- 01
Who is the data controller?
Mendly (hereinafter “Mendly”, “we”) is a SaaS service for solo founders. The data controller is Glodi Bandzouzi, reachable at: mendlyai01@gmail.com.
- 02
What data we collect
For browsing: no data is collected by any third-party tracker. Mendly uses no Google Analytics, no advertising pixel, no external measurement tool. For the service: your email and hashed password, the content of your projects and conversations with Mendly, your preferences, and your billing information — handled directly by Stripe, never stored by us. We also record internal usage events (feature used, timestamp), only while you are signed in and only in our own database.
- 03
Why we collect this data
Keep you informed about launch (waitlist). Improve our product (analytics). Provide you with the Mendly service (customer account). Comply with our legal obligations.
- 04
How long we keep your data
Account data: retained while your account is active + 30 days after deletion. Free plan conversation history: 30 days. Paid plan conversation history: unlimited. Analytics data: 12 months maximum.
- 05
Your rights (GDPR)
Under the GDPR, you have the right to access your personal data, rectify it, erase it (“right to be forgotten”), obtain an exportable copy, restrict its processing, object to that processing, and withdraw your consent at any time. To exercise these rights: mendlyai01@gmail.com. Response within 30 days. You can also delete your account and all of your data directly from your settings. If you believe your rights are not being respected, you may lodge a complaint with the CNIL (www.cnil.fr).
- 06
Third-party processors
We rely on the following sub-processors: Vercel (hosting), Supabase (database and authentication), Stripe (payments), Brevo (email), Resend (authentication email) and Google (AI models — Gemini). Several of them are established in the United States: your data may therefore be transferred outside the European Union. These transfers are covered by the European Commission's standard contractual clauses and, for providers that adhere to it, by the EU—US Data Privacy Framework. We neither sell nor rent your data to anyone.
- 07
Security
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. See our security pledge for more details.
- 08
Cookies
We only use essential cookies required for the site's operation. See our cookie policy.
- 09
Changes
We may update this policy. Significant changes will be notified by email to subscribed users.
- 10
Contact
For any question: mendlyai01@gmail.com
Privacy Policy
Last updated: 29 August 2026