Privacy Policy
Last updated:
1. Who this policy is from and what it covers
This policy explains how Savaş Türkoğlu (“we”, “us”) handles personal data in the 2Mind apps for iPhone, Mac and Android, the 2Mind Chrome extension, the 2Mind MCP server, and on the website use2mind.com. For data protection purposes we are the controller.
It does not cover services we link to but do not run, such as the Apple App Store or Google Play. Those are governed by their own policies.
Postal address: Kalkan Mah. Nilüfer Sok 33/1 Kaş, Antalya, Türkiye. Privacy contact: privacy@use2mind.com.
2. What we collect
Account data. Your email address and authentication credentials, handled through our authentication provider. If you sign in with Apple or Google, we receive the identifier and the email address that provider releases to us.
Content you create. The text you write or dictate, the audio recordings you attach, the images you capture, the transcripts and extracted text produced from them, and the tags, collections, summaries and to-do items 2Mind derives from that content. Your chat conversations with your own notes are also stored so you can return to them. On Android, the media files you attach are not uploaded — see section 3.
Content you capture in the browser. The pages, text selections, links and screenshots you save through the 2Mind Chrome extension. They are stored like any other entry, and the same rules apply to them.
Learning signals. When you move an entry to a different collection, we record that correction so routing improves. It is tied to your account and to the entry involved.
Subscription data. Whether your account has an active 2Mind Plus or Pro entitlement, and the anonymous purchase identifiers our subscription infrastructure returns. We never receive your card number: payment is handled entirely by the store you bought through — the Apple App Store or Google Play.
Assistant connections. If you connect an AI assistant through the MCP server or a plugin, we store the connection credentials (for example OAuth tokens) needed to authenticate it, and the questions it sends us.
Technical and diagnostic data. Basic app and device information such as app version, operating system version and device model, plus crash and error reports on iPhone and Mac, used to keep the app working. The Android app does not send diagnostic or crash reports.
What you send us. If you write to a support address or use the contact form, we keep your message and your email address so we can answer.
3. What happens on your device, not on a server
2Mind uses on-device engines for two steps that would otherwise require uploading raw media for analysis — Apple's on iPhone and Mac, Google's on Android:
- Speech-to-text. Voice recordings are transcribed on your device, using Apple's speech recognition on iPhone and Mac and Android's on-device speech recogniser on Android.
- Optical character recognition. Text visible in a photo is extracted on your device — Apple Vision on iPhone and Mac, ML Kit on Android.
This means the analysis of your audio and images happens locally. On iPhone and Mac, the resulting entry — including the media file you chose to attach — is then stored in your 2Mind account so it can sync across your devices and be searched later.
On Android, the media file you attach stays on your device and is never uploaded to your 2Mind account. What leaves the device is the text you wrote or dictated, the text extracted from the attachment, and an opaque reference to the attachment, which is what the entry stores and what our AI providers receive.
4. What we send to AI providers, and why
To provide the features the app is built around, the content of your entries is sent to third-party large language model providers acting as our processors. This happens when 2Mind:
- generates tags for an entry;
- decides which collection an entry belongs to;
- writes or updates a collection summary and extracts open to-do items;
- answers a question you ask in chat, by reading across your entries;
- answers a question your connected AI assistant — Claude, ChatGPT or any other MCP client — asks through the MCP server;
- runs a background research job you have started.
These providers process the content only to return a result to us. We instruct them contractually not to use your content to train their models. We do not send your content to advertising networks, data brokers or analytics companies, and we do not sell it.
If you connect an AI assistant through the MCP server or a plugin, the provider behind that assistant (for example Anthropic or OpenAI) also receives the content your assistant reads or asks about, and processes it under that provider's own terms and policies.
5. Why we are allowed to process it
Under the GDPR we rely on the following legal bases, and under the KVKK on the corresponding grounds in Article 5:
- Performance of a contract — running your account and delivering the features you asked for, including capture, tagging, filing, summaries, search and chat.
- Legitimate interests — keeping the service secure, preventing abuse, fixing crashes, and improving routing quality from the corrections you make.
- Legal obligation — keeping records we are required to keep, such as those relating to purchases.
- Consent — where we ask for it explicitly, for example before enabling an optional feature that needs it. You can withdraw consent at any time.
6. Who else is involved
We use a small number of processors to run the service. Each is bound by a data processing agreement:
- An authentication and database provider, which stores your account and your entries.
- Large language model providers, which generate tags, routing decisions, summaries, research results and chat answers.
- The AI assistant providers you choose to connect (for example Anthropic or OpenAI), which receive the content your connected assistant reads or asks about.
- Apple or Google, whichever store you installed the app from, which processes your purchase and manages your subscription, and our subscription infrastructure provider, which tells the app whether your entitlement is active.
- A hosting and email provider used for the website and for support correspondence.
We do not otherwise share your content. We may disclose data if the law requires it, and we will tell you where we are permitted to.
7. Where your data is processed
Our providers may process data outside your country, including in the United States. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or another recognised transfer mechanism, and by the corresponding requirements under Turkish law.
8. How long we keep it
Your entries stay in your account until you delete them or delete your account. Deleting an entry removes it from the app immediately and from our backups within 30 days.
If you delete your account, we delete your content within 30 days, except where we must keep specific records — for example transaction records — for the period the law prescribes.
MCP connections and their credentials are deleted when you remove the connection, and with your account.
Crash and diagnostic reports are kept for up to 12 months. Support correspondence is kept for up to 24 months.
9. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Under the GDPR these are Articles 15 to 22; under the KVKK they are Article 11.
You can delete an individual entry in the app at any time, and you can delete your whole account and its data from the app's settings on iPhone, Mac and Android, or by asking us. The steps are set out in “Delete your account and data”.
You can remove an AI assistant connection at any time, which immediately revokes its access to your account.
Write to privacy@use2mind.com. We answer within one month under the GDPR and within thirty days under the KVKK. We do not charge for this, and we will not ask you for more information than we need to confirm it is your account.
If you are not satisfied, you can complain to your national supervisory authority. In Turkey that is the Personal Data Protection Authority (KVKK); in the EU it is the authority in your country of residence.
10. Security
Data is encrypted in transit with TLS and encrypted at rest by our infrastructure providers. Access to production systems is restricted to the people who need it. Sensitive keys, including any service-role credentials, are held on the server side and are never shipped inside the app.
No system is perfectly secure. If a breach affects your data and creates a risk to you, we will notify you and the relevant authority within the deadlines the law sets.
11. Children
2Mind is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to privacy@use2mind.com and we will delete it.
12. Changes
If we change this policy in a way that materially affects you, we will say so in the app or by email before the change takes effect. The date at the top of this page always reflects the current version.
13. Contact
Privacy questions and data requests: privacy@use2mind.com. Everything else: hello@use2mind.com. Postal address: Savaş Türkoğlu, Kalkan Mah. Nilüfer Sok 33/1 Kaş, Antalya, Türkiye.
These documents describe how 2Mind is built and operated today. They are drafted in good faith and are not legal advice.