Legal

Privacy Policy

How MentorU handles personal information across the platform.

Last updated: August 24, 2026

Platform operator: Kahel Ventures LLC, an Oregon limited liability company, operating MentorU.

Policy Scope

This Privacy Policy explains how MentorU collects, uses, discloses, protects, and retains information when people visit MentorU public pages, create or use accounts, launch or administer workspaces, buy or access provider offerings, communicate through platform tools, or otherwise use MentorU services.

MentorU is a platform used by workspace owners, providers, admins, account users, customers, members, and visitors. Providers may also maintain their own privacy notices for the offerings, customer relationships, content, policies, and communications they control.

Connected Zoom Data

When a workspace owner connects Zoom, MentorU receives the authorizing user's Zoom account and host identifiers, display name, email, granted scopes, token expiration, and OAuth access and refresh tokens. The released integration requests the seven user-managed permissions needed to identify the authorizing user, create, read, update, and delete that user's meetings, obtain a short-lived Zoom Access Key for host start, and obtain a meeting-bound On Behalf Of token for an entitled member's embedded join.

When an authorized mentor schedules a Zoom-backed session, MentorU may process the meeting identifier, topic, scheduled time, duration, timezone, meeting settings, passcode, join URL, and host start information returned by Zoom. MentorU uses this information to keep the MentorU session and Zoom meeting synchronized and to render the exact meeting inside the authenticated MentorU experience.

OAuth access and refresh tokens are encrypted at rest and remain in server-side systems. They are not returned through customer-safe status APIs. For an exact embedded meeting, the authenticated browser may receive a short-lived Meeting SDK signature and either a short-lived, user-associated ZAK issued only after exact tenant, session, meeting, and host authorization, or a meeting-bound OBF token for an entitled member join. MentorU does not persist or log those short-lived credentials.

On a confirmed MentorU disconnect or valid Zoom deauthorization, MentorU immediately disables use of the connection and deletes its usable OAuth credentials and Zoom-derived account fields from active connection storage. Meeting records and secret-free lifecycle and security evidence follow the schedule in the Security and Data Protection Policy. Requests to access or delete retained personal information can be sent to support@mentoru.app and may require identity verification.

MentorU does not sell or rent Zoom-derived data, use it for advertising profiles or surveillance, or disclose it except to Zoom and infrastructure subprocessors that operate and secure the integration, or when legally required.

Connected Google Calendar and Google Meet Data

When a workspace owner connects Google Calendar, MentorU receives the authorizing user's Google account identifier, email, name, granted scopes, token expiration, and OAuth access and refresh tokens. MentorU also reads only the Calendar list fields it needs: calendar identifiers, names, primary status, access roles, time zones, and the selected calendar's supported conference types. These fields let the owner choose a writable calendar and let MentorU determine whether it supports Google Meet.

The Google Calendar events permission technically permits event access on calendars available to the authorizing account. MentorU directs its event requests only to the writable Calendar selected for that workspace. To find its own sessions without downloading unrelated event content, MentorU first reads only event identifiers, cancellation status, and recurring-series identifiers in a bounded time window. After an identifier matches a same-workspace MentorU session record, authorized workspace admins may read, create, display, update, or cancel that MentorU scheduling event. Only then does MentorU request the fields needed for that experience: event title, description, location, start and end times, recurrence details, links, and conference status. MentorU does not request detailed content for unrelated Google events or expose them through admin or member Calendar surfaces for tenant-owned Google connections.

Only the recorded workspace owner may select or manage Google Meet delivery. When selected, MentorU asks Google Calendar to create one unique external Meet conference for that event and stores the canonical join URL only after Google returns it. MentorU does not add Calendar attendees. MentorU does not request Google Meet API scopes and does not access Meet audio, video, recordings, transcripts, chat, or participant activity.

Google OAuth access and refresh tokens are encrypted at rest in server-side systems and are not returned through customer-safe status APIs. Calendar and Meet information is exposed only to authorized users of the same workspace as needed to provide the scheduling and join experience. Google-derived Calendar data is not indexed by, retrieved for, or sent to Mentor AI, OpenAI, or another model provider for inference or training. MentorU does not sell Google user data or use it for advertising, surveillance, broader analytics, generalized product development, or unrelated support. It is not subject to the broader sharing or successor-transfer provisions below except with documented user consent, for a security investigation, when legally required, or through infrastructure subprocessors that operate and secure the requested integration.

On a confirmed disconnect or valid revocation, MentorU disables the connection and deletes its usable Google OAuth credentials from active connection storage. Owners can disconnect in MentorU Connections or revoke MentorU through their Google Account permissions. Authorized users can cancel or delete MentorU sessions through scheduling tools. Secret-free scheduling, security, and audit records follow the retention practices in this policy. Requests to access or delete retained personal information can be sent to support@mentoru.app and may require identity verification.

MentorU's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

LiveKit Live Room Media

When an eligible workspace uses a MentorU Live Room, LiveKit provides the third-party media infrastructure that processes participants' live audio, video, and screen sharing for the call. MentorU issues a short-lived, room- and participant-bound admission credential after checking workspace, session, membership, schedule, and capacity authority. When a host or workspace admin turns on Live captions, each participant must accept a versioned audio-processing notice before joining captioned media. A speech-to-text-only LiveKit Agent sends room microphone audio to Deepgram through LiveKit Inference and returns live English captions. The Agent has no LLM, TTS, or audio output, and its LiveKit observability recording is disabled. When an authorized host or workspace admin explicitly requests a MentorU Live recording, every person in media must separately accept the current audio, video, and screen-sharing notice before LiveKit Egress begins. A person who declines may continue using room collaboration without entering recorded media. MentorU does not persist caption text, expose a transcript API, record automatically, or enable LiveKit chat.

MentorU retains the Live Session's provider-independent lifecycle, moderation, admission, convergence, security-audit, and support metadata, plus caption and recording lifecycle, consent, usage-reservation, and safe failure audit metadata. A finalized MP4 is stored in private Supabase Storage and served only through short-lived, same-workspace authorized access. It is automatically deleted thirty days after it becomes ready and may be deleted earlier by the host or workspace admin. A non-sensitive deletion tombstone remains without media, playback URLs, or storage credentials. Ending LiveKit media revokes media admission but does not itself delete authorized MentorU Discussion, Materials, Notes, recap, poll, Q&A, roster, or presence records, which follow their own access, retention, and deletion windows.

Information We Collect

We collect information you provide directly, information generated through platform activity, and information received from service providers that help operate MentorU. Depending on how you use the platform, this may include:

  • Account and contact data, such as name, email address, phone number, organization, role, login status, profile details, and support requests.
  • Provider and workspace data, such as workspace name, brand settings, public-site content, offerings, prices, setup status, admin users, and operational preferences.
  • Customer and member data, such as package access, membership status, course or content progress, scheduling activity, form responses, comments, and relationship history within a workspace.
  • Content, uploads, and communications submitted through MentorU, including files, images, messages, notes, announcements, comments, event details, and generated or edited workspace materials.
  • Payment processor metadata from third-party processors such as Stripe, including customer IDs, connected account IDs, subscription or checkout status, invoice status, amounts, fees, refunds, disputes, and transaction identifiers. MentorU does not store complete payment card numbers.
  • Technical and usage data, such as device and browser details, log data, IP-derived approximate location, cookie identifiers, page views, feature interactions, error diagnostics, and analytics events.

How We Use Information

We use information to provide, secure, operate, support, and improve MentorU. This includes using information to:

  • Maintain accounts, authentication, workspace access, member access, admin permissions, and platform settings.
  • Operate provider workspaces, public pages, checkout flows, content access, scheduling, comments, communications, reporting, and support workflows.
  • Process platform subscriptions, provider offering payments, fees, refunds, disputes, invoices, compliance checks, and payment-related support through third-party processors.
  • Send service notices, account messages, support responses, transactional email, workspace communications, and optional marketing where permitted.
  • Monitor security, debug errors, prevent misuse, enforce terms, maintain audit records, and protect users, providers, customers, members, MentorU, and third parties.
  • Measure usage, improve reliability, refine product features, develop new services, and understand how visitors and account users interact with MentorU.

Workspace and Customer Data

Workspace owners and providers control much of the workspace, offering, customer, member, content, and communication data submitted to their MentorU workspaces. MentorU processes that data to provide platform services, maintain tenant separation, support the workspace, and perform actions requested by authorized account users.

Customers and members should understand that information they submit inside a provider workspace may be visible to the applicable provider, workspace admins, invited team members, or other participants when the feature is designed for shared access.

Cookies and Analytics

MentorU may use cookies, local storage, pixels, analytics tools, and similar technologies to keep users signed in, remember preferences, secure sessions, measure page and feature usage, diagnose technical issues, and understand platform performance.

You can control some cookies through your browser settings. Blocking cookies may affect login, workspace access, checkout, personalization, or other platform features.

How We Share Information

MentorU does not sell personal information. We may share information when needed to operate the platform, support users, comply with law, or protect rights and security. This may include sharing with:

  • Workspace owners, providers, admins, team members, customers, or members as directed by platform features and workspace permissions.
  • Service providers and subprocessors that provide hosting, database, storage, authentication, email, payment processing, analytics, logging, security, customer support, and infrastructure services.
  • Payment processors, banks, card networks, fraud-prevention services, tax or compliance providers, and connected-account platforms as needed for payments and financial administration.
  • Professional advisors, legal authorities, regulators, or counterparties when required by law, legal process, compliance obligations, dispute handling, or protection of rights, safety, and platform integrity.
  • Successors or participants in a business transaction involving MentorU or Kahel Ventures, subject to appropriate confidentiality or transfer safeguards.

Security

We use technical, administrative, and organizational safeguards designed to protect information, including access controls, tenant separation, secure infrastructure providers, monitoring, and restricted administrative access. No internet service can guarantee absolute security, but we work to reduce risk and respond to security concerns.

Additional controls, security-reporting instructions, and operational practices are described in the Security and Data Protection Policy.

Retention

We retain information for as long as reasonably needed to provide the platform, maintain accounts and workspaces, support provider and member relationships, comply with legal, tax, accounting, payment, security, audit, and dispute obligations, enforce agreements, and improve MentorU. Retention periods may vary by data type, workspace settings, legal requirements, and operational need.

When information is no longer needed, we may delete, de-identify, or aggregate it unless retention is required or permitted by law, legitimate business needs, security obligations, backup systems, or provider-controlled workspace requirements.

The current operational retention schedule, including Zoom credentials, short-lived authorization material, meeting metadata, security evidence, support records, and backups, appears in the Security and Data Protection Policy.

Your Choices and Privacy Requests

Depending on your location and relationship to MentorU, you may have rights to request access, correction, deletion, portability, restriction, objection, opt out of certain communications, or withdraw consent where processing depends on consent. You may also update some account information directly through platform tools.

To make a privacy request, contact support@mentoru.app. We may need to verify your identity, clarify the workspace or account involved, and coordinate with the applicable provider when the request concerns provider-controlled customer, member, content, or communication data.

Children and Sensitive Information

MentorU is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Do not submit sensitive personal information, regulated information, or confidential third-party information unless you have the legal right to do so and the platform feature is appropriate for that use.

Providers using MentorU for youth programs must also follow the Minors and Youth Program Policy.

Related Platform Policies

Provider communications, uploaded content, checkout activity, and AI-assisted tools may also be governed by MentorU's Communications and Email Policy, Copyright and Intellectual Property Policy, Customer Purchase Terms, and AI and Automation Policy, as well as the Security and Data Protection Policy.

International Use

MentorU is operated from the United States. If you access MentorU from another location, your information may be processed in the United States or other jurisdictions where MentorU or its service providers operate.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the date on this page and may provide additional notice when appropriate.

Contact

If you have questions about this Privacy Policy or how MentorU handles information, contact support@mentoru.app.