Back to home

Privacy Policy

Last updated 27 August 2026

Mindmate matches people through what they write, which means the writing matters and so does what happens to it. This page describes what is actually collected and where it actually goes — including the parts that are less comfortable to say.

Who this is

Mindmate is operated by Raj Singh, an individual based in India (“we”, “us”). For anything in this policy, write to rajsinghast03@gmail.com.

What we collect

  • Your email address. Used to sign you in and to send account email. It is never shown to another user, at any stage.
  • Your password, if you sign up with one. It is handled entirely by our authentication provider and never stored or seen by Mindmate’s own code. If you sign in with Google we receive your email address and name and nothing else — no additional permissions are requested.
  • Your display name, age, and a city. The city is chosen from a dropdown and stored as a label like “Bengaluru, Karnataka, India”, together with the matching timezone.
  • Your Curiosity Profile — the ~100 words you paste in. This is the heart of the service and is covered separately below.
  • Messages you send in conversations, and timestamps for when you last opened a conversation or the notification panel.
  • Reports and blocks you file, including any free-text explanation you write.

What we never collect

These are absences in the software, not promises of restraint:

  • No photographs or images. There is no upload of any kind, anywhere in the product. Your avatar is the first letter of your name.
  • No precise location. Your browser is never asked for your location. The city you pick comes from a list served by us; no mapping or location service is contacted.
  • No phone numbers or social handles. We do not ask, and the profile checker actively rejects email addresses, links, and phone numbers pasted into your Curiosity Profile.
  • No IP addresses, device fingerprints, or session recordings are logged by Mindmate’s code. There is no advertising pixel, no Google Analytics, no error-tracking SDK.
  • No marketing email, ever. The only messages we send are the signup confirmation, a resend of it if you ask, and a password reset.

How your writing is used

Two things happen to your Curiosity Profile text, and both involve sending it outside our own systems.

It is turned into a numeric vector so we can find people whose interests sit near yours. The text is sent to Google’s Gemini API for this, and what comes back is a list of numbers we store. This happens when you save your profile and again only if you change the text.

It is used to write the explanation of why two people match. To do that, your text and the other person’s text are sent together, in one request, to Google’s Gemini API. The result is the short summary, shared curiosity, and opening question you see on a suggestion card.

If Gemini is unavailable when that happens, the same request — the same two blocks of prose, nothing more — may go instead to OpenAI, on the deployments where a key is configured for it; where none is, the suggestion is simply not created. It is a standby, not a second copy: exactly one provider receives your text, and only one is asked. Turning your text into a vector, the first step above, never uses this standby.

Worth being direct about: that second step happens when a suggestion is created, which is before either of you has agreed to connect. So your writing may be sent in a request alongside the writing of someone you never meet. The request contains only the two blocks of prose — no names, ages, cities, email addresses, or account identifiers are included.

Your text is never used to train anyone’s model by us, and we do not sell or share it for advertising. What Google does with API requests is governed by their own terms.

What other people can see

Before you connect, someone who is suggested to you (or you to them) sees your display name, age, city, and the AI-written resonance text. They do not see your raw Curiosity Profile. That text is only revealed once you have both agreed to connect.

Your email address is never visible to another user. Neither is the numeric match score — it exists in the database but is never shown to anyone.

While you have a conversation open, the other person in that conversation can see that you are currently in it — shown as “Online” in that thread — and whether you are typing. That label means only that you have this one conversation open. It is limited to that thread, it stops the moment you leave, and it is not visible anywhere else: there is no account-wide online status, no presence on your profile or in Discover, and no “last seen” timestamp anywhere in the product.

Who else handles your data

Mindmate is built on a small number of services, each of which processes some of it:

  • Supabase — the database and the authentication system. Your profile, messages, and account live here.
  • Google (Gemini API) — receives Curiosity Profile text as described above. Nothing else is sent.
  • OpenAI — the standby for the same two steps, used only where a key is configured and only on the occasions Google is unavailable. It receives the same Curiosity Profile text and nothing else.
  • Resend — delivers the three account emails. It is configured as the mail relay for our authentication provider; Mindmate’s own code never contacts it.
  • Vercel — hosts the site and provides page-view counts. The analytics are cookieless and do not track you between websites. Before any measurement leaves your browser, conversation identifiers are replaced with a generic placeholder and the entire query string is discarded. As with any host, Vercel’s servers see the network request needed to deliver the page.

Cookies and browser storage

There is no cookie banner because there is nothing to consent to — we set no advertising or analytics cookies. What exists is:

  • A session cookie that keeps you signed in, set by our authentication provider.
  • A short-lived cookie lasting one hour that remembers which page to return you to after signing in.
  • Your draft profile, kept in your browser’s local storage while you are onboarding so that it survives the trip to your email and back. It is cleared when you save your profile, sign out, or delete your data.

Reports, blocks, and moderation

When you report someone we record who filed it, who it is about, the category, anything you write, and which conversation it came from. The person you report is never told who reported them and can never read the report.

So that this is not a surprise: when a conversation is reported, a moderator can read the messages in that conversation in order to act on it. Access is limited to an explicit list of addresses and is tied to the specific report — it is not a general ability to browse anyone’s messages. But it does mean private messages in a reported thread can be read by a person.

Blocking records only who blocked whom. No reason is stored, and the person you block is not notified.

Keeping and deleting your data

You can delete everything from your profile page. It is immediate and cannot be undone. It removes your profile, your account itself, your matches and the text written about them, your conversations, and the messages you sent — including ones already delivered to the other person. Blocks you created and reports filed about you go too.

One consequence we would rather state than hide: because reports about you are deleted along with your account, someone could clear a complaint against them by deleting their account and signing up again. We think making deletion genuinely complete is the right trade, but it is a real gap and you should know it exists.

A profile draft saved during signup but never completed stops being usable after 24 hours and is deleted automatically shortly afterwards. Otherwise we keep your data for as long as your account exists.

Your rights

Under India’s Digital Personal Data Protection Act, 2023, you can ask what personal data we hold about you, ask us to correct it, and ask us to erase it. Most of this you can do yourself: your profile page shows everything on your account, lets you edit it, and lets you delete it outright. For anything else, write to rajsinghast03@gmail.com and we will respond as quickly as we reasonably can.

Age

Mindmate is for adults aged 18 and over. We do not knowingly collect data from anyone younger. Age is self-declared at signup — we do not verify identity documents — so if you believe someone under 18 is using the service, please tell us and we will remove the account.

Changes to this policy

If this policy changes in a way that materially affects how your data is handled, the date at the top will change and, where the change is significant, we will tell you in the product. Continuing to use Mindmate after a change means you accept it.

Contact

Questions, requests, or corrections: rajsinghast03@gmail.com. See also our Terms of Service.