Mentrast Logo
Mentrast
Effective Date: January 07, 2026

Privacy Policy

Mentrast Inc. ("Mentrast", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use Mentrast (collectively, the "Service").

Data MinimizationWe only collect signals necessary for verification.
Global StandardGDPR & CCPA compliant by default for all users.
EncryptedYour learning map is private and secure.

1. Introduction and Scope

This Privacy Policy applies to all personal data processed by Mentrast acting as a Data Controller. It covers data collected through our public-facing website, our application platform, and our API services. It does not cover data where we act as a Data Processor on behalf of an Enterprise Client; in such cases, the Enterprise Client's privacy policy governs.

By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.

2. Information We Collect

We collect information in three categories: Information you provide, information collected automatically, and information from third parties.

2.1 Information You Provide

  • Account Credentials: When you register, we collect your email address, password hash (we do not store plain text passwords), and username.
  • Profile Data: Optional information such as your role and learning goals.
  • Content Data: The structure of your learning map, including topics and verification history.
  • Payment Information: We use a third-party processor (Stripe) for payments. We do not store full credit card numbers.

2.2 Information Collected Automatically

  • Telemetry & Usage Data: We track how you interact with the Service, including mouse movements, click patterns, and feature usage. This is used solely for the "Behavioral Spec" engine to verify human agency.
  • Device Data: IP address, browser type, operating system, and simple hardware identifiers to prevent multi-accounting and bot farms.
  • Cookies: Session tokens and preference settings. See Section 11.

2.3 Information from Third Parties

  • Authentication Providers: If you sign up or log in using a third-party service (e.g., Google, GitHub), we receive basic profile information (e.g., email address, name) from that service.

3. How We Use Your Data

We process your data for specific, limited purposes:

Service Delivery

To maintain your learning map, sync data across devices, and track your progress.

Security & Verification

To keep the platform safe, prevent fraud, and ensure the integrity of the learning process.

Research & Development

We use anonymized data to improve our learning paths and make the system better for everyone.

Communication

To send transactional emails (password resets, billing) and critical system alerts. With your consent, we may send marketing communications.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), our processing is based on the following grounds:

  • Contractual Necessity: Processing is required to fulfill our Terms of Service (e.g., maintain your account, provide core service functionality).
  • Legitimate Interests: For security, fraud prevention, product improvement, and internal analytics, provided these interests do not override your fundamental rights and freedoms.
  • Consent: For optional marketing communications, non-essential cookies, or specific data processing activities where consent is explicitly requested and can be withdrawn at any time.
  • Legal Obligation: To comply with tax laws, law enforcement requests, and other legal requirements.

5. Data Sharing and Disclosure

We do not sell your personal data. We only share data in the following circumstances:

  • Service Providers: We use trusted third-party providers (subprocessors) for hosting (Vercel), database (Supabase), and payments (Stripe). These providers are contractually bound to confidentiality and data protection standards equivalent to our own.
  • Legal Requirements: We may disclose data if required by law, subpoena, or valid court order. We will attempt to notify you of such requests unless prohibited by law.
  • Business Transfers: If Mentrast is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal data.
  • With Your Consent: We may share your information for any other purpose with your explicit consent.

6. International Transfers

Your information, including Personal Data, may be transferred to—and maintained on—computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. Mentrast ensures that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), to protect your data during such transfers. By using our Service, you understand and agree to the transfer of your information to the United States and other countries where we operate.

7. Security Measures

We employ "defense-in-depth" security architecture:

  • Encryption: AES-256 for data at rest; TLS 1.3 for data in transit.
  • Access Control: Strict Role-Based Access Control (RBAC) specifically tailored to the Principle of Least Privilege.
  • Audits: Regular internal code reviews and third-party penetration testing.
  • Hashing: Sensitive identifiers are hashed before analytical processing.
  • Incident Response: We have established procedures for detecting, responding to, and reporting data breaches.

8. Data Retention

We retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.

  • Account Data: Retained for the lifetime of your account.
  • Deleted Accounts: Data exists in backups for up to 30 days before permanent erasure.
  • Logs: Server access logs are retained for 90 days for security auditing purposes.
  • Anonymized Data: We may retain anonymized and aggregated data indefinitely for research and product improvement purposes.

9. Your Data Rights

Regardless of your jurisdiction, Mentrast grants you the following rights, which you can exercise directly within the application settings:

Download Your DataGet a complete copy of your learning map and progress.
SETTINGS > DATA > EXPORT
Delete AccountPermanently remove your data and learning progress.
SETTINGS > DANGER ZONE

To rectify data, restrict processing, or object to processing, contact our DPO at privacy@mentrast.com. We will respond to your request within 30 days.

10. Your California Privacy Rights (CCPA)

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). These rights include:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
  • Right to Delete: You have the right to request the deletion of personal information that we have collected from you.
  • Right to Opt-Out: You have the right to opt-out of the sale or sharing of your personal information. Mentrast does not sell or share personal information as defined by CCPA/CPRA.
  • Right to Correct: You have the right to request the correction of inaccurate personal information.
  • Right to Limit Use and Disclosure of Sensitive Personal Information: Mentrast does not process sensitive personal information in a way that would require this right to be exercised.

You can exercise these rights via the Settings panel as described in Section 9, or by contacting our DPO. We will verify your request using information associated with your account, including email address.

11. Cookies Policy

We use essential cookies to authenticate users, maintain session state, and prevent fraudulent use of user accounts. These cookies are strictly necessary for the operation of the Service.

We may also use analytics cookies (e.g., Google Analytics) to collect information about how users interact with our Service, such as pages visited, time spent on pages, and click patterns. This helps us improve the Service. These cookies are not strictly necessary and are only used with your consent.

You can control your cookie preferences and withdraw consent at any time through the "Cookie Settings" modal, which appears upon your first visit and can be accessed via a link in the application footer. Most web browsers also allow you to control cookies through their settings preferences.

12. Children's Privacy

Our Service is not addressed to anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with Personal Data without your consent, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top of this Privacy Policy. We may also notify you via email or a prominent notice on our Service prior to the change becoming effective. You are advised to review this Privacy Policy periodically for any changes. Your continued use of the Service after any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Mentrast Inc.
Attn: Data Protection Officer
Lagos, Nigeria
Email: privacy@mentrast.com