Micro Mindfulness
This Privacy Policy (the “Policy”) explains how Micro Mindfulness Pte. Ltd. (the “Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data when you access or use the Micro Mindfulness mobile application and related services (collectively, the “Service”). It also describes the rights available to you and how you may exercise them. By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Policy.
This Policy is designed to comply with the Singapore Personal Data Protection Act 2012 (“PDPA”), Indonesia’s Law No. 27 of 2022 on Personal Data Protection (“PDP Law”), and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”). Where these frameworks differ, we apply the standard most protective of your personal data.
The entity responsible for the processing of your personal data under this Policy is Micro Mindfulness Pte. Ltd., a company incorporated in the Republic of Singapore. For any matter concerning this Policy or your personal data, including requests to exercise your rights, you may contact our privacy team at [email protected].
We collect only the personal data necessary to provide a secure, personalised, and functional Service. The categories below describe what we collect and the context in which it is obtained.
Data we do not collect. We do not collect precise geolocation, your device contacts, or microphone or camera input, except where you grant explicit, contemporaneous permission at the point you use a feature requiring it.
We process your personal data for the purposes set out below. Where the GDPR applies, the corresponding legal basis is indicated; under the PDPA and PDP Law, we rely on your consent and on the necessity of the processing for the performance of our services to you.
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service: authentication, maintaining your practice history, delivering content, issuing tickets, and sending transactional communications. | Performance of a contract |
| Personalisation: selecting content, tailoring prompts, and delivering reminders at times you have chosen. | Consent / legitimate interests |
| Service improvement using aggregated and anonymised usage information. | Legitimate interests |
| Safety and integrity: preventing fraud, spam, abuse, and harassment within community features. | Legitimate interests |
| Legal compliance: responding to lawful requests and meeting regulatory obligations. | Legal obligation |
We do not use your personal data to train third-party advertising models, and we do not profile you for advertising purposes.
Some information you provide—such as mood entries and wellbeing logs—may constitute sensitive personal data (including data concerning health) under the GDPR, the PDP Law, and comparable frameworks. We process such data solely to provide the wellness features you request, and on the basis of your explicit consent, which you give when you enter this information. You may withdraw that consent at any time by deleting the relevant entries or your account, as described in Section 8.
We disclose the minimum personal data necessary to trusted service providers who process data on our behalf and under contract, solely to operate the Service. Each provider is engaged under a data-processing agreement that restricts its use of your data to our documented instructions.
| Service provider | Function | Data processed |
|---|---|---|
| Mux | Video streaming | Playback URLs and viewing telemetry |
| Cloudflare R2 | E-book hosting | Delivery of purchased or free e-book files |
| Resend | Transactional email | Email address for verification, reset, and receipt messages |
| SuprSend (push relay) | Push notifications | Device push-notification token |
| Google (OAuth sign-in) | Authentication | Name, email, and profile picture, where you sign in with Google |
| Xendit | Payment processing | Payment metadata for ticket purchases |
| Emergent | Application hosting | Infrastructure processing on our behalf |
We may also disclose personal data where required to do so by law, in response to valid legal process, or where necessary to protect the rights, safety, and property of the Company, our users, or the public. We do not sell, rent, or otherwise disclose your personal data to advertisers or data brokers.
Content you contribute to community features—including polls, comments, and shared reflections—is visible to other authenticated users of the Service. You should not include personal identifiers or information you do not wish to make visible to others. You remain responsible for the content you choose to share.
We use only strictly necessary on-device storage, such as a secure authentication token and cached settings, to operate the Service. We do not deploy third-party advertising cookies or engage in cross-site tracking.
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Upon deletion of your account, we will delete or irreversibly anonymise your personal data within thirty (30) days, save for records we are legally required to retain.
Subject to applicable law, you have the right to:
Residents of the European Union, the United Kingdom, and Indonesia additionally have the right to lodge a complaint with their local supervisory authority. We ask that you contact us first so that we may seek to resolve your concern directly. We will respond to any request within the timeframes prescribed by applicable law.
If we intend to process your personal data for a purpose materially different from those described in this Policy—for example, a research initiative or a new integration—we will seek your consent before doing so and provide you with a clear choice. We will not sell or disclose your personal data for such purposes without your prior, explicit consent.
The Service is intended for adults aged eighteen (18) years and older. We do not knowingly collect personal data from individuals under the age of eighteen. If you believe that a person under 18 has provided us with personal data, please contact us at [email protected] and we will take appropriate steps to delete such data.
We operate from Singapore, and your personal data may be processed in Singapore, Indonesia, and other jurisdictions in which our service providers operate. Where personal data is transferred across borders, we implement appropriate safeguards—such as standard contractual clauses or equivalent measures—to ensure a comparable level of protection.
We maintain technical and organisational measures appropriate to the risk, including hashing of passwords, the use of short-lived session tokens stored within the device’s secure keystore, and encryption of data in transit via HTTPS. No method of transmission or storage is entirely secure; if you believe your account has been compromised, please contact us without delay.
We may update this Policy from time to time. Where a change materially affects your rights, we will notify you within the application and by email at least fourteen (14) days before the change takes effect. The “Effective date” above indicates when this Policy was last revised.
For questions, requests, or complaints regarding this Policy or your personal data, please contact our privacy team at [email protected]. We will acknowledge your communication within three (3) business days and endeavour to resolve it within thirty (30) days.
© 2026 Micro Mindfulness Pte. Ltd. All rights reserved. This document is provided for transparency and does not constitute legal advice.