Last updated: May 7, 2026 · Effective date: May 7, 2026
WinningMind AI is a mental performance coaching service. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have over it.
Plain English is the goal here. If something is unclear, email us at info@winningmind.com.
Under the California Privacy Rights Act, we provide this notice at or before the point of data collection:
You may exercise your California rights at any time — see §6.3 (California Users).
Winning Mind LLC
2358 University Ave., #265
San Diego, CA 92104, USA
Email: info@winningmind.com
Website: winningmind.ai
For EU/UK users: Winning Mind LLC is the data controller for personal data processed through WinningMind AI. We do not currently designate a formal Data Protection Officer (DPO) as we do not engage in large-scale systematic monitoring or processing of special category data. Our primary privacy contact is info@winningmind.com.
Account information: When you sign up, we collect your email address and chosen display name.
Athlete profile: To personalize coaching, we collect optional information: sport, position, age group, competitive level, team name, and years of experience.
Coaching conversations: Your text messages to the coaching AI and the AI’s responses are stored as part of your conversation history. This is what makes continuity possible — the coach knows your history, your goals, your patterns. You can delete your conversation history at any time through Account Settings.
Voice input: When you use voice mode, your spoken audio is captured and sent to OpenAI’s Whisper service for transcription. WinningMind does not retain the raw audio after transcription is complete. See Section 4 (Subprocessors) for details on OpenAI’s retention.
Payment information: When you subscribe, payment is processed by Stripe. WinningMind does not store your full credit card number, CVV, or bank account details. Stripe stores payment credentials under their own privacy and security standards.
Usage data: We collect information about how you interact with the service — session timestamps, features used, errors encountered. This is used to improve the product and diagnose problems.
Device and connection information: Browser or app type, operating system version, and IP address. IP addresses are used for fraud prevention, abuse detection, and approximate geographic location (country/region level). We do not build persistent location profiles.
Cookies and similar technologies: See Section 9 (Cookies).
Coaching conversations may include your self-reported mental states (such as anxiety, pressure, or confidence levels) related to athletic performance. We treat this information as sensitive personal information under the California Privacy Rights Act (Civil Code §1798.140(ae)). We use it only to provide the coaching service and for safety/moderation purposes. We do not use it for purposes unrelated to service delivery. You may exercise your right to limit our use of sensitive personal information by contacting info@winningmind.com.
When you use WinningMind’s file upload feature, you can share images, PDFs, and plain text files with your AI coach — scout reports, scorecards, training plans, or other documents relevant to your athletic development.
Here’s what happens to those files.
Where files go. Uploaded files are stored in Vercel Blob, a cloud storage service operated by Vercel, Inc. All storage is in the United States. Files are linked to your account and the specific conversation in which you uploaded them.
How files are processed. The content of your uploaded file is sent to Anthropic (Claude) for AI analysis — the same AI provider that processes your coaching conversations. This processing happens under our existing Data Processing Agreement with Anthropic, described in Section 4 (Subprocessors). Anthropic does not use the content of your files to train its foundation models.
How long files are stored.
Medical and clinical documents. If you upload a file that our system identifies as a medical or clinical document (such as a concussion clearance form, physical therapy plan, mental health intake record, or clinical assessment), that file is handled under the most restrictive data practices we apply:
See §2.6 for a complete list of document types that fall under this classification.
Automated document classification. We use an automated classifier to identify medical and clinical documents. This helps us apply the right level of care before any file content reaches your AI coach. The classifier is not perfect — if you believe a file has been misclassified, contact us at info@winningmind.com.
Image content moderation — a known limitation. For text-based files (PDFs, CSVs, plain text), crisis content is detected before the file is sent to the AI coach. For images, the current version of WinningMind detects crisis content in the AI’s response to your uploaded image, not before the image is processed. We are building pre-send image moderation for a future release. We’re disclosing this openly because you should know how the system works.
Files about other people. If a file you upload contains information about someone other than you — another athlete, a teammate, a patient — that content is processed for your session only and is not extracted or retained in any profile. We may decline to process documents that are primarily about a third party. See §2.7 for details.
File size and type limits. v1 supports images (PNG, JPG, GIF, WEBP), PDFs, plain text, and CSV files. Maximum file size is 10 MB per file and 25 MB per message. Account-level storage is capped at 500 MB. For upload limits by subscription tier, see the Terms of Service, §6.2.
Section §2.4 covers self-reported mental states you share in coaching conversations. When you upload files, you may share documents that contain a broader category of sensitive personal information. Under the California Privacy Rights Act and as a matter of care, we apply SPI-level protections to the following document types:
We use these documents to inform your coaching session. We do not extract clinical data into persistent memory, share it with third parties beyond our AI processing subprocessors, or use it for any purpose other than providing the coaching service.
You may request deletion of any uploaded file at any time through Account Settings or by contacting info@winningmind.com.
When you upload a file, we assume it contains information about you. Sometimes it doesn’t. Here’s what that means for how we handle it.
Photos with other people. If you upload a photo that includes other people, the image content is processed only for your session and is not extracted into your profile or anyone else’s. We do not perform facial recognition or identification of other individuals in your uploaded images.
Documents about other athletes. If you upload a document that is primarily about a person other than you — another player’s scout report, a teammate’s medical clearance, a roster file — we may decline to process it. Our coaching is designed to help you, not to create profiles about other people.
If a document contains information about both you and others (for example, a team report that includes your performance metrics alongside others’), we will use only the information about you for coaching purposes.
Third-party documents. WinningMind accounts are tied to one athlete’s coaching experience. If you upload a document that contains clinical or personal information about someone who is not the account holder, we apply the most restrictive retention rules and do not extract any information into the coaching profile. Contact us at info@winningmind.com if you have questions about how this applies to your situation.
We use your data to:
Lawful basis (EU/UK users). Our primary lawful bases under GDPR Article 6 are:
We work with the following third-party services that may process your data. Each is under contract with data processing obligations aligned to applicable law.
| Subprocessor | What they do | Data processed | Retention |
|---|---|---|---|
| Anthropic | Provides the Claude language model that powers coaching responses, and processes the content of uploaded images, PDFs, and text files when you use the file upload feature | Your conversation text (sent per session); content of uploaded files sent per message (images as vision input; PDFs as document blocks; text as context) | 30 days by default for prompt + completion data (Anthropic’s standard API retention). NOT used to train Anthropic’s models. SCCs (EU + UK Addendum) included in Anthropic’s standard DPA. File content is subject to the same retention and no-training terms as conversation content. See trust.anthropic.com. |
| OpenAI (Whisper + Moderation) | Transcribes voice input to text; provides content moderation for crisis detection | Raw audio (per voice session); flagged text (per moderation check) | 30 days for audio (OpenAI’s abuse-detection policy). Audio is NOT used to train OpenAI models. Moderation API requests are logged per OpenAI’s standard policy. |
| ElevenLabs | Generates voice output (text-to-speech) | Text of coaching responses | Ephemeral (real-time generation, no persistent storage). |
| Stripe | Processes subscription payments | Name, email, payment card details, billing address | Per Stripe’s privacy policy and PCI DSS Level 1 standards. See stripe.com/legal/privacy-center. |
| Vercel Postgres | Hosts our primary database | All app data (account, conversations, settings) | Stored in US region under Vercel’s standard DPA. SOC 2 Type II compliant. See trust.vercel.com. |
| PostHog | Feature flag evaluation and product analytics | Anonymized user identifier, feature flag evaluations, basic event metadata (no conversation content) | Per PostHog’s standard privacy policy. SOC 2 Type II compliant. See posthog.com/privacy. |
| Vercel Blob | Stores files you upload to share with your AI coach | Content of uploaded files (images, PDFs, text) linked to your account and conversation | Files are stored while your account is open and the linked conversation exists. Deleted when the linked conversation is deleted or your account is closed (within 90 days). Stored in US region under Vercel’s standard DPA. See trust.vercel.com. |
A note on OpenAI’s 30-day audio retention. When you use voice mode, your audio is processed by OpenAI Whisper. OpenAI retains audio for up to 30 days for abuse detection, after which it is deleted. WinningMind does not have access to your audio after transcription. OpenAI does not use API audio submissions to train its models. We are disclosing this proactively because we believe you should know who handles your voice data and for how long, even when we don’t control that retention window.
Conversation history: Retained as part of your active account. You can delete specific conversations or your full history through Account Settings at any time. If you close your account, your conversation data is deleted within 90 days unless we are required to retain it by law. At cancellation, you’ll be offered a download of your full conversation history before deletion.
Account information: Retained while your account is active, plus 12 months after deletion for fraud prevention and legal compliance purposes.
Voice audio: Not retained by WinningMind after transcription. OpenAI retains raw audio for up to 30 days (see Section 4).
Uploaded files. Files you upload are stored in Vercel Blob and are linked to your account and the specific conversation message. Files are deleted when the linked message or conversation is deleted. If you close your account, uploaded files are deleted within 90 days along with your conversation data. Files identified as medical or clinical documents are used only within the session they were uploaded and are not carried forward into persistent memory, though the file itself remains in storage until message/account deletion.
Payment data: Stripe retains payment records as required by payment industry regulations (typically 7 years for financial records).
Safety and moderation logs: Records of flagged safety events (without full conversation content where feasible) are retained for 24 months to maintain an audit trail for crisis response and legal defense.
Regardless of where you live, you can:
To make any request, go to Account Settings or email info@winningmind.com. We’ll respond within 30 days.
In addition to the rights above, if you are in the EU or UK, you have the right to:
How to exercise these rights: Email info@winningmind.com with the subject line “GDPR Rights Request.” We’ll acknowledge within 3 business days and respond within 30 days (extendable to 90 days for complex requests — we’ll tell you if we need more time).
Right to complain: You have the right to lodge a complaint with your national supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk.
If you are a California resident, you have the right to:
To make a CCPA request, email info@winningmind.com or use the in-app tools in Account Settings. We’ll respond within 45 days.
Do Not Sell or Share My Personal Information: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
WinningMind is not directed to children under 13, and we do not knowingly collect personal information from children under 13. In the European Economic Area and the United Kingdom, you must be at least 16 to use WinningMind, in keeping with applicable digital consent laws.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at sagal@winningmind.com and we will take steps to delete that information promptly.
WinningMind is an AI-powered service. Coaching responses are generated by artificial intelligence, not by a human coach. In compliance with the EU AI Act (Regulation 2024/1689) and as a matter of transparency everywhere we operate, we disclose:
AI-generated coaching reflects the quality and limitations of current AI systems. It can be insightful. It can also be wrong. Use your judgment. If something doesn’t fit your situation, say so — or talk to a qualified human professional.
File uploads. When you upload an image, PDF, or text file, that content is sent to Claude (Anthropic) for processing alongside your message. Claude interprets the file content in the context of your coaching session. For images, Claude’s vision capability is used. For PDFs, Claude’s native document processing is used. The same AI transparency conditions apply to uploaded content as to your typed messages: AI analysis can be wrong or incomplete, and nothing in an uploaded file should be treated as a substitute for professional medical, psychological, or clinical guidance.
We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how the service is being used.
Essential cookies: Required for the service to function. You cannot opt out of these.
Analytics cookies: Help us understand how users interact with WinningMind.
No advertising cookies: We do not use advertising or cross-site tracking cookies.
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect service functionality.
We implement technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS) and at rest, access controls limiting who can access user data, regular security reviews, and vendor security assessments.
No system is completely secure. If we become aware of a data breach that affects your personal information, we will notify you as required by applicable law.
WinningMind is based in the United States. If you are accessing the service from the EU, UK, or elsewhere, your data will be transferred to and processed in the United States.
WinningMind currently serves US users only. We will update this section before accepting users from the EU, UK, or other jurisdictions requiring cross-border transfer mechanisms.
When we update this Privacy Policy, we’ll post the new version at winningmind.ai/privacy and update the “Last updated” date. For material changes, we’ll notify you by email or in-app notice at least 30 days in advance. Continuing to use the service after a material change takes effect means you’ve accepted the update.
Privacy questions, rights requests, or concerns:
Winning Mind LLC
2358 University Ave., #265
Email: info@winningmind.com
Website: winningmind.ai/privacy
For EU/UK users, you also have the right to contact your local supervisory authority. We’d prefer you come to us first — we’ll respond within 30 days.
WinningMind AI: performance coaching, not mental health treatment. For crisis support: 988 (call or text) · Crisis Text Line: text HOME to 741741 · Emergency: 911