Privacy Policy
Privacy Policy
Effective date: 30 September 2026 · Version 1.3
1. Data Controller
The data controller for the Lotus Mind AI Hub is Lotus Mind Limited, Company No. 826314, incorporated on 18 September 2026 in Ireland. Our registered office is 10 Aderrig Manor, Adamstown, Lucan, Dublin K78 A4T8, Ireland.
Contact for data-protection matters: [email protected]
2. Scope & Prototype Status
This Privacy Policy applies to the Lotus Mind AI Hub web application (the "Hub"), accessible at lotusmind.one and on designated preview ports during development.
Important — prototype status: The Hub is currently a prototype / beta product. Member profiles, tool-run history, and rate-limiting records are stored server-side on Lotus Mind Limited’s servers (Hetzner, Germany). Your browser’s localStorage holds only your session token and UI preferences. Tool inputs submitted to AI-powered tools are answered by Lotus Mind's self-hosted AI model (no third-party provider) per request — see §8a.
3. What Data We Process
In the current prototype, the following categories of data are involved:
| Data | Where stored | Transmitted? |
|---|---|---|
| Display name + session token | Server (EU, Hetzner) — file-based store; 30 days | No |
| Profile: interests, skill level, preferred name | Server (EU, Hetzner) — only if you complete personalisation | No |
| Tool run inputs & outputs (AI-powered tools) | Server (EU, Hetzner) — retrievable 30 minutes; deleted from storage within 30 days; run metadata kept 30 days; see §8a | Yes — forwarded to Lotus Mind's self-hosted AI model per request |
| IP address (hashed, rate-limiting) | Server (EU, Hetzner) — 24 hours | No |
| UI preferences (theme, language) | localStorage — your device only | No |
| Session token | localStorage — your device only | No |
| Waitlist email (+ signup source) | Server (EU) — file-based store | Yes — only when you submit the form |
| Affiliate application details | Server (EU) — file-based store | Yes — only when you submit the form |
No cookies are set by the Hub prototype. No third-party analytics, advertising trackers, or session-recording tools are integrated. Browser-local data uses localStorage, which remains on your device. Server-stored categories (see table above) are kept only for the purposes stated and are never shared or sold.
Language & region counts (opt-in). If you switch on “Count my language & region” in Settings or on a tool page (it is off by default), viewing or running a tool adds one count for your browser language and — only if you set a country in your profile — that country, per tool per day. We store totals only: no name, account, IP address, session, device or text, and we never join these counts with your profile. Totals under 5 are hidden. Daily totals are kept for 400 days, then rolled up into all-time totals. Switch off at any time in Settings — counting stops immediately.
4. Legal Basis for Processing
Where GDPR applies, our legal basis for any processing described above is:
- Consent (Article 6(1)(a)) — where you have actively provided data or enabled functionality.
- Legitimate interests (Article 6(1)(f)) — improving the prototype product and detecting abuse.
- Performance of a contract (Article 6(1)(b)) — once a service agreement is in place (post-prototype).
Lotus Mind Limited acts as data controller for all personal data processed by the Hub. This includes server-side data (member profiles, tool-run history, rate-limiting records) and browser-side data (localStorage session tokens, UI preferences). For profiling/personalisation data, we process on the basis of your explicit consent (Art. 6(1)(a)), which you may withdraw at any time via Settings → Privacy or by emailing [email protected].
5. localStorage & Browser Storage
The Hub uses two storage mechanisms: (1) server-side flat files (member profiles, tool-run history, rate-limiting records) stored on Lotus Mind’s servers in Germany (Hetzner), and (2) browser localStorage for session tokens and UI preferences stored on your device.
You can clear localStorage at any time via your browser privacy settings (Settings → Privacy → Clear browsing data → Local storage / Site data). Clearing localStorage removes your session token and UI state but does not delete server-side data. To request deletion of server-side data, email [email protected].
No cookies requiring consent under the EU ePrivacy Directive are set by the Hub. If this changes — for example when analytics or authentication infrastructure is added — this Policy will be updated and a cookie-consent prompt will be implemented before the change takes effect.
6. Your GDPR Rights
Under the General Data Protection Regulation (GDPR) and applicable Irish data-protection law, you have the following rights in relation to any personal data we process:
- Right of access (Article 15) — to obtain confirmation of whether we process your data and to receive a copy.
- Right to rectification (Article 16) — to have inaccurate data corrected.
- Right to erasure (Article 17) — to have data deleted where processing is no longer justified ("right to be forgotten").
- Right to restriction of processing (Article 18) — to restrict how we use your data in certain circumstances.
- Right to data portability (Article 20) — to receive your data in a machine-readable format.
- Right to object (Article 21) — to object to processing based on legitimate interests.
- Right not to be subject to automated decision-making (Article 22) — where applicable.
We currently store only a minimal set of data on our servers — waitlist email addresses (and affiliate application details) you submit voluntarily. You can exercise all rights below at any time by contacting [email protected]. We respond to any request to exercise these rights within one month of receipt, extendable by up to two further months where the request is complex or numerous (GDPR Article 12(3)); where we extend, we will inform you within the first month of the reasons and your right to complain to the DPC.
If you believe your data-protection rights have been violated, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC):
Data Protection Commission Ireland
21 Fitzwilliam Square South, Dublin 2, D02 RD28
Phone: +353 1 765 0100
Web: dataprotection.ie — Online complaint form
7. Data Retention
localStorage data (preferences, tool state, 2FA enablement flag) is held on your device until you clear browser data.
Server-side data is retained as follows:
- Waitlist emails — retained until we contact you at launch or you request deletion (email: [email protected]).
- Affiliate application details — retained for up to 12 months for application review, then deleted unless an affiliate relationship is formed.
- 2FA verification secret — retained until you disable 2FA or request deletion. Not linked to your identity in the prototype.
When a full production backend is introduced, we will publish a comprehensive retention schedule and data-subject request process.
8. International Transfers
Server-stored data (waitlist emails, affiliate details, 2FA secrets) is hosted on our prototype server located in the European Union (Germany). It is not transferred outside the EEA.
If bot-protection (Cloudflare Turnstile) is enabled in future, your CAPTCHA solution data will be processed by Cloudflare as a processor on our behalf, under Cloudflare's privacy policy and our instructions. This will be disclosed clearly on the affected forms when activated.
When infrastructure is introduced, we intend to host all EU-user data within the European Economic Area (EEA). Any transfer outside the EEA will be subject to appropriate safeguards (e.g., Standard Contractual Clauses) as required by GDPR Chapter V.
§8a — AI Processing
Certain LotusMind tools use a large language model (LLM) to generate responses. These requests are answered by Lotus Mind's own self-hosted AI model (MiniMax M2.7), running on servers we operate and reached over a private encrypted link. No third-party AI provider, AI routing service or non-EEA sub-processor receives your words for these tool interactions. (Updated 2026-09-30: retention times corrected to match our servers' actual behaviour.)
- Data sent: Your tool input text for that specific request only; the model keeps no memory between requests.
- Retention: You can retrieve a run's content for 30 minutes; after that it is no longer accessible, and on most tools the stored text is scrubbed from storage within 30 minutes. On all tools it is permanently deleted from our servers within 30 days. Run metadata (the time of the request, a hashed IP address and the tool used) is kept for 30 days for quality and abuse review, then deleted. Inputs and outputs are never used to train models.
- Legal basis: Performance of a contract / legitimate interest (Art. 6(1)(b) and 6(1)(f) GDPR) — you explicitly chose to use an AI-powered feature. Where health or other special-category data is included in your input, you provide explicit consent for that request (Art. 9(2)(a)).
- Safety: Crisis indicators are detected before any model call and answered with a static support card — such inputs never reach the model.
9. Children and Young People
Who can hold an account today. Creating a Hub account currently requires you to confirm that you are 18 or over; we do not knowingly open accounts for children or teenagers until the parent-facing verification step described below is live. The Hub is nevertheless built as an age-aware service with a child-safe path, and that path is switched on for every member: we ask for a date of birth or age during onboarding and sort members into one of three age bands — child (under 13), teen (13–17) and adult (18 and over). If the date of birth you give shows you are under 18, the protections in this section apply to you immediately, whatever was confirmed at sign-up. Where the signals we hold disagree (for example a declared band and a date of birth) the more protective band always wins, the band recorded on an account cannot be overridden by an individual request, and a member whose band is not yet known is treated as a minor until it is.
Legal basis and the parental-consent ladder (GDPR Article 8). Under Article 8 GDPR and section 31 of the Irish Data Protection Act 2018, the digital age of consent in Ireland is 16; other EU/EEA countries set it between 13 and 16, and in the United States COPPA protects children under 13. The Hub applies one standard everywhere, and it is the more protective one: for every member under 18, personalisation (profiling) is switched off until a parent or guardian has given verifiable consent. Consent moves through a recorded ladder — none → declared (a parent/guardian record has been entered from the member's account) → verified (the parent or guardian confirms through a single-use link or code delivered to them outside the child's session, or through a school attestation). Only verified consent unlocks personalisation; a declaration on its own never does. Current status (16 September 2026): the parent-facing verification step is not yet live, so at present no account in the child or teen band holds personalisation — it stays off for every member under 18 until that step launches, and sign-up for under-18s opens only when it does. A parent or guardian can withdraw a declaration or consent at any time from the member's account; withdrawal switches personalisation off and clears the profiling data described below.
What members under 18 can use. Every tool applies the age bands above: tools built for the child band release only child-safe content (for example a public-domain story catalogue) — parental consent never unlocks other content for that band — and tools intended for teens or adults are refused to younger bands with a clear message rather than silently downgraded. The Hub currently offers no paid plans or payment features to anyone; when they arrive they will not be offered to members under 18.
What data a child's or teen's account holds, and why.
- Account data: display name, e-mail address and a hashed sign-in token — needed to operate the account and to honour your rights (Art. 6(1)(b)).
- Age band, and the date of birth or age it was derived from — needed to apply the age bands above and to keep age-inappropriate content away from minors (Art. 6(1)(c) and 6(1)(f); Art. 8).
- Locale and safety settings: country, language, units, time zone and education system — used only to give age-appropriate, locally correct answers; never used to profile a minor.
- Profiling data (interests, skill level, preferred name, well-being goals): collected ONLY after verified parental consent (Art. 8(1)), and cleared automatically if that consent is missing, withdrawn or cannot be confirmed.
- Parental-consent record: the parent or guardian’s name, relationship (parent, guardian, carer or school), the scope consented to, and their e-mail address stored as a salted hash plus a masked display form — we never keep the plain address. Verification codes, once issued, are single-use and expire after 48 hours.
- Tool inputs and outputs: retrievable for 30 minutes and permanently deleted from our servers within 30 days, with only run metadata (time, hashed IP, tool used) kept 30 days for safety and abuse review (see §8a); never used to train models and never sent to a third-party AI provider.
Safety rails for minors. Every request from any member — and especially from a child or teen — is checked for crisis indicators before it reaches any AI model; when they are found, the request is answered with a static support card (in Ireland this includes Childline for under-18s) and the text is not sent to the model. Where a member's age is not known, the Hub falls back to the child-safe path. Tools also tell every member, in plain words, when they are interacting with an AI system.
Rights and erasure. Parents and guardians may exercise the rights in §6 on behalf of their child, including access, correction and erasure. Erasing a member's account also erases the parental-consent record and any profiling data, and revokes all sessions. If you believe a child has provided data through the Hub without the consent described above, contact us at [email protected] and we will take appropriate steps, including deletion.
Children's data — absolute protections: Data relating to persons under 18 is never sold to any third party and is never used for advertising purposes, including targeted advertising, behavioural profiling, or any form of ad-tech processing. These protections apply unconditionally and without time limit, including following any acquisition or change of control of Lotus Mind Limited. This mirrors the commitment stated in our Free-Tier Commitment (v1.3, September 2026) and in Section 12.7 of the Terms of Service.
10. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of the page and, where changes are material, we will provide notice within the Hub. Continued use of the Hub after changes take effect constitutes acceptance of the revised Policy.
11. Contact
For all data-protection enquiries, please contact:
Governing law: the laws of Ireland, subject to applicable EU data-protection legislation.
© 2026 Lotus Mind Limited · Tools provide information only — not legal, financial, or professional advice.
Lotus Mind Limited · Private company limited by shares, registered in Ireland · CRO 826314 · Registered office: 10 Aderrig Manor, Adamstown, Lucan, Dublin K78 A4T8, Ireland · [email protected]