Data Policy
Last updated: April 3, 2026
This Data Policy provides detailed information about how ModelMind collects, processes, stores, and protects your data. It supplements our Privacy Policy.
What We Collect
Data stored locally on your device:
- Learning progress (lesson completions, scores, streaks, mastery levels)
- Exercise responses and answer patterns
- App preferences (theme, language, text size, notifications)
- Concept strength and spaced repetition schedules
Data stored on our servers (when cloud sync is enabled):
- Your email address and display name
- A copy of your learning progress for cross-device sync
- Account creation date and last sync timestamp
- Subscription status (managed by RevenueCat)
Anonymous usage data (when "Help Improve ModelMind" is enabled):
- Which screens you visit and how long you spend on them
- Exercise difficulty and timing (which exercises are hard, which are easy)
- App startup performance (how long the app takes to open)
- Crash reports (what went wrong if the app crashes)
- Device context per batch: operating system, app version, language
This data is sent in anonymous batches. No user account information is attached. We cannot trace any individual event back to a specific user. You can turn this off at any time in Settings.
Data we do not collect:
- Location data
- Contacts or address book
- Photos, camera, or microphone data
- Browsing history or data from other apps
- Payment card numbers or financial details
- Biometric data
- Device identifiers (no advertising ID, no device fingerprinting)
- Phone number
How We Process Data
All exercise grading happens locally on your device. Progress data leaves your device only when cloud sync is enabled. When "Help Improve ModelMind" is on, anonymous usage data is sent in batches to our servers. Each batch includes event type, timestamp, and device context (operating system, app version, language). No user account information is attached to this data. All data is transmitted over encrypted connections (TLS 1.3).
Data Training and Improvement
We may use anonymized, aggregated usage data to improve ModelMind's educational content and app performance. This includes:
- Identifying exercises that are too difficult or too easy based on aggregate success rates.
- Improving spaced repetition timing based on aggregate retention patterns.
- Improving app performance based on startup timing and crash reports.
- Understanding which parts of the app are used most to focus development effort.
- Training machine learning models to improve content recommendations, exercise generation, and educational outcomes.
All data used for training or analysis is fully anonymized before processing. No individual exercise responses, personal information, or account details are ever included. The anonymized data cannot be traced back to any individual user.
Your Opt-Out Right
You can opt out of data training in the App under Settings. When you opt out:
- Your future data will not be included in any aggregated analysis or training.
- Your app experience remains fully functional.
- Previously processed anonymized data cannot be retroactively removed as it is no longer linked to your identity.
Data Security
We protect your data through:
- Local storage: Stored in the app's private storage area on your device.
- In transit: TLS 1.3 encryption for all server communications.
- At rest: Encrypted storage on Cloudflare infrastructure.
- Server-side safeguards: Progress history snapshots before overwrites, rejection of empty-data overwrites to prevent accidental data loss.
Data Portability
You may request a copy of your personal data at any time by contacting privacy@model-mind.org. We will provide your data in JSON format within 30 days.
Data Deletion
You can delete your account and all associated server-side data through the App's Settings screen. Local data is deleted when you uninstall the app. Server-side data is permanently deleted within 30 days.
International Data Transfers
If you use ModelMind outside the United States, your data may be transferred to and processed in the United States through Cloudflare's global infrastructure. We ensure appropriate safeguards for these transfers.
California Privacy Rights (CCPA)
California residents have the right to:
- Know what personal information we collect and how it is used.
- Request deletion of personal information.
- Opt out of the sale of personal information (we do not sell personal information).
- Non-discrimination for exercising privacy rights.
European Privacy Rights (GDPR)
If you are in the European Economic Area, you have additional rights including:
- Right of access to your personal data.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to restrict processing.
- Right to data portability.
- Right to object to processing.
Our legal basis for processing is: (a) contract performance for providing the service; (b) legitimate interest for improving educational content through anonymized analysis. For data training, we rely on legitimate interest under GDPR Article 6(1)(f) with an accessible opt-out mechanism.
Contact
For questions about this Data Policy or to exercise your data rights, contact us at privacy@model-mind.org.