Privacy Policy
What we collect, and what we don't.
⚠️ Pre-launch — pending legal review
Our privacy policy is in final legal review and will be published in full before public signup opens. The outline below reflects what the final policy will cover. Customers who need the full draft for procurement review can request it from privacy@mintok.ai.
Outline of the final policy
- 01
Who we are
Mintok Inc. Contact for privacy: privacy@mintok.ai
- 02
What this covers
All Mintok services and the public calculator
- 03
Information we collect
PII (name, email), workload inputs, saved plans, billing data
- 04
How we use information
Operate the service, deliver AI features, communicate, prevent abuse
- 05
Legal bases (GDPR)
Contract, legitimate interest, consent, legal obligation
- 06
Subprocessors
Vercel, Neon, Clerk, Stripe, Anthropic (with ZDR), Cloudflare
- 07
International data transfers
SCCs Module Two + UK IDTA for EU/UK transfers
- 08
How long we keep your data
Active while account active + 30-day grace; logs 30-90 days; billing 7 years
- 09
Your rights
Access, deletion, portability, rectification — self-serve
- 10
Security
TLS, AES-256, Postgres RLS, JIT access, audit logs
- 11
Children's data
Not directed at children
- 12
Cookies
Strictly necessary + functional only; no advertising trackers
- 13
Automated decision-making
We make decisions about workloads, not individuals
- 14
Changes to this policy
30 days notice for material changes
- 15
Contact
privacy@mintok.ai · DPO: dpo@mintok.ai
Want the technical detail now?
The architecture, subprocessor list, and customer-facing audit features are documented in full at /security. That page is live today.