Zyur

MindPass Privacy Policy

Effective 11 September 2026. MindPass is provided by Zyur Ltd. Contact info@zyur.io with privacy questions or requests.

What stays on your device

MindPass uses Apple’s Screen Time frameworks to protect the individual apps you select. App-selection tokens, schedules, focus routines, pauses, strict-mode settings and earned passes are stored on your device in storage shared with MindPass’s extensions. We do not send these tokens, the names of your selected apps, or your browsing history to our learning service or analytics. MindPass does not need access to your messages, contacts or photos.

Identity and learning data

Firebase Authentication creates a pseudonymous account without requiring your name or email. Authentication credentials are stored in the iOS Keychain. The same account identifier is used for our learning service, product events and RevenueCat billing identity. Your selected interests, generated paths, lesson answers and learning progress may be stored by our backend so it can provide lessons and memory checks. Bundled discoveries and cached paths can be read locally.

AI-generated paths

When you choose Create my path, your subject, optional note and chosen starting level are sent through our backend to Google Gemini to generate lessons. Account identifiers, purchase history, selected apps and learning progress are not included in that request. Selecting interests for regular curated discoveries does not send those interests to Gemini. Do not include sensitive, confidential or unnecessary personal information. We store generated paths and request details to deliver them and safely handle retries. AI content may be inaccurate; source suggestions are not verification. See Google’s Privacy Policy and the applicable Gemini service terms for provider processing.

Purchases and allowances

Apple processes payments. RevenueCat helps verify subscriptions, purchases, restores and trial eligibility. It receives the account identifier and purchase information needed for that service. We do not receive your payment-card details. Our backend checks subscription access and stores billing-account mappings and generation accounting records to enforce the monthly allowance, prevent duplicate charges against it and keep it consistent after a restore. A device reinstall does not create a new allowance for the same verified billing account.

Product events and diagnostics

MindPass sends pseudonymous product events, such as onboarding completion, discoveries answered, passes started, subscription-flow results and routine changes. Events include an installation identifier, app version, timestamps and limited feature properties such as counts. These events do not include your app-selection tokens or learning prompts. We use them to understand reliability and improve the app, not to sell personal data or target advertising. Hosting and diagnostic systems may process technical information necessary to operate and secure the service.

Notifications and support

Optional pass-ended notifications are scheduled on your device. You can disable them in MindPass or iOS Settings. If you contact support, we process the information you choose to send so we can respond. Please do not send payment-card details or authentication credentials.

Purposes, sharing and retention

We process data to provide the service you request, administer purchases, protect against abuse, meet legal obligations, and improve reliability. Providers include Apple, Google/Firebase/Gemini, RevenueCat and our hosting providers. These services may process data outside your country; applicable contractual and legal safeguards govern those transfers. We retain learning and account data for as long as needed to provide the service and fulfil legitimate operational or legal requirements. Billing, security and accounting records may need to be retained after a deletion request. Cached device data can remain until removed from the device.

Delete your account

Open MindPass Settings → Delete account & data. This is available without Pro and during strict mode. After confirmation, MindPass deletes your owned learning paths, answers, progress, reports and linked product events from its active database, deletes your Firebase account, and clears local MindPass data and focus settings. If interrupted, deletion resumes when you retry or reopen the app. No new account is created until you explicitly start again. Uninstalling alone does not delete your account: Keychain credentials and server data may persist.

We retain a hashed account-suppression record to prevent stale requests from recreating deleted data. Limited pseudonymous billing mappings and completed-generation counts are retained for allowance integrity, fraud prevention and applicable legal obligations; prompt content and the raw account identifier are removed from those generation records. Apple and RevenueCat retain purchase records under their applicable policies. Backup and provider retention can differ from active-database deletion. Contact us for information about a specific record or a deletion that cannot finish. Deletion does not cancel an Apple subscription; use Apple subscription settings.

Your choices and rights

You can change interests and protected apps, manage your Apple subscription, and revoke Screen Time access in iOS Settings. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, obtain a copy of your data, or complain to your data-protection authority. Email info@zyur.io to exercise these rights. Because accounts are pseudonymous, we may need information to identify the correct account and verify the request. Never send passwords or authentication tokens.

Audience and changes

MindPass is designed for adults managing their own screen time, not for monitoring children or another person. We may update this policy as the service changes and will update the effective date and provide additional notice where required.