MINDZONE PRIVACY
Aiora Technologies LLC
Last updated 22 July 2026

Privacy, in plain words

Most privacy policies are written so you won't read them. This one is written so you will. It says what we store about you, where it goes, what could go wrong, and how to get everything deleted. If anything here is unclear, write to us and we'll answer, a person, not a bot.

01Who we are

MindZone AI is built and run by Aiora Technologies LLC, a company registered in Wyoming, USA. For anything in this document, email aioraownr@gmail.com. There is no support department. The person reading that inbox is the person who wrote the code.

Age and minors. MindZone is for people 13 and over. Anyone under 18 needs a parent or guardian's permission to take part. The Start Testing action records the tester's agreement that this permission exists; we do not separately collect or verify the guardian's identity. We don't knowingly collect anything from a child under 13; if you believe we have, email us and we'll delete it.

02What we store, and why

03Cookies, browser storage, and what we don't do

We use two first-party, necessary authentication cookies:

Both are HttpOnly, SameSite=Lax, Secure cookies in production. Logout removes the session cookie but keeps browser continuity for the next explicit Start Testing press. “Forget browser” revokes and removes both. Clearing site data has the same browser-side effect, but cannot revoke a copied value; use “Forget browser” when possible.

Local browser storage remembers interface choices: mz-theme, mz-lang, mz-landing-view, and whether this data notice was shown. MindWave also stores the user's biometric-toggle choice and local warning or cooldown state. These values are not account credentials and are not sent to us merely because they exist.

No advertising. No analytics scripts, trackers, or pixels. No selling or renting data. No reading your contacts, precise location, photos, or other device files. No device fingerprinting: we do not combine fonts, canvas, GPU, screen size, timezone, user-agent, or similar signals to identify you. Those attributes change and could merge different people or split one person incorrectly.

We also don't pretend. When the audio can't adapt to your heart rate (it's fixed once rendered), we say so, and only the visuals and breathing guide adapt. The same rule applies to this document: nothing here is aspirational. It describes the system as it is built.

04Where your data travels

Everything lives on a single server we rent from Hetzner, a European hosting company. There is no data warehouse and no analytics pipeline. Three things leave that server, and only when you use the matching feature:

05How it's protected

Traffic is encrypted (HTTPS). Passwords are hashed with bcrypt. Login-session and browser-profile credentials are stored only as SHA-256 digests, so the database does not contain the raw cookie values needed to replay them. Wearable tokens are encrypted at rest. The database and application files are readable only by the service itself. Logins are rate-limited and accounts lock after repeated failures. Every security-relevant event is logged.

06When things go wrong

Honest software plans for its own bad days. Here is ours:

07What we keep, and for how long

DataKept
Rendered audio filesabout 1 hour, then deleted
Live heart-rate streamnever stored
Session promptslast 200 per account
Biometric daily summarieslast 90 per account
Login sessions7 days, then expired and purged
Browser-profile credential digestup to 12 months; removed after expiry or revocation
Tester feedbackup to the last 500 entries per account
Account, security log, and tester agreementuntil you ask us to delete, or as legally required

08What we value

Minimal collection. Every stored field exists because a feature needs it. There is no "collect now, find a use later".

Honesty over polish. If a limitation exists, we name it. That's why this page lists our failure modes instead of hiding them in clause 14(b).

A real exit. Leaving should be as easy as joining. One email deletes everything.

Calm by design. The product exists to lower nervous-system load. Software that spies on its users raises it. Those two things can't coexist, so we chose.

09Your rights

Wherever you live, we treat GDPR as the floor. Email aioraownr@gmail.com. One-click tester accounts have no email address, so include the displayed username and be prepared to verify control of the current browser session. You can:

If you're in the EU or UK and unhappy with our answer, you can complain to your local data protection authority - the supervisory body for the country you live in.

10Changes

If this policy changes in a way that matters, we'll say so on the site and, for anything significant, by email, before it takes effect. The date at the top always tells you when it last moved. This page is currently published in English only; if any translation ever conflicts with it, the English text governs.