Mentorize LogoMentorize

Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your personal information across all Mentorize apps and services.

At a Glance

A plain-language summary of how we handle your data across all Mentorize apps and services.

What We Collect

Account info, usage data, AI conversation history, files, and content you create across all apps.

Why We Collect It

To power AI Mentor, deliver personalized learning, sync your workspace, and keep the platform secure.

Who We Share With

Only trusted infrastructure providers (cloud, AI APIs) under strict data processing agreements. Never sold.

Your Rights

Access, correct, export, or permanently delete all your data — across every app — anytime.

Introduction

Mentorize s.r.o. (we, our, or us), registered in the Czech Republic and headquartered in Prague, operates a suite of interconnected applications including the Learning App, AI Mentor, Chat, Drive, Docs, Slides, Sheets, Photos, and developer tools at dev.mentorize.me. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use any of our services — whether through mentorize.me, our subdomains, or our public API. By accessing or using any Mentorize service, you agree to the practices described in this policy. This policy complies with the EU General Data Protection Regulation (GDPR) and applicable Czech data protection law.

Information We Collect

We collect information you provide directly and information generated automatically through your use of our platform. The specific data collected varies by which apps and features you use.

Account & Identity

Name, email address, profile photo, username, and secure credentials. Social sign-in data from Google or GitHub when used.

AI Mentor Conversations

Messages you send and receive in AI Mentor sessions, selected AI model per conversation, conversation titles, and resumable session state. Conversation content is forwarded to your chosen AI provider to generate responses.

Learning Content

Courses, quiz answers, flashcard decks, progress data (completion rates, scores, streaks), notes, and media you upload in the Learning App at app.mentorize.me.

Chat & Collaboration

Messages, channel content, direct messages, voice/video call metadata (not recordings unless you explicitly save them), and files shared via chat.mentorize.me.

Files & Documents

Files uploaded to Drive, documents created in Docs, presentations in Slides, spreadsheets in Sheets, and photos in Photos — stored in your encrypted cloud workspace.

Usage & Analytics

Features you use, pages visited, time spent per session, click patterns, error events, and performance metrics. Used in aggregate to improve the platform.

Device & Technical

Browser type and version, operating system, IP address, device identifiers, time zone, language preference, and referral source.

Billing & Payments

Subscription tier (HOBBY, PRO, or ENTERPRISE), plan history, and invoice records. Full payment card data is handled exclusively by our payment processor (Polar) — we never store raw card numbers.

How We Use Your Information

We use your data to operate, personalize, secure, and improve all Mentorize services. We process your data under the following legal bases: contractual necessity, legitimate interest, legal obligation, and — for marketing — consent.

Service Delivery

Power AI Mentor responses via your chosen provider, sync your workspace across all apps, authenticate your account, and deliver course content and quizzes.

Personalization

Remember your preferred AI model, language, UI theme, notification settings, and learning pace. Surface relevant courses and content based on your activity.

AI Routing

Route your AI Mentor prompts to your chosen provider based on your in-session model selection. Prompts are transmitted securely and subject to the selected provider's privacy policy.

Platform Improvement

Analyze aggregated, anonymized usage patterns to identify bugs, optimize performance, and prioritize new features.

Security & Fraud Prevention

Detect unauthorized access, suspicious login patterns, abuse of the API, and potential data breaches. Enforce rate limits and fair-use policies.

Communication

Send transactional emails (account confirmation, password reset, billing receipts), product updates, and — only with your consent — marketing newsletters.

Legal Compliance

Fulfill obligations under GDPR, Czech data protection law, and other applicable regulations. Respond to lawful requests from Czech, EU, and international authorities.

Data Sharing & Disclosure

We do not sell your personal information. We do not share data for third-party advertising. Data is shared only in the following limited circumstances, always under data processing agreements that enforce equivalent protections.

AI Model Providers

When you use AI Mentor, your messages are forwarded to the provider and model you select. All major providers and their models are available. Each provider's terms govern how they handle prompt data. We recommend reviewing the policy of your chosen provider.

Infrastructure Partners

Cloud hosting, object storage (S3-compatible), email delivery (transactional), and monitoring services. All operate under data processing agreements with geographic restrictions where required.

Payment Processors

Polar processes all subscription payments. We share only your email and subscription tier — not full payment card data. Polar is PCI-DSS Level 1 compliant.

Analytics & Error Tracking

Aggregated, anonymized usage metrics may be processed by analytics tools (e.g., Sentry for error tracking). No personally identifiable information is included in error reports.

Legal Requirements

We may disclose data if required by a court order, subpoena, or applicable law in the EU or other jurisdictions. Where legally permitted, we will notify you before complying.

Business Transfers

In the event of a merger, acquisition, or asset sale, your data may transfer to the successor entity. You will receive notice at least 30 days before any transfer, with options to export or delete your data.

Data Retention

We retain your data only as long as necessary to provide services and comply with legal obligations. You can export or delete your data at any time.

Active Account Data

All account data, files, courses, AI sessions, and chat history are retained while your account is active. Deleting your account triggers a 30-day grace period, after which all data is permanently purged.

Post-Cancellation

After subscription cancellation, your data is retained until the end of the billing period. You can export everything during this window. Accounts not reactivated within 30 days of expiration are queued for deletion.

Anonymized Analytics

Aggregated, anonymized usage statistics (with all PII removed) may be retained indefinitely for product improvement and performance benchmarking.

Legal Holds

Some records (billing transactions, compliance logs) may be retained for up to 7 years to comply with Czech and EU accounting regulations and other applicable laws.

Backups

Encrypted backups are retained for up to 90 days. Deletion requests are applied to backups on the next backup rotation cycle after the 30-day grace period.

Your Rights & Choices

Under LGPD and GDPR, you have the following rights over your personal data. All requests are processed within 15 business days. Submit requests via accounts.mentorize.me or by emailing privacy@mentorize.me.

Access

Request a full export of all personal data we hold about you, across every app — courses, AI sessions, files, messages, and billing records.

Correction

Update or correct inaccurate account information, profile data, or preferences at any time through your account settings.

Deletion (Right to be Forgotten)

Request permanent deletion of your account and all associated data. Processed within 30 days, with exceptions for legally required retention.

Data Portability

Download your data in machine-readable JSON or CSV format — including courses, quiz results, AI conversation history, and documents.

Restriction of Processing

Request that we limit how we process your data (e.g., opt out of analytics, AI training, or marketing) while a dispute is resolved.

Opt-Out of Communications

Unsubscribe from marketing emails via the link in any email or through accounts.mentorize.me → Settings → Notifications. Transactional emails (receipts, security alerts) cannot be disabled.

International Data Transfers

Mentorize is registered in the Czech Republic (EU). To operate our global platform, some data may be processed outside the EU where our infrastructure partners or AI model providers are located (USA, Asia-Pacific). All such transfers are subject to appropriate safeguards — Standard Contractual Clauses (SCCs) — ensuring your data receives the same level of GDPR protection regardless of where it is processed.

Data Security

We implement enterprise-grade security across all Mentorize apps. Security is not an afterthought — it is built into every layer.

Encryption in Transit

All network traffic between your browser, our apps, and third-party providers is encrypted. Your data is protected at every step.

Encryption at Rest

All stored data — files, messages, course content, backups — is encrypted with strong encryption. Your data is protected even at rest.

Strict Data Isolation

Every user's data is fully isolated and partitioned at the database level. Cross-account data access is structurally impossible — your data belongs only to you.

Access Controls

Role-based access control limits employee access to production data. All internal access requires multi-factor authentication, is time-limited, and is fully logged and audited.

Regular Security Audits

We conduct quarterly penetration testing and annual third-party security audits of our infrastructure, APIs, and application code. Critical findings are patched within 48 hours.

Incident Response

Our security team responds to suspected incidents within 4 hours. Affected users are notified within 72 hours of a confirmed breach — in compliance with LGPD and GDPR requirements.

Cookies & Tracking Technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how you use the platform. You can control non-essential cookies through your browser or our cookie preferences.

Essential Cookies

Required for authentication, session management, and security. Cannot be disabled without breaking core functionality (e.g., staying signed in to accounts.mentorize.me).

Preference Cookies

Remember your settings — AI model preference, UI theme (dark/light), language, and notification preferences — so they persist across sessions and devices.

Analytics Cookies

Collect anonymized usage data (pages visited, feature interactions, session duration) to help us improve the platform. Opt out any time via cookie preferences or browser settings.

Contact Our Privacy Team

Have questions about this policy, want to exercise your data rights, or report a privacy concern? We respond to all privacy inquiries within 5 business days.

Questions About Your Privacy?

Our privacy team is here to help — whether you want to export your data, understand how AI Mentor handles prompts, or exercise any of your LGPD/GDPR rights.