Version 2026-01
Privacy notice
Who we are
- GrandeMinds is operated by DEEJAY, USA. Contact: TechTag-Queries@Grandeminds.com. Privacy and deletion requests can also be made through the Support page, with or without signing in.
Service providers
- Hosting and database: Emergent platform (MongoDB).
- AI features: OpenAI models accessed through the Emergent integration service.
- Image storage: Emergent private object storage.
- Payments: Stripe (currently test mode, no real charges).
- Staff sign-in emails: Resend via Emergent.
- Video huddles: Daily.co once connected (currently simulated, no audio or video is transmitted).
- Age verification: currently a sandbox simulation; a real provider will be named here before launch.
What we collect
- Email, country of residence, date of birth, preferred language, time zone, institution, subject and student status.
- Your exact birth date and verification details are private. Other members see only an age band.
Verification
- Age and student status are verified separately. We store signed results, age bands, expiry dates and provider references rather than identity-document images.
- Manual-review evidence is visible only to verification staff and is overwritten when a decision is made. Evidence that is never reviewed is erased automatically after 30 days by a nightly cleanup job, and the request must then be resubmitted.
AI processing
- AI features run only when a member requests them in an authorised room or project.
- We do not send identity documents, exact birth dates, payment information or unnecessary personal information to AI services.
- Private student content is not used by us to train models. You can exclude your messages from AI summaries in Settings.
Retention and your rights
- Moderation evidence is purged after 180 days and AI outputs are deleted after 90 days by a nightly cleanup job (administrators can adjust these periods).
- You can export your data and delete your account from Settings, or submit a privacy or deletion request through Support.
Security
- Encryption in transit (HTTPS), private image storage with short-lived authorised links, HTTP-only session cookies, rate limits, and mandatory two-step verification for administrators and moderators.
These rules describe how the service operates. Administrator country and consent settings are not, by themselves, proof of legal compliance in any jurisdiction.