Privacy Policy

How Minty Path handles your data.

This policy explains what is collected, why it is used, and the choices available to you.

1. Controller and contact

Minty Path is operated by Marko Vasic in Serbia. Privacy, account, export, deletion, or security questions can be sent to contact@vasicmarko.com.

2. Data collected

Minty Path collects account data such as name, email address, password hash, role, verification state, session/security information, timestamps, login activity, password reset tokens, and email verification tokens.

Minty Path stores the content you create in the app, including Growth Paths, branches, descriptions, status, Focus, Aim dates, Deadlines, Proof/evidence references and uploaded Proof files, relationships, Inbox items, reminders, recurring reminder settings, Todos, notes, Time Blocks, imports, exports, and backups needed to operate or recover the service.

When you configure inbound email capture, Minty Path stores the personal capture address, approved sender addresses, delivery records, and accepted message content needed to create Inbox items. When you share a Growth Path, it stores the access mode, share token, optional password hash or invitations, included-content choices, and related access-management records.

Technical data may include IP address, browser/device information, request timestamps, security logs, rate-limit records, and error logs generated by the server.

When public-site analytics or marketing tags are enabled and you allow them, those providers may receive public-page usage, device, browser, referral, and campaign information. Minty Path does not place those tags inside the authenticated app, Admin, or private Growth Paths.

3. Why data is used

Data is used to provide the service, authenticate users, secure accounts, prevent abuse, save organizer content, display linked Growth Path information, deliver authorized email captures, enforce sharing choices, support imports/exports, create recovery backups, troubleshoot problems, respond to user requests, and maintain the app.

Minty Path does not sell user data to advertisers.

5. Sharing and providers

Data may be processed by hosting, email, domain, backup, security, analytics, or infrastructure providers as needed to run Minty Path. Public-site measurement providers may be configured through Google Tag Manager or the controlled custom tracking settings and load according to the tracking choice shown on the website.

Minty Path does not currently send your Growth Path content to an AI provider. The Create with AI workflow gives you a prompt to use elsewhere; you decide what to share with that external AI assistant.

External links, Trello files, proof links, and resources may involve third-party services outside Minty Path. Those services are governed by their own privacy practices.

6. Retention

Account and organizer content is kept while the account remains active, unless deleted by the user or removed through an administrative process. Security, rate-limit, verification, reset, inbound-delivery, sharing, and error records may be kept for a limited time for safety, access control, and troubleshooting.

Guest Mode content remains in that browser rather than the Minty Path account database. Clearing browser storage or starting fresh removes that local copy.

Backups may remain for a limited period after content changes or account deletion so the service can recover from mistakes, corruption, or operational failure. Backup cleanup may be adjusted as the service matures.

7. Security and backups

Minty Path uses password hashing, session controls, CSRF protection, ownership checks, rate limiting, protected backup folders, and other reasonable safeguards. No system can be guaranteed perfectly secure.

Branch Private Details are encrypted and decrypted in the browser using the passphrase you provide. Minty Path cannot recover that passphrase or decrypt those entries for you. Normal Notes, Todos, Proof, Inbox items, and other ordinary organizer fields are not the same as Private Details.

Administrative full-system backups may include database rows such as account hashes, tokens, encrypted content, and user-created content. These backups are intended for recovery and must be kept private.

Users should export and keep independent copies of especially important information, proof links, or evidence.

9. Cookies and local storage

Minty Path uses essential session cookies for authentication, security, CSRF protection, and administrator separation. These essential cookies are not used for advertising.

When consent-based public tracking is enabled, the website stores your analytics choice in local storage. You can reopen Privacy choices from the public footer. Approved analytics or marketing providers may then set their own cookies or similar identifiers on public pages.

Local storage is also used for Guest Mode Growth Path content, theme preference, dismissed onboarding or tour state, default view, list page size, reminder defaults, reduced motion, and other device-specific interface preferences. Clearing browser data removes the local guest workspace and resets those preferences.

10. International transfers

Hosting, email, or infrastructure providers may process data outside Serbia. Where applicable, reasonable steps will be taken to use providers and safeguards consistent with legal requirements for international data transfers.

11. Children

Minty Path is not directed to young children. A person who is not legally able to agree to these terms in their jurisdiction should use the service only with appropriate parent or guardian involvement.

12. Changes to this policy

This policy may change as Minty Path develops, moves to a new domain, adds providers, or introduces new functionality. Material changes will be reflected by updating the effective date and, where appropriate, providing additional notice.

Questions can be sent to contact@vasicmarko.com.