Effective August 12, 2026
This policy applies to people who use the Mendly app for themselves, without a therapist.
It does not apply if a therapist invited you to Mendly. In that case your information is protected health information handled on your therapist’s behalf under HIPAA, and their notice of privacy practices governs it. See the final section below.
We collect only what you enter. We do not infer health data from your behavior, buy it from anyone, or take it from other apps or devices.
We do not collect precise location, biometric identifiers, contacts, photos, data from Apple Health or Google Fit, or any information about reproductive or gender-affirming care.
Every category above comes directly from you, entered in the app. We have no other sources of consumer health data.
We do not use your consumer health data for advertising, and we do not use it to train any machine learning model.
We do not sell your consumer health data. We have never sold it and we do not have a process for doing so.
We share it only with service providers who process it on our behalf, under contract, and only as needed to run Mendly:
Notifications we send never contain health information. They say Mendly is ready for you and nothing more, so the services that deliver them never see anything about your check-ins. Your daily reminder never leaves your phone at all — it is scheduled on the device itself.
We may also disclose information if legally compelled, or where necessary to protect someone from imminent harm.
If you subscribe to Mendly Plus, your check-in responses and notes are processed by a large language model to produce your weekly written report. The model runs on Amazon Bedrock inside Mendly's own AWS environment. Your data is not used to train or improve any model. The report is stored against your account and shown only to you.
When we generate your weekly report we also screen the text you wrote for language suggesting suicidal ideation or self-harm. If we see it, we raise the 988 Suicide and Crisis Lifeline to the top of that report. That is the entire response.
We do not contact anyone on your behalf — not emergency services, not family, not a therapist. We do not restrict your account, build a risk profile, keep a risk score, or share the result with anyone. We record only a daily count of how many referrals were shown, which carries no identifier and cannot be traced back to you.
This is a check on language, not a diagnosis or a clinical judgement, and it is never presented as one. Our full protocol is published at mendly.me/legal/crisis-protocol.
You may, at any time:
To exercise any of these, delete your account in the app under Settings or at mendly.me/delete-account, or email privacy@mendly.me. We respond within 45 days.
If we deny a request you may appeal by replying to our decision. If we deny the appeal, you may complain to the Washington State Attorney General, or to your own state’s attorney general.
Data is encrypted in transit and at rest. Access is limited to staff who need it, and access to health data is logged. On your phone, your credentials are held in the device keychain and the app locks after a period of inactivity.
We keep your data until you delete it. Deleting your account removes it from Mendly immediately, and from our backups within 30 days.
If a therapist invited you, your check-ins are part of their clinical record. That information is protected health information under HIPAA, Mendly handles it as their business associate, and this policy does not apply to it. Those records are kept separate from consumer data in our systems and are never combined.
If you were a therapist-linked patient and later switch to using Mendly on your own, you receive a copy of your past entries. The originals stay in your therapist's record, because they are legally required to keep them.
If we change this policy we will post the new version here and notify you in the app before it takes effect. We will not apply a material change to data already collected without asking you first.
Mendly LLC · privacy@mendly.me