Our security pledge

Your ideas are yours. Forever.

What we commit to

The moment you trust Mendly with your project, you trust us. We take that seriously. Here's exactly how we protect what you share with us.

01

Encrypted in transit and at rest

Your data travels encrypted (TLS) and is stored encrypted (AES-256) by our database host. These are our providers' standard mechanisms, not a home-made scheme we ask you to take on faith.

02

Where your data lives

Your database is hosted by Supabase and the site by Vercel. To answer you, the content of your messages is sent to Google's Gemini model. Several of these providers are based in the United States: those transfers are covered by the European Commission's standard contractual clauses. The details are in our privacy policy.

03

Your GDPR rights, no runaround

You can delete your account and all your data from your settings. To get a copy of your data, write to us: we send it within the timeframe set by the GDPR.

04

We NEVER train on your data

Your ideas, documents and conversations with Mendly — nothing is used to train models. Ever. This commitment is written into our Terms of Service.

05

No third-party sharing

We don't sell, rent, or share your data with anyone. Period.

06

What we don't claim

Mendly has not yet undergone an independent security audit. We will say so here the day it has. Meanwhile: database access limited to the people who run the service, dependencies kept up to date, strict security headers across the site.

If you find a vulnerability

Email us at mendlyai01@gmail.com. We reply within 48 hours and keep you posted until it is fixed.

Got a question?