HeadTidy Try HeadTidy free

Privacy

Last updated 10 September 2026

Data controller. Rene Reede, Skroblų g. 15, LT-03139 Vilnius, Lithuania, operating HeadTidy under Lithuanian individual activity certificate No. 1465029 (computer programming activity 621090). Contact headtidy@gmail.com.

1. What is stored

Using HeadTidy without an account keeps everything in your browser's session storage. It never reaches a server. Signed-in accounts sync their profile, folders, map content, comments, share permissions, activity, versions and recovery checkpoints to HeadTidy's cloud database so the same workspace is available on your other devices.

If you explicitly connect Google Calendar, this browser stores the calendars you chose and a minimal read-only event snapshot: title (or “Busy” where Google does not expose it), start/end time, all-day status, location, calendar name/colour and Google event link. The short-lived Google access token stays in memory only and is not stored. Calendar data is not sent to HeadTidy's Supabase or Vercel services. An imported .ics calendar similarly remains a browser-local snapshot.

Your maps can contain personal data you choose to enter. HeadTidy does not routinely inspect or classify map content. The service is not designed as a password manager, payment vault, identity-document repository, patient-record system or repository for biometric, genetic or similarly high-risk data; do not enter that material. If you add information about another person, you are responsible for having a lawful reason and for giving them any notice the law requires.

2. Why HeadTidy is allowed to process it (legal bases)

Under the GDPR every use of your data needs a legal basis. HeadTidy relies on: performance of a contract for your account, your maps, sync, sharing and support, because without processing them the service cannot exist; legitimate interests for keeping the service secure, preventing abuse, and understanding aggregate page traffic, balanced against your privacy and not used to inspect map content for advertising or profiling; legal obligation for payment, invoice and tax records; and consent only where something is genuinely optional, which you may withdraw at any time without affecting anything done beforehand. HeadTidy does not use your data for automated decision-making or profiling that produces legal effects.

3. Images and link previews

Images are processed on your device, stripped of their original metadata and converted to an optimised format before anything is stored. For signed-in accounts the optimised image is uploaded to private storage that only you can access, and the map holds a temporary signed link rather than the image itself. The original file is never uploaded. Guest and local modes keep the image on your device.

Link previews are fetched only when you explicitly create or refresh a Link card. HeadTidy sends that web address to its Vercel-hosted preview endpoint, which requests the public page title, description, site name, declared favicon address and preview-image address; it does not send map content, your account identity or private credentials. Displaying a remote preview image or favicon, including the conventional same-site favicon fallback, may then contact that public website's image host. Do not create a Link card for a secret or token-bearing address.

4. Video cards and third-party players

A Link card for a YouTube address becomes a video card. Until you press play it is a still picture and a button: the still is requested from YouTube's image host, which serves images and sets no cookies, and no player, script or tracking code is loaded. Pressing play is the point at which YouTube is contacted properly.

Because that request leaves HeadTidy, the first press asks before it happens rather than after. You can play the video once, allow YouTube for this browser so the question is not repeated, or open the video on YouTube in a new tab instead and load nothing here at all. The player is always requested from youtube-nocookie.com, which is Google's reduced-tracking host, but once it loads Google's own terms and privacy policy govern that player and HeadTidy has no control over what it stores. Choosing "always allow" records that preference in your browser under headtidy-embed-consent; removing it withdraws consent for future cards, and clearing this site's browser data removes it too.

A visible Map widget loads its current geographic area from OpenStreetMap so the card can show a real interactive map; this request exposes the normal connection metadata and requested map area to OpenStreetMap, but not the rest of the mind map. Saved place names stay inside HeadTidy until you explicitly choose Open map, Directions, Route all, or Find in Google Maps; that click opens a new Google Maps tab and sends only the place names needed for that request. Nothing else in HeadTidy embeds a third party. There are no social widgets, comment systems, chat bubbles, session recorders, heat maps or advertising pixels anywhere in the product or on this website.

Google Calendar is separate and optional. Only after you press Connect does HeadTidy load Google's authorization library and request two limited read-only permissions: calendar.calendarlist.readonly to load the calendars available to your Google account and let you choose which ones to show, and calendar.events.readonly to retrieve and display events from the calendars you select. Both permissions use the same HeadTidy OAuth client. HeadTidy cannot create, edit, delete or share Google calendars or events and does not send your maps or HeadTidy tasks to Google. While Plan is open, HeadTidy may refresh your selected events when the current short-lived access token is still valid. It does not refresh while Plan is closed and never opens a Google authorization prompt by itself. The visible Refresh control lets you update on demand and asks Google again when the token has expired or the page was reloaded.

5. Analytics, feedback and advertising

HeadTidy uses Vercel Analytics for anonymous, aggregated page views: page path, referrer, country, device type, operating system and browser. Private share-link visits are excluded, and query strings are removed before a page view is recorded. Google Analytics 4 is also available for product measurement only after you accept analytics cookies; it receives the fixed, content-free events described below. Interface fonts are bundled with the application, so no font provider is contacted.

HeadTidy also records a small, fixed set of anonymous product events so it can tell how far people get: opening the example map, finishing or skipping the introduction, creating a first thought, creating an account, a first successful cloud save, returning on a later day, submitting feedback, and creating or opening a shared link. These carry no map names, thought text, note text, notes, file names, search queries, email addresses, share tokens or link URLs. Where an event includes a count it is rounded into a band such as "up to twenty" rather than reported exactly, and where it includes a label the label comes from a fixed list such as "view", "comment" or "edit". The events are not tied to an identifier for you and cannot be used to reconstruct anything you wrote. If your browser sends a Do Not Track or Global Privacy Control signal, no product events are recorded at all.

If you submit the in-app feedback form, HeadTidy stores your chosen type and message plus the app version, browser, device type and current view. You may explicitly add one screenshot; it is optimized and stripped of source metadata on your device, previewed before sending, stored privately with the feedback, and retained for up to 180 days. HeadTidy never captures or attaches map titles, thought or note text, table data, links or workspace images automatically.

6. Cookies and browser storage

Analytics storage starts denied. On first visit HeadTidy asks whether you want to allow analytics cookies; rejecting them keeps analytics storage off. You can change the choice through the Cookie settings link. Necessary session and local browser storage keep sign-in and offline work functioning and are not used to build an advertising profile.

In plain terms, this is everything HeadTidy keeps in your browser:

HeadTidy does not sell personal data or use analytics to inspect map content. Clearing this site's data in your browser removes local maps, preferences and consent choices, including any embed consent you have given.

7. Your controls

You can withdraw analytics consent through Cookie settings, and withdraw consent for third-party video players at any time by clearing this site's browser data, which removes the relevant preferences and makes every video card ask again before it loads anything. You can disconnect Google Calendar in Settings at any time; HeadTidy removes the local connection metadata and event snapshot and asks Google to revoke the current token when it is available. You can also remove HeadTidy from your Google Account permissions.

Signing out ends the local session while keeping your maps for next time. Clearing this site's browser data removes local accounts and maps from that browser. Deleting your account hides it and revokes its share links immediately, then schedules permanent removal after a recovery window. Export a backup first if the content matters: HeadTidy exports lossless JSON, Markdown, OPML, PNG and PDF on every plan.

8. Sharing and processors

Private share links behave like passwords: anyone holding one can use its View, Comment or Edit permission until it expires or you revoke it. Owners can add a passcode and can see last access time and open counts.

The current providers that may process personal data for HeadTidy are listed below. HeadTidy assesses its processors, puts the required data-processing terms in place and remains responsible for its own controller duties. This notice will be updated before a new category of provider receives personal data.

Some of these providers are established outside the EU or use infrastructure outside it. Where personal data is transferred outside the European Economic Area, it is done under the European Commission's Standard Contractual Clauses or an equivalent approved safeguard, together with the provider's own technical protections. You can ask for details of the safeguards that apply.

9. How long things are kept

10. Security and what happens if something goes wrong

HeadTidy uses risk-appropriate technical and organisational measures intended to protect confidentiality, integrity, availability and recovery. Current measures include database row-level access policies designed to isolate accounts, private image storage with short-lived signed links, encryption in transit, infrastructure-provider encryption at rest, server-only credentials kept out of the browser, content-free diagnostics, revisioned saves and recovery checkpoints. These measures are reviewed as the service and risks change; no internet service can promise perfect security.

HeadTidy documents every confirmed personal data breach, including its effects and remedial action. Where a breach is likely to risk people's rights, HeadTidy will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, affected people will also be told without undue delay in clear language, including what happened, the likely consequences, the response and practical protective steps.

If you suspect that your account, a private link or any HeadTidy data has been accessed or disclosed without authorisation, email headtidy@gmail.com promptly. Preserve relevant messages or screenshots, revoke affected links and secure your email account and device, but do not send passwords, authentication codes or unnecessary map content in the report.

11. Children

HeadTidy is not directed at children under 14, the age of digital consent in Lithuania. If you believe a child under 14 has created an account, email headtidy@gmail.com and it will be removed.

12. Payments

If you subscribe to HeadTidy Pro, payment is processed by Stripe, which acts as an independent controller for the payment itself. Your card details are entered on Stripe's own pages and are never seen or stored by HeadTidy. Stripe receives your email address, billing country and the amount, and returns a customer and subscription reference plus the plan status. HeadTidy stores only those references and the status, which is what decides whether your account is on Free or Pro. Card numbers, expiry dates and security codes are never stored by HeadTidy in any form.

Stripe processes payment data under its own privacy policy and may transfer it outside the EU under safeguards it maintains. Payment and invoice records are retained for as long as tax and accounting law requires, which is longer than the recovery window that applies to your maps.

13. Contact and your rights

Data controller: Rene Reede, trading as HeadTidy, Skroblų g. 15, LT-03139 Vilnius, Lithuania. Lithuanian individual activity certificate No. 1465029 (computer programming activity 621090). Privacy contact: headtidy@gmail.com. You have the right to access, correct, receive or export, restrict or erase your personal data, to object to processing, to withdraw consent where consent is the basis, and to complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) or the authority where you live or work. These rights are subject to the lawful exceptions in the GDPR. HeadTidy will normally respond within one month and will explain any refusal or extension.

Read the terms of use