Privacy & GDPR
What we process and why
Privacy-first — here’s exactly what we do and don’t collect.
✉ What we collect
This website collects an e-mail address only when you purchase the founding licence. The access request is filled in directly at munwyn.app and handled by the app, not by this site. We use it solely to contact you about access and the launch, or to deliver what you bought — no sharing for marketing, no selling of data.
◈ Purchases
When you buy the founding licence, your e-mail and payment details are processed by Stripe Payments Europe, Ltd. as our payment processor; card numbers never reach our servers. We keep the records needed for accounting and to deliver the licence (your invitation and its activation). Data inside the app itself — your thoughts and attachments — is covered by the in-app Privacy Policy and the Terms of Service.
◍ Legal basis
We process the data from your access request in order to create and run your account — that is, to perform a contract and take steps before entering into it, under Article 6(1)(b) GDPR. An e-mail from a founding-license purchase is processed to fulfil the order and to meet our accounting obligations.
◉ Cookies
This site uses no analytics, advertising or tracking cookies. We store a single essential cookie only to remember your cookie choice — you can browse the whole page without it.
⏳ Data retention
We keep your e-mail only until launch, or until you ask us to remove it — whichever comes first. After that it is deleted. Once Munwyn launches, these data-retention terms will be updated to cover the use of the service.
⚖ Your rights (GDPR)
You can ask at any time what data we hold, request a correction, or have it deleted. To exercise these rights — or to be removed from the early-access list — write to .
⇩ You can take your data with you
Under Settings → Your data you can have a package prepared at any time with everything we hold about you. It arrives as a ZIP: data.json for machines (complete, importable elsewhere) and myslenky.md for humans, plus your attachments as files. Passwords, two-factor secrets and API keys are not in it — those are not data about you — those are the keys to the lock. The package is deleted after 48 hours.
✕ Closing your account
You close the account yourself in the same place. It is not immediate: a fourteen-day cooling-off period runs, during which one click withdraws the request. Only then are the account and all of its content permanently erased. Before you do it, we recommend having an export prepared.
◈ Where your data runs
The application, the database and the search index run on a server in Vienna — in the EU; backups stay in the EU. The only exception is AI inference. The details, including the list of subprocessors and recovery targets, are on Trust and security.
Last updated: July 2026 · A full privacy policy will be published at launch.