Privacy Policy

KMind Zen Privacy Policy

This Privacy Policy covers KMind Zen Desktop, the website and Web services, plugins, optional account linking, Apple in-app purchases, and related support flows.

Effective date: 2026-03-12 · Last updated: 2026-07-11 · Operator: ZIHAO SONG · Contact: kmind_app@outlook.com

1. Scope and service operator

This Privacy Policy applies to the KMind Zen macOS desktop app, website, Web services, plugins, account and entitlement recovery, Apple in-app purchases, and server notification flows operated by ZIHAO SONG.

If you have a privacy question, you can contact us using the email address listed on this page.

2. Information we may process

The desktop app accesses project files you choose in macOS Open or Save panels, open from Finder or another system handoff, or ask KMind to reopen from its authorized recent-project list. Project content stays on your device by default; buying, restoring, or linking an account does not upload your mind-map files.

App-private state such as recent file paths, preferences, workbench state, and account entitlement snapshots is stored locally. If you link an account, the local account cache stores an access token, user information, and an entitlement snapshot so the sign-in can persist.

When you actively use Web App cloud projects, the mind-map document snapshots, SVG previews, project image assets, and related project metadata you submit are uploaded and stored to provide cloud saving, reopening, export, and revision recovery. This flow is separate from Electron Desktop local files; buying, restoring, or linking an account in Desktop does not automatically upload a local project.

If you choose to link a KMind account, we may process your name, email address, user ID, device-authorization session, app version, platform, app name, IP address, browser and device information, session state, and last-seen time to authenticate the connection and protect the account.

An Apple App Store purchase can activate locally without a KMind sign-in. If you are signed in and the Mac has an active purchase, the app sends the transaction identifier or other necessary purchase-verification information to our server so we can confirm the purchase and link the entitlement to your account. We keep the transaction records needed for verification, restoration, refunds, and support, but do not retain the complete purchase receipt submitted by the device on a long-term basis.

Apple may notify us when the status of a purchase, refund, or revocation changes. We keep the event identifier, purchase environment, product and transaction identifiers, purchase region, currency, price, purchase and revocation dates, and processing status needed to manage the entitlement. Purchase information received while you are signed out is held as an unclaimed record; after a successful account link, the original purchase is associated with the first KMind account that claims it.

Apple handles your payment method; we do not receive your card number or Apple Account password.

When you use the website or online services, we may process basic request logs, language preferences, and technical information used for security, reliability, and abuse prevention. The current desktop app does not upload crash logs or performance diagnostics.

3. Why we process this information

We use this information to provide optional account linking, verify and restore App Store purchases, maintain KMind Zen Standalone Pro entitlements and their desktop and mobile seats, prevent duplicate or cross-account claims, process revocation or refund states, provide support, prevent fraud, and secure the service.

We do not use this information for third-party advertising, data brokerage, or tracking across apps, and we do not expand desktop data collection for unrelated marketing purposes.

4. Sharing with service providers

We exchange the necessary product and transaction information with Apple for App Store purchase verification, restoration, and status updates. Service providers may also process information required for email, authentication, hosting, and infrastructure operations.

We do not sell your personal information. We may disclose information where required by law, regulation, court order, or to protect legal rights and service security.

5. Retention, security, and cross-border processing

We keep authentication sessions, token hashes, transaction records, and notification records for reasonable periods needed for account security, transaction lifecycle handling, entitlement recovery, duplicate or cross-account claim prevention, refund and revocation handling, financial compliance, support, and dispute resolution.

Cloud projects remain available while you use that feature. You can move a project to trash and then delete it permanently. Permanent deletion removes the project record, and the product no longer makes that project available in your workspace. Related underlying storage objects, backups, or security records may continue to be retained for storage integrity, security, disaster recovery, or legal obligations. You can request further deletion through the privacy contact on this page, and we will handle the request under applicable law.

We use reasonable technical and organizational safeguards to protect information. If a payment, email, or cloud provider processes data outside your country or region, we rely on the legal mechanisms and safeguards required for that transfer where applicable.

6. Your rights and how to contact us

Where applicable law grants you privacy rights, you may ask to access, correct, delete, export, or object to certain uses of your information.

For privacy requests or questions, contact us at kmind_app@outlook.com.