Mindarin is operated by LD Data, owned by Lee Durbin. This Privacy Policy explains how we collect, use, and protect your personal information.
Note: Mindarin is an independent application and is not affiliated with, endorsed by, or associated with Mandarin Blueprint or any other Chinese learning platform.
1. Information We Collect
Account Information
- Email address - Required for account creation and authentication
- Name - Optional, can be provided during signup
- Password - Securely hashed using industry-standard methods (never stored in plain text)
- Profile image - Optional, if you choose to upload one
Application Data
- Chinese character cards - Characters, pinyin, tones, meanings, and notes you create
- Study progress - Learning statistics, review history, and spaced repetition data
- Mnemonic configurations - Your custom actors, sets, rooms, and props
- Tags and notes - Any tags or notes you add to your cards
Feedback Data
- Feedback submissions - When you submit feedback through the application, we collect and store your feedback message along with your user ID, email address, and the page you were on
- Purpose - This information helps us understand context, follow up with you if needed, and improve the application based on user feedback
- Not anonymous - All feedback is associated with your account and is not anonymous
Technical Data
- Session tokens - For maintaining your authenticated session
- IP addresses - Used for rate limiting and security purposes
- Usage analytics - Anonymized performance metrics (page load times, Core Web Vitals)
2. How We Use Your Information
- To provide and maintain the Mindarin learning service
- To personalize your learning experience and track your progress
- To enable spaced repetition and study scheduling
- To collect and respond to user feedback for service improvement
- For security and fraud prevention (rate limiting login attempts)
- To analyze and improve application performance (anonymized analytics)
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Data Storage and Security
- Your data is stored securely in PostgreSQL databases hosted by Prisma Postgres (via Vercel)
- Passwords are hashed using bcrypt with industry-standard security practices
- All data is encrypted in transit (HTTPS/TLS) and at rest
- Access to your data is restricted to authorized personnel and automated systems
- We implement connection pooling and security headers to protect against common vulnerabilities
4. Third-Party Services
Service Providers
- Vercel - Hosting platform and analytics (Core Web Vitals tracking)
- Prisma Postgres - Database hosting and storage
- Prisma Accelerate - Database connection pooling for improved performance
Analytics
- Vercel Analytics - Tracks anonymized Core Web Vitals and performance metrics
- No personal tracking - We do not use tracking cookies or personal identifiers
- No advertising - We do not use advertising networks or trackers
These services are essential for providing the Mindarin application. All third-party services are bound by their own privacy policies and data protection agreements.
5. Your Rights
You have the following rights regarding your personal data:
Access
You can export all your data at any time through the Export page in your account settings.
Deletion
You can request account deletion, which will permanently remove all your data from our systems. Contact us at the email below to request account deletion.
Correction
You can update your profile information, email, and name at any time through your account settings.
Data Portability
You can export your data in multiple formats (YAML, CSV, JSON, Markdown) for use in other applications.
6. Data Retention
- Your data is retained until you request account deletion
- When you delete your account, all associated data (including cards, progress, configurations, and feedback submissions) is permanently removed
- Automated backups may retain data for up to 30 days before permanent deletion
- Session tokens expire automatically and are cleaned up regularly
7. Children's Privacy
Mindarin is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
8. Cookies and Tracking
- We use session cookies for authentication (required for the service to function)
- We do not use tracking cookies or advertising cookies
- Analytics are anonymized and do not track individual users
- You can disable cookies in your browser, but this will prevent you from using the service
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of any material changes by updating the "Last updated" date at the top of this page. Your continued use of Mindarin after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights (such as data deletion), please contact us at:
Email: hello@leedurbin.co.nz
Business: LD Data
Owner: Lee Durbin
We will respond to your inquiry within a reasonable timeframe.
GDPR Compliance
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to access your personal data
- Right to rectification (correction) of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
To exercise any of these rights, please contact us using the information provided above.