Legal
Privacy Policy
Last updated: 9 June 2026
This policy explains what personal data Myhnd collects, why, who we share it with, and the rights you have over it. We keep it short and plain on purpose. If anything is unclear, email us at henoch@hsmart.dev.
Who we are
Myhnd (“Myhnd”, “we”, “us”) is a personal-link-library service operated by Henoch Schmohe, an independent professional (autónomo) registered in Spain, trading as hsmart.dev. For data-protection purposes we are the data controller for the information described below.
Contact: henoch@hsmart.dev.
What we collect
- Account data — your email address, an optional display name, and a securely hashed password. If you sign in with Google or Apple, we receive your email and a unique account identifier from them (never your password).
- Content you save — the links (URLs) you add, plus the title, summary, category, tags, and other metadata our AI generates about each link. This is your private library; only you can see it.
- Usage counts — how many AI enrichments you run per month, so we can manage fair-use limits.
- Technical data — standard server logs (IP address, timestamps, errors) kept briefly for security and debugging.
We do not collect special-category data, and we do not sell your data to anyone.
How we use it, and our legal basis
- To provide the service (store and organise your links, run search) — legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
- AI enrichment — when you save a link, we fetch its public metadata and send the link and that metadata to Google’s Gemini API to generate a summary, category, and tags. Legal basis: contract.
- Security, abuse prevention, and fair-use limits — legal basis: our legitimate interests (GDPR Art. 6(1)(f)).
- Service emails (e.g. password reset) — legal basis: contract. We do not send marketing email without your consent.
Our AI processing is enrichment only — your saved content is not used to train Google’s models or ours (Gemini API content is excluded from training under Google’s API terms).
Who processes data for us (sub-processors)
We use a small set of trusted providers to run Myhnd. Each only processes data on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Neon | Database hosting | EU (Frankfurt) |
| Vercel | App hosting & delivery | EU / global edge |
| Google (Gemini) | AI enrichment & Google Sign-in | EU / US (SCCs) |
| Apple | Sign in with Apple | EU / US (SCCs) |
| Resend | Transactional email | EU / US (SCCs) |
| Stripe / RevenueCat | Payments (paid plans only) | EU / US (SCCs) |
Where a provider processes data outside the EU, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
Where your data lives
Your account and library are stored in the EU (Frankfurt, Germany). Some sub-processors above may process limited data in the US under appropriate safeguards.
How long we keep it
We keep your account and library for as long as your account is active. When you delete your account, your data is permanently removed from our database, normally within 30 days (backups are rotated out shortly after). Technical logs are kept only briefly.
Your rights
Under the GDPR you can ask us to access, correct, export, or delete your data, and to restrict or object to certain processing. You can delete your account and all its data from inside the app, or by emailing us. We respond within one month.
You also have the right to complain to a supervisory authority — in Spain the AEPD (aepd.es), in France the CNIL (cnil.fr), or your local authority.
Children
Myhnd is not directed at children. You must be at least 16 (or the minimum digital-consent age in your country — 14 in Spain, 15 in France) to use it.
Changes
If we make material changes to this policy, we’ll update the date above and, where appropriate, notify you. Continued use after a change means you accept the updated policy.
Contact
Questions or requests: henoch@hsmart.dev. See also our Terms of Service.