MindSync Tips
September 18, 2026

Is Your Mental Health App Data Private? A Checklist Before You Type Anything

Mood data is health data, and most privacy policies are written to be skimmed past. A ten minute method for reading any mental health app's policy, the seven words to search for, and the questions worth asking support before you commit.
A soft enclosed shape in mint and forest tones, quiet and protected

You type a sentence into an app that you have not said out loud to anyone. For about a second you wonder where that sentence actually goes, and then you keep typing. Good instinct, wrong ending. Here is a ten minute method for answering the question about any mental health app, including this one.

This is a checklist, not a sales page. It should be just as useful if you never install MindSync, and it has to survive being pointed at MindSync.

Why mood data is a different kind of data

A mood log is not a list of numbers about your days. It is a dated map of when you were struggling.

Put a few months of it together and it supports conclusions nobody typed in: which weeks you slept badly, when a relationship went wrong, which stretch you were off work. Free text goes further. Your notes contain other people by name, and none of them agreed to anything.

The law mostly recognizes this. Under the EU General Data Protection Regulation, health data sits in a special category with extra restrictions, in Article 9. In the United States, several state laws now reach consumer health data specifically, including Washington's My Health My Data Act, passed in 2023. None of this is legal advice, and the rules differ by country.

What research and regulators actually found

Huckvale, Torous and Larsen assessed 36 top-ranked apps for depression and smoking cessation across Android and iOS, published in JAMA Network Open in 2019. Of those 36, 33 transmitted data to third parties, which is 92%. Only 25 had a privacy policy at all. Among the apps sending data on to Google or Facebook services, fewer than half said so in their policy. The caveat is real: a 2019 snapshot, two conditions, a limited sample, and apps change. The pattern is still a reason to check.

The Mozilla Foundation's Privacy Not Included project reviewed the category twice. In the 2022 edition, 28 of the 32 mental health apps reviewed got its warning label. In the 2023 update, 19 of 32 did. That is a nonprofit review with a published methodology, not peer-reviewed research. Things improved. Most apps still got flagged.

Regulators moved too. In 2023 the US Federal Trade Commission finalized an order against an online counseling company, requiring a payment of $7.8 million and banning it from disclosing consumers' health data to third parties for advertising. In 2024 the same agency finalized changes to its Health Breach Notification Rule to make clear it covers health apps not covered by HIPAA.

Confidential does not mean here what it means in therapy

Therapy confidentiality is a professional obligation

Your therapist is bound by a professional ethics code and by the body that licenses them. In the US, confidentiality sits in Standard 4 of the American Psychological Association's Ethics Code, with parallel rules elsewhere. Breaking it is not a customer service problem. It is a licensing problem, with a complaints procedure attached.

A consumer app usually runs on a privacy policy instead

An app you downloaded yourself normally runs on a document the company wrote and can amend. It binds the company through contract and regulation rather than through a professional code. That is not automatically worse, but it is a different kind of promise, enforced by different people.

Where health privacy rules apply, and where they usually do not

In the US, HIPAA applies to covered entities such as health plans and most health care providers. A wellbeing app you found in the App Store is usually neither. In the EU and the UK, GDPR treats health data as a special category no matter who holds it.

The ten minute privacy policy read

You are not going to read the whole thing. You do not need to. Open the policy and search it.

Search the document for seven words

Use Ctrl+F, or the find function on your phone, on each of these: sell, share, third party, advertising, partners, retention, delete. Seven searches, under three minutes.

What you want is an unambiguous sentence about selling and a named list of the companies that touch your data. What should slow you down: trusted partners with nobody named, sharing with affiliates that never says which affiliates, and a policy that never mentions how long anything is kept.

Run it on us. MindSync's privacy policy says "We never sell your personal data", states that there are no ads in the app, and names its processors instead of gesturing at partners: Heroku for hosting, OpenAI for AI analysis, PostHog for analytics, Google Firebase for notifications, Loops for email, Webflow for the website, and the two app stores for payments. The same list also names Contentsquare, plus advertising tags from Google and Meta that run on the marketing website rather than inside the app, and that distinction is exactly the sort of thing worth checking for yourself. It says data is encrypted in transit and at rest. Verify all of it against the document rather than against this paragraph.

Check what happens when you delete your account

Look for two things: a number of days, and the word backups. A policy that promises instant deletion and never mentions backups has either simplified or has not thought about it. Ours says personal data is permanently erased within 30 days, backups included, with the usual carve-outs for records that tax law requires keeping.

Then find the button before you need it. In MindSync it is at the bottom of the Account screen, which you open from the side menu by tapping your own name. The button says Delete Account, and it asks for your password, or another sign in with Google or Apple, before anything happens. You never have to email support.

Check whether analytics gets the content or only the events

There is a large difference between a company knowing you opened the summary screen on Tuesday and a company knowing what the summary said. Decent policies separate usage data from content and say which one goes where. Then check whether advertising SDKs appear on the list at all, because an app with no ads has no reason to carry them.

One more question belongs here, and most policies written before 2023 do not answer it. If an app does anything it calls AI, something is leaving your device. Our policy names OpenAI as the processor doing that analysis. Look for the equivalent sentence in whatever app you are assessing, and treat its absence as an answer.

Our own answers here are mixed. MindSync has no in-app switch that turns product analytics off. Settings has a Privacy and Data section with two toggles, one for profiling used to personalize content and one for use of therapy treatment data, and neither of them is that switch. On model training the policy is specific: our agreement with OpenAI means your entries are not used to train its models.

Check who owns the company, and what changes if it is sold

Almost every privacy policy has a line about mergers and acquisitions. Find it and read it. MindSync's version says your data leaves in three cases: you share it yourself, the law requires it, or MindSync changes owners. The third case is close to universal here. The useful question is whether the company says it out loud.

Questions worth asking support before you commit

Four questions, one email. How support answers is information in itself. A company that replies in two sentences with links behaves differently from one that sends a paragraph of reassurance.

  • Which companies process my entries, and what do they receive? You want a named list with a role next to each name. Industry leading partners is not a list.
  • If I delete my account today, what is gone in 30 days and what is not? A number plus named exceptions, such as billing records, beats a promise that everything disappears immediately.
  • Can I export everything I have written, and in what format? The answer should point at a specific place in the app or a specific request process.
  • Is anything I write used to train models? Yes or no, plus a pointer to where that is written down. Silence is an answer too.

What you control, whatever app you use

Reading policies is the half of this you do once. The rest is habit.

Write what you need, not everything. A line that says "argument with M, Tuesday, same pattern as last month" will serve you as well six weeks later as three paragraphs with full names, and it carries a fraction of the exposure. Initials cost you nothing.

Know where deletion lives before you need it, and know what deleting actually does.

Therapy timeline in MindSync

Therapy timeline
Everything you have written sits on one filterable timeline with a recycle bin, so removing something is a calm decision. Try it free in MindSync →

In MindSync that bin is called Recently Deleted, behind the trash icon on the Therapy tab, and it keeps things for 24 hours, not days. You can restore something. You cannot empty it early, and some things never go there at all.

Decide how big a footprint you need. Not everyone needs a diary. If you only want to know whether this month went better than last, a daily rating of two or three things gets you the trend with almost no text stored anywhere. There is more on what mood data can and cannot tell you, and if you are keeping notes on how a medication is going, that is health data too.

Wellbeing check-ins
A one minute rating of the areas you are working on, which is the smallest useful footprint if you want the trend without the diary. Try it free in MindSync →

Review permissions once a quarter. Microphone, notifications, health data, photos. Apps ask for permissions when they ship a feature and rarely hand them back.

Keep the part you are not ready to store out of storage. If you would not want something sitting in a cloud service, it does not go in one. Paper still works.

The rest of our answers are in the privacy policy and on the page about how your entries are stored and who can see them, with the mechanics in how MindSync itself works.

Frequently asked questions

Are mental health apps confidential?

Usually not in the sense therapy is. Your therapist is bound by a professional ethics code and a licensing body, with a complaints procedure behind it. Most consumer apps run on a privacy policy instead, which is a document the company writes and can change. Some are stricter than the law requires and some are not, so the answer depends on the policy rather than on the category.

Do mental health apps sell your data?

Some have shared it, which is not the same word and often the more important one. Huckvale and colleagues found in 2019 that 33 of 36 depression and smoking cessation apps transmitted data to third parties, frequently without disclosing it. Search any policy for the word sell, then search it again for share, because the second word is where the activity usually lives.

Is my mental health app covered by HIPAA?

Probably not, if you downloaded it yourself. HIPAA covers health plans, most health care providers and the business associates working for them, and a direct-to-consumer app is usually none of those. The US Federal Trade Commission updated its Health Breach Notification Rule in 2024 to reach health apps outside HIPAA. This is not legal advice, and rules differ elsewhere.

Can my therapist see what I write in an app?

Only if you show them. In MindSync there is no switch today that sends anything to a therapist. If you want your therapist to see something, you bring your phone to the session and show them, or you share a single card, your check-ins for example, as an image from the share button, or you simply tell them what you wrote. Any app that does have such a switch should tell you what gets shared and let you turn it off.

How do I delete my data from a mental health app?

Find the account deletion option in the app's settings first, because deleting the app from your phone removes nothing from the company's servers. Then check the policy for how long full erasure takes and whether backups are included. In the EU and the UK you can request erasure directly under GDPR, and several US state laws give comparable rights.

Keep more from every session

MindSync keeps your sessions and the week between them in one place, so your progress stops slipping away. The trial is free, no credit card needed.

Get it on Google PlayDownload on the App Store