Privacy Policy
Last updated: September 2, 2026
Mindsill ("we", "us") is a desktop application that captures your ideas and tasks, files them by project with AI, and prepares a daily briefing. This policy explains what data Mindsill handles, where it lives, and what leaves your machine. The short version: Mindsill is local-first — your notes, tasks and calendar data live in plain markdown files on your own computer, not on our servers.
1. Data stored on your device
Everything you capture in Mindsill — ideas, tasks, notes, project descriptions, your profile, daily logs — is stored as plain .md (markdown) files in a folder on your computer that you control and can relocate. We do not host, back up, or have access to this folder. Deleting the folder, or uninstalling Mindsill and deleting the folder, removes this data entirely.
Application settings — including API keys you provide and authentication tokens — are stored in a local settings file on your device and are never transmitted to us.
2. AI processing
When you capture text or use the chat and briefing features, the relevant text (your capture, your project names and descriptions, your profile line, and relevant tasks or calendar events) is sent to a large-language-model provider to be classified or summarized:
- Default: requests are routed through our API proxy (hosted on Vercel) to an AI model provider. We keep minimal request logs (timestamps, device identifier, token counts) for abuse prevention and cost control. We do not use your content to train models, and our model providers are used under terms that prohibit training on API data.
- Bring your own key: if you configure your own API key in Settings, requests go directly from your device to that provider under your own account, bypassing our proxy entirely.
3. Google user data (Google Calendar)
Mindsill optionally connects to Google Calendar so your daily briefing can show today's events. If you choose to connect your Google account:
- What we access: read-only access to your calendars and events, via the
calendar.readonlyscope. Mindsill never creates, edits, or deletes calendar data. - How it is used: event titles and times for the current day (and the next) are displayed in your briefing and, when you use the chat or briefing features, may be included in the text sent for AI processing as described in section 2. They are used for no other purpose.
- Where it is stored: your Google authentication tokens are stored only in Mindsill's local settings file on your device. Calendar data is fetched directly from Google's API by the app on your device and is not stored on, or routed through, our servers.
- Sharing: we do not sell, rent, or share Google user data with any third party. We do not use it for advertising. No human at Mindsill can read it — it never reaches us.
- Revoking access: you can disconnect Google Calendar at any time in Mindsill's Settings, or revoke Mindsill's access from your Google Account permissions page. Revoking access invalidates the stored tokens; you can also delete them by removing Mindsill's settings file or uninstalling the app.
Mindsill's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Website and waitlist
If you join the waitlist on mindsill.com, we store the email address you submit and use it only to contact you about Mindsill early access and product updates. You can ask us to delete it at any time. The website sets no analytics or advertising cookies.
5. What we never do
- We do not sell or rent your data — any of it — to anyone.
- We do not use your content or your Google user data for advertising.
- We do not use your content or your Google user data to train AI models.
- We do not store your notes, tasks, or calendar data on our servers.
6. Data retention and deletion
Your content lives on your device: delete the data folder to erase it. Proxy request logs are retained only as long as needed for abuse prevention and are then deleted. To have your waitlist email removed, or for any other deletion request, write to us at the address below.
7. Children
Mindsill is not directed at children under 16, and we do not knowingly collect data from them.
8. Changes to this policy
If we change this policy, we will update this page and the date at the top. Material changes affecting Google user data will be communicated before they take effect.
9. Contact
Questions or requests about privacy: hello@mindsill.com.