Our security pledge
Your ideas are yours. Forever.
What we commit to
The moment you trust Mendly with your project, you trust us. We take that seriously. Here's exactly how we protect what you share with us.
01
Encrypted in transit and at rest
Your data travels encrypted (TLS) and is stored encrypted (AES-256) by our database host. These are our providers' standard mechanisms, not a home-made scheme we ask you to take on faith.
02
Where your data lives
Your database is hosted by Supabase and the site by Vercel. To answer you, the content of your messages is sent to Google's Gemini model. Several of these providers are based in the United States: those transfers are covered by the European Commission's standard contractual clauses. The details are in our privacy policy.
03
Your GDPR rights, no runaround
You can delete your account and all your data from your settings. To get a copy of your data, write to us: we send it within the timeframe set by the GDPR.
04
We NEVER train on your data
Your ideas, documents and conversations with Mendly — nothing is used to train models. Ever. This commitment is written into our Terms of Service.
05
No third-party sharing
We don't sell, rent, or share your data with anyone. Period.
06
What we don't claim
Mendly has not yet undergone an independent security audit. We will say so here the day it has. Meanwhile: database access limited to the people who run the service, dependencies kept up to date, strict security headers across the site.
If you find a vulnerability
Email us at mendlyai01@gmail.com. We reply within 48 hours and keep you posted until it is fixed.