Legal & Compliance

Privacy Policy & Data Practices

Effective date: March 2026 Kingdom Age Capital Holdings LLC
🏥
HIPAA-Aligned Infrastructure Hosted on AWS HIPAA-eligible services
🔒
No Patient Data Retained Submissions processed transiently
🔐
Encrypted in Transit TLS 1.2+ on all connections

1 Overview

MindLedger is a service provided by Kingdom Age Capital Holdings LLC ("we," "us," or "our"). This Privacy Policy describes how we collect, use, and protect information when you use MindLedger's provider registration platform and patient intake form service at mindledger.io.

We are committed to responsible data stewardship. MindLedger is built on HIPAA-eligible Amazon Web Services infrastructure and is designed with data minimization as a core principle — we collect only what is necessary to deliver the service and do not retain patient information beyond the immediate processing of each intake submission.

2 Information We Collect

From healthcare providers (our customers):

From patients completing intake forms:

Important: Patient intake responses are processed transiently to generate a clinical PDF summary. This summary is delivered immediately to the provider's registered email address. MindLedger does not retain patient responses in any database after the PDF is generated and delivered. The provider is responsible for the storage, security, and HIPAA-compliant handling of the PDF once received.

3 How We Use Information

We use the information we collect solely to provide and improve the MindLedger service:

We do not sell, rent, or share any personal information — provider or patient — with third parties for marketing, advertising, or any commercial purpose unrelated to delivering the MindLedger service.

4 HIPAA Compliance & Infrastructure Security

MindLedger is built on Amazon Web Services (AWS), which provides HIPAA-eligible infrastructure under AWS's shared responsibility model. Our infrastructure includes:

Kingdom Age Capital Holdings LLC is in the process of executing a Business Associate Agreement (BAA) with AWS, which formalizes AWS's role as a business associate under HIPAA and confirms that the underlying infrastructure meets the technical safeguard requirements of the HIPAA Security Rule.

MindLedger operates as a conduit for protected health information (PHI) — similar in function to a secure fax or encrypted email service. Patient data passes through our system to generate and deliver the PDF; it is not stored, indexed, or analyzed beyond that transaction. This architecture is designed to minimize our exposure to PHI and reduce compliance obligations for providers using the service.

5 Provider Responsibilities

Healthcare providers using MindLedger are responsible for:

MindLedger provides the intake collection and PDF generation infrastructure. The treating provider remains the covered entity responsible for their patient relationships and records management.

6 Data Retention

Provider account data is retained for the duration of the provider's active account and for a reasonable period thereafter for billing and legal compliance purposes. Providers may request deletion of their account data at any time by contacting us.

Patient intake data is not retained by MindLedger. Intake responses are held in memory only for the duration of PDF generation — typically a matter of seconds — and are not written to any persistent storage. Once the PDF is delivered to the provider, MindLedger holds no copy of the patient's responses.

7 Cookies & Analytics

MindLedger's marketing site may use standard web analytics to understand visitor behavior and improve the product. No personally identifiable information is collected through analytics. We do not use third-party advertising cookies or tracking pixels.

The intake form itself does not use cookies or analytics of any kind. Patient sessions on the intake form are entirely stateless.

8 Your Rights

Providers may at any time:

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

9 Changes to This Policy

We may update this Privacy Policy as the service evolves. When we make material changes, we will update the effective date at the top of this page and notify active providers by email. Continued use of MindLedger after changes are posted constitutes acceptance of the updated policy.

Questions about privacy or data?

We take these questions seriously. If you have concerns about how MindLedger handles data — as a provider, a patient, or a curious clinician evaluating the service — please reach out directly.

Kingdom Age Capital Holdings LLC
Operating as MindLedger
[email protected]