Privacy Policy for Minovative Mind CLI

Effective Date: June 1, 2026

Minovative Mind ("we", "us", or "our") respects your privacy and is committed to protecting the personal and project information you share with us while using the Minovative Mind CLI (the "Service"). This Privacy Policy explains what information we collect, how we use it, how it is shared, and your choices regarding that information.

1. Information We Collect

When you use the Minovative Mind CLI, we may collect the following types of information:

A. Account and Authentication Information

To use the Service, you must authenticate via GitHub. When you run minovative-mind-cli login, we collect basic profile information provided by the GitHub OAuth API, which may include:

  • Your GitHub username and user ID
  • Your primary email address associated with your GitHub account
  • An OAuth access token to authenticate your requests to our backend services

Local Credential Storage: Your authentication credentials, Firebase User IDs (UIDs), and refresh tokens are stored locally on your machine in plain-text JSON format at ~/.minovative-mind-cli.json. The application does not use secure system keychains or native OS-level credential management services.

B. Workspace Metadata and Code Context Data

The Minovative Mind CLI is an intelligent agent that needs context to help you write code. To function correctly, the CLI reads files from your local workspace and manages workspace configurations.

  • Workspace Metadata Transmission: When you initialize, register, or use a workspace, the CLI transmits absolute local directory paths (e.g., /Users/username/projects/my-app), workspace names, and your user UID to Google Firestore (hosted via Firebase). This data is stored on our database servers to map and manage your workspaces, track active projects, and link usage to your account.
  • Transmitted Code Context Data: When you interact with the agent (e.g., via minovative-mind-cli chat), the CLI bundles your prompts, relevant file contents, error messages, and terminal outputs, and sends them to our custom proxy endpoint which routes securely to our AI inference providers (such as Google Cloud Vertex AI) to generate responses.
  • No Long-Term Storage of Source Code: While your workspace metadata (directory paths and workspace names) is stored in Firestore, we do not store the contents of your source code, proprietary files, or actual code context on our database servers. Code context data is processed ephemerally by the AI models and is not retained by Minovative Mind once the session completes.

C. Usage Data and Telemetry

To improve the Service, we collect usage statistics and telemetry data, including:

  • CLI commands executed (e.g., chat, login, models, sub-agents, plan)
  • AI model usage statistics (e.g., tokens sent/received, response latency, model selected)
  • System information (e.g., Operating System, Node.js version, CLI version)
  • Crash reports and error logs (to help us debug and fix issues)

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To Provide the Service: To authenticate you, manage active workspaces, map project paths, process your coding requests, and deliver AI-generated code and command suggestions to your terminal.
  • To Maintain and Improve the Service: To debug issues, analyze usage patterns, optimize performance, and develop new features for the CLI.
  • To Communicate with You: To send important technical notices, security alerts, or updates regarding the Terms of Use and Privacy Policy.

3. Data Sharing and Third-Party Subprocessors

We do not sell your personal information or your source code to third parties. However, we share data with trusted third-party service providers necessary to operate the Service:

  • Google Cloud Run & Vertex AI (Google LLC): We host our API/proxy endpoints on Google Cloud Run and use Google's Vertex AI (including Gemini models like gemini-3.5-flash) to process your prompts and analyze local file context. As per Google Cloud's enterprise privacy commitments, data sent to Vertex AI via the API is not used by Google to train their foundational models.
  • Google Firebase & Cloud Firestore (Google LLC): We store your user UID, workspace names, and absolute local directory paths in Google Firestore to maintain configuration state.
  • GitHub: Used for authentication and verifying your identity.

4. Data Security

We take technical and organizational measures to protect your data:

  • Encryption: All communication between the CLI, our backend services, and third-party AI providers is encrypted in transit using industry-standard TLS/HTTPS.
  • Local Credentials: Because we store your authentication tokens in plain-text at ~/.minovative-mind-cli.json without native OS-level secure enclaves, you must secure access to your local user account to prevent unauthorized access to these tokens.

5. Your Responsibilities Regarding Sensitive Data

Because the CLI reads your local workspace and transmits it to an LLM for processing, you are strictly responsible for ensuring you do not pass sensitive information to the AI. You must ensure that:

  • Hardcoded API keys, passwords, and database credentials are excluded from the context.
  • Personally Identifiable Information (PII) or Protected Health Information (PHI) is not present in the files the CLI inspects.
  • You utilize .gitignore or CLI-specific ignore files (if supported) to prevent the CLI from reading .env files or other secret-containing directories.

6. Data Retention

  • Account and Database Data: We retain your authentication metadata and workspace metadata (such as paths and workspace names stored in Firestore) for as long as your account is active or as needed to provide the Service.
  • Code Context: As stated above, we do not store your code context or chat history on our database servers. It is processed ephemerally by the AI models.
  • Telemetry Data: Anonymized usage and crash reports are retained for a period necessary to analyze and improve the Service.

7. Your Choices and Rights

Depending on your location, you may have certain rights regarding your personal information, including the right to access, correct, or delete your data.

  • Account Deletion / Logout: You can revoke access at any time by running minovative-mind-cli logout and revoking the OAuth application from your GitHub account settings.
  • Opting Out of Telemetry: (If applicable) You can opt out of anonymous telemetry collection by setting an environment variable (e.g., MINOVATIVE_TELEMETRY=0) or updating your CLI configuration. Please refer to the documentation for specific instructions.

8. Cross-Border Data Transfers

Minovative Mind operates globally, and our backend infrastructure (including Google Cloud Run and Google Firestore) is primarily hosted in the United States. By using the Service, you acknowledge and agree that your workspace metadata, telemetry, and ephemerally processed code context may be transferred to, stored, and processed in the United States or other countries where our third-party subprocessors operate. We take appropriate safeguards to ensure that your data remains protected in accordance with this Privacy Policy, regardless of where it is processed.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify you of any material changes by updating the "Effective Date" and, when feasible, providing a notification within the CLI. Your continued use of the Service after the effective date constitutes your acceptance of the updated Privacy Policy.

10. Contact Us

Security Reporting Form: https://forms.gle/QexZY2resdXpahUK6