Your information. Clearly explained. Minds, Inc. Updated 14 September 2026 What Minds processes, why it is needed, and the choices you have. This notice covers the website, hosted workspace, Helm, and the services we operate. 1. Who this notice covers Minds, Inc., 2701 North Central Expy., Richardson, TX, operates Minds. In this notice, “Minds,” “we,” and “us” refer to that service provider. Contact privacy@minds.sh about this notice or your personal information. We determine how account, service administration, billing, support, and website information is used to operate our business. When your organization puts personal information into a Mind, we process that customer content to provide the service on its behalf. Your organization controls the purposes of that processing. Its privacy notice and any agreed data processing terms also apply. If you use Minds through an employer or another organization, its administrators may manage your access, integrations, and stored information. Direct requests about that organization’s content to it first; we can help it respond. Software you run entirely on your own infrastructure is under your control, except for information you send to hosted services or to us for support. 2. Information the service processes The information involved depends on the features you use and the integrations you enable. - Account and workspace information: name, email address, user and organization identifiers, profile information, membership, permissions, and account settings. - Customer content: Helm conversations, instructions, uploaded documents, memories, relationships, embeddings, retrieved passages, tool results, and other material you or your agents submit. Hosting and retrieving this information is a core part of Minds. - Instance and service information: instance identifiers, selected services, configuration, deployment state, API access records, usage measurements, and operational events. - Billing information: selected plans, subscriptions, checkout and transaction references, invoices, billing contact details, and usage used to calculate charges. Payment details entered into a payment provider’s checkout are handled under that provider’s terms and notice. - Technical information: network addresses, browser or device information, request and error details, access times, and security logs. Some records can include identifiers or request context. - Communications: information you send in support, sales, privacy, partnership, or other requests, including attachments you choose to share. 3. Why we use it We use information to create and secure accounts, authenticate users and agents, provision and operate Minds, respond to instructions, preserve and retrieve customer knowledge, provide support, measure usage, bill for the service, and communicate about your account. We also use operational information to diagnose faults, prevent abuse, improve service reliability, and meet legal obligations. Product analytics, where enabled, can help us understand which parts of the workspace people use and where a journey fails. Analytics events can be associated with account identifiers and profile information; they should not be understood as anonymous simply because they concern product usage. Where European or UK data protection law applies, our bases for processing our own business information include performing a contract or taking requested steps before one, legitimate interests in running and protecting the service, legal obligations, and consent where it is required. Where we act on your organization’s behalf, the organization is responsible for identifying its lawful basis and instructions. 4. Helm, agents, and model providers Helm can use your message, relevant memory, conversation context, and tool results to answer or carry out a request. An agent or integration that you authorize may read or change information within the permissions you give it. Check the context, permissions, and destination before connecting a service or sharing sensitive material. If a feature uses an external model or tool provider, the information needed for that request may be transmitted to that provider. The providers and routing can depend on your deployment and configuration. Their handling of requests is governed by the applicable provider arrangements and your organization’s configuration; a dedicated instance does not mean that all inference runs inside it. Under our Terms, we do not use Customer Data to train models we offer to other customers unless an Order expressly provides otherwise. Learning within your Mind and using external model services are different processing activities. Confirm the model provider’s own data handling requirements before sending restricted information. 5. When information is shared Information may be processed by service providers that support hosting, networking, identity, billing, communications, diagnostics, and other service functions. Our service provider page describes the roles to review. The applicable vendor, processing location, and contractual protections depend on the service and deployment. We share information with people, agents, and services you authorize; with your organization’s administrators where their role permits it; and with advisers or authorities when necessary to protect rights, address abuse, comply with law, or carry out a corporate transaction subject to appropriate protections. We do not make customer memory publicly available merely because it is stored in Minds. 6. Storage and international processing Hosted Minds involves both your dedicated instance and platform services that manage identity, workspace access, deployment, support, and billing. Those services may process information separately from your instance. A selected instance region alone does not establish the location of every category of account or operational data. If you require a particular region or a restriction on international transfers, agree that scope with us before submitting the affected information. Where required, the applicable agreement must identify a valid transfer mechanism and its scope. This notice does not itself execute Standard Contractual Clauses or guarantee that a particular transfer arrangement applies. 7. Retention and deletion Retention depends on the purpose of the record, your configuration, the terms of your account or Order, security and troubleshooting needs, and applicable legal requirements. Customer content is retained to provide the service until deleted through the relevant controls or handled under the applicable termination terms. Billing, dispute, security, or legally required records may need to be retained separately. Removing a conversation, deleting a memory, deleting an instance, and closing an account are different operations. A deletion in one area does not necessarily delete related exports, copies in connected services, or records that must be retained for another purpose. Backup expiry and restoration procedures also affect the completion of deletion. For a required retention period, deletion confirmation, or a coordinated account-level request, contact privacy@minds.sh. We will identify the relevant data and applicable handling rather than promise a single retention period for all information. The Terms and any executed agreement govern contractual export and deletion commitments. 8. Cookies, browser storage, and analytics Authentication and workspace preferences can use cookies or browser storage to maintain a session, protect sign-in flows, and remember your choices. Disabling necessary storage can prevent sign-in or other service functions from working. Depending on the surface and configuration, product analytics and diagnostic tools can receive page activity, technical events, and account identifiers. Embedded website experiences also make requests to their delivery providers. We do not describe every event as opt-in or every website visit as cookie-free. Your browser can block or clear site storage; your organization can ask us which analytics and diagnostics apply to its deployment. A provider’s technology appearing in our source or network policy is not by itself proof that it is enabled for every visitor. For current deployment-specific information or a privacy preference request, contact privacy@minds.sh. 9. Your choices and rights Depending on your location and the applicable law, you may have rights to access, correct, delete, or obtain a portable copy of personal information; restrict or object to certain processing; and withdraw consent where processing relies on it. These rights can be subject to exceptions and identity verification. Send requests to privacy@minds.sh from your account email where possible. Describe what you want to do and whether the information is in your own account or an organization’s Mind. Do not send a password or API key. We may ask for information necessary to verify your authority and locate the relevant records, and we will respond within the period required by applicable law. California residents may have additional rights to know categories and specific pieces of personal information, request correction or deletion, and opt out of qualifying sale or sharing, subject to the law’s applicability and exceptions. You may use an authorized agent subject to verification. We will not discriminate against you for exercising a protected privacy right. Contact us to make or clarify a request, including a request relating to sensitive information. You can raise a concern with us at privacy@minds.sh and, where applicable, complain to your local data protection authority. If information was submitted by one of our customers, we may refer your request to that customer and assist it under the applicable agreement. 10. Security and sensitive information We use safeguards appropriate to operating the service, and the Akasha engine offers controls for access, protected connections, and stored data. The protections that apply depend on deployment and configuration. No internet service can guarantee that a security incident will never occur. Do not submit information requiring a specific regulatory agreement, such as a healthcare business associate agreement, unless that agreement is in place and the relevant configuration has been confirmed. Product examples do not establish regulatory approval. Report suspected security issues privately to security@minds.sh. 11. Children Minds is intended for adults and organizations. The service is not directed to children, and the Terms require users to be at least 18. If you believe a child has provided personal information to us contrary to those requirements, contact privacy@minds.sh so we can investigate and take appropriate action. 12. Changes and contact We may update this notice as the service or applicable requirements change. We will revise the date above and provide additional notice where required. Questions and privacy requests go to privacy@minds.sh; agreement and data processing requests go to legal@minds.sh. Our published contracting name is Minds, Inc.