Privacy Policy
Announced 17 September 2026 · Effective 3 October 2026
This policy explains how Mitchell Stanton-Nicholson (ABN 93 361 512 919), trading as fymnd ("fymnd", "we", "us"), handles your personal information. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
1. The Most Important Thing to Understand
fymnd has two kinds of data, treated completely differently:
Goals, records, progress updates, and outcomes you seal to the Ledger are published on the open internet. Their chain record cannot be altered once sealed. After a valid erasure request, readable text may be permanently redacted, but the entry's chain position, timestamp, redaction marker, and any external anchor remain. Once per day, a fingerprint of each member's chain is submitted to the Bitcoin blockchain via OpenTimestamps; that anchor cannot be removed by fymnd. Do not seal anything to the Ledger you may later need kept private.
Everything else — your account details, email, course activity, payment information — is private and handled as described below.
2. What We Collect
- Account data: your email address, handle, and a password (which we store only as a salted hash, never in plain text).
- Ledger data: the declarations, targets, progress updates, and outcomes you choose to seal, plus timestamps and chain hashes.
- Payment data: processed by Stripe. We store your Stripe customer ID and subscription status. We do not store card numbers or card details — those remain with Stripe.
- Course enrolment data: if you purchase a course, we record your enrolment and lesson completion progress.
- Creator identity and compliance data (creators only): we collect your entity type, legal first and last name, date of birth where applicable, business or residential address, country, phone number, ABN (if provided), and GST registration status. Stripe holds payout bank details. FYMND retrieves Stripe account identifiers only when required for ATO, SERR, tax, or related legal reporting.
- Marketplace reporting data: for creator sales we retain transaction identifiers, dates, amounts, currency, supplier identity and address records for the Sharing Economy Reporting Regime (SERR), tax, accounting, audit, fraud-prevention, and other legal purposes.
- Usage data: log data such as IP address, device/browser type, pages viewed, and timestamps, used for security and to improve the Platform.
- Communications: messages you send us (e.g. support emails).
We do not knowingly collect information from anyone under 18.
3. How We Use It
- To provide and operate the Platform, including publishing your Ledger entries as the service is designed to do
- To manage your account and subscription, and process payments via Stripe
- To communicate with you about your account, the service, and material changes
- To secure the Platform, prevent fraud, and detect fabricated records
- To improve the Platform (using our own server records on an aggregated basis; we do not run third-party analytics)
- To comply with legal obligations
We do not sell your personal information. We do not use your private data for third-party advertising.
4. Who We Share It With
- The public: your Ledger entries, by design (section 1)
- Stripe — payment processing (Stripe's privacy policy applies to payment data)
- Resend — transactional email delivery (e.g. verification and password-reset emails)
- Creators and Stripe Connect — if you purchase a marketplace course, fymnd's creator dashboard shows the creator aggregate sales statistics, not your individual email address. Because the payment is processed as a Stripe Connect transaction for that creator, Stripe may make transaction or customer details, including your email address, available to the connected creator through Stripe according to Stripe's permissions and privacy policy. Course access is managed by fymnd directly.
- Cloud hosting and infrastructure providers — application hosting, database and object storage, backups, security, and server infrastructure
- ATO and other legal disclosures: where required by the Australian Taxation Office, SERR, tax law, court order, regulator, or to protect our legal rights
- Business transfer: if fymnd is sold or restructured, data may transfer to the successor under this policy
5. Overseas Disclosure
Our service providers (including Stripe and Resend) may store or process data outside Australia, including in the United States. Where this occurs, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles. Because the Ledger is public, Ledger entries are accessible worldwide by design.
6. Retention
- Private data: kept while your account is active, then retained only as long as needed for legal, accounting, tax, SERR, dispute, fraud-prevention, or security purposes before deletion.
- Creator compliance and reporting records: entity type, legal name, date of birth where applicable, address, country, phone, ABN/GST status, Stripe account identifiers, and marketplace transaction records are retained for the period required by tax, SERR, accounting, and other applicable law. Stripe controls retention of bank details.
- Ledger data: permanent. Sealed entries are retained and published indefinitely, including after account closure. This permanence is a disclosed, consented feature of the service.
7. Your Rights
- Access the personal information we hold about you
- Correct inaccurate private data (account details can be updated in settings)
- Delete your account and private data, subject to legal retention requirements
- Complain — contact us first; if unresolved, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au
Ledger limitation: correction and deletion rights do not extend to sealed Ledger entries. If we receive a valid erasure request for Ledger content, we will apply a tombstone — the readable text is permanently deleted from our database and replaced with a redaction notice. The cryptographic chain slot is preserved (so the chain remains intact), and any Bitcoin blockchain anchor already submitted cannot be removed. This is the maximum erasure technically possible without destroying the chain entirely.
If you are in a jurisdiction with additional rights (e.g. the EU/UK under GDPR), we will honour applicable rights on the same basis: fully for private data; for Ledger data, publication is based on your explicit consent and contract performance, and the chain's integrity means full erasure is technically and functionally incompatible with the service you contracted for. Do not use the Ledger if you may require erasure.
8. Security
We take reasonable technical and organisational measures to protect private data, including encryption in transit, access controls, salted password hashing, and reliance on Stripe for payment security. No system is perfectly secure; notify us immediately of any suspected unauthorised access to your account. We will comply with our obligations under the Notifiable Data Breaches scheme where applicable.
9. Cookies
We use essential cookies only — for sign-in and session management. We do not set analytics or advertising cookies. You can control cookies via your browser; disabling essential cookies may break sign-in.
10. Changes to This Policy
We may update this policy. Material changes will be notified via the Platform or email before taking effect. The "last updated" date above reflects the current version.
11. Contact
Mitchell Stanton-Nicholson trading as fymnd
Email: admin@fymnd.com