Privacy Policy
Last updated: March 2, 2026
This Privacy Policy describes how Kollabor AI ("we", "us", "our") collects, uses, and protects your information when you use the Mentiko platform at mentiko.com.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password (hashed). If you sign in with GitHub, Google, or Microsoft, we receive your profile name, email, and avatar URL from those providers.
Billing Information
Payment processing is handled by Stripe. We do not store your credit card number, CVC, or full card details. Stripe provides us with a customer ID, subscription status, and the last four digits of your card for display purposes.
Instance Data
Data you create on your Mentiko instance (agents, chains, configurations, API keys) is stored on your provisioned server. We do not access this data except for operational purposes (backups, troubleshooting at your request).
Usage Data
We collect basic usage data including login timestamps, instance status, and provisioning events. We do not use third-party analytics or tracking scripts.
2. How We Use Your Information
We use your information to:
- Create and manage your account
- Provision and maintain your Mentiko instance
- Process payments through Stripe
- Send transactional emails (verification, password reset, billing notifications)
- Provide customer support
- Monitor system health and prevent abuse
We do not sell your information. We do not use your data for advertising. We do not train AI models on your instance data.
3. Data Storage and Security
Your account data is stored in a PostgreSQL database on our control plane server. Your instance data is stored on your provisioned server. Both are hosted on third-party infrastructure providers with data centers in the United States and Europe. Providers may change over time; the current list is maintained in Section 4 below.
We use encryption in transit (TLS/HTTPS) for all connections. Passwords are hashed using bcrypt. Access to production systems is restricted to authorized personnel.
4. Third-Party Services
We use the following third-party services:
- Stripe - Payment processing. See Stripe's Privacy Policy.
- Linode/Akamai - Server hosting for the control plane and tenant instances. May also provide DNS and object storage.
- Hetzner - Server hosting for tenant instances (select plans).
- Cloudflare - DNS management, DDoS protection, and object storage (select plans).
- GitHub/Google/Microsoft - OAuth authentication (only if you choose to sign in with these providers).
5. API Keys (Bring Your Own)
Mentiko uses a bring-your-own-keys model. API keys you configure on your instance (OpenAI, Anthropic, etc.) are stored on your provisioned server. We do not have access to these keys through the control plane. You are responsible for managing and rotating your API keys.
6. Cookies
We use essential cookies for authentication (session tokens). We do not use tracking cookies, advertising cookies, or third-party cookie-based analytics.
7. Data Retention
- Active accounts: Data retained while your account is active.
- Cancelled subscriptions: Instance data deleted within 30 days of cancellation. Account data retained for billing records.
- Deleted accounts: All data deleted within 30 days, except billing records retained as required by law.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your instance data
- Object to processing of your data
To exercise these rights, email support@mentiko.com.
9. Children's Privacy
Mentiko is not intended for use by anyone under 18 years of age. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the platform. The "Last updated" date at the top indicates the latest revision.
11. Contact
Questions about this Privacy Policy? Email us at support@mentiko.com.