Legal

Privacy Policy

Version 1.2 Effective 5 July 2026 Mindslake (India) Phase 1 private beta, India

PinPapers lets you keep private documents pinned to places, stored in encrypted form. This policy explains what personal data we process, why, who receives it, how long we keep it, and the rights you have. We have written it to describe only what the app actually does today.

A note on plain language: PinPapers protects your documents with strong encryption, but we do not claim your stored documents are “end-to-end encrypted” or that “only you can ever read them.” We hold a separate escrow-wrapped copy of each file’s key so that we can produce decrypted access under a strictly-limited, compelled legal process (see §3 and §10). We would rather be exact than reassuring.

1. Who we are

PinPapers (“we”, “us”, “our”) is operated by Mindslake, the data controller / data fiduciary for the personal data described here.

Controller / Developer
Mindslake, B609 Century Celeste, Jakkur, Bengaluru 560064, Karnataka, India
Data Protection Officer
Abhinandan B — info@mindslake.com
Grievance Officer (DPDP §13)
Abhinandan B — info@mindslake.com (grievances acknowledged within 7 days; resolved within 30 days)

During this private beta a single mailbox, info@mindslake.com, serves the DPO, Grievance Officer and general privacy contact. Role-specific aliases will be introduced at a later compliance review.

2. Scope

This policy covers the PinPapers mobile application (iOS, iPadOS and Android), the backend services it talks to, and the limited admin surfaces operated by Mindslake (collectively, the “Service”). It applies to the India-only Phase 1 private beta and to general availability once we launch it.

It does not cover third-party services you reach through the Service (for example, a website linked from a note you saved). Those are governed by their own privacy practices.

3. Personal data we process

3.1 Identity data

  • Your email address, stored as a salted hash (we do not retain the plaintext beyond the federated sign-in callback).
  • Your phone number in E.164 format, used to verify you and to enforce our one-primary-device model.
  • An optional display name you may set for yourself — shown only to you, editable or removable at any time, and erased when you delete your account.
  • Opaque sign-in identifiers from your identity provider (Google, and Apple on iOS) and an internal account UUID.

3.2 Device data

  • A device identifier that is a random UUID generated on first launch and held in your device’s Keychain (iOS) or Keystore (Android). We do not use your IMEI or any persistent hardware identifier, and we do not request phone-state permission.
  • Platform (iOS / Android), OS version and app version.
  • Short-lived attestation tokens (Apple App Attest / Google Play Integrity), verified server-side and not stored long-term.
  • Your optional app-lock preference. When you turn it on, your device’s Face ID / fingerprint / passcode is required to open the app; the biometric check happens entirely on your device and PinPapers never receives or stores biometric data.

3.3 Content data — and how it is encrypted

Your documents, photos, voice notes and pin note bodies are content you create. Here is exactly how we protect and hold it:

Your documents, photos, voice notes and pin note bodies are encrypted on your device (AES-256-GCM) before they are uploaded, and we store them only in encrypted form. Each file’s encryption key is wrapped twice: once to your own device, and separately under an escrow key we manage in AWS KMS. In ordinary operation no PinPapers system and no PinPapers employee decrypts your content — there is no automated or routine decryption path, and we cannot read it in day-to-day operation. We are, however, technically able to obtain decrypted access to specific files, and only through a strictly-limited, multi-party “lawful-access” governance process — designed so that no single person can act alone, so that any decryption capability is narrowly time-bound and scope-limited to the specific data the request covers, and so that every such access is recorded in a tamper-evident audit trail — which we invoke only when compelled by valid legal process. Because that escrow path exists, we do NOT describe stored documents as “end-to-end encrypted” and we do NOT claim that “no one but you can ever read your data.”

When you open a document, the app may keep an encrypted copy on your device so re-opening is fast. That cached copy is in the same encrypted form as the server copy, is size-capped, and is cleared when you sign out.

3.4 Location data

  • Pin coordinates (latitude / longitude), captured only when you explicitly create or move a pin. This is precise location. Your location is not tracked continuously and we do not use background location.

3.5 Technical and diagnostic data

  • Your IP address at sensitive operations (sign-in, consent capture, identity change), captured for security auditing.
  • Crash reports — collected only if you grant the optional crash-and-analytics consent (C2), and stripped of personal data before transmission to our crash-reporting processor.

4. Why we process it, and our lawful basis

For each purpose we name the lawful basis under both the EU GDPR and India’s Digital Personal Data Protection Act, 2023 (DPDP).

Purposes and lawful basis
PurposeGDPR basisDPDP basis
Create your account and sign you inArt. 6(1)(b) contract§4 — consent
Verify your phone number (OTP)Art. 6(1)(b) contract§4 — consent
Account recovery and identity updatesArt. 6(1)(b) contract§4 — consent
Store your encrypted documentsArt. 6(1)(b) contract§4 — consent
Security audit loggingArt. 6(1)(f) legitimate interest§4 — legitimate use (security)
Prevent account takeover (one email / one phone)Art. 6(1)(f) legitimate interest§4 — legitimate use
Optional app-lock (biometric / device credential)Art. 6(1)(f) legitimate interest§4 — legitimate use
Optional display name (personalisation you invoke)Art. 6(1)(b) contract§7 — voluntary provision
Optional periodic re-verification (C1)Art. 6(1)(a) consent (withdrawable)§6 — consent (withdrawable)
Optional crash & analytics reporting (C2)Art. 6(1)(a) consent (withdrawable)§6 — consent (withdrawable)
Lawful admin access (compelled legal process)Art. 6(1)(c) legal obligation§4 — per legal compulsion

5. Who receives your data

We rely on the processors below. Each is bound by a written data-processing agreement limiting use to the named purpose. We do not sell your personal data, and we do not share it with anyone for advertising purposes.

Processors and sub-processors
ProcessorWhat they do for usBased in
Google LLCFederated sign-in (Sign in with Google)United States
Google Maps PlatformMap display and place search — the map area you view and any place-search text you type are sent to Google to render the map and return search resultsUnited States
Apple Inc.Federated sign-in (Sign in with Apple, on iOS)United States
Amazon Web ServicesEncrypted storage, key management (KMS), database, authentication and logging — primarily in AWS Mumbai (ap-south-1)India (control-plane metadata may transit other AWS regions)
Twilio Inc.SMS one-time-passcode deliveryUnited States
SentryCrash reporting — only if you grant optional consent C2 (personal data stripped first)United States

5.1 Sharing a pin with another PinPapers user

When you share a pin, sharing is encrypted end-to-end in the normal case: your own device re-wraps each shared file’s key directly to the chosen recipient’s device (using ECIES), and our servers only relay that recipient-sealed key envelope without being able to open it. Two facts stop us from claiming end-to-end in every case, so we don’t. First, for rare edge cases the direct path can’t serve — for example, the recipient changed devices after you shared, or a file was added to an already-shared pin while you were offline — we offer an optional, owner-consented “escrow-assisted” re-wrap in which our servers use the escrow key to prepare the recipient’s copy; this only ever runs with your recorded consent and is logged, never silently. Second, the underlying stored file itself remains escrow-wrapped, so it stays subject to the same multi-party lawful-access workflow described for storage. You choose the recipient (an existing PinPapers user), set an expiry, and can revoke at any time — revocation deletes the recipient’s key copies and denies further access. We keep a tamper-evident internal record of each share carrying only a hashed reference to the recipient, never disclosed to any third party.

6. Where your data is processed

PinPapers primarily processes your data in AWS Mumbai (ap-south-1, India), and the Phase-1 closed beta is India-only. Some data still crosses borders. Our sub-processors Google (federated sign-in), Google Maps Platform (map display and place search), Apple (Sign in with Apple, iOS), Twilio (SMS OTP delivery), and — only if you enable optional crash reporting (C2) — Sentry are US-headquartered, so limited data (for example a salted email/phone reference used for sign-in and OTP, or PII-stripped crash traces) may transit US infrastructure; AWS control-plane metadata may transit other AWS regions per the AWS Customer Agreement. If you share a pin with a recipient whose access is served from a different region, that pin’s encrypted files may transit across regions so the recipient can open them, recorded in our internal disclosure log. Legal transfer mechanism: for India residents, DPDP §16 (“Processing of personal data outside India”), which permits transfer to all countries except any the Government of India notifies as restricted — none are notified-restricted as of the effective date; for EU/EEA residents, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) supplemented by the technical measures in our records of processing.

7. How long we keep it

Account deletion is a crypto-shred: within 30 days of your request we destroy the keys that wrap your files, after which the stored ciphertext is mathematically undecryptable — even by us. A small set of immutable, attributed audit records is retained for the legal periods below.

Retention periods
CategoryRetention
Identity data (email hash, phone) and display nameAccount life + 30-day deletion window
Encrypted documents, photos, voice notesAccount life + 30-day window, then keys crypto-shredded
Immutable legal / disclosure audit records (attributed)7 years (DPDP §8(7) / GDPR Art. 17(3)(b))
Routine authentication audit events90 days
Crash reports at Sentry (only if C2 granted)90 days; withdrawal deletes within 30 days
Encrypted database backupsRolling 30-day window
Inert encrypted file bytes under storage Object-LockUntil each object’s lock expires (undecryptable once keys are shredded)

8. Your rights

You have rights under the GDPR and the DPDP Act. During the private beta, exercise every right by email to info@mindslake.com — there is no in-app privacy-request form. Please send your request from the email address registered to your account so we can verify ownership. We acknowledge any request within 48 hours; formal grievances are acknowledged within 7 days and resolved within 30 days (DPDP §13).

  • Access (GDPR Art. 15; DPDP §11) — a copy of your personal data, within 1 month.
  • Correction (GDPR Art. 16; DPDP §12) — you can change your email and phone in-app; other corrections by email, within 1 month.
  • Erasure (GDPR Art. 17; DPDP §12) — within 1 month; your files’ keys are crypto-shredded within the 30-day window (see §7). Certain immutable audit records are retained attributed for the periods in §7.
  • Portability / export (GDPR Art. 20) — within 1 month. In-app export is hidden during the closed beta; email us and we will provide your export. In-app export becomes available at general availability.
  • Restriction (GDPR Art. 18) — within 1 month.
  • Objection (GDPR Art. 21) — within 1 month; applies in particular to the optional C1 periodic re-verification.
  • No solely-automated decisions (GDPR Art. 22) — the only automated decision we make is rejecting a duplicate email/phone at sign-up; manual review is available on request within 1 month.
  • Withdraw consent — you can withdraw any optional consent (C1, C2) at any time; withdrawal does not affect your ability to use the Service.
  • Nominate another person (DPDP §14) — you may nominate someone to exercise your rights on your behalf in the event of your death or incapacity; email us to record a nominee.

Account deletion during the beta is also handled by email — see our Account & Data Deletion page for the exact steps.

At sign-up we present granular, per-item choices. Factual notices about how the Service works (for example, that stored documents are escrow-wrapped and that deletion is irreversible after the window) require your acknowledgement; optional items (C1 periodic re-verification, C2 crash and analytics reporting) are true consents you may grant or decline independently, and declining does not affect your ability to use the Service. You can review your consent history in the app, and withdraw any optional consent at any time. If we make a material change to this policy, you will be asked to acknowledge the new version before continuing.

10. Lawful admin access

Because a separately-held escrow key exists (see §3.3), PinPapers is technically able to produce decrypted access to specific user data. We do this only when compelled by valid legal process (for example, a court order or lawful demand under applicable Indian law), never for our own purposes. Our lawful-access governance is deliberately multi-party, and is designed so that no single person can decrypt your data. Under it:

  • A legal request is triaged, and its scope and necessity are reviewed.
  • Approval by multiple independent authorisers is required before any decryption capability is issued — no single person can authorise access.
  • Any decryption capability is time-bound and scoped to the specific data the request covers — it is not a general key.
  • Every access is recorded in a tamper-evident, append-only audit trail.
  • Where we are legally permitted to do so, we notify affected users of an access event; where a legal prohibition applies, we notify them as soon as that prohibition lifts.

11. Cookies and similar technologies

The PinPapers mobile app does not use cookies. Our admin surfaces may use a small number of strictly-necessary session cookies for authentication; these are internal-operations only and are not used for advertising or cross-site tracking.

12. Children

PinPapers is not directed at anyone under 18 years of age. You must be 18 or older to create an account, and you affirm your age at sign-up. If we learn that a user is under 18, we suspend the account and securely delete the data within 30 days. We do not knowingly process children’s data and we do not run behavioural advertising to minors.

13. Breach notification

Personal-data breach notification is governed by DPDP §8(6) — the data fiduciary’s statutory duty to give the Data Protection Board of India and each affected data principal intimation of a breach, in the form and manner prescribed by the DPDP Rules. This is the correct Indian statutory hook (§27 concerns the Board’s powers and functions, not the breach-intimation duty). For EU/EEA residents, GDPR Art. 33 (notify the lead supervisory authority within 72 hours of becoming aware) and Art. 34 (notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms) also apply.

14. Complaints

If you are unhappy with how we have handled your data, please contact our Grievance Officer first at info@mindslake.com (acknowledged within 7 days; resolved within 30 days). You also have the right to complain to a regulator:

  • India — the Data Protection Board of India, once its complaint portal is operational.
  • EU/EEA — your local supervisory authority in your country of habitual residence.

15. Changes to this policy

We may update this policy from time to time. Material changes (a new processor, a new purpose, a change in retention or cross-border destination, or a change in lawful basis) are announced in-app and you will be asked to acknowledge the new version. Editorial changes (clarifications, contact updates) are published with a new effective date. This is version 1.2, effective 5 July 2026.

16. Contact

All privacy matters, DPO and Grievance Officer
Abhinandan B — info@mindslake.com
Postal
Mindslake, B609 Century Celeste, Jakkur, Bengaluru 560064, Karnataka, India

Related pages: Account & Data Deletion · Support · Terms of Service · Closed Beta Privacy Notice.