Skip to main contentSkip to main content
Immediate danger? Call Triple Zero (000). My Mind Is Ok is not monitored as a crisis service. Find urgent support
My Mind Is Ok
Menu

Legal & governance · Policy version 2026.09.1

Privacy Policy and Collection Notice

What MMIO collects, what stays on your device, why information is used and how to exercise privacy rights.

Effective 6 September 2026Australian servicePlain-language policy
Important: These policies preserve rights that cannot legally be excluded. They do not make MMIO a clinical or emergency service.

1. Our privacy position

This Privacy Policy and Collection Notice explains how My Mind Is Ok trading as My Mind Is Ok (ABN 35903228833) handles personal information through My Mind Is Ok. We apply the Australian Privacy Principles as the operational baseline for MMIO, including where a small-business exemption might otherwise be arguable. This is the safer position for a wellbeing service because account, support and usage information can become health information depending on its content and context.

Some Australian States and Territories have additional health-records or health-information laws. Those rules may apply because of where a person is located, where information is handled, or whether MMIO is considered to provide a health service. This policy does not reduce those rights.

Private tool writing is designed to stay in your browser. Where a feature says that writing is browser-local and the feature operates as described, MMIO does not receive that text. Account data, support messages, security records, payment metadata and server logs are different: they may reach MMIO or a service provider and are covered below.

2. Information we may collect

Account and membership information

  • name or display name;
  • email address and account identifiers;
  • membership plan, status, start and renewal dates;
  • consent and policy-version records;
  • trusted-browser labels, keyed device-token hashes and recent access times;
  • support, cancellation and complaint history.

Payment and transaction information

Stripe processes card and payment-method details. MMIO may receive a Stripe customer identifier, subscription and invoice identifiers, payment status, amount, currency, billing cadence, limited payment-method description and fraud/risk signals. MMIO does not need to receive the complete card number or security code.

Technical and security information

  • IP address in web-server, security or hosting logs;
  • browser, operating system, device category and request timestamps;
  • login, error, abuse-prevention and security event records;
  • cookie and local-storage identifiers needed for sessions, preferences and trusted-browser controls.

Communications

If you email, submit a contact form, reply to a survey, make a complaint or request support, we collect the message and contact details needed to respond. Please do not send detailed medical histories, diagnoses, therapy notes, information about another person, identity documents or crisis disclosures unless we have specifically explained why the information is necessary and how to send it safely.

Health or sensitive information

MMIO does not require a diagnosis to create a standard membership. A message can nevertheless reveal mental health, disability, medication, treatment or other sensitive information. We will collect sensitive information only with consent or where another lawful exception applies, and only when reasonably necessary for a legitimate function such as handling a complaint, accessibility request, safety report or legal obligation.

3. Information that ordinarily stays on your device

Depending on the product, the following may be stored in browser local storage, IndexedDB or a first-party cookie:

  • tool drafts, reflections, plans and keep cards;
  • activity choices, favourites and personal menus;
  • learning practice markers and portfolio material;
  • game progress and local preferences;
  • a random trusted-browser token stored in an HttpOnly cookie.

Browser-local does not mean indestructible. Data can be lost when browser storage is cleared, a device is reset, private browsing ends or a profile becomes unavailable. Export material you need to preserve.

A future sync, analytics, AI, crash-reporting or support feature could change whether information leaves the browser. MMIO must update this notice and obtain any required consent before enabling such a change. We do not treat a statement in this policy as permission to introduce silent centralisation.

4. How we collect information

We collect information directly from you, automatically through the website and security systems, from Stripe and other contracted service providers, and occasionally from an authorised representative. We do not buy mental-health profiles or sell lists of members.

5. Why we use information

  • to create, secure and administer accounts;
  • to provide the plan and products purchased;
  • to process payments, cancellations, invoices and refunds;
  • to enforce trusted-device and one-active-session controls;
  • to answer support, accessibility, privacy and complaint requests;
  • to maintain reliability, prevent abuse and investigate incidents;
  • to keep evidence of consent and contractual communications;
  • to comply with tax, accounting, consumer, privacy, court and regulatory obligations;
  • to improve aggregate product reliability where measurement is designed not to collect private writing;
  • to send marketing only where consent or another lawful basis exists and an unsubscribe route is provided.

We do not use private writing that remains on the device to build advertising profiles, train general-purpose AI models or infer a diagnosis.

6. Disclosure and service providers

We may disclose the minimum necessary information to providers that help operate MMIO, such as:

  • Stripe for payments, subscriptions and fraud prevention;
  • website hosting, content delivery, domain, email and security providers;
  • professional advisers, insurers, auditors and incident responders under appropriate confidentiality;
  • government, regulators, courts, police or emergency services where disclosure is required or authorised by law;
  • a successor in a genuine business sale or restructure, subject to confidentiality and applicable notice duties.

We do not sell personal information. We do not disclose private wellbeing writing that we never receive.

7. Overseas processing

Cloud, payment, email and security providers may process information outside Australia. Provider locations can change. Before appointing a provider, MMIO should identify likely processing locations, assess privacy and security terms, and take reasonable steps required by Australian law. Stripe and hosting-provider privacy information should be consulted for current locations.

Where Australian Privacy Principle 8 applies, MMIO remains accountable for taking reasonable steps in relation to overseas recipients unless a lawful exception applies. Contact support@mymindisok.com for the current supplier and location register.

8. Direct marketing

Account, security, billing and service messages are transactional and may be necessary to provide the membership. Marketing is separate. You can unsubscribe using the link in a marketing message or by contacting info@mymindisok.com. We will not require you to log in or provide excessive information merely to unsubscribe.

9. Security

MMIO uses layered controls appropriate to the size and risk of the service, which may include access restriction, multifactor authentication for administrators, software updates, least-privilege accounts, encryption in transit, secure payment providers, backups, logging, release testing, trusted-browser controls and incident-response procedures.

No system is risk-free. Do not email passwords, verification codes or unnecessary health documents. If you believe your account or information has been compromised, contact support@mymindisok.com promptly.

10. Retention and deletion

Different records are kept for different periods. Transaction and tax records may need to be retained for statutory periods. Consent, complaint, dispute and security records may be retained while a claim could reasonably arise. Short-lived logs and support material should be deleted earlier when no longer needed. Browser-local writing is controlled through the browser and product deletion controls.

Deletion is not absolute where information must be retained by law, is needed for an active dispute, exists temporarily in a protected backup cycle, or has been irreversibly de-identified. The public retention summary provides more detail.

11. Access and correction

You may request access to personal information MMIO holds about you, or ask for correction if it is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify identity. We will respond within a reasonable period and explain any lawful refusal.

MMIO cannot retrieve browser-local text that never reached our systems. Use the relevant product’s export controls before deleting a device profile.

12. Privacy complaints

Send a privacy request or complaint to support@mymindisok.com. Describe the issue and the outcome sought without including unnecessary sensitive information. We aim to acknowledge promptly, investigate fairly and provide an update within a reasonable period.

If the matter is not resolved, you may be able to complain to the Office of the Australian Information Commissioner. The OAIC generally expects you to first give the organisation a reasonable opportunity to respond. State or Territory health-privacy and health-complaints bodies may also have jurisdiction.

13. Data breaches

MMIO maintains an internal data-breach and cyber-incident procedure. Where the Notifiable Data Breaches scheme applies, suspected eligible data breaches are assessed promptly and within the statutory assessment period, and the OAIC and affected individuals are notified where required. We may also notify people voluntarily where doing so is a reasonable protective step.

14. Changes to this policy

We will publish the current version and effective date. Material changes that expand collection, use or disclosure will not be treated as consent merely because this page changed. We will provide notice and obtain consent where required.

15. Contact

Operator: My Mind Is Ok trading as My Mind Is Ok (ABN 35903228833)
Privacy contact: support@mymindisok.com
General contact: info@mymindisok.com
Service address: Australia (service address available through the business contact where legally required)

Policy version 2026.09.1, effective 6 September 2026.