Privacy Policy

19 July 2026

This policy explains how Mitchell Stanton-Nicholson (ABN 93 361 512 919), trading as fymnd ("fymnd", "we", "us"), handles your personal information. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

1. The Most Important Thing to Understand

fymnd has two kinds of data, treated completely differently:

Public — by design

Goals, records, progress updates, and outcomes you seal to the Ledger are published permanently on the open internet. They are cryptographically chained and cannot be edited or deleted once sealed — by you or by us. Do not seal anything to the Ledger you may ever want removed.

Private

Everything else — your account details, email, course activity, payment information — is private and handled as described below.

2. What We Collect

  • Account data: email address; if you sign in with Google, your name, email, and profile picture as provided by Google. We do not receive your Google password.
  • Ledger data: the declarations, targets, progress updates, and outcomes you choose to seal, plus timestamps and chain hashes.
  • Payment data: processed by Stripe. We receive subscription status, plan, and partial card details (e.g. last four digits) for support purposes. We never store full card numbers.
  • Usage data: log data such as IP address, device/browser type, pages viewed, and timestamps, used for security and to improve the Platform.
  • Communications: messages you send us (e.g. support emails).

We do not knowingly collect information from anyone under 18.

3. How We Use It

  • To provide and operate the Platform, including publishing your Ledger entries as the service is designed to do
  • To manage your account and subscription, and process payments via Stripe
  • To communicate with you about your account, the service, and material changes
  • To secure the Platform, prevent fraud, and detect fabricated records
  • To improve the Platform (analytics on an aggregated basis where practicable)
  • To comply with legal obligations

We do not sell your personal information. We do not use your private data for third-party advertising.

4. Who We Share It With

  • The public: your Ledger entries, by design (section 1)
  • Stripe — payment processing (Stripe's privacy policy applies to payment data)
  • Google — if you use Google sign-in
  • Replit — hosting and infrastructure
  • Legal: where required by law, court order, or to protect our legal rights
  • Business transfer: if fymnd is sold or restructured, data may transfer to the successor under this policy

5. Overseas Disclosure

Our service providers (including Stripe and Google) may store or process data outside Australia, including in the United States. Where this occurs, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles. Because the Ledger is public, Ledger entries are accessible worldwide by design.

6. Retention

  • Private data: kept while your account is active, then retained only as long as needed for legal, accounting, or security purposes before deletion.
  • Ledger data: permanent. Sealed entries are retained and published indefinitely, including after account closure. This permanence is a disclosed, consented feature of the service.

7. Your Rights

  • Access the personal information we hold about you
  • Correct inaccurate private data (account details can be updated in settings)
  • Delete your account and private data, subject to legal retention requirements
  • Complain — contact us first; if unresolved, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au

Ledger limitation: correction and deletion rights do not extend to sealed Ledger entries, which cannot be altered without breaking the integrity of the chain. This limitation is disclosed before you seal each entry and is fundamental to the service.

If you are in a jurisdiction with additional rights (e.g. the EU/UK under GDPR), we will honour applicable rights on the same basis: fully for private data; for Ledger data, publication is based on your explicit consent and contract performance, and the chain's integrity means erasure is technically and functionally incompatible with the service you contracted for. Do not use the Ledger if you may require erasure.

8. Security

We take reasonable technical and organisational measures to protect private data, including encryption in transit, access controls, and reliance on Stripe and Google for credential and payment security. No system is perfectly secure; notify us immediately of any suspected unauthorised access to your account. We will comply with our obligations under the Notifiable Data Breaches scheme where applicable.

9. Cookies

We use essential cookies for sign-in and session management, and basic analytics cookies to understand Platform usage. You can control cookies via your browser; disabling essential cookies may break sign-in.

10. Changes to This Policy

We may update this policy. Material changes will be notified via the Platform or email before taking effect. The "last updated" date above reflects the current version.

11. Contact

Mitchell Stanton-Nicholson trading as fymnd
Email: CEO@FYMND.com