MentalClarity

Privacy Policy

Last updated: September 12, 2026

Dala Primelab AB (reg. no. 559593-4133), Gamla tunavägen 43i, Borlänge, Sweden, is the data controller for personal data processed through MentalClarity. This policy explains what we collect, why, and your rights under the GDPR.

1. Data we collect

  • Account data: your email address and, if you provide it, your name.
  • Test and usage data: test answers, IQ results, game scores, streaks and training history.
  • Purchase data: payment status, subscription state and transaction references. Card details are handled only by our payment provider; we never see or store your full card number.
  • Technical data: IP-derived country (used to set language and currency), device and browser information.
  • Marketing data: Meta Pixel events (page views, purchases) and the _fbp/_fbc identifiers when you consent to marketing cookies.

2. Purposes and legal bases (GDPR art. 6)

  • Providing the service, scoring your test and operating your account — performance of a contract.
  • Processing payments and managing your subscription — performance of a contract.
  • Improving the service and preventing abuse — legitimate interest.
  • Marketing measurement via Meta Pixel and Conversions API — consent. These tools are not activated before you accept optional tracking.
  • Sending recovery and service emails — legitimate interest; you can unsubscribe at any time.
  • Inviting customers who have completed a purchase to share an honest review of their experience through Trustpilot — legitimate interest in receiving feedback. You can object to this use of your data by contacting us.

Automated profiling — legitimate interest: your test result is used to automatically generate a personal training program based on your weakest reasoning areas. This does not have legal or similarly significant effects on you, so it is not automated decision-making under Article 22 GDPR. You may object at any time by emailing support@mentalclarity.me.

3. Third parties and international transfers

We use the following processors, who may process data outside the EU/EEA, including in the United States:

  • Our payment provider — payment processing. Payment data may be transferred to the United States. Transfers rely on the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
  • Meta Platforms Ireland Ltd. and Meta Platforms, Inc. — advertising measurement (Meta Pixel and Conversions API). For this measurement we and Meta Platforms Ireland Ltd. act as joint controllers under Article 26 GDPR; Meta Platforms, Inc. processes the data in the United States under the EU-US Data Privacy Framework (see the certified-organisation list at dataprivacyframework.gov/list) and/or Standard Contractual Clauses. This only occurs where you have consented to marketing cookies.
  • Resend (Plus Five Five, Inc., United States) — transactional, billing and recovery email delivery. Your email address and message content are transferred to the United States under a data processing agreement incorporating the EU Standard Contractual Clauses.
  • Trustpilot A/S — when your first purchase is confirmed, Trustpilot receives a hidden copy of your purchase confirmation, including your email address and the payment details in that confirmation, to schedule an invitation to review your experience. Trustpilot sends the invitation and manages your invitation preferences. No test answers, IQ scores or payment card details are included in the confirmation. See the Trustpilot data processing agreement.
  • Supabase (database, authentication and file storage) — stores your account, test and billing records. Supabase Inc. is based in the United States; the processing agreement incorporates the EU Standard Contractual Clauses, with additional technical safeguards such as encryption in transit and access controls.

Data processing agreements with our sub-processors are public: payment provider DPA, Meta data processing terms, Resend DPA, Supabase DPA. You can also request a copy of the relevant transfer safeguards by emailing support@mentalclarity.me.

4. Retention

  • Account data and test results: deleted 24 months after your last sign-in.
  • Payment and invoice records: retained for 7 years, as required by the Swedish Bookkeeping Act (bokföringslagen).
  • Marketing data (Meta event data, recovery-email leads): 12 months, or until you withdraw consent or unsubscribe, whichever comes first.

You may request earlier deletion at any time, subject to the statutory retention above.

Children and age limit

MentalClarity is intended for adults and you must be at least 18 to create an account. We do not knowingly process data about minors. If we learn that a minor has used the service without the consent of a holder of parental responsibility, we delete the account and all associated data. Contact support@mentalclarity.me if you believe this has happened.

5. Your rights

You have the right to access, rectify, erase, restrict or port your personal data, and to object to processing based on legitimate interest. You may withdraw cookie consent at any time. To exercise any right, email support@mentalclarity.me. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.

6. Security

We use encryption in transit, row-level access controls on our database, and limit access to personal data to what is strictly needed to operate the service.

7. Contact

Data controller:

Dala Primelab AB

Reg. no. 559593-4133

VAT no. SE559593413301

Gamla tunavägen 43i, Borlänge, Sweden

+46 73 251 25 59

support@mentalclarity.me