimate interests do not override your privacy rights. You have the right to object to processing based on legitimate interests (see Section 12).
In exceptional cases, we may process your information to protect:
(a) Your life or physical safety;
(b) The life or physical safety of others.
This legal basis is rarely used and only in emergency situations.
We use your personal information for the following purposes, corresponding to the legal bases
described in Section 6:
You can opt out of marketing communications at any time by:
This section is critically important. Please read it carefully.
Under UAE Federal Decree-Law No. 45 of 2021, GDPR Article 9, and other applicable data protection laws, Sensitive Personal Data includes data revealing:
In the context of MindLight, the following data categories may constitute Sensitive Personal Data:
(a) Mood Data / Wellbeing Data:
Your self-reported mood ratings and historical tracking may reveal information about your mental and emotional state.
(b) Diary / Journal Data:
Your diary entries are unstructured text input and may contain:
(c) AI Chat Data:
Your conversations with the AI chat assistant may contain:
(d) Life Sphere Diagnostics:
Your self-assessments of life spheres (career satisfaction, relationship quality, health, etc.) and the resulting derived insights (profiling) may reveal sensitive information about your life circumstances, priorities, and psychological state.
Legal Basis:
We process Sensitive Personal Data based on:
Performance of contract – processing is necessary to provide the wellbeing, journaling, AI chat, and diagnostic services you have requested under our Terms of Service.
Processing Activities:
(a) Mood Data:
Storage: Securely encrypted and stored on our servers;
Retention: Until you delete it, or up to 30 days after account deletion (see Section 11);
Access: Accessible only to you (and our technical staff with strict access controls for support or troubleshooting);
Use: Displayed to you in charts, trends, and historical views. NOT used for profiling, automated decision-making, or training AI models.
(b) Diary Data:
Storage: Securely encrypted and stored on our servers;
Retention: Until you delete it, or up to 30 days after account deletion;
Access: Accessible only to you (we do NOT read, review, or moderate your diary entries);
Use: Displayed to you for personal reflection. NOT shared with third parties. NOT used to train AI models. NOT analyzed for marketing or profiling.
(c) AI Chat Data:
Processing Flow:
Storage: Encrypted and stored on our servers;
Retention: Up to 90 days (you may delete at any time via app settings);
Access: Accessible only to you (and technical staff for troubleshooting, with strict access controls); Use: Displayed to you to maintain conversational context. NOT used to train our general AI models.
(d) Life Sphere Diagnostics:
Processing: Your self-assessments are analyzed using algorithms to generate insights, scores, and recommendations;
Profiling: This processing constitutes Profiling (automated evaluation of personal aspects);
Storage: Encrypted and stored;
Retention: Until you delete it, or up to 30 days after account deletion;
Use: NOT used for automated decision-making that produces legal effects or similarly significantly affects you (prohibited under Article 18 of UAE Data Protection Law and GDPR Article 22);
Your Right: You may object to profiling at any time (see Section 12.6).
We do NOT and will NEVER:
(a) Sell, rent, or trade your Mood Data, Diary Data, AI Chat Data, or Life Sphere Diagnostics to third parties for monetary consideration;
(b) Use your Sensitive Personal Data for marketing or advertising (e.g., targeting ads based on your mood or diary content);
(c) Share your Diary Data with any third party (except as required by law – see Section 9.3);
(d) Use your Mood Data, Diary Data, or AI Chat Data to train our general AI models or for purposes unrelated to providing the Service to you;
(e) Provide medical, psychiatric, or professional psychological advice based on your data (see Section 8.4);
(f) Make automated decisions with legal effects based on profiling (e.g., credit decisions, employment decisions, insurance underwriting);
(g) Discriminate against you based on your Sensitive Personal Data;
(h) Disclose your Sensitive Personal Data to employers, insurers, law enforcement, or other third parties (except as strictly required by law – see Section 9.3 and 9.4).
CRITICAL DISCLAIMER:
MindLight, including all mood tracking, diary, AI chat, and life sphere diagnostic features, DOES NOT provide, and is NOT intended to provide:
All features, insights, and AI responses are for informational, self-exploration, and entertainment purposes only. They are NOT a substitute for face-to-face professional consultations with licensed healthcare providers, therapists, psychiatrists, or counselors.
If you are experiencing:
DO NOT USE THE SERVICE
Immediately:
The Company is NOT liable for any consequences arising from your use of or reliance on the Service in lieu of professional medical or psychological care.
IMPORTANT – Cross-Border Data Transfer:
When you use the AI chat assistant, your chat messages are transmitted to third-party AI Providers located outside your country for processing.
AI Provider Details:
(a) AI Provider Identity:
We use large language model (LLM) providers.
AI Providers are located primarily in the United States and may process data on servers in the USA, EU, or other jurisdictions.
(b) Data Shared with AI Providers:
What IS shared:
What is NOT shared:
(c) AI Provider Data Handling Commitments:
We select AI Providers based on their privacy and security practices and require them (contractually) to:
(d) Cross-Border Transfer Safeguards:
Transfers of AI Chat Data to AI Providers in the USA or other third countries are protected by:
(e) AI Provider Privacy Policies:
For more information, you may review AI Provider privacy policies.
However, we cannot guarantee AI Providers’ compliance. If you have specific concerns about
third-party processing, contact us at hello@mindlight-app.com or refrain from using the AI chat feature.
AI Chat is not a crisis oriented service. If AI Chat filters detect keywords related to self-harm, suicide, severe distress – AI Chat will automatically display the crisis message and will not process the query with the AI Provider. No records of such messages is retained.
You have the right to:
(a) Withdraw consent at any time by:
Withdrawal of consent does not affect the lawfulness of processing based on consent before
withdrawal.
(b) Access your Sensitive Personal Data (see Section 12.1);
(c) Rectify inaccurate Sensitive Personal Data (see Section 12.2);
(d) Erase or Delete your Sensitive Personal Data (see Section 12.3);
(e) Restrict processing of your Sensitive Personal Data (see Section 12.4);
(f) Data portability – receive your Sensitive Personal Data in a structured, machine-readable format (see Section 12.5);
(g) Object to processing based on legitimate interests or profiling (see Section 12.6);
(h) Lodge a complaint with the UAE Data Office or your local supervisory authority (see Section 12.8).
If you mention or include personal information of other individuals (names, details, characteristics) in your diary entries or AI chat messages, you represent and warrant that:
(a) You are providing this data for purely personal or household activities (e.g., personal journaling, self-reflection);
(b) You have obtained necessary consents from those individuals (where required by applicable law) or have another lawful basis for processing their data;
(c) You comply with applicable data protection laws governing third-party data.
Company’s Role:
We implement strict data minimization:
Your Responsibility:
You are solely responsible for:
You agree to indemnify and hold the Company harmless from any claims arising from your
unauthorized processing of third-party data (see Terms of Service, Section 16).
Profiling Disclosure:
In accordance with UAE Data Protection Law, Article 18, and GDPR Article 22, we disclose the following:
(a) Profiling Occurs:
The Life Sphere Diagnostics feature involves Profiling – automated analysis of your self-assessments to generate insights about your life circumstances, priorities, and areas for improvement.
(b) No Legal Effects or Similarly Significant Effects:
This profiling DOES NOT constitute automated decision-making that produces legal effects
concerning you or similarly significantly affects you within the meaning of Article 18 of UAE Data Protection Law or GDPR Article 22.
Specifically, we do NOT use profiling to:
(c) Purpose of Profiling:
Profiling is conducted solely to:
(d) Your Rights:
You have the right to:
We do not sell, rent, or trade your personal information to third parties. We share your information only in the limited circumstances described below, and only to the extent necessary to provide the Service, comply with law, or protect our rights.
We engage third-party service providers to perform functions on our behalf, acting as data
processors under our instruction:
(a) Cloud Infrastructure and Hosting:
(b) Payment Processing:
(с) AI and Machine Learning Providers:
(d) Analytics and Performance Monitoring:
(e) Customer Support:
(f) Email and Communications:
All service providers are contractually bound to:
If we are involved in a merger, acquisition, reorganization, sale of assets, bankruptcy, or similar business transaction, your personal information may be transferred to the successor entity, subject to:
(a) Notification to you via email and/or prominent notice on the Website;
(b) Same or equivalent privacy protections as provided in this Privacy Policy;
(c) Option to delete your account before the transfer (if you do not consent).
We may disclose your personal information if required to do so by law or in response to:
(a) Court orders, subpoenas, warrants, or legal processes;
(b) Lawful requests from government authorities, regulators, or law enforcement agencies;
(c) National security or public safety requirements;
(d) UAE Data Office requests (under Article 24 of UAE Data Protection Law).
We will:
We may disclose your information to:
(a) Enforce our Terms of Service and other agreements;
(b) Detect, prevent, or investigate fraud, security breaches, or illegal activity;
(c) Protect life or physical safety (yours, ours, or that of others) – for example, If you disclose
imminent risk of self-harm or harm to others in AI chat or diary, and we determine immediate action is necessary, we may disclose relevant information to emergency services or authorities;
(d) Establish, exercise, or defend legal claims in litigation or arbitration.
Note: We do NOT proactively monitor or review your Diary Data or AI Chat messages. Disclosure under this Section would occur only in exceptional circumstances where we become aware of
imminent risk.
We may share your information with third parties for purposes not described in this Privacy Policy if we obtain your explicit consent.
We may share anonymized and aggregated data that cannot identify you individually with:
(a) Business partners for analytics or research;
(b) Advertisers or marketing partners (aggregate usage statistics);
(c) Academic researchers (for publications or studies);
(d) The public (in reports, presentations, or blog posts).
This data is not considered personal information under data protection laws.
The Company is located in the United Arab Emirates. When you use the Service, your personal information may be transferred to, stored in, and processed in:
(a) The United Arab Emirates (where the Company is based);
(b) The United States (where cloud infrastructure providers are located);
(c) The European Union (where some service providers are located);
(d) Other countries where our service providers operate.
Some of these countries may not provide the same level of data protection as your country of
residence.
In accordance with UAE Federal Decree-Law No. 45 of 2021, Articles 22 and 23, we ensure that cross-border data transfers are protected by appropriate safeguards:
(a) Adequacy Decisions (Article 45 GDPR):
Where applicable, we rely on adequacy decisions issued by the European Commission, such as the EU-U.S. Data Privacy Framework (DPF), when transferring personal data to certified service
providers located in the United States.
(b) Standard Contractual Clauses (Article 46 GDPR):
For transfers to countries without an adequacy decision (including transfers from the EU to the UAE), we implement appropriate safeguards, primarily relying on the standard data protection clauses (SCCs) adopted by the European Commission, coupled with supplementary technical and organizational measures (such as robust encryption).
(c) Additional Safeguards:
We implement supplementary measures, including:
(d) Your Consent:
For certain transfers (e.g., to AI providers in third countries), we obtain your explicit consent by:
You have the right to:
(a) Object to transfers to specific countries or providers;
(b) Request information about the safeguards protecting your data;
(c) Obtain a copy of the Standard Contractual Clauses or other transfer mechanisms.
If you object to cross-border transfers, we may be unable to provide certain features of the Service.
(a) AI Processing via Third-Party APIs:
When you use the AI chat assistant, your chat messages may be transmitted to third-party AI Providers located in the United States.
This transfer is:
(b) Cloud Storage:
Your account data, User Content, and Generated Content are stored on servers operated by cloud providers located primarily in:
We select data center locations to optimize performance and comply with data localization
requirements where applicable.
We retain your personal information only for as long as necessary to:
(a) Provide the Service and fulfill the purposes described in this Privacy Policy;
(b) Comply with legal, tax, accounting, or regulatory obligations;
(c) Resolve disputes and enforce our agreements;
(d) Protect our legal rights and defend against claims.
After the retention period expires, we delete or anonymize your personal information in accordance with UAE Data Protection Law, Article 5(7).
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Data (email, User ID, password) | Duration of account + 90 days after deletion | Provide Service, allow account recovery, prevent abuse |
| Mood Data (ratings, history) | Until you delete it, or 30 days after account deletion | Provide Service, user access, historical insights |
| Diary Data (journal entries) | Until you delete it, or 30 days after account deletion | Provide Service, user access, personal reflection |
| AI Chat History | Up to 90 days (you may delete earlier via app settings) | Provide conversational context, improve AI responses |
| User Content (tasks, habits, goals, life diagnostics) | Until you delete it, or 30 days after account deletion | Provide Service, user access |
| Practices Usage Data | 90 days to 2 years (depending on type) | Analytics, service improvement |
| Optional Numerology Data (name, DOB, gender) | Until you delete it, or 30 days after account deletion | Provide numerology features (if opted in) |
| Generated Content (AI responses, reports) | Until you delete it, or 30 days after account deletion | Provide Service, user access |
| Third-Party Data (mentioned in diary or chat) | Until you delete the entry, or 30 days after account deletion | Provide Service, comply with data subject rights |
| Transaction Data (payments, subscriptions) | 7 years from transaction date | Legal obligation (tax, accounting), fraud prevention |
| Support Communications (emails, tickets) | 3 years from last message | Customer support, legal claims |
| Usage and Analytics Data (logs, sessions, clicks) | 90 days to 2 years (depending on type) | Service improvement, security, fraud detection |
| Marketing Consent Records | 3 years from withdrawal of consent | Legal obligation (proof of consent) |
| Cookies | See Section 13 (varies: session to 2 years) | Functionality, analytics, marketing |
When retention periods expire or you request deletion, we:
(a) Permanently delete your data from active systems;
(b) Delete backup copies within 90 days (backups are retained temporarily for disaster recovery);
(c) Anonymize data used in aggregated analytics (so it can no longer identify you);
(d) Securely destroy physical copies (if any).
Deletion is irreversible and you will not be able to recover data after it is deleted.
We may retain data longer than the standard retention period if:
(a) Required by law (e.g., litigation hold, regulatory investigation);
(b) Necessary for legal claims (until the claim is resolved);
(c) You have requested (e.g., to preserve evidence for a dispute);
(d) Anonymized (anonymized data is no longer personal data and may be retained indefinitely).
Under UAE Federal Decree-Law No. 45 of 2021 and other applicable data protection laws, you have the following rights regarding your personal information:
You have the right to obtain:
(a) Confirmation of whether we are processing your personal information;
(b) Access to your personal information;
(c) Information about the processing, including:
How to exercise: Email us at hello@mindlight-app.com or access your account settings. We will respond within 15 working days (or as required by applicable law).
You have the right to:
(a) Correct inaccurate personal information;
(b) Complete incomplete personal information.
How to exercise: Update your information in account settings or contact us at
You have the right to request deletion of your personal information if:
(a) The data is no longer necessary for the purposes for which it was collected;
(b) You withdraw consent (where processing is based on consent);
(c) You object to processing (see Section 12.6);
(d) The data has been unlawfully processed;
(e) Deletion is required by law.
Exceptions: We may refuse deletion if retention is necessary for:
How to exercise: Delete your account in app settings or contact us at hello@mindlight-app.com. We will delete your data within 30 days (except as noted in Section 11).
You have the right to request that we restrict processing (i.e., stop using but continue storing) your data if:
(a) You contest the accuracy of the data (restriction applies while we verify);
(b) Processing is unlawful but you prefer restriction over deletion;
(c) We no longer need the data, but you need it for legal claims;
(d) You object to processing (restriction applies while we verify our legitimate grounds).
How to exercise: Contact us at hello@mindlight-app.com.
You have the right to:
(a) Receive your personal information in a structured, commonly used, machine-readable format;
(b) Transmit the data to another service provider (where technically feasible).
This right applies only to data:
How to exercise: Request a data export by emailing hello@mindlight-app.com. We will provide your data within 30 days.
Data included in export:
You have the right to object to processing based on:
(a) Legitimate interests (Section 6.4) – we will stop unless we demonstrate compelling legitimate grounds that override your rights;
(b) Direct marketing – we will stop immediately (opt-out links are provided in all marketing emails);
(c) Profiling or automated decision-making – we will stop or provide human review.
How to exercise: Click «Unsubscribe» in marketing emails, adjust account settings, or contact us at hello@mindlight-app.com.
Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. In accordance with Article 7(3) of the GDPR, we ensure that it is as easy to withdraw your consent as it is to give it. How to exercise:
You have the right to lodge a complaint with the UAE Data Office if you believe we have violated your privacy rights:
UAE Data Office
Website: https://u.ae/en/about-the-uae/digital-uae/data
Phone: +97126118229
You may also lodge a complaint with the supervisory authority in your country of residence (if
different from the UAE), such as:
To exercise any of the above rights:
(a) Contact us at:
(b) Include in your request:
(c) Verification:
We may request additional information to verify your identity (to prevent unauthorized access). We will not use information provided in a request for any other purpose.
(d) Response time:
(e) Fees:
We do not charge a fee for exercising your rights, unless your request is manifestly unfounded or excessive (e.g., repetitive requests). In such cases, we may charge a reasonable administrative fee or refuse the request.
Your rights are not absolute. We may deny or limit requests if:
(a) Legal obligation: Processing is required by law;
(b) Public interest: Processing is necessary for public health, safety, or vital interests;
(c) Legal claims: Data is needed to establish, exercise, or defend legal rights;
(d) Trade secrets: Disclosure would reveal confidential business information;
(e) Rights of others: Your request would adversely affect others’ rights.
We will inform you of any denial and the reasons, and you may challenge our decision with the UAE Data Office or applicable supervisory authority.
Cookies are small text files placed on your device (computer, phone, tablet) when you visit a website or use an app. Cookies allow the service to recognize your device, remember your preferences, and provide personalized experiences.
We also use similar technologies such as:
(a) Strictly Necessary Cookies (Essential)
Purpose: Enable basic functionality of the Service, the Service cannot function without them.
Examples:
Legal basis: Legitimate interest (necessary to provide the Service).
Retention: Session (deleted when you close browser) or up to 30 days.
Consent required: No (essential for Service operation).
(b) Functional Cookies
Purpose: Remember your preferences and choices to enhance your experience.
Examples:
Legal basis: Legitimate interest or consent (depending on jurisdiction).
Retention: Up to 1 year.
Consent required: In some jurisdictions (e.g., EU, UK).
(c) Analytics and Performance Cookies
Purpose: Understand how users interact with the Service, measure performance, identify errors. Examples:
Data collected: user behavior, device type, OS, pages visited, clicks and session duration, linked to your internal user identifier (NOT Mood Data, Diary Data, or AI Chat Data).
Legal basis: Consent (required in EU, UK, California).
Retention: as configured with the analytics provider.
Opt-out:
(d) Marketing and Advertising Cookies
Purpose: Deliver targeted advertising, measure ad effectiveness, build user profiles for marketing. Examples:
Legal basis: Explicit consent required (EU, UK, California).
Retention: Up to 2 years.
Opt-out:
Note: We currently do not use marketing/advertising cookies, but may do so in the future with your consent.
(a) Consent Banner:
When you first visit our Website or use the Service, we display a cookie consent banner allowing you to:
Your choice is saved for 12 months.
(b) Changing Your Preferences:
You can change your cookie preferences at any time by:
(c) Browser Controls:
Most browsers allow you to:
Browser instructions:
Note: Blocking essential cookies may prevent you from using certain features of the Service.
(d) Mobile App Tracking:
On mobile devices, you can:
Some browsers offer a «Do Not Track» (DNT) signal. We currently do not respond to DNT signals because there is no industry standard for how to interpret them. We will update this Policy if we adopt a DNT protocol in the future.
For a detailed list of cookies used on our Website and in our apps, including cookie names, providers, purposes, and expiration periods, please visit our Cookie Policy or contact us at
We take the security of your personal information seriously. We implement appropriate technical and organizational measures to protect your data against:
(a) Unauthorized or unlawful access;
(b) Accidental loss, destruction, or damage;
(c) Alteration or disclosure;
(d) Cyberattacks (hacking, malware, ransomware);
(e) Data breaches.
Our security measures are designed to comply with UAE Federal Decree-Law No. 45 of 2021, Articles 7 and 20, as well as international best practices.
(a) Encryption:
(b) Access Controls:
(c) Network Security:
(d) Application Security:
(e) Data Minimization and Pseudonymization:
feasible, with encryption keys managed separately.
(a) Policies and Procedures:
(b) Training:
necessary for troubleshooting (with user consent).
(c) Vendor Management:
measures.
(d) Incident Response:
In accordance with UAE Data Protection Law, Article 9, if a data breach occurs that is likely to result in a risk to your rights and freedoms, we will:
(a) Notify the relevant supervisory authorities (including the UAE Data Office and/or competent EU authorities) without undue delay, and where subject to the GDPR, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to your rights;
(b) Notify affected users via email and/or in-app notification, including:
(c) Document the breach and remedial actions taken.
We will also comply with breach notification requirements under GDPR, CCPA, and other applicable laws.
While we implement robust security measures, the security of your information also depends on you:
(a) Protect your password:
(b) Secure your device:
(c) Beware of phishing:
(d) Log out:
(e) Report suspicious activity:
No security system is impenetrable. While we strive to protect your information using
industry-standard measures, we cannot guarantee absolute security. You acknowledge and accept the inherent risks of transmitting data over the internet.
In the event of a data breach despite our safeguards, our liability is limited as set forth in our Terms of Service, Section 16.
The Service may contain links to third-party websites, applications, or services (e.g., social media platforms, payment processors, external resources, wellbeing content providers). This Privacy Policy does NOT apply to third-party services. We are NOT responsible for the privacy practices or content of third parties. We encourage you to review the privacy policies of any third-party services you access.
We use third-party AI models and APIs to power our AI chat assistant feature. When you send chat messages, your data may be transmitted to Third-Party AI Providers, including but not limited to:
(a) Large language model providers;
(b) Specialized AI content generation services.
See Section 8.5 for comprehensive details about AI Provider data handling.
When using AI chat, the following data may be sent to AI Providers:
What IS shared:
What is NOT shared:
We select AI Providers based on their privacy and security practices and require them (contractually) to:
(a) Process data only for generating AI responses (not for their own purposes);
(b) NOT use your chat messages to train their general AI models:
We utilize enterprise API endpoints with «Zero Data Retention» and «Opt-Out from Training» policies enabled;
Your chat data is excluded from AI Provider training datasets per our Data Processing Agreements.
(c) Delete your chat messages immediately after processing (typically within seconds or minutes);
(d) Implement robust security measures:
(e) Comply with applicable data protection laws (GDPR, CCPA, UAE Data Protection Law).
However, we cannot guarantee AI Providers’ compliance. We recommend reviewing AI Providers’ privacy policies if you have specific concerns:
By using the AI chat assistant feature of the Service, you:
(a) Consent to the transmission of your chat messages to third-party AI Providers as described above;
(b) Acknowledge that AI processing may involve cross-border data transfers (see Section 10);
(c) Understand that AI-generated responses are inherently unpredictable and may contain errors, inaccuracies, or inappropriate content («hallucinations»);
(d) Accept that AI Providers may be located in jurisdictions outside your country of residence
(typically the United States).
If you do not consent to AI processing via third-party providers, you should not use the AI chat assistant feature.
If you choose to:
(a) Share Generated Content (Reports) on social media:
We use third-party analytics platforms (see Section 13.2(c)) such as:
(a) Amplitude (privacy policy: https://amplitude.com/privacy).
These platforms may collect data about your device and usage for analytics purposes. You can opt out via browser settings or platform-specific opt-out mechanisms.
The Service is not intended for use by individuals under 18 years of age (or the age of majority in your jurisdiction, whichever is greater).
In accordance with our Terms of Service (Section 3), we do not knowingly:
(a) Collect personal information from children under 18;
(b) Allow children under 18 to create accounts or use the Service;
(c) Target marketing or advertising to children.
We do not have mechanisms for obtaining parental consent for children’s use of the Service because the Service is age-restricted and children are prohibited from using it.
If we become aware that we have inadvertently collected personal information from a child under 18, we will:
(a) Delete the data as soon as reasonably practicable (within 30 days);
(b) Terminate the account (if any);
(c) Take steps to prevent future access by the child.
If you are a parent or guardian and you discover that your child has provided personal information to us:
(a) Contact us immediately at hello@mindlight-app.com;
(b) We will delete the child’s data and account promptly.
We comply with:
(a) UAE Data Protection Law (no special provisions for children, but general prohibition applies);
(b) GDPR (Article 8: minimum age for consent is 16, or lower as set by Member States);
(c) COPPA (USA) (Children’s Online Privacy Protection Act: applies to children under 13);
(d) UK GDPR and other applicable children’s privacy laws.
Our blanket prohibition on use by individuals under 18 exceeds the requirements of most children’s privacy laws.
We reserve the right to update, modify, or replace this Privacy Policy at any time to:
(a) Reflect changes in our data practices;
(b) Comply with new legal requirements;
(c) Introduce new features or services;
(d) Improve clarity or transparency.
When we make material changes to this Privacy Policy, we will notify you by:
(a) Posting the updated Privacy Policy on the Website and in the Service;
(b) Updating the «Effective Date» and «Last Updated» date at the top of this Policy;
(c) Sending an email to the email address associated with your account (for material changes);
(d) Displaying an in-app notification or banner (for material changes);
(e) Requiring re-acceptance (if required by law).
Material changes include (but are not limited to):
(a) Expansion of the purposes for which we process personal information;
(b) Addition of new categories of personal information collected (especially Sensitive Personal Data);
(c) Changes to the legal basis for processing;
(d) Introduction of new third-party recipients or cross-border transfers;
(e) Changes to your rights or how to exercise them;
(f) Changes to retention periods or security measures.
By continuing to use the Service after the updated Privacy Policy becomes effective, you accept the changes.
If you do not agree to the updated Privacy Policy:
(a) Stop using the Service;
(b) Delete your account before the effective date of the changes (to avoid being bound);
(c) Contact us at hello@mindlight-app.com if you have questions or concerns.
We encourage you to review this Privacy Policy periodically (at least every 6-12 months) to stay informed about how we protect your information.
If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact us:
MINDLIGHT PROJECT – FZCO
Registration Number: 64926
Registered Address: [●]
Email: hello@mindlight-app.com
Support: hello@mindlight-app.com
Website: mindlight.ae
For privacy-specific inquiries or to exercise your data subject rights, contact our Data Protection Officer:
Email: hello@mindlight-app.com
Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates
We will acknowledge your inquiry within 3 business days and provide a substantive response within:
(a) 10 working days (extendable by 5 days) under UAE Data Protection Law;
(b) 1 month (extendable by 2 months for complex requests) under GDPR;
(c) 45 days (extendable by 45 days) under CCPA;
(d) Such other period as required by applicable law.
If you are not satisfied with our response or believe we have violated your privacy rights, you may lodge a complaint with:
UAE Data Office
Website: https://u.ae/en/about-the-uae/digital-uae/data
Phone: +97126118229
And/or the supervisory authority in your jurisdiction (see Section 19 for regional contacts).
This Section provides additional information for users in specific jurisdictions with enhanced privacy protections.
(a) Legal Basis for Processing
See Section 6 for our legal bases under GDPR/UK GDPR. We process your data based on:
For Sensitive Personal Data (Mood Data, Diary Data, AI Chat Data, Life Sphere Diagnostics), we rely on:
(b) Your Rights
See Section 12. You have enhanced rights under GDPR, including:
(c) Supervisory Authorities
EU Member States:
Each EU country has a data protection authority.
Find yours at: https://edpb.europa.eu/about-edpb/board/members_en
United Kingdom:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk
Phone: +44 303 123 1113
Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
Website: https://www.edoeb.admin.ch
Email: info@edoeb.admin.ch
(d) International Data Transfers
Transfers from the EEA, UK, Switzerland to the UAE or USA are protected by:
See Section 10 for details.
(e) GDPR Representative (EU/UK/CH)
As we are established outside the European Union and the United Kingdom, we have appointed a designated representative pursuant to Article 27 of the GDPR and the UK GDPR. Supervisory
authorities and data subjects in the EU and UK may address our Representative, in addition to or instead of the Company, on all issues related to processing to ensure compliance with the GDPR. Please direct all such inquiries to:
Email: hello@mindlight-app.com
Note: We act as our own point of contact for GDPR compliance pending formal designation of a third-party representative, if legally required based on processing scale.
(a) California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act).
(b) Personal Information Collected
In the past 12 months, we have collected the following categories of personal information:
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email, IP address, User ID | Yes |
| Commercial information | Purchase history, subscription status | Yes |
| Internet/electronic activity | Browsing history, clicks, usage data | Yes |
| Geolocation data | Approximate location (city/country from IP) | Yes (approximate only) |
| Biometric information | NOT collected | No |
| Professional and employment info | N/A | No |
| Education info | N/A | No |
| Inferences | Preferences, characteristics derived from usage | Yes (limited) |
| Sensitive personal information | See below | Limited |
Sensitive Personal Information (SPI) under CPRA:
We collect the following SPI:
We do not collect:
(c) Sources of Personal Information
See Section 5:
(d) Purposes of Use
See Section 7. We use personal information for:
(e) Disclosure to Third Parties
In the past 12 months, we have disclosed the following categories of personal information to third parties:
We do not sell your personal information for monetary consideration. However, we may «share» certain identifiers and internet activity information with our advertising partners for cross-context behavioral advertising purposes (e.g., through marketing cookies). You have the absolute right to opt-out of this sharing by clicking the link in our footer or broadcasting a GPC signal.
(f) Retention
See Section 11.
(g) Your California Rights
1. Right to Know:
You have the right to request:
2. Right to Delete:
You have the right to request deletion of your personal information, subject to exceptions (legal obligations, fraud prevention, etc.).
3. Right to Correct:
You have the right to request correction of inaccurate personal information.
4. Right to Opt-Out of Sale and Sharing:
We do not sell personal information. We do not share personal information for cross-context
behavioral advertising. Therefore, no opt-out is required.
Our Website is configured to detect and honor Global Privacy Control (GPC) signals and similar opt-out preference signals sent by your browser. If we receive a GPC signal, we will automatically treat it as a valid request to opt-out of the «sale» and «sharing» of your personal information for cross-context behavioral advertising.
5. Right to Limit Use of Sensitive Personal Information:
You have the right to limit our use of Sensitive Personal Information (SPI) to:
We already limit use of SPI to these purposes. If you wish to object, contact us at
6. Right to Non-Discrimination:
We will not discriminate against you for exercising your California privacy rights (e.g., we will not deny service, charge different prices, or provide different quality of service).
How to Exercise Your Rights:
You may also authorize an agent to submit a request on your behalf. The agent must provide proof of authorization.
Verification:
To protect your privacy, we will verify your identity by:
Response Time:
We will respond within 45 days (extendable by 45 days for complex requests).
Right to Limit the Use of Sensitive Personal Information
We process your Sensitive Personal Information solely to perform the services reasonably expected by you and we do not use it to infer characteristics about you. Therefore, the statutory
right to limit such use is already satisfied by our strict processing and immediate deletion
policies.
(h) California «Shine the Light» Law
California Civil Code Section 1798.83 allows California residents to request information about
disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
(i) Contact for California Residents
Email: hello@mindlight-app.com
Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates California Attorney General (for complaints):
Website: https://oag.ca.gov/privacy
Phone: (916) 210-6276
(a) Applicability
If you are a Canadian resident, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).
(b) Valid and Meaningful Consent:
In accordance with Section 6.1 of PIPEDA and Principle 3, we ensure that our request for your consent is clear and understandable. By using our AI generation features, you acknowledge that you
understand the nature, purpose, and consequences of the collection, use, and disclosure of your
personal information (including temporary processing of Biometric Data). You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice.
(c) Cross-Border Transfers
Your data may be stored on servers in the USA or UAE. By using the Service, you consent to such transfers. We implement safeguards (see Section 10).
(d) Your Rights
You have the right to:
How to exercise: Contact us at hello@mindlight-app.com.
(e) Accountability and Privacy Officer
In accordance with Principle 1 of PIPEDA (Accountability), we have designated a Privacy Officer who is accountable for our compliance with Canadian privacy principles. Our global Data Protection Officer serves in this capacity for Canadian users.
Email: hello@mindlight-app.com
Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates
(f) Complaints
If you have a privacy complaint, contact our Privacy Officer (above). We will investigate and respond within 30 days.
If you are not satisfied, you may complain to:
Office of the Privacy Commissioner of Canada
Website: https://www.priv.gc.ca
Toll-free: 1-800-282-1376
Phone: 819-994-5444
TTY: 819-994-6591
Email: info@priv.gc.ca
(g) Breach of Security Safeguards (RROSH)
In compliance with Division 1.1 (Section 10.1) of PIPEDA, we will report to the Privacy
Commissioner of Canada and notify you of any breach of security safeguards involving your personal information if it is reasonable in the circumstances to believe that the breach creates a «real risk of significant harm» (RROSH) to you, such as identity theft, financial loss, or damage to reputation. We also maintain a record of all breaches in accordance with Section 10.3 of PIPEDA.
If you are located in a jurisdiction not specifically addressed above (e.g., Brazil, Japan, South Korea, India, etc.), we will comply with applicable local data protection laws to the extent they apply to our processing activities.
For jurisdiction-specific questions, contact us at hello@mindlight-app.com.
This Privacy Policy is drafted in English. If we provide translations into other languages, the English version shall prevail in the event of any conflict or ambiguity.
If any provision of this Privacy Policy is found to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect.
Our failure to enforce any right or provision of this Privacy Policy shall not constitute a waiver of such right or provision.
This Privacy Policy, together with our Terms of Service and any other policies referenced herein, constitutes the entire agreement between you and the Company regarding the processing of your personal information.
Sections that by their nature should survive termination of your use of the Service (e.g., data retention, your rights, limitations of liability, dispute resolution) shall survive.
By using MindLight, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
MINDLIGHT PROJECT – FZCO
Registration Number: 64926
Registered Address: Dubai Silicon Oasis DSO-IFZA, IFZA Properties, Dubai, PO Box 34, United Arab Emirates
Email: hello@mindlight-app.com
Website: mindlight.ae
Support: hello@mindlight-app.com
Last Updated: April 29, 2026