Summary
If you only read one section: we collect what we need to operate Myndlab — account info, project data, usage telemetry, billing details. We never sell your data. We never use your prompts or generated code to train AI models. You can export everything and delete your account anytime.
Data we collect
We collect three categories of data:
Account data
- Name, email, organization, and password hash.
- Authentication tokens from SSO providers (Google, GitHub, Microsoft) when used.
- Billing address and last-four credit-card digits (full card data handled by Stripe — we never see it).
Project data
- Prompts, voice transcripts, and natural-language inputs.
- Generated source code, design DNA, and project assets.
- GitHub sync metadata, branch history, and commit messages you author.
Usage telemetry
- Pages visited, features used, error events.
- Approximate IP-derived location (country + city level).
- Device, browser, and OS for compatibility diagnostics.
AI training — never
Your prompts, code, and project content are not used to train Myndlab's models or any third-party AI provider's models.
Where we route to third-party AI vendors (Anthropic, OpenAI), contractual agreements explicitly restrict training and retention. Anthropic data is processed under their commercial zero-retention terms. OpenAI traffic uses their enterprise API with training opt-out enabled.
Data residency
You pick a region at signup. Your project data stays in that region.
- UAE (Dubai) — me-central-1, primary GCC region.
- Saudi Arabia (Riyadh) — sovereign edge cluster.
- European Union (Frankfurt) — eu-central-1.
Account and billing metadata is replicated to the EU for accounting. No project content leaves your chosen region.
Your rights
Regardless of where you are based, every Myndlab user has the following rights:
- Access — request a full export of your account and project data.
- Deletion — request permanent deletion of your account and content.
- Correction — fix anything we have wrong about you.
- Portability — export to a standard format you can use elsewhere.
- Withdraw consent — opt out of analytics and product communications.
Exercise any of these rights by emailing privacy@permus.io. We respond within 30 days, faster in most cases.
Retention & deletion
Account data is retained for as long as your account is active.
On account cancellation, all customer data is deleted within 30 days. Encrypted backups retain data for up to 90 days for disaster recovery, then expire. You receive a written confirmation of deletion.
Anonymous, aggregated analytics may be retained indefinitely. This data cannot be linked back to you.
Subprocessors
Myndlab uses a small set of vetted subprocessors. Each is bound by a DPA, contractually restricted from training on customer data, and subject to our annual vendor security review.
The current list is published at the Trust & Security center and updated within seven days of any change.
Changes to this policy
We notify customers by email at least 30 days before material changes take effect. The full revision history is published on the Trust & Security center.
Contact
Permus Software House, Dubai World Trade Centre, Dubai, United Arab Emirates.
Data Protection Officer: privacy@permus.io
EU representative: Permus EU Representative B.V., Amsterdam, Netherlands.