1Mynd — Privacy Policy
Last updated: September 28, 2026
1. Who we are
1Mynd is a product of Helpful Human, LLC. It is goal-aligned task and time management, currently in beta. This policy covers the 1Mynd web app at app.1mynd.xyz, the 1Mynd API and MCP server at api.1mynd.xyz, the 1Mynd Android app, and sites you publish with 1Mynd.
This policy describes what 1Mynd does today. Where the product does something imperfectly, we say so rather than round it up.
2. What 1Mynd stores
1Mynd is organized around workspaces. Inside a workspace you can keep:
- Projects, sections, and tags — including details you add to a project, such as an address or area
- Tasks — titles, due dates, status, subtasks, and who they are assigned to
- Notes and playbooks — free text, including drafts written for you by an AI assistant
- Time blocks — calendar spans with an optional title and location, plus recurring protected-time templates
- Files — documents, images, PDFs, and web pages you upload, organized in folders
- Forwarded email — messages you send to your workspace's inbound address (section 11)
- Sites and QR codes — pages you publish and trackable links you create (section 12)
- Validators — checks you write that review a file against your own rules
- Delegates — named labels for how work gets done; a delegate is not an account and has no login
We also keep a history of changes so that edits can be reviewed and reverted — see section 17.
3. Signing in
You sign in with Google or Microsoft using OpenID Connect, with the scopes openid email profile. We store the provider's subject identifier, your email address, your name, and your time zone.
There is no password. 1Mynd never receives one and never stores one. Every sign-in flow uses PKCE and a CSRF state parameter.
4. Google user data: what we access
Connecting Google Calendar is a separate, explicitly opt-in grant, distinct from sign-in, and 1Mynd works without it. When you connect, we request:
- https://www.googleapis.com/auth/calendar.app.created
- https://www.googleapis.com/auth/calendar.readonly
- https://www.googleapis.com/auth/tasks
With these, 1Mynd accesses:
- Your calendar list — each calendar's id and name, and your primary calendar's time zone
- Events on the calendars you choose to sync (your primary calendar by default), within the date range you are viewing — each event's title, location, start and end time, and whether it is all-day
- The names of your Google Tasks lists — we do not read the tasks inside your lists
- Your Google account's email address and identifier, so we know which account is connected
We do not access your calendars' sharing settings, your calendar settings, or any other Google service.
5. Google user data: how we use it
Reading your schedule. Events from your calendars become busy intervals, shown in your own schedule so you can see what you would be scheduling over and so 1Mynd can find conflict-free time for your work.
Writing time blocks. 1Mynd creates one dedicated secondary calendar named "Mynd" in your Google account and writes events only there. Because the grant is calendar.app.created, 1Mynd cannot create, edit, or delete events on any calendar it did not create — Google enforces that, not only our code. Each event carries a title composed from the tasks attached to the time block, the time block's location, the text of notes attached to those tasks as the event description, and a private marker so we can recognize our own events.
Mirroring due dates. A task's due date mirrors into a dedicated list named "Mynd" in Google Tasks, carrying the task title. Completing the task in 1Mynd marks it completed there. We create and update only tasks in that list.
Time zone. Your primary calendar's time zone is used to decide what "today" means for you across 1Mynd.
We do not use Google user data for advertising, for credit or lending decisions, or to build profiles, and we do not create aggregated or anonymized datasets from it.
6. Google user data: who it is shared with
We do not sell Google user data, and we do not transfer it to advertisers, data brokers, or information resellers. Google user data reaches others only in these ways, all in service of features you use:
- You. It is shown back to you in 1Mynd.
- Not your workspace. Events from a calendar you connect are visible only to you, not to other members of your workspace.
- AI features. Calendar event data may be sent to our AI provider to power AI features you invoke — see section 8. Today, 1Mynd's built-in AI does not receive calendar event data.
- AI assistants you connect. If you connect your own AI assistant to 1Mynd (section 14), it can read your schedule, including event titles and locations, when you ask it to. That assistant is a service you chose, governed by its own terms.
- Feedback you send. If you submit feedback while viewing your calendar, the text on your screen — which can include event titles — is included in the report (section 15).
- Infrastructure. Our hosting and database providers (section 16) process data on our behalf to run the service.
7. Google user data: protection, retention, and deletion
- Event data is not stored on our servers. Event titles, times, and locations are fetched from Google when you view your schedule and are not written to our database. The 1Mynd app keeps a copy in your browser's local cache so your schedule loads quickly; it is cleared when you sign out.
- What we do store is the connection itself: your Google account's email and identifier, which calendars you chose to sync, the ids of the calendar and task list we created, and your primary calendar's time zone.
- Tokens. Google access and refresh tokens are encrypted at rest under a dedicated key, separate from the keys that protect the rest of your data.
- Disconnecting in 1Mynd deletes the "Mynd" calendar we created, removes the events and tasks we mirrored, and deletes the connection record, including your tokens.
- Revoking. You can also revoke 1Mynd's access at any time at https://myaccount.google.com/permissions. Disconnecting inside 1Mynd does not by itself revoke the grant at Google, so do both if you want the grant gone.
8. AI features and your data
1Mynd's built-in AI features use a third-party AI model provider through a paid API. Under that provider's terms, it does not use prompts or responses to train or improve its models, and keeps them only for a limited period to detect abuse.
- Ask Mynd — your message, the page you are on, and a summary of your workspace: projects, tasks due or scheduled today, and upcoming deadlines. While answering, it can read your projects, tasks, and notes.
- Filing captures — the captured note, your open task titles, and candidate projects.
- Validators — the full contents of the file being checked, which can include a forwarded email, and the rule you wrote.
- Grounded search — available to AI assistants you connect (section 14): a search query and, if a project is named, its area and topics. This runs real web searches on your behalf.
We do not use your data, including Google user data, to train AI models — neither our own nor our provider's. AI-made changes are attributed as AI-authored and can be reverted.
Limited Use. 1Mynd's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This includes our use of raw or derived Google user data with AI models.
9. Microsoft calendar and tasks
You can instead connect a Microsoft account, using the Calendars.ReadWrite, Tasks.ReadWrite, and offline_access scopes, with change notifications so your schedule stays current. It works the same way: a separate opt-in grant, revocable from your Microsoft account.
10. What the people in your workspace can see
A workspace has two roles, owner and editor, and there is no per-project or per-note visibility control. Every member can see every project, task, note, playbook, file, and time block in the workspace, and every other member's name, email address, and role.
Time blocks are shared across the workspace. A time block with no assignee is mirrored to the connected calendar of every member, including the text of notes attached to its tasks.
Invites are single-use, expiring, revocable, and bound to the invited email address.
11. Forwarded email
Each workspace has an inbound address at in.1mynd.xyz. It accepts mail only from members' own addresses and addresses you have verified. We store the message as you forwarded it — headers, recipients, body, and attachments — as files in your workspace. That can include other people's personal information, which you are responsible for having the right to share with us.
12. Things you publish
Nothing you create is public unless you publish it. When you do:
- Published files are served from a public link. Anyone with the link can open it.
- Sites go live at a 1Mynd-hosted address or on a subdomain you own, when a workspace owner — or an editor the owner has allowed — presses publish. An AI assistant cannot publish a site.
- QR codes redirect to a link you set. For each scan we record only the time — no IP address, device, or location, and no cookies.
13. What we do not do
- No analytics SDK and no third-party scripts in the app
- No advertising and no ad tracking
- No session replay and no heatmaps
- No cookies beyond the app's own session cookie
- No device location — location data is only what you type in
- We do not sell personal information
14. AI assistants you connect
You can connect your own AI assistant to 1Mynd over its MCP server, with a personal access token or an authorized connection. The assistant acts on your behalf and can read and change your workspace data, including your schedule. Understand what that means:
- It reaches every workspace you belong to, not just one
- Data it reads leaves 1Mynd and is handled under that assistant's terms, not ours
- Personal access tokens are shown once and stored only as a hash
- You can revoke access at any time, and every action it takes is recorded
15. Feedback
When you send feedback from the app, we include the text visible on your screen, your screen size, and your browser type, so we can see what you saw. Our team, and an automated tool that sorts reports, read it. Avoid sending feedback from a screen showing something you would rather we not see.
16. Service providers
1Mynd relies on these kinds of providers to run the service:
- Cloud infrastructure — servers, file storage, and encryption key management, in the United States
- Database hosting
- An AI model provider — built-in AI features, and web search for grounded search
- Email providers — sending email, and receiving email you forward to your workspace
- A push notification provider — Android notifications
- Website hosting — serving sites you publish
- Mapping services — turning places you type into locations
- A property data provider — home value estimates; we send the property address and details you provide
- Google and Microsoft — sign-in and calendar connections, when you choose them
For local market statistics and community events, 1Mynd downloads public datasets and feeds; nothing about you is sent to those sources.
17. Security
- Session cookies and personal access tokens are stored only as hashes, never in recoverable form
- Encryption at rest is in progress. Notes, playbooks, file details, folder names, site details, QR link targets, and your account email address are encrypted at the field level under per-account keys held in a managed key service. Tasks, projects, time blocks, and the change history (which holds prior copies of content, including notes) are protected by our infrastructure's storage encryption but are not yet encrypted at the field level. File contents are encrypted at the storage level.
- Logs are redacted so that email addresses, phone numbers, and tokens are not written to them
- A request for a workspace you do not belong to returns "not found", so a workspace's existence is not revealed to outsiders
No system is perfect, and 1Mynd is in beta. Keep your own copy of anything you cannot afford to lose.
18. Retention and deletion
We will not promise deletion the product does not perform. Here is what actually happens:
- Tasks, projects, notes, and files are archived before they are deleted, and deletion is a soft delete — the record is hidden but kept
- Deleting a workspace is also a soft delete. On request, we can permanently erase its files
- The change history is never deleted. It is what makes every change, including AI changes, revertable and auditable, and it holds prior copies of content such as task titles and note text
- Ask Mynd conversations are kept for 30 days, access records for 180 days, and QR scan records for 400 days
- Sessions expire after 30 days
- Google calendar data is covered in section 7
You can export your workspace's files as a ZIP from the app. There is no self-service export of tasks or notes and no self-service account deletion. To request deletion of your data, or a copy of it, email hello@1mynd.xyz. These requests are handled manually.
19. Children
1Mynd is not directed to children under 13, and we do not knowingly collect personal information from them. The product has no age gate, so if you believe a child has given us information, email hello@1mynd.xyz.
20. Changes to this policy
We will update this policy as 1Mynd changes. Updates are posted on this page with a new date at the top.
21. Contact
Questions about this policy, or a request about your data? Email hello@1mynd.xyz.