Back to home

Privacy policy

Draft dated 14 September 2026. This is not an approved legal document.

Controller and outstanding details

MindFind connects patients with verified psychology professionals through search, profiles, appointments and chat. The app is in development. This presentation website offers no registration or forms and its code includes no third-party analytics. Processing of hosting technical logs is [PENDIENTE] confirmation.

Account and authentication: email, identifier, role, display name, avatar and optional contact and location details. Preferences: reasons for seeking support, session format, budget, languages, area, availability and expectations. Professionals: public profile, registration details, private credential documents, practice address, schedules and verification status.

Records cover bookings, changes, cancellations, participants, session format and price; conversations, messages and read status; saved profiles, feedback, notification preferences and device tokens. Profile visits are measured per patient, professional, UTC day and source; professionals see aggregates. If follow-up is enabled, records include consented relationships, activities, goals, resources, contributions and shared preparation, as well as private professional notes. These texts may contain sensitive information.

The design uses this data to manage accounts and verification, find professionals, book, communicate, share follow-up, and handle notifications, exports and deletion requests. Verified published profiles are public; appointments and chats are limited to participants. Private drafts and notes do not appear in patient lists or ordinary exports. Controller and processor roles, legal grounds for each purpose and health data processing are [PENDIENTE] legal review.

The backend uses Supabase for authentication, database, files and real-time updates. OpenAI is planned for optional AI features. Processing agreements, subprocessors, actual regions, transfers and applicable safeguards: [PENDIENTE]. No claim is made that all data stays within a particular region.

Assisted search requires explicit acceptance of a versioned notice before sending the message and draft preferences to OpenAI; the form remains available. The person reviews and confirms preferences. Note assistance sends the version or fields selected by the professional and returns a private draft that is never published automatically. Consent requirements and the legal basis for this feature are [PENDIENTE]. Free text may contain identifiers. The planned configuration does not save responses for later retrieval in the API, but does not establish zero provider retention. AI remains disabled according to available verification; it does not provide therapy or diagnoses.

General account deletion is scheduled after 14 days: it unpublishes the professional and cancels their future appointments; explicitly signing in before the deadline cancels deletion without restoring those appointments or republishing the profile. This period does not authorise purging care documentation. Where follow-up or notes exist, purging remains blocked until a retention policy is approved and implemented. The design specifies 30 days for matching sessions/exposures, 2 days for quotas and 24 hours for private AI proposals; these expiries require the relevant worker and do not apply to confirmed notes. Other periods, backups and exceptions: [PENDIENTE].

The app lets you request an export and download the private result once processing is complete; email delivery is not promised. Professionals export their own notes. A patient’s ordinary download includes shared content and does not resolve a full request for access to care documentation. The controller must assess each request, third-party data and possible exceptions individually. For access, correction, erasure, objection, restriction, portability or withdrawal of consent: controller email [PENDIENTE]; procedure, deadlines and competent authority [PENDIENTE].

Follow-up, attachments and notes remain disabled on the server according to repository verification; local implementation does not establish remote availability. Before real data is used, responsibilities, information and consent, retention, providers and rights procedures must be approved. This draft will be updated after that review.