Privacy Policy

KMind Zen Privacy Policy

This Privacy Policy covers KMind Zen Desktop, the website and Web services, plugins, optional account linking, Apple in-app purchases, and related support flows.

Effective date: 2026-03-12 · Last updated: 2026-07-11 · Operator: ZIHAO SONG · Contact: kmind_app@outlook.com

1. Scope and service operator

This Privacy Policy applies to the KMind Zen macOS desktop app, website, Web services, plugins, account and entitlement recovery, Apple in-app purchases, and server notification flows operated by ZIHAO SONG.

If you have a privacy question, you can contact us using the email address listed on this page.

2. Information we may process

The desktop app accesses project files you choose in macOS Open or Save panels, open from Finder or another system handoff, or ask KMind to reopen from its authorized recent-project list. Project content stays on your device by default; buying, restoring, or linking an account does not upload your mind-map files.

App-private state such as recent file paths, preferences, workbench state, and account entitlement snapshots is stored locally. If you link an account, the local account cache stores an access token, user information, and an entitlement snapshot so the sign-in can persist.

When you actively use Web App cloud projects, the mind-map document snapshots, SVG previews, project image assets, and related project metadata you submit are uploaded and stored to provide cloud saving, reopening, export, and revision recovery. This flow is separate from Electron Desktop local files; buying, restoring, or linking an account in Desktop does not automatically upload a local project.

If you choose to link a KMind account, we may process your name, email address, user ID, device-authorization session, app version, platform, app name, IP address, browser and device information, session state, and last-seen time to authenticate the connection and protect the account.

An Apple App Store purchase can activate locally without a KMind sign-in. If you are signed in and the Mac has an active purchase, the app sends the transaction identifier or other necessary purchase-verification information to our server so we can confirm the purchase and link the entitlement to your account. We keep the transaction records needed for verification, restoration, refunds, and support, but do not retain the complete purchase receipt submitted by the device on a long-term basis.

Apple may notify us when the status of a purchase, refund, or revocation changes. We keep the event identifier, purchase environment, product and transaction identifiers, purchase region, currency, price, purchase and revocation dates, and processing status needed to manage the entitlement. Purchase information received while you are signed out is held as an unclaimed record; after a successful account link, the original purchase is associated with the first KMind account that claims it.

Apple handles your payment method; we do not receive your card number or Apple Account password.

When you use the website or online services, we may process basic request logs, language preferences, and technical information used for security, reliability, and abuse prevention. The current desktop app does not upload crash logs or performance diagnostics.

3. Why we process this information

We use this information to provide optional account linking, verify and restore App Store purchases, maintain KMind Zen Standalone Pro entitlements and their desktop and mobile seats, prevent duplicate or cross-account claims, process revocation or refund states, provide support, prevent fraud, and secure the service.

We do not use this information for third-party advertising, data brokerage, or tracking across apps, and we do not expand desktop data collection for unrelated marketing purposes.

4. Sharing with service providers

We exchange the necessary product and transaction information with Apple for App Store purchase verification, restoration, and status updates. Service providers may also process information required for email, authentication, hosting, and infrastructure operations.

We do not sell your personal information. We may disclose information where required by law, regulation, court order, or to protect legal rights and service security.

5. Retention, security, and cross-border processing

We keep authentication sessions, token hashes, transaction records, and notification records for reasonable periods needed for account security, transaction lifecycle handling, entitlement recovery, duplicate or cross-account claim prevention, refund and revocation handling, financial compliance, support, and dispute resolution.

Cloud projects remain available while you use that feature. You can move a project to trash and then delete it permanently. Permanent deletion removes the project record, and the product no longer makes that project available in your workspace. Related underlying storage objects, backups, or security records may continue to be retained for storage integrity, security, disaster recovery, or legal obligations. You can request further deletion through the privacy contact on this page, and we will handle the request under applicable law.

We use reasonable technical and organizational safeguards to protect information. If a payment, email, or cloud provider processes data outside your country or region, we rely on the legal mechanisms and safeguards required for that transfer where applicable.

6. Cookies and browser local storage

This section was updated on 2026-09-11. Cookies are small pieces of information stored by your browser that may be sent with requests to the relevant website. localStorage and IndexedDB are browser-provided local storage. Their purposes and retention differ; using them does not itself mean advertising tracking.

When you sign in or use authenticated features, we use session cookies to maintain your sign-in and support account authentication and security. Session cookies expire according to their validity period and may be updated as your sign-in state changes. You can sign out or manage cookies in your browser settings. Blocking these cookies may prevent sign-in or authenticated features from working.

The Web editor uses localStorage for preferences such as language and keyboard shortcuts, guide state, and workspace navigation, and IndexedDB for local mind maps, project metadata, and assets such as images. The guest editor also generates random device and project identifiers locally; these identifiers are not your name or email address. Browser local storage is separate from server storage used when you actively use cloud projects. A local save does not mean a cloud backup has been made.

localStorage and IndexedDB generally have no automatic expiry and persist until removed by product operations, you, or your browser. Browser storage cleanup, space reclamation, resets, or private browsing may also remove this data. We cannot guarantee that your browser will retain it permanently.

You can inspect or clear cookies and local storage in your browser's site-data settings. Clearing cookies may sign you out. Clearing site data may also delete preferences and mind maps and images stored only in this browser. First export important mind maps outside the browser and check that your backups are usable. Clearing browser data does not delete your account or cloud projects on our servers; use the methods described in this policy for those deletion requests.

We do not use the storage described above for third-party advertising or cross-site tracking. If we introduce non-essential analytics or marketing uses that legally require consent, we will provide purpose information and mechanisms to consent, refuse, and withdraw before enabling them, rather than treating browsing as consent.

When you actively enter a third-party payment page, such as Stripe, that provider may use storage technologies under its own privacy and cookie policies. Please review the information on that page. Browser storage settings for our website do not replace your choices on third-party pages.

7. Your rights and how to contact us

Where applicable law grants you privacy rights, you may ask to access, correct, delete, export, or object to certain uses of your information.

For privacy requests or questions, contact us at kmind_app@outlook.com.