Privacy Policy
How we collect, use, and protect your personal information on the OceanMind platform.
Last updated: March 9, 2026
This summary provides key points from our Privacy Policy. You can find more details about any topic by using our table of contents below.
- What personal information do we process? When you use our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use.
- Do we process any sensitive personal information? We may process health and wellness-related information when you voluntarily provide it to use our Services. We process this data with your consent or as otherwise permitted by law.
- Do we use AI technologies? Yes, AI features are integral to OceanMind and always enabled. We use artificial intelligence (including OpenAI's services) to generate all personalized wellness practices. Using the app requires consent to AI processing.
- Do we sell your personal information? No. We do not sell your personal information to third parties.
- What are your rights? Depending on your location, you may have rights to access, correct, delete, or export your personal information.
- How do you exercise your rights? Contact us at info@oceanmindapp.com.
- Scope & Who We Are
- Information We Collect
- How We Use Information
- Legal Bases for Processing
- How We Share Information
- AI-Powered Products
- Cookies, Analytics & Tracking
- Data Retention
- Security
- International Data Transfers
- Your Privacy Rights
- Consumer Health Data
- State-Specific Privacy Rights (U.S.)
- Children's Privacy
- Do Not Track & Opt-Out Signals
- Third-Party Websites & Services
- Changes to this Policy
- Contact Us
1. Scope & Who We Are
This Privacy Policy explains how OceanMind Wellness Inc ("OceanMind," "we," "our," "us") collects, uses, shares, and safeguards personal information when you use the OceanMind mobile application and our related services and websites (collectively, the "Services").
Data Controller: OceanMind Wellness Inc, a company incorporated in the United States.
Our Commitment: We are committed to protecting your privacy and being transparent about our data practices. We process personal information only when we have a valid legal basis and in compliance with applicable privacy laws.
By using our Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree, please do not use our Services.
2. Information We Collect
We collect information that you provide directly, information collected automatically, and in some cases, information from third parties.
2.1 Information You Provide Directly
Account & Contact Information:
- Name
- Email address
- Password (encrypted) or single sign-on (SSO) identifiers
- Username (optional)
Profile & Preferences:
- Practice goals and interests
- Language preference
- Time zone
- Communication preferences
Wellness Inputs (Voluntary & Optional):
- Mood check-ins and reflections
- Practice logs (breathwork, movement, meditation)
- Perceived stress levels
- Journal entries or notes
- Progress tracking data
- Health-related goals and preferences
Communications:
- Messages to customer support
- Survey responses and feedback
- Correspondence history with us
Payment Information:
- Handled by third-party payment processors (Apple App Store, Google Play Store, Stripe)
- We receive limited transactional metadata (subscription status, purchase date)
- We do NOT receive or store full credit card numbers
2.2 Information Collected Automatically
When you use our Services, we automatically collect certain information:
Usage Information:
- Features and functions you access
- Practice session timestamps and duration
- Content you view or interact with
- App version and settings
- Actions taken within the app
- Search queries within the Services
Device & Technical Information:
- Device model and manufacturer
- Operating system and version
- Mobile carrier
- Unique device identifiers (advertising ID, device ID)
- IP address
- Browser type and version
- Platform type and internet connection speed
- Crash logs and diagnostic data
- Performance metrics
Location Information:
- Approximate location derived from IP address
- With your permission, precise geolocation from your mobile device
- You can disable location tracking in your device settings
Cookies & Similar Technologies:
- First-party cookies for functionality and authentication
- Mobile SDKs for analytics and performance monitoring
- Web beacons and pixels (on our website)
- Session identifiers
2.3 Information From Third Parties
Single Sign-On (SSO):
If you sign in using Apple, Google, Facebook, or other SSO providers, we receive:
- User identifier
- Email address (if you grant permission)
- Name and profile picture (if you grant permission)
- Friend lists (only if you explicitly grant access)
The information we receive depends on your privacy settings with the SSO provider.
Service Providers:
Third-party service providers acting on our behalf may process information, including:
- Cloud hosting providers
- Analytics services
- Customer support platforms
- Payment processors
- Email and communication tools
3. How We Use Information
We process your information for the following purposes:
3.1 Core Service Delivery
- Provide and personalize the Services: Create your account, deliver requested features, customize content recommendations
- Authenticate and secure accounts: Verify your identity, prevent unauthorized access, protect against fraud
- Enable core functionality: Save your preferences, sync across devices, maintain session state
3.2 Communication & Support
- Provide customer support: Respond to inquiries, troubleshoot technical issues, address problems
- Send service communications: Account notifications, security alerts, changes to terms or policies
- Request feedback: Surveys, reviews, user research (with your consent)
3.3 Improvement & Analytics
- Improve the Services: Analyze usage patterns, identify bugs, test new features, enhance performance
- Develop new features: Understand user needs, prioritize product development
- Generate aggregated insights: Create de-identified, statistical data about usage trends
3.4 Safety & Legal Compliance
- Protect security: Detect, prevent, and investigate fraud, abuse, security incidents
- Enforce our Terms: Monitor compliance with our Terms of Service and policies
- Comply with legal obligations: Respond to legal requests, court orders, regulatory requirements
- Protect rights and safety: Defend our legal rights, protect users and the public from harm
3.5 Marketing (With Your Consent)
- Send promotional communications: New features, tips, special offers (you can opt out anytime)
- Personalize marketing: Tailor content based on your interests and usage (where permitted)
- Analyze campaign effectiveness: Measure engagement and optimize communications
We will NOT use your information for any purpose incompatible with those described above without obtaining your consent.
4. Legal Bases for Processing
We process personal information only when we have a valid legal basis. Depending on your location and the type of processing, we rely on:
4.1 For EU/UK/Switzerland Users (GDPR/UK GDPR)
Performance of a Contract:
- To provide the Services you've requested and signed up for
- To create and manage your account
- To process payments and subscriptions
Legitimate Interests:
- To improve and secure our Services
- To conduct analytics and research
- To detect and prevent fraud and abuse
- To optimize performance and user experience
- To support our marketing activities
- To diagnose technical problems
Consent:
- To send marketing communications
- To process sensitive wellness data for personalization
- To use optional features you enable
- To share data for purposes you've authorized
Legal Obligations:
- To comply with applicable laws and regulations
- To respond to lawful requests from authorities
- To cooperate with regulatory bodies
You have the right to withdraw consent at any time, which will not affect the lawfulness of processing based on consent before withdrawal.
5. How We Share Information
We do not sell your personal information. We share information only in the following limited circumstances:
5.1 Service Providers & Processors
We share information with third-party vendors who perform services on our behalf under strict contractual obligations:
Categories of Service Providers:
- Cloud hosting & infrastructure: AWS, Google Cloud Platform, or similar
- Analytics & performance: To understand app usage and improve services
- Customer support tools: To respond to your inquiries efficiently
- Payment processors: Stripe, Apple, Google (for subscription management)
- Email & communication platforms: For sending service and marketing emails
- Data security & fraud prevention: To protect against unauthorized access
- Authentication services: For SSO functionality
- AI service providers: For personalization features
Contractual Safeguards:
- Service providers can only use your information as instructed by us
- They cannot share your information with other organizations without our permission
- They must implement appropriate security measures
- They must comply with applicable data protection laws
- Data Processing Agreements (DPAs) are in place with all processors
5.2 Business Transfers
In the event of a merger, acquisition, financing, sale of assets, bankruptcy, or similar corporate transaction:
- Your information may be transferred to the acquiring entity
- We will require the new entity to honor this Privacy Policy
- We will notify you via email and/or prominent notice on our Services
- You will have the opportunity to delete your account before the transfer
5.3 Legal Requirements & Safety
We may disclose information to:
- Comply with law: Respond to subpoenas, court orders, legal processes
- Enforce our rights: Protect our Terms of Service, investigate violations
- Protect safety: Prevent fraud, abuse, security threats, or illegal activities
- Public interest: Cooperate with law enforcement, regulatory agencies, or national security
- Defend legal claims: As evidence in litigation involving us
6. AI-Powered Products
OceanMind uses artificial intelligence technology, including OpenAI's services, to provide personalized wellness features ("AI Products"). This section explains how we collect, process, and protect your data when using AI features.
6.1 What AI Products We Offer
AI-Generated Personalized Content:
- Personalized breathing exercises tailored to your current state and preferences
- Custom meditation practices based on your wellness goals
- Adaptive movement sequences responding to your progress
- Wellness insights and recommendations from your practice patterns
- Personalized coaching guidance based on your usage data
AI Content Disclosure: All AI-generated content is clearly identified within the app and is not represented as human-created content.
6.2 AI Service Providers
Primary AI Provider:
- OpenAI LLC - We use OpenAI's GPT models for natural language processing and personalized content generation
- Service Agreement: We operate under OpenAI's Business Associate Agreement and Services Agreement
- Data Location: OpenAI processes data in the United States
Additional AI Services:
- We may integrate with other AI platforms as we develop new features
- All new AI providers will be subject to the same strict data protection requirements
- We will update this policy to reflect any new AI partnerships
6.3 How We Process Your Data Using AI
Data Collection and Consent:
- Mandatory AI Processing: AI features are integral to the OceanMind experience and are always enabled when you use the app
- Explicit Consent: By using OceanMind, you explicitly consent to having your data processed by our AI systems and third-party AI service providers (including OpenAI)
- Required for Core Functionality: AI-powered personalization is essential to providing the OceanMind wellness experience and cannot be disabled while using the app
- No Opt-Out While Using App: If you do not consent to AI processing, you cannot use OceanMind services
Information Shared with AI Providers:
- Your wellness state inputs and preferences (mood, stress level, practice goals)
- Anonymized practice history and usage patterns
- Your prompts and requests submitted to AI features
- Session context and personalization parameters
Information We Do NOT Share with AI Providers:
- Your real name or email address
- Payment information
- Device identifiers
- Location data
- Contact information
6.4 Enhanced Data Protection Safeguards
Contractual Protections:
- Data Processing Agreements: AI providers can only process data as we specifically instruct
- No Training on Your Data: We contractually prohibit AI providers from using your personal information to train their public models or improve their services
- Purpose Limitation: Data can only be used for generating your personalized content, nothing else
- No Data Retention: AI providers must delete your data immediately after processing (typically within 30 days)
- Security Standards: AI providers must implement enterprise-grade security measures
- Audit Rights: We retain the right to audit AI providers' compliance with these requirements
⚠️ Important Data Usage Uncertainty:
- Third-Party Processing: While we have contractual protections in place, we cannot guarantee or control exactly how AI providers (including OpenAI) may internally process, store, or handle the data we send to them
- Limited Oversight: We rely on AI providers' representations about their data handling practices, but we do not have direct oversight of their internal systems
- Policy Changes: AI providers may change their data handling practices, and we will notify you of any material changes that affect your data
- Your Acknowledgment: By using AI features, you acknowledge this uncertainty and accept the inherent risks of third-party AI processing
Technical Safeguards:
- Data Minimization: We send only the minimum data necessary for AI processing
- Anonymization: Personal identifiers are removed before data is sent to AI providers
- Encryption: All data in transit to AI providers is encrypted using TLS 1.3
- Access Controls: Strict access controls limit which employees can access AI processing systems
6.5 Your Rights and Control Over AI Processing
Consent Management:
- Account Deletion: The only way to withdraw consent for AI processing is to delete your OceanMind account entirely
- No Partial Opt-Out: You cannot use OceanMind while opting out of AI processing, as AI features are integral to the app's functionality
- Alternative Services: If you do not consent to AI processing, you must seek alternative wellness apps that do not use AI
Data Control:
- Content Deletion: You can delete specific AI-generated content or all AI content through your account settings
- Data Portability: Request a copy of AI-related data in machine-readable format
- Account Deletion: Delete your entire account to stop all AI processing of your data
- Data Export: Export your data before account deletion if desired
6.6 Important Limitations and Disclaimers
⚠️ CRITICAL MEDICAL DISCLAIMER:
- Not Medical Advice: AI-generated practices are NOT medical advice, professional health guidance, or medical recommendations of any kind
- Not 100% Perfect or Correct: AI-generated content is not guaranteed to be accurate, appropriate, or safe for your individual health condition
- Mandatory Medical Consultation: You MUST consult with a qualified healthcare professional, doctor, or medical specialist before following any AI-generated breathing exercises, movement practices, or wellness recommendations
- Individual Health Assessment: Only a qualified healthcare provider can determine if AI-generated practices are appropriate for your specific health status, medical conditions, physical limitations, or medications
- Your Responsibility: You are solely responsible for consulting with healthcare professionals to ensure AI-generated content is safe and suitable for your individual circumstances
AI Content Limitations:
- Accuracy Disclaimer: May contain errors, inaccuracies, inappropriate recommendations, or potentially harmful suggestions
- No Professional Review: AI-generated content is not reviewed by medical professionals, certified wellness instructors, or healthcare providers
- Bias and Limitations: May reflect biases, limitations, or errors present in AI training data
- Individual Suitability: May not be suitable for users with specific health conditions, injuries, disabilities, or physical limitations
- No Personalized Assessment: AI cannot assess your current health status, physical condition, or medical history
When to Seek Professional Help:
- Before Starting: Consult a healthcare provider before beginning any new breathing, movement, or wellness practice
- Medical Conditions: Especially important if you have heart conditions, respiratory issues, pregnancy, injuries, or chronic health conditions
- Discomfort or Pain: Stop immediately and consult a healthcare provider if you experience any discomfort, pain, dizziness, or adverse reactions
- Mental Health: Consult mental health professionals for psychological or emotional concerns
Emergency Situations:
- Not for Emergencies: AI features are not designed for medical or mental health emergency situations
- Seek Immediate Help: If you are experiencing a medical or mental health emergency, contact emergency services immediately (911 in the US)
- Crisis Support: For mental health crises, contact the Suicide & Crisis Lifeline at 988 (US) or your local emergency services
- Do Not Delay: Do not rely on AI-generated content in crisis situations - seek immediate professional help
7. Cookies, Analytics & Tracking
7.1 Cookies & Similar Technologies
We use cookies, web beacons, pixels, and mobile SDKs to:
- Maintain your session and keep you logged in
- Remember your preferences and settings
- Analyze usage patterns and performance
- Measure the effectiveness of features
- Provide security and prevent fraud
Your Control:
- Browser Settings: Most browsers allow you to block or delete cookies
- Mobile Settings: Disable advertising IDs in your device settings
- In-App Settings: Manage analytics preferences where available
Impact of Disabling: Some features may not function properly without essential cookies or SDKs.
7.2 Analytics Services
Google Analytics:
We use Google Analytics to understand user behavior and improve our Services. We have implemented:
- IP anonymization (last octet removed)
- Data sharing with Google disabled for advertising purposes
- Contractual data processing terms
Other Analytics:
- Firebase Analytics (for mobile app performance)
- Mixpanel or similar (for product analytics)
- Error tracking services (Sentry, Bugsnag, or similar)
All analytics providers operate under data processing agreements.
7.3 Do Not Sell or Share My Personal Information
We do not sell personal information.
To the extent any cookies or analytics are considered "sharing" under state privacy laws:
- You can opt out via our Cookie Settings
- You can disable cookies in your browser
- We honor Global Privacy Control (GPC) signals where required by law
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
8.1 General Retention Periods
While Your Account is Active:
- Account and profile information: Retained for account duration
- Wellness data and practice logs: Retained for account duration
- Communications and support tickets: Up to 7 years
- Usage logs and analytics: Up to 3 years (aggregated/anonymized thereafter)
After Account Deletion:
- Most personal information is deleted within 90 days
- Some information may be retained for legitimate purposes:
- Legal compliance (e.g., financial records for 7 years for tax purposes)
- Fraud prevention (hashed identifiers to prevent re-registration by banned users)
- Backup systems (deleted within 180 days from backups)
- De-identified analytics data (indefinitely)
When you request deletion:
- We will delete or anonymize your information within 30-90 days
- Some information may be retained as noted above
- We will confirm completion via email
- Deletion is permanent and cannot be reversed
9. Security
We take data security seriously and implement reasonable technical, organizational, and administrative safeguards designed to protect your personal information.
9.1 Technical Safeguards
Encryption:
- Data in transit: TLS 1.2 or higher encryption for all data transmission
- Data at rest: AES-256 encryption for sensitive data stored in databases
- End-to-end encryption for certain sensitive communications
Access Controls:
- Multi-factor authentication (MFA) for employee access
- Role-based access controls (RBAC) limiting data access
- Least privilege principles (employees access only necessary data)
- Regular access reviews and automated de-provisioning
Infrastructure Security:
- Secure cloud hosting with SOC 2 Type II certified providers
- Network segmentation and firewalls
- Intrusion detection and prevention systems
- Regular security scanning and penetration testing
- DDoS protection and rate limiting
9.2 Your Role in Security
Protect Your Account:
- Use a strong, unique password
- Enable biometric authentication (Face ID, Touch ID, fingerprint)
- Never share your password or login credentials
- Log out from shared devices
- Enable two-factor authentication when available
- Report suspicious activity immediately
Limitations:
Despite our efforts, no security measures are perfect or impenetrable. No electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
10. International Data Transfers
10.1 Cross-Border Transfers
OceanMind is based in the United States. Your information may be transferred to, stored, and processed in:
- The United States
- Countries where our service providers operate
- Any country where we have operations or affiliates
These countries may have data protection laws different from your country of residence.
10.2 Transfer Mechanisms
When transferring personal information from the EU/EEA, UK, or Switzerland, we use approved transfer mechanisms:
- Standard Contractual Clauses (SCCs): European Commission-approved SCCs for EU/EEA transfers
- UK International Data Transfer Agreement (IDTA) for UK transfers
- Swiss-approved clauses for Swiss transfers
Additional Safeguards:
- Encryption in transit and at rest
- Strict access controls
- Contractual commitments from service providers
- Regular compliance audits
11. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information. We honor these rights as required by applicable law.
11.1 Rights Available to Most Users
- Right to Access: Request confirmation of whether we process your personal information and obtain a copy
- Right to Correction: Request correction of inaccurate or incomplete information
- Right to Deletion: Request deletion of your personal information
- Right to Opt-Out of Marketing: Unsubscribe from marketing emails and push notifications
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
11.2 Additional Rights for EU/UK/Swiss Users (GDPR/UK GDPR)
- Right to Restriction: Request that we limit processing of your information in certain circumstances
- Right to Data Portability: Receive your information in a structured, commonly used, machine-readable format
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent for processing based on consent at any time
- Right to Lodge a Complaint: File a complaint with your local supervisory authority
11.3 How to Exercise Your Rights
Self-Service:
- Access and update most information in your account settings
- Delete your account via in-app settings
Contact Us:
- Email: info@oceanmindapp.com
- Subject line: "Privacy Rights Request"
- Include: Your name, email, specific request, and jurisdiction
Response Time:
- We will acknowledge your request within 5 business days
- We will fulfill requests within 30-45 days (or as required by local law)
- Complex requests may require an extension (we will notify you)
12. Consumer Health Data
Certain jurisdictions (including Washington, Nevada, Connecticut, and other U.S. states) have enacted laws specifically regulating "consumer health data."
12.1 What is Consumer Health Data?
Under these laws, consumer health data includes information that:
- Identifies or could reasonably be linked to an individual
- Relates to physical or mental health, health conditions, treatments, or similar information
Examples from OceanMind:
- Mood check-ins and emotional wellness reflections
- Stress level assessments
- Wellness practice patterns and goals
- Mental health-related journal entries
12.2 How We Collect and Use Health Data
Collection:
- We collect health data only when you voluntarily provide it
- Collection is necessary to provide the wellness services you request
- You have full control over what wellness data you share
Use:
- To personalize your wellness experience
- To provide AI-powered insights (with your consent)
- To improve our Services and develop new features
- To generate aggregated, de-identified research
We do NOT:
- Sell your health data
- Use health data for advertising purposes
- Share health data except with service providers under strict contracts
- Use health data to discriminate or make decisions about eligibility
12.3 Your Rights Regarding Health Data
In addition to general privacy rights, you have specific rights for health data:
- Right to Consent Management: We obtain your consent before collecting health data; you can withdraw consent at any time
- Right to Access Health Data: Request a list of all health data we have collected about you
- Right to Delete Health Data: Request deletion of all health data (we will delete within 30 days unless retention is required by law)
- Right to Know About Sharing: Request a list of third parties with whom we shared your health data
13. State-Specific Privacy Rights (U.S.)
13.1 California Residents (CCPA/CPRA)
Your Rights:
- Right to Know: What personal information we collect, use, disclose, sell, or share
- Right to Access: Request a copy of your personal information
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
- Right to Limit: Limit use and disclosure of sensitive personal information
- Right to Non-Discrimination: Not be discriminated against for exercising rights
We Do NOT Sell Personal Information: We do not sell your personal information to third parties for monetary consideration.
13.2 Other State Privacy Laws
Residents of the following states have similar rights under their respective laws:
- Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA): Right to access, correct, delete, and obtain a copy; right to opt out of targeted advertising, sale, and profiling
- Utah (UCPA), Montana, Oregon, Texas: Right to access, delete, and obtain a copy; right to opt out of sale and targeted advertising
- Other states: Rights similar to above, with variations based on state law
How to Exercise:
- Email info@oceanmindapp.com with subject "Privacy Rights Request - [State]"
- Specify your state of residence and the right you wish to exercise
- We will respond within the timeframe required by your state law (typically 45 days)
14. Children's Privacy
14.1 Age Restrictions
The Services are NOT intended for children under the age of 13 (or 16 in the EU/UK).
We do not knowingly collect personal information from children under 13 (or 16 in EU/UK) without verifiable parental consent.
14.2 Parental Consent
If you are a parent or guardian and believe your child has provided personal information without consent:
- Contact us immediately at info@oceanmindapp.com
- Subject line: "Child Privacy Concern"
- Provide your child's name and account information
We will:
- Verify your parental relationship
- Promptly delete the child's information
- Terminate the child's account
15. Do Not Track & Opt-Out Signals
15.1 Do Not Track (DNT)
Current Standard: Most web browsers offer a "Do Not Track" (DNT) signal. However, there is no industry consensus on how to respond to DNT signals.
Our Response: We currently do not respond to DNT browser signals. We honor legally required opt-out mechanisms.
15.2 Global Privacy Control (GPC)
For California, Colorado, Connecticut, and other applicable states:
- We honor Global Privacy Control (GPC) signals
- GPC signals are treated as a valid request to opt out of sale/sharing
- Configure GPC in supported browsers or browser extensions
15.3 Mobile Opt-Outs
- iOS: Settings > Privacy > Tracking > "Allow Apps to Request to Track" (OFF)
- Android: Settings > Google > Ads > "Opt out of Ads Personalization"
16. Third-Party Websites & Services
16.1 Links to Third-Party Sites
Our Services may contain links to third-party websites, applications, or services not operated by us:
- Social media platforms
- Partner websites
- Integrated services
- Embedded content
We are NOT responsible for:
- Privacy practices of third-party sites
- Content or security of external links
- Terms or policies of linked sites
16.2 Third-Party Integrations
Social Media Features:
If you use social sharing features:
- The social platform may collect information about you
- Your activity may be visible to others per your social media settings
- Governed by the social platform's privacy policy
SSO Providers:
If you sign in with Apple, Google, Facebook:
- The provider collects authentication information
- Review their privacy policies for details
- You can revoke access in your provider account settings
17. Changes to this Policy
17.1 Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices or Services
- Legal, regulatory, or operational developments
- New features or technologies
- User feedback or privacy best practices
Effective Date: Updates are effective on the "Last Updated" date at the top of this Policy.
17.2 Notice of Material Changes
For material changes that significantly affect your rights or how we process your information:
We will provide notice via:
- Email to your registered email address (at least 30 days before effective date)
- Prominent notice within the Services
- Push notification (if you have enabled notifications)
By continuing to use the Services after changes become effective:
- You acknowledge the updated Privacy Policy
- You agree to be bound by the revised terms
- Your continued use constitutes acceptance
18. Contact Us
18.1 Privacy Questions
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices:
Email: info@oceanmindapp.com
Subject Line: "Privacy Inquiry"
18.2 Data Protection Officer (DPO)
For EU/UK/Swiss users, you may contact our Data Protection Officer:
Email: info@oceanmindapp.com
Subject: "DPO - Privacy Matter"
18.3 Privacy Rights Requests
To exercise your privacy rights (access, delete, correct, opt-out):
Email: info@oceanmindapp.com
Subject: "Privacy Rights Request - [Your State/Country]"
Include in your request:
- Full name
- Email address associated with your account
- Specific right you wish to exercise
- Your jurisdiction (state/country)
- Any relevant details
Response Time:
- Acknowledgment within 5 business days
- Fulfillment within 30-45 days (or as required by applicable law)
18.4 Security Incidents
To report a security vulnerability or data breach:
Email: security@oceanmindapp.com
Subject: "Security Report - [Urgent/High/Medium/Low]"
18.5 Complaints & Regulatory Contact
United States:
- Federal Trade Commission (FTC): ftc.gov/complaint
- State Attorney General (varies by state)
EU/EEA:
- Your local Data Protection Authority: edpb.europa.eu
UK:
- Information Commissioner's Office (ICO): ico.org.uk
Canada:
- Office of the Privacy Commissioner of Canada: priv.gc.ca
Thank you for trusting OceanMind with your wellness journey. Your privacy matters to us.