Last updated 22 September 2026

Privacy Policy

What we collect, what we do not, and what you can make us do about it.

The short version. When you practice alone, your camera and microphone are processed entirely on your own device and never reach us — that has not changed and will not. If you choose to join a Meditation Meetup, that is a live video call and your camera and audio do leave your device, to the other people in that sit. You are asked each time, before it starts. We hold your email address, your practice minutes and your THETA balance. We do not sell your data, we do not share it for advertising, and you can delete all of it by asking.

1. Who we are

Theta Mind is a service of Only Love LLC, which is the controller of the personal data described here. You can reach us at support@thetamind.now about anything in this policy, including to exercise any of the rights in section 8.

Only Love LLC, trading as Theta Mind
411 Walnut Street, #25654, Green Cove Springs, FL 32043, United States

2. What we collect

Your email address, when you sign in. We use it to identify your account across devices, to send you a sign-in link, and — only if you opt in — to send you a periodic update about Theta Mind.

Your password, if you set one. We store it only as a one-way hash with a salt unique to you, using a deliberately slow algorithm. We never hold your actual password, we cannot recover it, and a breach of our database would not reveal it. You can also sign in without one, using an emailed link.

Your practice record. For each session: the date, how long you sat, how much of it was verified, the measurement method used, and the THETA credited. Plus your streak of qualifying days and the Free Month Credits you have earned and used. This is the ledger the product is built on: without it there is no balance and nothing to redeem. It is derived data only — no camera images, no video and no audio are part of it, or are stored anywhere by us.

Ordinary technical data. Requests to our servers produce logs containing an IP address, a timestamp and a user agent, retained briefly for security and debugging.

3. Solo practice: nothing leaves your device

When you sit alone, no video, no audio and no images ever leave your device. Presence Mode uses your camera and microphone, and every frame is analyzed in your browser on your own machine. What leaves your device is a handful of numbers — how long you have been verified as practicing, and two 0-100 scores — and nothing that could be reconstructed into a picture or a recording. There is no upload path in the software for it to travel down.

Those numbers are sent during the session as well as at the end, roughly every thirty seconds, so that the time we credit is time we actually observed passing rather than a total announced afterwards. It is the same handful of numbers either way. Nothing measured from your face, your pulse or your breathing is sent, and we hold none of it: those readings exist only in your browser, and they are gone when the session ends.

This is the default and it is what happens unless you deliberately do something else. Joining a Meditation Meetup is that something else, and section 3a describes it.

We do not perform facial recognition, do not create or store a faceprint or voiceprint, and do not attempt to identify you from your appearance. The eye check reads only smoothness and brightness in a region of the image, and that measurement is discarded frame by frame.

We do not collect health records, we do not infer medical conditions, and we do not buy data about you from anybody.

3a. Meditation Meetups: a live video call, by your choice

A Meditation Meetup is people meditating together over live video. It works the way any video call works: your camera and microphone are transmitted to the other participants in that sit, directly between your device and theirs.

The video and audio do not pass through our servers. Our part is introducing the participants to each other so their browsers can connect, and we hold nothing of the call itself. If that ever changes — some networks need a relay in the middle — we will say so here before it does.

You are asked every single time, before anything is transmitted. Not once at signup, not buried in these terms — a clear question immediately before that particular sit begins, which you can decline. Declining costs you nothing: you keep practicing alone exactly as before.

We do not record Meditation Meetups. The video and audio pass through and are not written to disk by us. We keep only who attended and for how long, so the sit can be credited as practice.

What we cannot promise, stated plainly: we cannot stop another participant from photographing or recording their own screen. No video platform can. Treat a Meetup the way you would treat being in a room with those people — because in the way that matters, you are. The Meditation Meetup release says this too, and you agree to it before your first one.

4. Why we are allowed to hold it

Where the UK GDPR or EU GDPR applies, our lawful bases are: performance of a contract for your account and practice record, since we cannot provide the service without them; consent for marketing email, which you may withdraw at any time without affecting your account; and legitimate interests for security logging and fraud prevention, balanced against your rights.

5. Who else sees it

We use a small number of processors, each under contract, each doing one job:

  • Vercel — hosting and delivery of the site and API.
  • Turso — the database holding accounts and the practice ledger.
  • Resend — sending sign-in links and, if you opt in, updates.
  • Stripe — taking payment and holding your card. Card details are entered on Stripe's own page and never reach us; we keep the brand, the last four digits and the expiry date so you can recognise the card on file.

We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined by the California Consumer Privacy Act. We have never done so and there is no mechanism in the product for it.

We may disclose data where legally compelled, and will tell you unless prohibited from doing so.

6. Where it is held

Our processors operate internationally, so your data may be processed outside your country, including in the United States. Where required, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

7. How long we keep it

Your account and practice record are kept while your account exists. Delete your account at any time at /account/deleteand we erase them within 30 days, except where we must retain a record to comply with law. Sign-in links are deleted after use or expiry. Security logs are kept for up to 90 days.

8. Your rights, and how to use them

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, export it in a portable form, object to or restrict processing, withdraw consent, and — under the CCPA — to know what is collected and to be free from discrimination for exercising any of it.

Email support@thetamind.now and we will respond within 30 days. We will never charge you or degrade your service for asking.

These rights cannot be signed away, including by agreeing to our Terms. If you are in the UK or EU you may also complain to your supervisory authority — in the UK, the Information Commissioner’s Office.

9. Storage on your device

We use your browser’s local storage to keep you signed in and to remember your preferences — sound on or off, which piece you chose, light or dark. That is strictly necessary for the service to work, which is why you are not asked to consent to it.

We set no advertising or analytics cookies, and we do not track you across other websites. There is nothing here to opt out of because there is nothing being collected for that purpose. If that ever changes, you will be asked first.

10. Automated decisions

Whether a session counts, and how much THETA it earns, is decided by software rather than a person. It has no legal effect on you and does not significantly affect you in the sense the GDPR means — but you can ask a human to review any session you think was scored wrongly, and we will look at it.

We do not profile you, and nothing about your practice is used to make decisions about you outside the app.

11. Children and students

Theta Mind is for a general audience. You must be 13 or older to create your own account, and we do not knowingly allow anyone under 13 to create one. If we learn that a child under 13 has created a personal account outside an approved school or institutional program, we will delete the account and its information. If you believe this has happened, contact support@thetamind.now.

Users under 13 may access Theta Mind only through approved school or institutional programs made available by us. Before any such program launches, we will publish information about how student data is handled.

12. Security, honestly stated

Data is encrypted in transit. Sign-in links are stored only as a one-way hash, so a breach of our database would not let anyone sign in as you. We keep the amount of data we hold deliberately small, because the safest data is data that was never collected.

No service can promise it will never be breached, and we are not going to be the first to claim it. If a breach affects you, we will notify you and the relevant regulator as the law requires.

13. Changes

If we change this policy materially we will say so in the app before the change takes effect, rather than quietly updating the date at the top.