Privacy Policy
Version 1.0.0 · Effective 2026-08-29 · Last updated 2026-08-29
1. Scope
This policy describes what personal information the OPEN MINDED platform at openmindedlab.com, operated by OPENMINDED, actually collects and how it is used. It covers the website and the platform services behind it.
2. Information we collect
Account and authentication:
- email address, display name, and an internal account identifier;
- a one-way hash of your password (Argon2id) — we cannot read the password itself;
- account security events (sign-ins, sign-outs, failed attempts, verification), kept for account protection;
- email-verification and password-reset tokens, stored only as hashes.
Billing (paid plans):
- Stripe customer and subscription identifiers, plan, subscription status, and webhook event records. Card details are entered on Stripe’s hosted checkout and are processed and stored by Stripe, not by us.
Content you create (yours, stored to provide the service):
- Skill Tree User Work (titles, bodies, revision history, visibility);
- community write-ups, likes, and creator reputation events;
- strategies and strategy drafts;
- research notes, bookmarks, reading progress, and recent searches;
- chart drawings, workspaces, and alerts;
- learning progress in the Skill Tree, when you use it.
Operations:
- server logs with request identifiers for reliability and security (structured logs; we do not log passwords or message bodies);
- email delivery records with our email provider;
- encrypted-at-rest style operational backups (see section 8).
We do not run advertising, third-party analytics, or tracking pixels, and we do not buy data about you.
3. How information is used
- to provide and secure the Service (authentication, authorization, abuse prevention);
- to run subscriptions and billing through Stripe;
- to send transactional email (verification, password reset, account notices);
- to store and display your content according to its visibility settings;
- to operate, debug, and back up the platform.
We do not sell personal information, and we do not use your content to train AI models. Our learning agent consumes only governed official curriculum, never user content.
4. User Work and public content
Content you create is private to your account by default. If you deliberately make something public (public User Work, published community write-ups, public strategy profiles), other signed-in users can see it together with your display name. Making content public never transfers ownership and never makes it official platform content. When you make public content private again it stops being served to others immediately, though it may persist temporarily in backups (section 8). Private content is private from other users; like any hosted service, our systems and operators can technically access stored data and do so only to operate the Service.
5. Service providers
Personal data is processed by these categories of provider:
- Stripe — payment processing (your billing details and card, under Stripe’s own terms);
- Resend — transactional email delivery (your email address and the messages we send you);
- our cloud hosting provider — the servers and databases the Service runs on.
Market-data vendors supply the platform’s analysis systems with market data; they do not receive your personal information.
7. Data retention
Account records, content, and billing records are retained while your account exists. Some records are append-only by design for auditability (for example, content revision history, security events, and billing event records). A formal retention schedule has not yet been adopted; this section will be updated when one is.
8. Security and backups
Passwords are stored only as strong one-way hashes; access to production systems is restricted; service credentials are kept out of the browser; and databases are backed up automatically so your data can survive a failure. Backups mean deleted or privated data can persist in backup copies for a limited operational window before those copies rotate out.
9. Your choices and requests
You can edit your account details, manage your content and its visibility, and cancel your subscription from the billing portal. Self-service account deletion is not yet available — contact us at openmindedlab@gmail.com for account and data requests and we will handle them manually. Where we act on a request, some records may be retained where needed for security, billing, audit, backup, dispute, or legal purposes.
10. Jurisdiction-specific rights
The Service is operated under the laws of the State of New York, United States. The applicability of specific privacy regimes (such as GDPR, UK GDPR, or CCPA/CPRA) depends on jurisdiction and circumstances; whatever applies, you can always reach us at openmindedlab@gmail.com with a privacy request and we will respond to it in good faith.
11. Minors
The Service deals with financial-market content and is intended for individuals 18 or older; the Terms of Service require users to be at least 18. Account creation does not collect a date of birth, and no separate age verification is performed today.
12. Changes
Each version of this policy carries a version number and effective date; we will give notice of material changes before they take effect.
13. Contact
Privacy questions and requests: openmindedlab@gmail.com.