Important: This policy is written for the current early-stage Minty Path service at https://mintypath.com. It should be reviewed when hosting providers, analytics, payments, advertising, mobile apps, notification providers, or material product behavior changes.
Privacy Policy
How Minty Path handles your data.
This policy explains what is collected, why it is used, and the choices available to you.
1. Controller and contact
Minty Path is operated by Marko Vasic in Serbia. Privacy, account, export, deletion, or security questions can be sent to contact@vasicmarko.com.
2. Data collected
Minty Path collects account data such as name, email address, password hash, role, verification state, session/security information, timestamps, login activity, password reset tokens, and email verification tokens.
Minty Path stores the content you create in the app, including Growth Paths, branches, descriptions, status, Focus, Aim dates, Deadlines, Proof/evidence references, relationships, Inbox items, reminders, recurring reminder settings, Todos, notes, Time Blocks, imports, exports, and backups needed to operate or recover the service.
Technical data may include IP address, browser/device information, request timestamps, security logs, rate-limit records, and error logs generated by the server.
Minty Path does not include advertising trackers or third-party analytics in this release.
3. Why data is used
Data is used to provide the service, authenticate users, secure accounts, prevent abuse, save organizer content, display linked Growth Path information, support imports/exports, create recovery backups, troubleshoot problems, respond to user requests, and maintain the app.
Minty Path does not sell user data to advertisers.
4. Legal bases
Depending on context, processing may be based on providing the service requested by the user, legitimate interests in operating and securing Minty Path, legal obligations, or user consent where consent is specifically requested.
5. Sharing and providers
Data may be processed by hosting, email, domain, backup, security, or infrastructure providers as needed to run Minty Path. These providers should be selected and configured to support reasonable security and privacy expectations.
Minty Path does not currently send your Growth Path content to an AI provider. The Create with AI workflow gives you a prompt to use elsewhere; you decide what to share with that external AI assistant.
External links, Trello files, proof links, and resources may involve third-party services outside Minty Path. Those services are governed by their own privacy practices.
6. Retention
Account and organizer content is kept while the account remains active, unless deleted by the user or removed through an administrative process. Security, rate-limit, verification, reset, and error logs may be kept for a limited time for safety and troubleshooting.
Backups may remain for a limited period after content changes or account deletion so the service can recover from mistakes, corruption, or operational failure. Backup cleanup may be adjusted as the service matures.
7. Security and backups
Minty Path uses password hashing, session controls, CSRF protection, ownership checks, rate limiting, protected backup folders, and other reasonable safeguards. No system can be guaranteed perfectly secure.
Administrative full-system backups may include database rows such as account hashes, tokens, and user-created content. These backups are intended for recovery and must be kept private.
Users should export and keep independent copies of especially important information, proof links, or evidence.
8. Your rights
Depending on applicable law, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data. Many account and export actions are available from Profile.
For another request, contact contact@vasicmarko.com. Identity may need to be verified before account information is disclosed or changed.
You may also submit a complaint to the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia.
9. Cookies and local storage
Minty Path uses essential session cookies for authentication, security, CSRF protection, and administrator separation. These cookies are not used for advertising.
Local storage is used for theme preference, dismissed onboarding or tour state, default view, list page size, reminder defaults, reduced motion, and other device-specific interface preferences. Clearing browser data resets those local preferences.
10. International transfers
Hosting, email, or infrastructure providers may process data outside Serbia. Where applicable, reasonable steps will be taken to use providers and safeguards consistent with legal requirements for international data transfers.
11. Children
Minty Path is not directed to young children. A person who is not legally able to agree to these terms in their jurisdiction should use the service only with appropriate parent or guardian involvement.
12. Changes to this policy
This policy may change as Minty Path develops, moves to a new domain, adds providers, or introduces new functionality. Material changes will be reflected by updating the effective date and, where appropriate, providing additional notice.
Questions can be sent to contact@vasicmarko.com.