Privacy Policy

Effective date: 2026-01-24 · Version: 2026-01-24

1. Who we are

This Privacy Policy explains how José de Freitas ("we", "us") processes personal data when you use DeeplyClear(the "Service").

Contact: contact@deeplyclear.com

2. What we do (high-level)

DeeplyClear lets you create mindmaps, collaborate, and optionally publish mindmaps to a community gallery. The Service also includes an optional AI Assistant feature that can generate suggestions and operations for your mindmaps.

3. Data we collect and process

3.1 Account data
Email address, password-derived authentication data (handled by our authentication system), and optional profile data such as username and avatar selection.
3.2 Mindmap and community content
Mindmap content you create (nodes, edges, titles, descriptions), collaboration metadata (e.g. presence), and community actions such as starring and forking. If you make a mindmap public, it becomes visible to other users.
3.3 AI Assistant (AI) inputs and outputs
If you use AI Assistant, we send the text you enter and a limited representation of your current mindmap state (a subset of nodes and edges and selected conversation history) to an LLM model provider to generate a response. We store AI Assistant conversation threads and messages in our database so you can continue the conversation and apply operations.
3.4 Analytics and event logging
We log privacy-friendly usage events (e.g. map views, shares, forks, stars, signups/signins, animation starts/completions) for internal product analytics and quality.
For unique public map view counting, we use a short-lived viewer fingerprint hash (derived from client signals such as user-agent/language/screen size plus date). We do not use cookies for this purpose. These hashes are automatically deleted on a short retention window.
3.5 Support communications
If you contact us (e.g. by email), we process the information you provide to respond and support you.

4. Purposes and legal bases (EEA/UK)

Depending on where you are located, we rely on one or more of the following legal bases to process personal data:

Contract (Art. 6(1)(b) GDPR): providing the Service, authentication, storing mindmaps, collaboration features.
Legitimate interests (Art. 6(1)(f) GDPR): security, abuse prevention, internal analytics and service improvement, debugging and quality.
Consent (Art. 6(1)(a) GDPR): where required for specific optional processing (if applicable).
Legal obligations (Art. 6(1)(c) GDPR): if we must comply with laws or lawful requests.

5. Service providers (processors)

We do not sell your personal data. We do not share your personal data with third parties for advertising or data brokerage.

We use a small number of service providers solely to operate the Service (acting as data processors where applicable), including:

Database and backend infrastructure: Convex (used for real-time sync, storage, and analytics rollups).
LLM provider for AI Assistant: OpenRouter (used to route requests to LLM models). When you use AI Assistant, relevant inputs are transmitted to this provider to generate the response.
Email delivery: Resend (used for password reset / one-time codes when configured).

These providers receive only the data needed to provide their part of the Service.

6. International transfers

Depending on your location and the location of our service providers, personal data may be processed in countries other than your own. Where required, we use appropriate safeguards for international transfers.

7. Retention

We keep personal data only as long as necessary for the purposes described above.

Public mindmaps remain public until you change sharing settings or delete them.

Analytics viewer fingerprint hashes are short-lived and automatically deleted on a rolling basis.

8. Your rights

Depending on your jurisdiction, you may have rights such as access, correction, deletion, portability, objection, or restriction. You can delete mindmaps from within the app. For account-level requests, contact us at contact@deeplyclear.com.

9. Security

We implement reasonable technical and organizational measures to protect data. However, no method of transmission or storage is 100% secure.

10. Changes

We may update this Privacy Policy. If changes are material, we will provide an appropriate notice in the Service. Continued use of the Service after the effective date means you have read the updated policy.