Mentat Privacy Record
Document control / data handling policy
Controlled Document

Privacy Policy

Last updated: March 2026

Information We Collect

Mentat collects the minimum data necessary to provide the service:

  • Account dataUsername and a SHA-256 hash of your API key. Plaintext API keys are not stored.
  • Conversation dataQueries and generated responses are stored to provide conversation history and continuity.
  • Usage metricsPipeline execution statistics including token counts, stage completions, and evaluation scores.
  • Browser context (optional)If you use the Chrome extension and grant permission, page titles and selected content from active tabs may be sent to enhance analysis. This data is processed in-session and not stored separately.

How We Use Your Data

  • Service deliveryTo provide and improve the Mentat workspace.
  • Quality reviewTo generate comparative evaluations and quality signals.
  • History retentionTo maintain conversation history within your account.
  • Aggregate system improvementTo compute anonymized performance statistics for platform improvement.

Third-Party Services

Mentat routes queries through OpenRouter and other configured providers to access language models. Your queries are subject to the privacy policies of those providers. We do not sell or share your personal data with unrelated third parties.

Data Retention

Conversation data is retained for the lifetime of your account. You may delete individual conversations at any time. Account deletion removes all associated data.

Security

API keys are hashed with SHA-256 before storage. Sessions use HTTP-only cookies. Production traffic is expected to use TLS encryption.

Contact

For privacy inquiries, contact ASIKM at the registered business address.