Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how PathMiner (“PathMiner,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use pathminer.ai and related apps, APIs, and integrations (the “Service”). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Who we are

PathMiner is an AI-assisted career and income planning product. We help users turn skills, goals, and constraints into path recommendations, roadmaps, daily tasks, coaching, and related documents. For privacy questions, contact [email protected].

2. Information we collect

2.1 Account and identity

  • Name, email address, and password (stored hashed)
  • Optional sign-in via Google or Apple (we receive identifiers and profile details those providers share with your consent)
  • Email verification / OTP codes and related delivery metadata
  • Account settings (timezone, reminders, preferences)

2.2 Intake, profile, and product content

  • Intake answers you submit (e.g. country, city, situation, education, skills, hours, budget, timeline, income goals, motivation, challenges, constraints, and any “own idea” you describe)
  • Generated and refined content: path cards, roadmaps, tasks, check-ins, progress and income logs, coach conversations, and library items
  • Files you upload (e.g. to Coach or Library), including file names, types, sizes, and content needed to store or process them
  • Build handoffs, documents, and deliverables you request or save

2.3 Billing and payments

  • Subscription status, plan, trial dates, renewals, cancellations, and payment outcomes
  • Billing provider identifiers (e.g. Stripe or Razorpay customer / subscription IDs)
  • Country or region used to select payment provider and currency. Card, UPI, and similar payment credentials are collected and processed by Stripe or Razorpay — we do not store full card numbers on our servers

2.4 Technical and usage data

  • Device and browser information, IP address, approximate location derived from IP, pages viewed, and feature usage
  • Cookies and similar technologies (see Section 6), including anonymous session identifiers (e.g. for pre-account intake)
  • Logs for security, abuse prevention, rate limiting, and reliability
  • Server-side product events (e.g. paths shown, checkout started, trial started)

2.5 Connected apps (MCP / OAuth)

If you connect a third-party AI client (for example Claude, ChatGPT, or another MCP client) via OAuth, we store application registration details, consent records, tokens or token hashes, scopes granted, and connection metadata so that client can act on your behalf within the permissions you approve. You can revoke connected apps in Settings.

2.6 Communications

  • Support emails and messages you send us
  • Transactional emails (verification, password reset, trial reminders, billing notices, task reminders if enabled)

3. How we use information

We use personal data to:

  • Create and manage accounts, authenticate users, and secure the Service
  • Generate and personalize paths, roadmaps, tasks, check-ins, coach replies, and documents
  • Process trials, subscriptions, invoices, and entitlement to paid features
  • Send service-related notices and optional reminders you enable
  • Provide support and respond to requests
  • Monitor performance, fix bugs, prevent fraud and abuse, and enforce our Terms
  • Improve product quality, prompts, routing, and user experience (using aggregated or de-identified insights where practical)
  • Comply with law and protect rights, safety, and property

4. Artificial intelligence processing

To deliver the Service, we send relevant prompts and context (including intake answers, path/roadmap data, coach messages, and document briefs) to third-party AI providers under our contracts. Those providers process the content to return model outputs.

  • We configure production usage for product delivery. We do not sell your content as a training dataset, and we instruct providers according to their enterprise / API terms where available.
  • Model outputs can be inaccurate or incomplete. You remain responsible for how you use them. See our Terms for disclaimers.
  • Do not submit secrets you are not allowed to share (passwords, full payment card data, government IDs, health records of others, or confidential third-party data) unless the feature explicitly requires and you have rights to share that information.

5. How we share information

We share information only as needed to operate the Service:

  • Payment processors: Stripe (typically outside India) and Razorpay (typically India) for checkout, mandates, subscriptions, and refunds
  • AI providers: to generate paths, coaching, documents, and related features
  • Infrastructure vendors: hosting, databases, email delivery, file storage, logging, and error monitoring
  • Identity providers: Google / Apple when you choose social sign-in
  • Connected apps you authorize: MCP / OAuth clients receive data only within scopes you approve
  • Analytics / ads measurement: limited conversion events (e.g. trial or payment) may be sent to advertising platforms via server-side APIs where configured, to measure marketing performance
  • Legal and safety: if required by law, regulation, legal process, or to protect users, PathMiner, or the public
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality

We do not sell your personal information.

6. Cookies and similar technologies

We use cookies and local storage for:

  • Session authentication and CSRF protection
  • Anonymous intake continuity before you create an account
  • Remembering preferences and improving reliability

You can control cookies through your browser settings. Disabling essential cookies may prevent login or core features from working.

7. Data retention

We retain account and product data while your account is active and as needed to provide the Service. After deletion or long inactivity, we delete or anonymize personal data within a reasonable period, except where we must keep records for legal, tax, security, dispute, or billing purposes (for example subscription and payment records). Backups may persist for a limited time before rotation.

8. Security

We use industry-standard measures such as encrypted transport (HTTPS), hashed passwords, access controls, and rate limiting. No method of transmission or storage is 100% secure. If you suspect unauthorized access, contact us immediately at [email protected].

9. Your rights and choices

Depending on your location, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated personal data (subject to legal retention)
  • Export or receive a copy of certain data
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based
  • Opt out of non-essential marketing emails (transactional mail may still be sent)
  • Revoke connected apps and manage reminder settings in-product

To exercise these rights, email [email protected] from the address on your account. We may verify your identity before fulfilling requests. Residents of the EEA/UK, California, India, and other jurisdictions may have additional rights under local law; we will honor applicable requirements.

10. International transfers

We and our processors may process data in countries other than where you live, including the United States, India, and the European Economic Area. Where required, we rely on appropriate safeguards (such as standard contractual clauses or vendor commitments) for cross-border transfers.

11. Children

The Service is not directed to children under 16 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.

12. Third-party links and services

The Service may link to third-party sites or integrate with third-party tools. Their privacy practices are governed by their own policies. Review those policies before sharing data with them.

13. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date. Material changes may also be communicated by email or in-product notice. Continued use after the effective date constitutes acceptance of the updated Policy.

14. Contact

Privacy requests and questions: [email protected]
See also our Terms of Service and Contact page.