Effective 17 July 2026 · v2026-07-17
Privacy Policy
Minder holds some of the most sensitive documents you own — your passport, Emirates ID, visa. This page states plainly what we collect, how it is protected, who else ever touches it, and the rights you have to see it, export it, or delete it. It describes what the software actually does, not an aspiration.
01Who we are
Minder is operated by CodexaAI(“we”, “us”), the data controller for the personal data described here. For any privacy question, or to exercise a right below, contact privacy@codexaai.io.
Minder is currently in Beta. We serve individuals in the UAE — expats and freelancers personally responsible for their own renewals — and we process personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies to you, the GDPR.
02What we collect
- Your email address. This is your entire account — Minder has no passwords. We use it to send your sign-in link and the reminders you ask for.
- The obligations you add. Titles, dates, amounts, categories and notes you type — your visa expiry, a licence renewal, a bill. This is the content of the product.
- Documents you choose to upload. Passport, Emirates ID, visa and similar scans. Uploading is optional; you can use Minder without storing a single document.
- A little profile detail, if you give it. Name, nationality, emirate, timezone — used to personalise reminders and get dates right for where you live. All optional.
- Minimal technical records. When you sign in we record the time and the originating IP address, as a security log — so you (and we) can spot an account being accessed from somewhere it shouldn’t.
We do not ask for or store passport or Emirates ID numbers as plain fields. If such a number is inside a document you upload, it is protected as part of that encrypted file (see below), never extracted into a readable column.
03How your documents are protected
Documents are the highest-risk thing we hold, and they are treated that way:
- Encrypted before they touch our disk. Every file is encrypted with AES-256-GCM the moment it arrives. The unencrypted file never has an existence on our storage.
- Validated by content, not by name. We check a file’s actual bytes to confirm it is a real PDF or image, and accept only a short allowlist of types. A filename is never trusted or used to build a storage path.
- Never opened by us. Our servers do not render, decode, or run OCR on your files. They are sniffed, encrypted, and stored — nothing more.
- Stored under a random identifier. The file’s name lives only as metadata; the stored object is a random UUID, so nothing about the file is guessable from the outside.
04Who else ever processes your data
We keep the list of third parties deliberately short. As of this version:
- Anthropic — when you type a request in plain language (e.g. “my visa renews next March”), the text is sent to Anthropic’s Claude API to interpret it into a structured obligation. Only the text needed to understand that request is sent. If you ever ask Minder to read an expiry date from a document, that interpretation also happens at Anthropic’s API — it is the only place a document is ever interpreted, and only at your explicit request.
- Our email provider (Amazon SES) — delivers your sign-in links and reminder emails. It sees your email address and the message, nothing more.
- Our hosting (Amazon Web Services) — runs the servers and the encrypted store, within the region we operate.
We do not sell your data, share it with advertisers, or use it to train any model. There are no advertising or analytics trackers embedded in your documents or obligations.
05How long we keep it
We keep your data while your account is active, because the product’s whole job is to remember your obligations for you. When you delete your account:
- Access ends immediately. Your session stops working on the very next request; no one can sign in to the account.
- Your data is held for 30 days, then permanently erased. This grace period exists so an accidental deletion — of, say, your only passport scan — is recoverable. After 30 days the account, its obligations, and its encrypted files are hard-deleted and cannot be recovered by anyone.
06What an administrator can see
Minder has a small operator (super-admin) view. It is bound by the same privacy line as the rest of the product: an administrator can see that an account exists, when it signed up, how many obligations or documents it holds, and a metadata activity log (for example, that a sign-in happened from a given IP, or that a document was viewed). An administrator cannot read the content of your obligations, and cannot open or decrypt your documents. We watch for abuse through behaviour, never by reading what you wrote.
07Your rights
You can, at any time and yourself:
- Access & export everything you’ve stored, from your Settings — no request to us required.
- Correct or update any obligation, document, or profile detail.
- Delete your account and, after the 30-day window, have all of it permanently erased.
Under the UAE PDPL and the GDPR (where it applies to you) you also have the right to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with your data protection authority. To exercise any right we don’t already put directly in your hands, email privacy@codexaai.io and we’ll respond within the timeframe the law requires.
08Children
Minder is for adults managing their own legal obligations. It is not intended for anyone under 18, and we do not knowingly collect their data.
09Changes to this policy
If we change how we handle your data in a material way, we’ll update this page, change the version and effective date at the top, and — where the change requires it — ask you to agree again before you continue. The version you agreed to is recorded against your account, so we always know which text applied to you.