Effective August 18, 2026
This policy covers the Mendly app used without a therapist. If a therapist invited you to Mendly, different rules apply — see the section on therapist accounts below.
The health-specific disclosures required by Washington's My Health My Data Act and Nevada SB 370 are in our Consumer Health Data Privacy Policy, which those laws require to be a separate document.
HIPAA applies to health care providers and the companies handling data for them. When you use Mendly on your own, there is no provider involved, so HIPAA does not apply to your information.
That does not mean it is unprotected. Your information is covered by the FTC Health Breach Notification Rule, by state consumer health data laws including Washington's My Health My Data Act and Nevada SB 370, and by the commitments in this policy.
We say this plainly because health apps are often assumed to be HIPAA-covered when they are not, and we would rather you know exactly which rules apply.
You give us: your email address, your name, your check-in responses and notes, your setup answers, and your preferences.
If you sign in with Apple or Google: we receive the email address and name that service passes to us, and nothing else. We never tell Apple or Google what you use Mendly for.
Your device gives us: a notification token if you allow notifications, your time zone, and your app version and device type for troubleshooting. The token lets us tell you a weekly report is ready. Your daily reminder is scheduled on your phone and does not use it.
We do not collect precise location, contacts, photos, your address book, advertising identifiers, data from Apple Health or Google Fit, or anything from other apps.
We do not use advertising, attribution, or session-recording tools. There is no advertising SDK and no general-purpose analytics SDK in the Mendly app. The one third-party SDK we do include is RevenueCat, which handles subscription purchases — it is used only on personal accounts, never on accounts linked to a therapist.
We do not sell your information, share it with advertisers, or use it to train AI models.
Only service providers, under contract, acting on our instructions:
We may disclose information if legally required, or where necessary to prevent imminent harm. If Mendly is ever acquired, your information may transfer as part of that — we will notify you first and you will be able to delete your account before any transfer.
Mendly Plus generates a weekly written report from your check-ins and notes using a large language model running on Amazon Bedrock within Mendly's AWS environment. Your information is not used to train any model. Reports are stored against your account and visible only to you. If you do not subscribe, no AI processing happens.
While generating that report we also screen your text for language suggesting suicidal ideation or self-harm. If we see it, we show you the 988 Suicide and Crisis Lifeline. We do not contact anyone on your behalf and we do not keep a risk score. Our protocol is published at mendly.me/legal/crisis-protocol.
Your full rights, and how to exercise them, are set out under Your rights, and how to use them below.
Set out the way state privacy laws ask for it. Everything below comes from you, or from Apple or Google if you sign in or subscribe through them. We do not buy information about you, obtain it from data brokers, or take it from other apps on your device.
We disclose these categories only to the service providers named under Who we share it with, under contract, and only to run Mendly. We keep each category until you delete your account, then remove it immediately and from backups within 30 days.
We have never sold personal information, and we do not share it for cross-context behavioural advertising. There is no advertising in Mendly, no advertising identifier, no tracking pixel, and no general-purpose analytics service.
Because we do not sell or share it, there is nothing for you to opt out of — but if that ever changes we will say so here and ask you first. We also do not use your sensitive information for anything beyond providing Mendly to you, so the right to limit its use has nothing to restrict.
Depending on where you live — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana — you have some or all of these rights. We extend them to everyone rather than checking where you are.
To make a request, use Settings in the app, start a deletion at mendly.me/delete-account, or email privacy@mendly.me. We answer within 45 days and may take another 45 if a request is complex, in which case we will tell you why before the first period ends. We verify a request by the email address on the account; for a deletion we may ask you to confirm from that address before we act, because a deletion cannot be undone.
You may use an authorised agent by having them email us with your written permission. We will still verify the request with you directly. In California an agent may instead act under a lawful power of attorney.
If we deny an appeal you may complain to your state attorney general. Californians may also contact the California Privacy Protection Agency.
Mendly is not for anyone under 18. We do not knowingly collect information from children under 13, and we do not knowingly collect or sell the personal information of anyone under 16. If we learn that we have, we delete it. If you believe a child has given us information, email privacy@mendly.me.
Your check-ins are part of your therapist's clinical record and are protected health information under HIPAA. Mendly handles that information as your therapist's business associate under a written agreement, and their notice of privacy practices governs it. Those records are stored separately from personal-use data and are never combined.
Deleting your Mendly login does not delete your clinical record. Your therapist is legally required to keep those records for a period set by law and their professional obligations. Deleting your account removes your access and stops new entries; it does not erase what your therapist already has.
Encryption in transit and at rest. Multi-factor authentication available on every account. Access to production data limited to staff who need it, and logged. On your device, credentials are stored in the system keychain and the app locks after inactivity.
No system is perfectly secure. If a breach affects your health information we will notify you and the FTC as the Health Breach Notification Rule requires — without unreasonable delay and no later than 60 days after discovering it.
We keep your information until you delete it. Deleting your account removes it from Mendly immediately, and from our backups within 30 days. Information is held in the United States on AWS infrastructure, and Mendly is intended for use in the United States only.
We will post changes here and, if material, notify you in the app before they take effect.
Mendly LLC · privacy@mendly.me