How Minds IN Order handles your information

Effective Date: November 2, 2025

Minds IN Order, operated by Minds IN Order, LLC, respects your privacy. This Privacy Policy explains how we handle information collected through our program website, app, and messaging services.

1. Information We Collect

We collect only the information you choose to provide when using the Minds IN Order program, such as your email address, phone number, and self-reported progress data. We do not collect personally identifiable information unless you voluntarily provide it.

2. How We Use Information

Information is used solely to support your participation in the Minds IN Order program, including:

  • Sending lesson and Check-In reminders (email or text message, if you opt in).
  • Improving program quality and functionality.
  • Generating anonymous, aggregated research data to advance understanding of mood management and recovery.

3. Sharing and Disclosure

We never sell or share your personal information. De-identified data may be used for research or statistical purposes. We may disclose limited information if required by law. Within the app, your reports are visible to another person only when you explicitly share them, and only the report categories you select.

4. Messaging and Opt-In

Text and email reminders are sent only to users who explicitly opt in from within their Minds IN Order account Settings. You may unsubscribe at any time from within the app or by replying STOP to any text message.

5. Data Security

HIPAA-compliant architecture: bcrypt password hashing, TOTP two-factor authentication, CSRF token rotation, PDO prepared statements, rate-limited login, Cloudflare Turnstile CAPTCHA. Config files stored outside the web root. Role-based access controls separate user, partner admin, and system admin capabilities. All authentication events and data access are audit-logged.

6. HIPAA Compliance

Minds IN Order maintains safeguards consistent with the Health Insurance Portability and Accountability Act (HIPAA) to protect your health information. HIPAA BAA signed with AWS. All PHI encrypted at rest and in transit.

All authentication events and PHI (protected health information) access are logged in a comprehensive audit trail. Data sharing access is tracked per-grantee. Admin impersonation is fully logged. The system supports data export for compliance requests.

We execute Business Associate Agreements (BAAs) with all covered entities and service providers that handle protected health information on our behalf. We do not use or disclose your health information except as described in this policy or as required by law.

7. Your Data Rights

You can download a complete copy of your data anytime in Settings under Privacy & Security, and you can request permanent deletion of your account and all data from the same place.

8. Contact Us

For privacy questions, data requests, or concerns, email support@mindsinorder.com.

By using our website or app, you agree to this Privacy Policy.

Need help? Help Center · Contact support