Security

Security at MindFriend

Mind Friend AB (Sweden) · talk@mindfriend.com · Last updated: 20 July 2026

On this page

We take the security of your data seriously and design the Platform to collect the minimum we need. Below is how we protect your information today.

Data in transit

All connections between you and the Platform — sign-in, messages, profiles, bookings, and video/audio sessions — are encrypted in transit using TLS.

Payment data

We never store your card number. Payments are handled directly by a PCI-DSS-compliant payment provider (Stripe); MindFriend holds only a payment reference, not card details.

Access and infrastructure

  • Access to personal data is role-based and limited to staff who need it for their work.
  • The Platform runs behind firewall and DDoS protection, and we keep server logs to detect and investigate security issues.
  • Passwords are stored only as salted hashes, never in plain text.

What we deliberately do not do

  • We do not record sessions (no audio or video recordings). Your messages and in-session chat are encrypted while stored and automatically deleted after 14 days.
  • We do not store clinical notes or therapy records (your professional, an independent controller, holds those).
  • We do not use your health or booking data for advertising, and we use no third-party analytics provider.

Reporting a security issue

If you believe you’ve found a security vulnerability, please email talk@mindfriend.com. We ask that you give us reasonable time to investigate and fix before any public disclosure.

Out of scope for reports: automated vulnerability-scanner output, social-engineering attempts, DoS/DDoS, physical security testing, issues in third-party apps/websites, and missing security headers without a demonstrated impact.