What Mini keeps, and what it never touches.
Mini is local-first. Your tasks live in a file on your device. If you never make an account, nothing you type leaves that device — except the text you deliberately hand to an AI feature.
Last updated 25 July 2026
The short version
Your tasks are stored on your device. With an account, a copy syncs through our servers so your devices stay in step. Mini sends small usage counts that never contain task text, notes, email addresses or account IDs. We don't sell data, we don't run ads, and we don't train AI models on your tasks.
What we store, and where
- Without an account: your tasks and settings stay on your device, in a local database file. The usage counts described below still apply.
- With an account: your email address, a password hash (handled by Supabase Auth), and your synced task data — titles, notes, sections, cases, flags and timestamps — in our Supabase project hosted in the EU. Row-level security means only your own authenticated session can read your rows.
- Billing: the paid tier is not live yet, so no payment data exists. When it launches, card details will be handled entirely by our payment provider and never reach us. This page will name that provider before the first charge is taken.
AI features
When you use an AI action — structuring a brain-dump, or autofill — the text you submit is sent through our server-side proxy to a third-party model provider (currently OpenRouter), and the result is returned to you. We count how many AI runs you make each day (a date, a tier and a number) so that quotas can be enforced fairly.
We do not use your content to train models. OpenRouter's own policy governs their handling of the text while they process it.
If you are signed out and have not supplied your own model API key, AI features are switched off and nothing is sent anywhere.
Usage analytics
Mini sends minimal first-party usage analytics automatically. Each installation gets a random, persistent identifier. An event can carry the event name, the platform and app version, the hour on your device's clock, a signed-in or signed-out flag, and one small allowlisted value such as a screen name or a count.
Events never include your task titles, your notes, your email address, your account ID, or anything else you type.
Our Cloudflare endpoint derives a two-letter country code from the connecting IP address. The IP is used for that lookup and for basic rate limiting only — it is not written to our analytics database or our application logs. Raw events are deleted after 90 days; daily totals are kept so we can see how the product is used over time. In the current version this collection is always on and there is no in-app opt-out.
What we don't do
No advertising. No selling personal data. No cross-site tracking. No reading your tasks, except as needed to operate the service or where the law requires it.
Your controls
- Use the app with no account at all, indefinitely, entirely on your own device.
- Delete your account in Settings and your synced rows are removed from our servers. The local file stays yours to keep or delete.
- Email info@heorhiishekunov.org to exercise your GDPR rights — access, rectification, erasure and portability. You also have the right to complain to the Irish Data Protection Commission.
Who processes what
- Supabase — hosting, authentication, database, analytics storage
- Cloudflare — site hosting and analytics ingest
- OpenRouter — AI inference, reached through our proxy
Changes
Changes are posted here and dated. Anything material is announced in the app as well.
Who we are
Mini is made by Heorhii Shekunov, a sole developer, at Waterford, Ireland, X91 F1PX.
Contact: info@heorhiishekunov.org