Privacy notice
This notice explains what personal data Mente Prima (menteprima.app) processes, what for, who it is shared with, and what you can demand at any time. It is written to be understood, not to cover us.
1. Who the controller is
The controller of your personal data is the individual who operates Mente Prima (menteprima.app); you will find their identity and address in section 9 of this notice.
For anything privacy-related, or to exercise the rights described below, write to jesusalsn8n@gmail.com.
2. The bare minimum we ask for
Mente Prima requires an account, and all it takes to create one is an email address and a password. Your progress and your creations — your systems, your palaces, your routines — are stored in your device’s local storage; they are only copied to our server through cloud sync.
Beyond the account, we only process personal data when you write in the suggestion box, post on the blog, or buy a paid plan.
3. What personal data we process
- Identification and contact: your email address and an encrypted password. If you sign in with Google, we receive your email and your Google account identifier, never your password.
- Public name: the nickname you sign blog entries with. Optional, and chosen by you.
- Your content and progress: while signed in, your systems, palaces, routines and training progress are copied to our server so you can use them across devices.
- Devices: a random device identifier, a descriptive label and a last-seen date, to enforce the free plan’s limit (one active device at a time) and to stop the free trial from being claimed over and over. Paid plans do not limit devices.
- Suggestion box: the message you write, its category and your email address.
- Blog: what you publish, your comments, the public name you sign with, and any images you upload.
- Payment data: if you buy a plan, our payment gateway processes the charge. We do NOT receive or store your card number; only your subscription status, its expiry date and the tax details needed to invoice you.
- Unavoidable technical data: our hosting providers log IP addresses and basic request data in order to serve and protect the app.
We process no sensitive data. We carry out no profiling and no automated decisions with legal effects on you.
4. What we use your data for
NECESSARY purposes, without which the service cannot be provided:
- Creating and maintaining your account, and signing you in.
- Storing and syncing your content and progress across your devices.
- Enforcing plan limits and preventing free-trial abuse.
- Charging you, invoicing you and meeting our tax and accounting obligations.
- Answering what you write to us and providing support.
- Detecting and preventing fraud, abuse and unauthorised access.
NON-NECESSARY purposes, which you can object to without losing any part of the service:
- Publishing your content and public name on the blog, if you choose to publish.
- Sending you notices about significant product changes, if you subscribe to them.
To object to any of these, write to jesusalsn8n@gmail.com.
5. Legal bases (users in the EU, the UK and Brazil)
If the European or UK General Data Protection Regulation, or Brazil’s LGPD, applies to you, we process your data on these bases:
- Performance of the contract: account, sync, paid plan and support.
- Legal obligation: invoicing, accounting and tax.
- Legitimate interest: plan limits, fraud prevention and service security.
- Consent: publishing on the blog and receiving product notices. You can withdraw it at any time, without affecting processing carried out before.
6. Who we share your data with
Only with providers that process data on our behalf under contract. We do not sell, rent or trade personal data to anyone for commercial purposes:
- Supabase — database, accounts and storage for blog images.
- Netlify — hosting and delivery of the app.
- Our payment gateway — payment processing, only if you buy a plan.
- Our electronic invoicing provider — issuing tax receipts.
- Google Fonts — the app loads its typefaces from Google servers, which receive your IP address when it does.
We may also disclose data where a competent authority or a legal obligation requires it.
7. International transfers
Our providers may store and process data outside your country, including in the United States and the European Union.
Where a transfer leaves the European Economic Area or the United Kingdom, it relies on the standard contractual clauses approved by the European Commission or the equivalent UK mechanism. For users in Mexico and Brazil, transfers are made with the contractual safeguards required by applicable law.
8. How long we keep your data
- Account data and synced content: as long as the account exists. Delete it and it is gone.
- Tax receipts and accounting records: for as long as the law requires (five years in Mexico).
- Suggestion box messages: until we resolve them, and deleted if you delete your account.
- Blog posts and comments: they stay published, but without your name, if you delete your account.
- Technical security logs: only for as long as strictly necessary for their purpose.
9. Your rights, wherever you live
Two rights are one tap away, with no need to ask us or wait:
- Erasure: Account → Delete my account. Immediate and irreversible.
- Portability: Settings → Export downloads your data as a standard JSON file.
For anything else, write to jesusalsn8n@gmail.com from your account’s email address, telling us which right you want to exercise. We will answer within twenty working days at most, and sooner where we can.
These rights are exercised against the data controller: Jesús Alberto López Soto, address Calle A núm. 1231, Col. Encanto Sur, C.P. 21440, Baja California (México).
10. If you are in Mexico
You have ARCO rights: to access your data, rectify it where inaccurate, cancel it where you consider it is not required for the purposes in this notice, and object to its processing for specific purposes.
You may also withdraw any consent you have given us, and limit the use or disclosure of your data.
If you believe your right to data protection has been infringed, you may turn to the competent Mexican data protection authority.
11. If you are in the EU, the EEA or the UK
You have the right to access, rectify, erase, restrict and object to the processing of your data, to data portability, and to withdraw your consent at any time.
You may lodge a complaint with your country’s supervisory authority. In the United Kingdom that is the Information Commissioner’s Office (ico.org.uk).
12. If you are in Brazil
Under the LGPD you have the right to confirm that processing exists, access your data, correct it, anonymise, block or delete it, obtain portability, know who we share it with, and withdraw your consent.
You may complain to the Autoridade Nacional de Proteção de Dados (ANPD).
13. If you are in the United States
We do NOT sell your personal information, and we do not share it for cross-context behavioural advertising. We use no behavioural analytics and no third-party trackers.
Regardless of whether your state’s legal thresholds apply to us, we give you the same rights as everyone else: to know what data we hold, obtain a copy, correct it and delete it. Exercising them will never get you a worse service or a different price.
14. Cookies and on-device storage
Mente Prima uses no advertising or analytics cookies, so you will not see a consent banner: there is nothing to consent to.
We do use the browser’s local storage (localStorage and IndexedDB) for two essential things: keeping your progress and creations on the device, and keeping you signed in. The app cannot work without them, which is why the law does not require prior consent.
You can wipe it whenever you like from Settings → Reset, or from your browser settings.
15. Children
You must be at least 16 to create an account. We do not knowingly collect data from anyone below that age; if we find such an account, we delete it.
Since the app is only usable with an account, Mente Prima is reserved for people aged 16 and over. If someone younger wants to train with it, the account must be created and supervised by a parent or guardian.
16. Security
We apply reasonable technical and organisational measures: encryption in transit, passwords stored using key derivation functions, and per-user isolation at database level, so that nobody can read anyone else’s rows.
No system is infallible. Should a security breach occur that poses a risk to your rights, we will tell you and notify the relevant authority within the deadlines the law sets.
17. Changes to this notice
If we change anything material we will say so inside the app before it takes effect, and update the date shown above. The version in force will always be available on this screen.