Privacy Policy
Zenith Mind (“we,” “our,” or “us”) respects your privacy. This policy describes how we handle information when you visit our website or use our services. We may update it from time to time; the date at the bottom reflects the latest version.
Data controller. Zenith Mind is operated by mrackwitz UG (haftungsbeschränkt), Managing Director Marius Rackwitz, Dunckerstr. 83, 10437 Berlin, Germany. For privacy questions or to exercise your rights, contact us at privacy@zenithmind.app.
Information we collect
Depending on how you use Zenith Mind, we may collect account details (such as name and email), profile information you choose to share, event and booking data necessary to run the platform, communications you send us, and technical data such as device type, browser, and approximate location derived from IP address for security and analytics.
Closed-alpha scope. Zenith Mind is in a closed alpha. Several capabilities described below are part of the broader platform but are not enabled in the current alpha — including payments, profile facets (and astrology birth data), the community marketplace, connections and private notes, and video rooms. Those sections describe how each will work once available; while a feature is switched off, no data of that kind is collected.
Closed-alpha waitlist. If you join the early-access waitlist, we collect your email address, your optional display name and short message about what brings you to Zenith Mind, and your explicit consent to receive alpha invitations and launch updates. We use this information to understand interest, select a relevant alpha cohort, and contact you about access. You can withdraw at any time by emailing privacy@zenithmind.app.
Connections. When you use the Participate perspective, we store information about your social connections — who you follow, mutual connection requests you send or accept, and the context in which you met (for example, a shared event). If you choose to write private notes about someone you have connected with, those notes are stored and are visible only to you; the person you wrote about cannot see them.
Event reflection prompts. After attending an event, you may receive reflection prompts in your private Reflect space. Your responses are private to you and are never shared with the event facilitator or other attendees. Facilitators may see only an anonymous count of how many participants reflected, and only once a minimum number of responses have been collected (to prevent identifying individuals).
Community marketplace listings. If you publish a listing in a community marketplace, the listing content (title, description, images, and price) is visible to members of that community, consistent with your profile visibility settings. No payment information is collected or processed on the platform for marketplace transactions.
Profile facets. You may optionally add self-authored “facets” to your profile — expressive modules such as astrology or role vectors (a role-literacy model covering how you relate, lead, or surrender across different areas of life). Some facets, or parts of them, may describe sensitive personal characteristics, including your sexual orientation or practices. These are entirely opt-in, and the more sensitive parts are shown only to people you are mutually connected with and who have shared the same kind of information back to you. You choose whether to build a facet yourself or, for role vectors, import a summary from a third-party quiz result you paste in yourself — we never fetch anything from that third party on your behalf.
Astrology facet — birth data. If you add an astrology facet, we ask for your birth date and, optionally, your birth time and place, to compute your chart. This information is encrypted at rest and is never included in any read that serves another person — only you can view or edit it, in your own astrology editor. Everyone else only ever sees the computed chart positions (which cannot be used to reconstruct your birth date, time, or place), and only to the extent you choose to reveal. You can delete your birth data independently of the facet itself at any time; deleting your account deletes both permanently.
Payments. When you pay for an event booking or a facilitator workspace subscribes to a paid plan, payment is handled by our payment processor, Stripe. Your card details are entered on Stripe-hosted pages and go directly to Stripe — they never touch or get stored on our systems. We keep a record of the transaction itself (amount, currency, what it paid for, its status, and any refunds) and, for billing, your name, email address, and — if you provide one — a VAT or tax ID. Facilitators who receive payouts complete identity verification directly with Stripe; those verification documents stay with Stripe. If you use AI credits, we also keep your or your workspace’s credit balance and a history of purchases, grants, usage, expiry, and support adjustments. A usage entry contains an internal correlation reference, not your prompt or the AI response.
How we use information
We use this information to:
- Provide, maintain, and improve the platform
- Process registrations, bookings, and facilitator applications
- Enable social features — connection graphs, familiar-faces surfacing, and private connection notes — at the pace and scope you choose
- Deliver event integration prompts into your private Reflect space and surface anonymous aggregate engagement signals to facilitators
- Support community marketplace listings and connect buyers with sellers via in-app messaging
- Send service-related messages and, where you opt in, product updates
- Protect users and the service against abuse and fraud
- Comply with legal obligations
Sharing
We do not sell your personal information. We work with a small number of service providers who help us operate the platform, including:
- Vercel Inc. — website hosting, edge delivery, EU-region media storage, and (on the marketing site) anonymous traffic analytics
- Neon — managed PostgreSQL database hosting for your account, early-access, and application data, hosted in the EU (Frankfurt, AWS
eu-central-1) - Resend — transactional email delivery (booking confirmations, appointment reminders, application receipts, account messages)
- Whereby AS — video room provisioning, only when a practitioner has enabled automatic video links for a session type. We share the meeting time window with Whereby; no attendee identity or session content is sent.
- Stripe, Inc. — payment processing for event bookings, facilitator payouts, and subscriptions. We share your name, email address, and the details of what you are paying for; Stripe collects your card details directly and also acts as an independent controller for its own fraud-prevention and legal obligations. See Stripe’s privacy policy.
- Functional Software, Inc. (Sentry) — error diagnostics, so that a crash reaches us instead of only you. When a page or a request fails we send the error message, the stack trace, the route path without its query string, and the release and environment it happened in. We do not send your identity, your cookies, request bodies, query parameters, or session recordings, and the message text is scrubbed for email addresses and tokens before it leaves. Because the report is sent from your browser or from our server, Sentry necessarily sees the originating IP address. Our Sentry organisation is in the EU region.
These providers process data on our behalf under written agreements that constrain how they may use it. We may also disclose information if required by law or to protect rights and safety.
International data transfers
Our database (Neon) and media storage are hosted in the EU. Some other providers are based in the United States — for example Vercel and Resend, and Stripe once payments are enabled. Where personal data is transferred outside the EU/EEA, it is protected by an appropriate safeguard: the provider’s participation in the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
Cookies and similar technologies
The marketing site at zenithmind.co does not set tracking or advertising cookies. The one exception is a strictly necessary attribution cookie (zm_entry) set only when you enter a gift code on the marketing site; it carries the attribution to the application, contains no personal data, and expires after 30 days. The application at zenithmind.app sets a small number of strictly necessary cookies for authentication and security (session identifier, CSRF token). A facilitator’s own website, which we host, may ask visitors to enter an access phrase the facilitator shared with them, before the site opens to the public. Entering that phrase sets a cookie so you won’t be asked again on your next visit, and previewing the site from the facilitator’s own dashboard does the same for them. Neither cookie holds anything about you — no name, no identifier, nothing that would let us or anyone else tell you apart from someone else who received the same phrase. We do not use third-party advertising cookies, tracking pixels, or fingerprinting beyond what is described under “Analytics” below.
Analytics
We use Vercel Web Analytics to understand how the marketing site is used. It does not set cookies or store personal identifiers in your browser. Each daily visit is counted via a salted hash of your IP address and User-Agent string, regenerated every 24 hours and discarded shortly after. We see aggregated metrics — page views, country, browser, referrer — but cannot tie a visit back to an individual.
Lawful basis: legitimate interest (Art. 6(1)(f) GDPR) in measuring how our website is used, balanced against the minimal, anonymous nature of the data collected. You can object to this processing by emailing privacy@zenithmind.app or by enabling Do Not Track or a content blocker in your browser, both of which Vercel honours.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. Contact us at privacy@zenithmind.app to make a request. We will respond within a reasonable time.
Data retention
We keep information only as long as needed for the purposes above or as required by law, then delete or anonymize it. AI-credit balances and usage history are deleted when their owning account or workspace is deleted. Payment and invoice records are an exception: we retain them for as long as statutory accounting and tax rules require, even if you delete your account.
Closed-alpha waitlist details are retained while the alpha list is active or until you withdraw your consent or ask us to remove them.
Contact
Questions about this policy: privacy@zenithmind.app or see our Contact page.
Last updated: 9 August 2026