Privacy policy

Your workspace starts on your own computer.

This policy explains what stays on your computer, what can leave it only when you choose an optional integration, and how Mind Marshal handles that information.

Effective date: August 14, 2026

Publisher: Thomas Whiteford

Privacy contact: support@mindmarshal.com

Information stored locally

Mind Marshal is a local-first workspace for notes, journals, projects, databases, attachments, and optional AI-assisted workflows. The app stores the workspace content you create, settings, saved views, activity history, and workflow configuration in its local application data container.

Credentials and tokens are stored in the operating system credential store where it is available. The app does not require a product account or a cloud workspace for local use, and it does not send local workspace data to the publisher by default.

How the local-first design works in practice: see the full feature list.

Optional calendar access

If you choose Show my calendar on the Home page, the app asks macOS for permission to read your calendars. If you allow it, the app reads that day's events from the macOS calendar store so it can show their titles, times, locations, and calendar names on the Home page. It does not request calendar credentials and does not upload calendar data to the publisher or any service.

You can decline the request or revoke calendar access later in System Settings → Privacy & Security → Calendars. The app continues to work without calendar access.

Optional services and information sent off your computer

The app sends workspace content to an external service only after you configure that service. Direct AI requests require a deliberate button, command, or shortcut; opening a page or board, or simply typing, does not send workspace content to an AI provider. A workflow automation or integration sync can run later only when you explicitly enable that automation or subscribe a connected channel or repository.

  • AI providers: When you explicitly ask a selected provider to analyze, continue, summarize, or transform content, the relevant prompt and context are sent to that provider. This includes Ask AI, Continue writing, inbox organization, project planning, daily-note reflections, and the Get an AI suggestion button on a board. A workflow you explicitly configure to run on a card entering a stage or on an interval can send its configured card context when it runs.
  • OAuth providers: When you sign in with a supported provider, the browser and provider exchange authorization data. The app receives the tokens and account metadata needed for that integration.
  • Google Drive selected-file links: In builds configured with Google Drive support, you choose files in Google's system-browser Picker. The connector uses exactly the drive.file scope, stores OAuth access and refresh tokens in the operating system credential store with local SQLite fallback when that store cannot accept or return the credential, and never returns tokens to the UI. Mind Marshal stores local metadata for selected files: file ID, name, MIME type, modified time, web link, size when supplied, trashed/check/error state, and optional Google account display name, email, or permission ID. It uses Drive GET requests only and never uploads, edits, moves, deletes, shares, or organizes Drive files. Refresh is manual and not part of the Slack, Discord, and GitHub 15-minute capture schedule. Removing a link removes local metadata only; disconnecting removes credentials but keeps local links usable as web links.
  • Slack, Discord, and GitHub: When connected, the app sends the requests required for the integration and stores the resulting integration state locally. GitHub can use one-click sign-in or a fine-grained personal access token to read selected repositories' open issues and pull requests assigned to you. Scheduled and manual capture-in never writes back. Separately, the editor's user-triggered Push code action can commit one file through GitHub's Contents API when the connection has Contents read and write access. The app never writes to Slack or Discord. Once you subscribe channels or repositories, it checks for new items every 15 minutes by default. In Settings, set Check connected sources to Only when I press Sync now to turn scheduled capture off.
  • Collaboration: If you enter a collaboration server, workspace updates and the display name you provide are sent to that server.
  • Web research: Web research is available from the research chips on a template board and, when you turn it on in Settings → AI, from the Develop idea and Create action plan page actions (off by default). When used, a search query — built from board row titles, or from the page title plus a short excerpt for the page actions — is sent to DuckDuckGo, and the top public result pages are fetched. The page actions send nothing to a search or page host unless you opt in.
  • Local endpoints: If you configure Ollama or another local AI endpoint, requests remain on your device or local network according to that endpoint’s configuration.

Do not send highly confidential or regulated information to an external provider unless you have reviewed that provider’s terms and are authorized to do so.

Software updates

Signed public builds can check the fixed HTTPS update feed once after the app has been idle for ten seconds, or when you choose Check for updates in Settings. This request retrieves public release metadata, not workspace content. If an update is available, the app shows a notice and downloads or installs it only after you choose to do so. As with any HTTPS request, the hosting service can receive ordinary network metadata such as your IP address and request time.

Website download analytics

To understand which public builds people download, the website records aggregate download starts from its own server logs. A download start is a completed full-file request for a published installer. We exclude partial range requests and our monitoring checks, so this is not a count of installations or active users.

This uses no analytics SDK, cookies, fingerprinting, advertising identifiers, or customer profiles. Short-retention server logs can contain ordinary network metadata such as an IP address and request time while a request is handled. The owner dashboard retains only aggregate totals by date, version, and installer file. It never receives app workspace content and is separate from the Mind Marshal desktop app.

What we do not do

The Mind Marshal desktop app does not include advertising, cross-app tracking, analytics, crash-reporting telemetry, or data brokerage. We do not sell personal information. We do not request access to your camera, location, contacts, or photo library. Dictate requests microphone and speech-recognition permission only after you press the control. On macOS, audio is transcribed on-device and discarded after transcription; it is not uploaded. Read aloud is separate: the built-in neural voice is local, while the optional ElevenLabs Chris voice sends selected text, or the current page when nothing is selected, only after you explicitly enable it and consent.

Retention and deletion

Local workspace data remains on your computer until you delete it or remove the application data. Removing the app itself may not remove its application data. Connected services may retain requests, account data, or content under their own policies. To remove local workspace data, use the app’s available deletion controls or remove its application data after making any backup you want to keep. To disconnect an integration, sign out in the app and revoke access with the provider when available.

Security

The app uses the macOS Keychain for API keys and OAuth tokens when available, and uses the app’s sandboxed application-data container in the Mac App Store build. Network requests use TLS where the selected service supports it. Keep your operating system, providers, and backups protected.

Children

The app is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes and contact

This policy may be updated when the app’s data practices or legal requirements change. The effective date will change with a new version. For privacy questions or requests, contact support@mindmarshal.com.