Legal
Effective Date: February 1, 2026 · Last Updated: February 11, 2026
MindBacklog ("we," "our," or "us") operates the MindBacklog platform, a product management tool that uses artificial intelligence to help product managers collect, analyze, and prioritize feature requests and feedback.
This Privacy Policy explains what information we collect, how we use it, how we protect it, and what choices you have. It applies to all users of our website (mindbacklog.com) and platform services.
By using MindBacklog, you agree to the practices described in this policy. If you do not agree, please do not use our services.
Account Information
When you create an account, we collect your name, email address, and password (or OAuth credentials if you sign in with Google or Microsoft). If you subscribe to a paid plan, we collect billing information processed securely through Paddle, our Merchant of Record — we never store your payment details.
Product & Workspace Data
When you create a product workspace, you may provide product documentation, URLs, descriptions, vision documents, and answers to clarifying questions. This information is used to build your product context within the MIND intelligence system.
Feedback & Source Data
When you connect external sources, the platform ingests data from those sources on your behalf:
Feedback Widget End Users
When your organization embeds the MindBacklog feedback widget on your website or application, we may collect data from your end users including feedback text, email (if voluntarily provided), page URL, and browser metadata. This data is processed as Customer Data within your Workspace and is subject to the same protections described in this policy. Your organization is responsible for providing appropriate notice to your end users about data collection through the widget.
Usage Data
We automatically collect standard usage information including IP address, browser type, device information, pages visited, features used, and timestamps. This helps us improve the platform and diagnose issues.
| Data Type | Purpose |
|---|---|
| Account info | Authentication, billing, account management, customer support, and transactional communications |
| Product context | Powering the MIND intelligence system — AI recommendations, feature scoring, and story generation specific to your product |
| Feedback data | AI clustering, sentiment analysis, pattern identification, and feature extraction within your workspace |
| Jira / DevOps data | Velocity tracking, Gantt chart projections, and two-way sync of features and user stories |
| Usage data | Platform analytics, performance monitoring, bug diagnosis, and product improvement |
We do not use your product data, feedback, or workspace content to train AI models. Your data is processed to provide services to you and is never used to improve models for other customers.
MindBacklog uses artificial intelligence to provide core platform features including feedback clustering, feature scoring, user story generation, and product context analysis.
How AI processes your data:
What AI does not do:
We use third-party AI model providers to process certain requests. When data is sent to these providers, it is transmitted securely and subject to their data processing agreements, which prohibit the use of customer data for model training. We select providers whose data handling practices meet our security requirements.
MindBacklog integrates with and uses the following categories of third-party services:
| Category | Services | Data Shared |
|---|---|---|
| Hosting | Railway App | All platform data (encrypted at rest) |
| Payments | Paddle (Merchant of Record) | Billing info, email, plan details |
| Authentication | Google OAuth, Microsoft OAuth | Email, name, profile ID |
| AI Processing | Google Gemini, locally-hosted LLMs | Product context and feedback text (per-request, not retained by provider) |
| AWS SES | Email address, notification content | |
| CDN & Security | Cloudflare | Request metadata, cached static assets |
| Integrations | Jira, Azure DevOps | Features, stories, comments, estimates (as configured by you) |
Each third-party service is bound by their own privacy policies. We encourage you to review them. We select services that meet our security and privacy requirements and maintain data processing agreements where applicable.
We maintain a list of sub-processors who process Customer Data on our behalf. The third-party services table above reflects our current sub-processors.
We will notify customers by email at least 30 days before adding a new sub-processor that handles Customer Data. If you object to a new sub-processor, you may terminate your subscription before the change takes effect and receive a prorated refund for prepaid but unused service.
A signed Data Processing Addendum is available upon request for customers who require one for GDPR, CCPA, or other regulatory compliance. Contact privacy@mindbacklog.com to request a DPA.
We take the security of your data seriously and implement industry-standard measures to protect it:
While we implement robust security measures, no system is 100% secure. In the unlikely event of a data breach, we will notify affected users within 72 hours of discovery as required by applicable law.
Active accounts: We retain your data for as long as your account is active and as needed to provide services.
Cancelled accounts: When you cancel your subscription, your account and workspace data are retained for 30 days in case you wish to reactivate. After 30 days, workspace data (product context, feedback, features, AI-generated content) is permanently deleted.
Account deletion: You may request complete account deletion at any time by contacting us. Upon request, all personal data, product data, and workspace content will be permanently deleted within 30 days. Some data may be retained in encrypted backups for up to 90 days before being purged.
Billing records: Transaction records are retained for 7 years as required by financial regulations.
Anonymized data: We may retain anonymized, aggregated data that cannot identify you for analytics and product improvement purposes indefinitely.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@mindbacklog.com. We will respond within 30 days.
California residents (CCPA): You have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information.
European residents (GDPR): Our legal bases for processing personal data are detailed below:
| Processing Purpose | Legal Basis |
|---|---|
| Providing the platform and its core features | Contract performance |
| Payment processing via Paddle | Contract performance |
| AI processing of your product data | Contract performance |
| Sending transactional emails (e.g., password resets) | Contract performance |
| Platform security and fraud prevention | Legitimate interest |
| Usage analytics and product improvement | Legitimate interest |
| Processing feedback widget end-user data | Legitimate interest of our customer (your organization) |
| Marketing communications | Consent |
You have the right to lodge a complaint with your local data protection authority.
We use cookies and similar technologies for the following purposes:
| Type | Purpose | Required |
|---|---|---|
| Essential | Authentication, session management, security | Yes |
| Functional | Remembering preferences, workspace settings | Yes |
| Analytics | Understanding platform usage, feature adoption, performance | No |
We do not use advertising cookies or tracking pixels. We do not share cookie data with third-party advertisers. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the platform from functioning properly.
MindBacklog is a business-to-business product designed for professional use. We do not knowingly collect personal information from anyone under the age of 16. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@mindbacklog.com.
MindBacklog may process and store data in locations outside your country of residence. When we transfer data internationally, we implement appropriate safeguards including standard contractual clauses and data processing agreements to ensure your data remains protected in accordance with this policy and applicable law.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email and update the "Last Updated" date at the top of this page.
We will not retroactively reduce your rights under this policy without your explicit consent. We encourage you to review this page periodically.
If you have questions, concerns, or requests related to your privacy or this policy, you can reach us at:
We aim to respond to all privacy-related requests within 30 days.