Privacy Policy · Effective October 11, 2026

Privacy Policy

This policy explains what information Mend handles and why. Mend is made by Akira Patafio, an individual developer (“we” or “us”). It covers:

In short: the app sends no analytics or usage data to us and contains no advertising or tracking. This website sets no cookies and runs no analytics. A Mend server stores reduced, mostly numeric transition reports, and its Mend AI learns from verified outcomes and Claude’s checked corrections. When its operator turns cloud AI on, the server uses Anthropic (Claude) for layout checks and for transitions Mend AI is unsure about, and OpenAI only if the operator also enables that; those providers process what they receive under their own terms. Workspace owners and developers can each turn cloud AI and learning off, and an app that embeds the Mend SDK can offer the same switches to the people using it. When online checkout is open, Stripe handles payment and Mend keeps only subscription IDs, plan and status.

The Mend app

App Store privacy label: Data Not Collected. The app sends no analytics, usage data or diagnostics, calls no AI provider, and contains no tracking. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots. The sections below about servers, the SDK and AI describe software that runs elsewhere, not in the app.

No analytics or tracking

The app sends no analytics or usage data to us. It contains no analytics, advertising, crash-reporting, or tracking SDKs, does not track you across other companies’ apps or websites, and does not require an account with us. It has no in-app purchases. It contacts only the Mend server you enter; if that is the mend.solutions pilot we operate, we receive those requests as described below.

Offline features

The Try it tab runs a fixed sample entirely on your device and makes no network requests. Explore sample reports in the Reports tab shows example reports, example transition hotspots and sample server status that are bundled inside the app; loading them uses no network connection. They were produced by a Mend server from example transitions and contain no information about you.

Connecting to a server

The app contacts a server only after you enter its address and choose Connect and save. It then connects over HTTPS only to that address, sends the gateway username and password you entered so the server can authenticate you, and reads the server’s status, monthly usage counters, saved transition reports, and transition hotspots. It does not follow redirects to another address, and it turns off cookie, cache, and credential storage for these requests. The operator of that server—you, your organization, or us for the mend.solutions pilot—receives these requests along with your device’s IP address, as with any internet connection.

Stored on your device

After a successful connection, the app saves the server address, gateway username, and gateway password in this device’s Keychain, set to be available only on this device while it is unlocked. If you save a GitHub repository link, the app stores that link in its own preferences (UserDefaults) on the device. The app does not access the repository; Open GitHub passes the link to your browser. Reports and hotspots loaded from a server are kept in memory while the app is running and are not saved by the app. Copy snippet puts a hotspot’s code snippet on this device’s clipboard only when you choose it.

Apple

If you have chosen in your device settings to share analytics or crash data with app developers, Apple may provide us with aggregated usage statistics and crash reports. We use them only to fix and improve the app. Apple’s own handling of this data is described in Apple’s privacy policy.

This website

mend.solutions is a set of static pages. It sets no cookies, uses no browser storage, and loads no analytics, advertising, third-party scripts, fonts, or embedded content. Its content security policy prevents the pages from opening network connections after they load. Apart from the owner workspace, the only link the Mend server answers is the checkout link in the plan descriptions: it asks the server for a Stripe checkout page when online checkout is open, and otherwise only sends you back. It sets no cookies, and Mend writes nothing about it to disk; to limit abuse it counts these requests in memory for 10 minutes, without your IP address, and keeps only totals of turned-away requests until the server restarts.

The interactive demo runs entirely in your browser with fixed local actions. Its observations, and the signal latency you choose for it, stay in the page’s memory and are cleared when you refresh or leave the page. It makes no network requests and does not call an AI provider.

The site has no forms. If you use an email link, your email app sends the message only when you choose to send it.

Server logs

We serve https://mend.solutions from our own Raspberry Pi: HAProxy passes each encrypted connection to Caddy, which serves the pages. Their configuration does not record an entry for each visit: HTTP access logging and connection logging are not enabled, and the Mend server process does not log requests. To limit abuse, HAProxy counts each IP address’s open and recent connections in memory and drops the address about 60 seconds after its last connection; this count is never written to disk. HAProxy passes connections on without the visitor’s IP address, so Caddy and Mend see only a local address. Like most server software, these programs write operational messages—such as startup, certificate renewal, and errors—to the server’s system log. An error entry can include the request method, the requested page and request headers such as the browser’s user agent, but not your IP address; Caddy leaves login and cookie headers out of these entries by default. We use these messages only to operate and secure the service, and the system log discards the oldest messages automatically as it reaches its size limit.

Plain HTTP requests

Always use https://mend.solutions. An unencrypted http:// request for mend.solutions or www.mend.solutions that arrives from the internet (port 80) is answered by HAProxy with a permanent redirect to https://mend.solutions; it is not logged and never reaches Mend. Other plain-HTTP requests reach a separate network-onboarding service that runs on the same device: requests for other names arrive there through HAProxy with this device's address, and requests from the local network arrive directly, where that service can record the requesting IP address for network security. We do not use those records for Mend.

Owner workspace and links

The workspace at /workspace is not a public service. It requires a login issued by us; there is no public sign-up. When online checkout is open, someone who buys a plan receives their workspace login from us by email. Unlike the public pages, the workspace loads its fonts from Google Fonts, so Google receives the IP address and browser details of whoever opens it. Links to other sites, such as Apple, Anthropic, and OpenAI, lead to services governed by their own privacy policies.

The Mend service

Mend’s server software runs either on a developer’s own computer or on a server we operate for the pilot. Whoever operates a server decides how its data is used and kept; if you use a server run by you or your organization, its operator is responsible for it. This section describes what the software does and how we handle data on the mend.solutions pilot service, where we are the operator. Access to a server’s workspace and API requires the operator’s gateway login. Each server has a single workspace; there are no separate customer accounts.

In apps that use the Mend SDK

Developers add the Mend SDK to their own web apps. In the browser of a person using such an app, it measures only the screen changes and elements the developer marks, keeps its observations in the page’s memory, and sends layout findings only to the app’s own server, and only if the developer sets that up and cloud AI is on. If the person picks a signal latency or turns cloud AI or learning off, that choice is saved in that site’s browser storage, only after they choose. This is the app’s site, not mend.solutions.

What a Mend server receives and stores

Mend AI learning memory

Each server runs Mend AI, a small outcome model. It keeps counts of browser-verified successes and failures for each recovery action (train) and counts of which action Claude chose when Mend AI was unsure and Claude’s answer passed Mend’s checks (fix), each keyed by a hash of the measurement pattern. Mend AI answers on its own once its verified-outcome counts make it confident and asks Claude about a transition only when they do not; correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Only action labels and counts are kept, never Claude’s text, and a correction never counts as a verified success. The memory stays on that server and is not shared. Mend AI is not a language model, and Mend never sends your data to train Anthropic’s or OpenAI’s models. Mend’s rules for Mend AI are improved by an automated job that uses only synthetic test transitions from Mend’s source code (iterate), never data from any server or app, and every change is reviewed before it ships. The workspace owner and developers can each turn learning off, an app that embeds the Mend SDK can offer that switch to the people using it, and the owner can delete learning data. Learning off stops the counters; the reports themselves are still kept until the owner deletes them.

How long data is kept

These records have no time-based expiry: they remain on the server’s disk until they are replaced as described above or removed by the operator. The workspace offers Delete learning data, which removes the learned counters, or the counters and every transition report; it does not yet offer per-item deletion. Backups, and records held by AI providers or Stripe, follow their own schedules.

Billing

Workspace usage billing, which meters a workspace’s AI usage to Stripe, is turned off by default and is not enabled on the mend.solutions service. If an operator enables it, Stripe-hosted Checkout collects payment details directly—Mend never receives card numbers—and Mend sends Stripe its workspace, customer, and plan identifiers and numeric usage amounts. Stripe’s notifications to Mend, which can include customer contact details, are processed in memory and not stored. Billing records are then kept on the server within the fixed limits described in the AI and data disclosure.

Online checkout on this website

When online checkout is open, a paid plan can be bought on Stripe’s hosted checkout page, which can offer Apple Pay, Google Pay and cards. Stripe collects your email address, your card or wallet details, the billing details it asks for, and device and browser data, under the Stripe Privacy Policy; Mend never receives card numbers. A checkout page left unpaid expires after about 30 minutes, and Mend keeps nothing about it. After a payment, Stripe sends Mend a signed notification; Mend checks it with Stripe and keeps only the subscription’s Stripe customer and subscription IDs, plan, test or live mode, status, start, payment-cleared, update and end times, and whether we have sent your workspace login. We look up your email address in our Stripe account to send that login within 1 business day and to answer you; the Mend server does not store it. The server keeps at most 1,000 subscriber records and removes each one 90 days after its subscription ends. Stripe keeps its own billing records under its terms. The companion app is free, has no in-app purchases and has no part in this.

AI providers

A Mend server works without cloud AI: local rules and Mend AI, its on-server learning memory, provide diagnoses. Cloud AI is used only when the server’s operator adds a provider’s API key and leaves cloud AI turned on.

Mend’s requests to AI providers do not include page text, form values, screenshots, repository code, URLs, element identifiers, source labels or transition names, review summaries, or your gateway login. API keys stay on the server. For the mend.solutions pilot, any AI processing uses our provider accounts. A developer who connects the SDK to a different diagnosis backend controls what that backend receives.

Under the providers’ terms

Anthropic and OpenAI process these requests under their own commercial or API terms and data controls, not this policy; those terms govern how long they keep the data and how they may use it. Anthropic’s Commercial Terms state that Anthropic may not train models on customer content from its services, and its privacy center explains how long API data is kept and the exceptions. OpenAI’s API data controls page states that API data is not used to train OpenAI’s models unless the customer opts in, and describes its own retention. Read the providers’ pages for their current terms:

Usage guardian and the free demo

A fixed set of rules checks every cloud AI request before it is sent, except the optional pause explanation described above, which is sent only after a pause and counts against the monthly Claude allowance rather than the hourly limits or website billing. It pauses cloud AI when requests or tokens in the last hour pass their limits, when a monthly allowance or budget is being used up much faster than the month is passing, after repeated provider failures, when a provider reports a credit or spend-limit problem, or, if the owner turns the revenue cap on, when this month’s estimated AI cost reaches a share of recent Stripe income. The decision never depends on an AI model. Local diagnosis continues while cloud AI is paused. The free demo on this website, the free demo in the workspace, and the app’s Try it tab use no AI tokens; only the private workspace playground can, and the guardian can cut it off.

What data Mend uses

This is every kind of data Mend’s software, this website, the app and our support mailbox handle, with where it comes from, why, where it is kept, for how long, who else receives it, and how to opt out. The same list, with live counts, appears in the workspace under Settings → Data & AI.

In an app that uses the Mend SDK

This stays in the browser of a person using an app whose developer added the Mend SDK. The mend.solutions website does not monitor its visitors; its demo watches only its own sample preview.

Screen-change observations

Data
For each control the developer marks: the transition name, from/to and group labels, the trigger and expected-screen element IDs, start and end times, duration, the signal latency in effect and where it came from, size, position, opacity and visibility before and after, up to 24 timeline steps, standard JavaScript error names (never messages) and an optional developer source label. For transition hotspots, record.hotspot holds a checked copy of the developer’s source label and transition name (a repo-relative path and line such as src/cart/CartButton.tsx:42 and a plain name), or nothing when a label fails the checks. With a registered redirect, the recovery controller adds the fallback element ID (fallbackTargetId) to the record it passes to diagnosis
Source
The Mend SDK in the person’s browser, only for elements the app’s developer marks
Purpose
Notice when a screen change is slow or stuck, measured against the signal latency
Where stored
Page memory only: 60 records by default, at most 200. Other scripts on the same page can read them through the mend:transition event and window.Mend, and failed records are written to the browser console.
Retention
Until the page is closed or reloaded
Shared with
Nobody, by the SDK itself. With automatic recovery, the app’s own code sends a failed record to the developer’s backend, which can pass it to a Mend server (see “Records as received”).
How to opt out
Developer: remove the data-mend-transition and data-mend-motion attributes, or call Mend.stop(). data-mend-hotspots="off" on the page’s <html> or <body>, the connect tag, or any marked element or its container, or hotspots: false for the monitor or recovery controller, leaves record.hotspot empty; the recovery controller removes it before each diagnosis request whenever any of these is off. A person can turn cloud AI and learning off where the app offers it, but cannot switch off observation inside an app.

Layout findings

Data
For elements marked data-mend: the element ID, check type, severity and measurements (widths, contrast ratio, opacity or image size)
Source
The SDK’s layout checks in the browser
Purpose
Choose a supported, reversible repair
Where stored
Page memory: the current findings and the last 100 repairs. Other scripts on the same page can read them through the mend:visual event and window.Mend.visual.
Retention
Until the page is closed or reloaded
Shared with
Only if the developer sets data-mend-endpoint: up to 32 findings per request go to that same-origin address on the app’s own server. Never sent while cloud AI is off for the app or the person.
How to opt out
Developer: leave out data-mend-endpoint or set data-mend-cloud="off". Person: the app’s privacy controls or Mend.setPrivacy({ cloudAi: false }).

A person’s own choices

Data
The signal latency the person picked (Fast, Balanced, Patient or a number of milliseconds) and which of the cloud AI and learning switches they turned off
Source
The person, through controls the developer mounts (Mend.mountLatencyPicker, Mend.mountPrivacyControls) or the app’s own code
Purpose
Apply and remember the choice on that site
Where stored
That site’s browser storage, keys mend:signal-latency:v1 and mend:privacy:v1, written only after the person makes a choice. If storage is blocked, the choice lasts for the page only.
Retention
Until the person resets the choice (the stored entry is removed) or clears the site’s data
Shared with
Switches that are off travel as a privacy flag with the SDK’s layout requests, and with diagnose and outcome calls where the app’s recovery code and backend pass them on; the latency in effect is recorded in each observation.
How to opt out
Make no choice, reset to the app default, or clear the site’s data. Developer: data-mend-user-latency="false" ignores any stored latency.

On a Mend server

Whoever operates a Mend server controls this data: we do for the mend.solutions pilot, and any other server is run by its own operator. Files sit in the server’s data directory with owner-only permissions.

Records as received, before reduction

Data
Complete screen-change records and layout findings as an app’s backend or the owner workspace sends them, including labels, element IDs, source labels, event text and positions, the hotspot labels and any fallback element ID, plus any privacy flags and the workspace demo marker
Source
Requests to /api/analyze, /api/transitions/diagnose and /api/transitions/outcome
Purpose
Reduce each request to fixed codes and numbers before anything is kept or sent to AI
Where stored
Not stored, apart from what transition reports keep. Labels, element IDs (apart from the hashes in transition reports), event text, source labels and positions are discarded during reduction. The one exception is a failed transition’s hotspot source label and transition name, kept after the server checks them again unless hotspot labels are off. Layout findings are answered and discarded.
Retention
Only while the request is handled
Shared with
No one in this form
How to opt out
Developers can send fewer fields; nothing beyond the reduced form is kept

Transition reports

Data
Failure code and type, duration, the signal latency in effect (milliseconds, source and preset), before/after size, opacity and visibility measurements, the expected element’s ID stored only as a one-way hash (an unsalted SHA-256, so anyone who can guess an ID such as “account-panel” can confirm it) and, with a registered redirect, the same kind of hash of the fallback element’s ID, the developer’s source label and transition name for transition hotspots unless hotspot labels are off (a file path and line such as src/cart/CartButton.tsx:42 and a name such as “Open cart”, never the code itself), the diagnosis and its reason (Claude may have written it), how Mend AI routed it (an escalation rule, Mend AI itself, Claude or local rules, and why), a marker when Claude’s answer became a Mend AI correction with Mend AI’s earlier best guess, any notice, the browser verification result with a hash of that observation, the Astra review result and its token counts, and markers when cloud AI or learning was off or the request came from the workspace demo
Source
Diagnose and outcome requests from the owner workspace or an app’s backend
Purpose
Show reports to the developer and suggest a recovery
Where stored
transition-memory.json in the server’s data directory
Retention
The newest 500 reports (fewer only if the file would pass 3 MB), with no time-based expiry, until the workspace owner deletes them
Shared with
The reduced measurements (not the hashes, the hotspot labels, the latency source, the routing or the markers) go to Anthropic Claude when a cloud diagnosis is requested and Mend AI is not confident, and to OpenAI Astra when the operator turns reviews on, unless cloud AI was off when the report was made: that marker keeps it from cloud AI later. Anyone with the gateway login can read reports and transition hotspots in the workspace or the companion app.
How to opt out
Workspace owner: Delete learning data → counters and every report; turn hotspot labels off in Settings → Data & AI, which also deletes the labels already stored. Developer: do not send failed records to a Mend server, or add data-mend-hotspots="off" to keep the hotspot labels out (a registered redirect still sends its fallback ID). Learning off still keeps the report and its outcome, marked, for the developer, but never learns from it.

Mend AI learning (verified outcomes and Claude corrections)

Data
Per measurement pattern (a hash of the failure code, the transition type and four yes/no facts such as whether the screen was hidden) and recovery action: how many browser-verified recoveries succeeded and failed (train), and how many times Claude’s validated diagnosis chose that action while Mend AI was unsure (fix). Only the action label is counted, never Claude’s text
Source
Recovery outcomes: a success counts only when the browser verified it and, while Astra review is on, Astra agreed. Corrections: Claude diagnoses that passed Mend’s checks; they never count as verified successes.
Purpose
Let Mend AI, the small model on this server, answer on its own once verified outcomes make it confident and ask Claude about a transition only when they do not. Correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Mend never uses it to train Anthropic or OpenAI models.
Where stored
transition-memory.json
Retention
Up to 2,048 patterns (at most 160 can occur with today’s pattern key) of outcomes and of corrections, with no time-based expiry, until the workspace owner deletes learning data
Shared with
No one; never sent to AI providers
How to opt out
Workspace owner: turn learning off (no outcomes or corrections are recorded), turn cloud AI off (Claude is never asked, so nothing is corrected) or delete learning data. Developer: pass { learning: false } (or a person’s choice) as the recovery controller’s privacy option and have the app’s backend forward privacy with diagnose and outcome calls. A person’s Mend.setPrivacy({ learning: false }) and the connect tag’s data-mend-learning="off" take effect only through that path; on their own they send nothing that is learned from.

Transition hotspots (owner only)

Data
Hotspots ranked from stored reports: per developer source label, transition name and type, failure counts, timing medians, verified recovery counts, and a recommendation (resolve, redirect or review) with steps and a code snippet to copy
Source
Computed by rules from stored transition reports and outcome counters on each GET /api/hotspots; no AI is used
Purpose
Show the developer where transitions fail in their code and whether Mend should resolve in place, redirect to a registered fallback or leave it for review
Where stored
Not stored: computed on each request
Retention
Only while the request is handled
Shared with
Anyone with the gateway login, in the workspace or the companion app; never sent to AI providers
How to opt out
Workspace owner: hotspot labels off groups hotspots by transition type only. Developer: data-mend-hotspots="off".

Monthly AI usage counters

Data
Claude and Astra request and token counts for the current month
Source
Each cloud AI request
Purpose
Enforce the monthly request limits and the usage guardian
Where stored
usage.json and astra-usage.json
Retention
Replaced when a new month starts
Shared with
No one
How to opt out
Not needed: counts only, with no content

Mend AI routing counts

Data
Per month: transitions diagnosed; how many an escalation rule, Mend AI, Claude or local rules decided; why Mend AI asked Claude (unsure, a failed verification or not yet learned); Claude calls, answers, blocked calls and token totals; Astra reviews and tokens; correction counts and browser-verified outcomes by engine
Source
Each diagnosis and recorded outcome on this server, except workspace demo traffic
Purpose
Show the owner how often Mend AI handles transitions without Claude, Claude calls per 100 transitions and the estimated AI cost per verified fix
Where stored
mend-ai-routing.json
Retention
The newest 13 months
Shared with
No one; never sent to AI providers
How to opt out
Not needed: counts only, with no content

App Store review summaries

Data
Summaries the workspace owner types, with an optional star rating and review ID, and links to verified reports
Source
The owner, in Settings → Learn from App Store feedback
Purpose
Investigate reported problems
Where stored
review-feedback.json
Retention
The newest 100 summaries
Shared with
No one; never sent to AI providers
How to opt out
Do not add summaries; leave out reviewer names and other personal information

Usage guardian record

Data
Guardian settings (including the optional revenue cap: on or off, the share of income and the buffer), the current pause, the last 20 pauses with the figures that triggered them (for a revenue-cap pause, this month’s estimated AI cost and the cap), consecutive provider failure counts and this month’s explanation count
Source
The usage guardian and the owner’s settings. Whether a provider error was a credit or spend-limit error is read from at most 4 KB of an HTTP 400 or 429 error body, which is then discarded
Purpose
Stop runaway AI usage and keep cloud AI spend within a share of income
Where stored
guardian.json (hourly call and token counts stay in memory and reset on restart)
Retention
The last 20 pauses
Shared with
No one. An optional Claude Haiku explanation of a pause receives aggregate numbers only (see Anthropic Claude).
How to opt out
Not applicable: a safety record with no content

Workspace settings

Data
The owner’s cloud AI, learning, hotspot labels and default signal latency choices
Source
The owner, in Settings → Data & AI
Purpose
Apply those choices on this server
Where stored
workspace-settings.json, written only after a setting changes
Retention
Until changed
Shared with
No one
How to opt out
Change them in Settings → Data & AI

Billing records (only when website billing is on)

Data
Workspace billing ID, Stripe customer and subscription IDs, status, plan, billing-period usage, usage reservations and unsent meter events
Source
Stripe Checkout and verified Stripe webhooks
Purpose
Charge for included and extra AI usage
Where stored
billing.json, only when billing is enabled
Retention
The last 24 billing periods, 20 checkout attempts, 100 open reservations and 1,000 unsent meter events
Shared with
Stripe receives billing IDs, the plan, return addresses and usage amounts with event IDs and timestamps. Stripe-hosted pages collect card and contact details; Mend never receives card numbers. Webhook events, which can include customer contact details, are processed in memory and not stored.
How to opt out
Billing stays off unless the operator enables it; it is not enabled on mend.solutions

Money flow totals (owner only)

Data
Stripe balance transactions, subscriptions, invoices and payouts for the operator’s own Stripe account, reduced to totals by day, plan and month. No customer names, emails, addresses, card details, descriptions or raw Stripe IDs are kept or shown; payout IDs are shortened.
Source
Stripe, read with read-only requests and the server’s Stripe key when the owner opens Money flow, and every 6 hours while the owner’s revenue cap is on
Purpose
Show the owner income, fees, estimated AI and fixed costs, net contribution and AI funding advice, and set the revenue cap
Where stored
Not stored: the totals stay in server memory. For the revenue cap, the last 30 days’ net, its currency, test or live mode and the time it was read also stay in memory
Retention
Up to 60 seconds in memory; the 30-day net until the next read or a restart
Shared with
Only the signed-in owner sees the totals; Stripe receives the read requests
How to opt out
Not applicable: the operator’s own accounting view. It reads nothing until a Stripe key is configured

Website subscriber records (only when online checkout is on)

Data
For each website subscription: the Stripe customer and subscription IDs, the plan, test or live mode, Stripe’s subscription status, when it started, when its payment cleared, when it was last updated and ended, and whether the owner has sent the workspace login yet (and when). No names, email addresses, postal addresses or payment details.
Source
Signature-verified Stripe webhooks, each confirmed by a fresh request to Stripe before anything is kept
Purpose
Know who has paid, email each new subscriber a workspace login within 1 business day, and follow renewals and cancellations
Where stored
customers.json in the server’s data directory, written only after the first verified subscription
Retention
Up to 1,000 subscribers; an ended subscription is removed 90 days after it ends
Shared with
Only the signed-in owner, in Money flow. The owner opens each customer in the Stripe Dashboard, where Stripe keeps the contact and payment details.
How to opt out
Online checkout stays off unless the operator turns it on. Ask support@mend.solutions about the record we hold for you; it is needed while a subscription runs.

Gateway login

Data
The username and password sent with workspace, API and companion-app requests to a hosted server
Source
The person signing in
Purpose
Let only the owner reach the workspace and API
Where stored
On the mend.solutions pilot, the HTTPS proxy keeps only a bcrypt hash of the owner password in its protected configuration. It checks the login and removes it, with any cookies, before a request reaches Mend.
Retention
Until the operator changes the password
Shared with
No one
How to opt out
Not applicable: required for access

Server and proxy logs

Data
Operational messages such as startup, certificate renewal and errors. A proxy error entry can include the request method, page and headers, with login and cookie headers left out; the Mend process logs no requests.
Source
The Mend process and the HTTPS proxy on the server
Purpose
Operate and secure the service
Where stored
The server’s system log. On mend.solutions the ingress also counts each client IP address’s connections in memory, for about 60 seconds after its last connection, to limit abuse; that count is never written to disk.
Retention
The system log discards the oldest messages as it reaches its size limit
Shared with
No one
How to opt out
Not applicable

Sent to AI providers

From a Mend server, only when its operator adds a provider’s API key and cloud AI is on, and for transition diagnosis only when Mend AI is not confident. Each provider processes what it receives under its own terms and privacy policy. The improvement loop runs in Mend’s own repository on synthetic data. Mend never sends your data to train Anthropic’s or OpenAI’s models.

Anthropic Claude

Data
Layout checks: check type, severity and measurements, with placeholder IDs. Transition diagnosis: failure code, type, duration, signal latency in milliseconds and reduced before/after measurements. After a usage-guardian pause: aggregate usage numbers for an optional short explanation. Never page text, form values, element IDs, labels, URLs, screenshots, source code or review text.
Source
Layout checks run automatically when a Claude key is set and cloud AI is on; transition diagnosis only when requested (Ask Claude, or useCloud: true from automatic recovery) and Mend AI is not confident; at most 10 pause explanations a month
Purpose
Diagnose transitions Mend AI is unsure about and suggest a registered recovery, and explain a usage pause. A validated answer becomes a Mend AI correction unless learning is off
Where stored
Mend keeps only the reduced report, Claude’s short reason and, as a Mend AI correction, the action it chose. Anthropic processes requests under its own terms.
Retention
At Anthropic: as its terms and privacy pages describe
Shared with
Anthropic
How to opt out
Workspace owner: cloud AI off or no Claude key; pause explanations can be switched off. Developer: data-mend-cloud="off" and the recovery controller’s privacy option. Person: Mend.setPrivacy({ cloudAi: false }). The usage guardian also pauses cloud AI on its own.

OpenAI GPT-6 Astra (off by default)

Data
Reduced before/after measurements of a recovery, the recovery action and whether the browser verified it, sent with store: false
Source
Recovery outcomes, only when the operator sets MEND_AUDIT_ENABLED=1 with a separate key
Purpose
An independent review before a successful recovery is learned
Where stored
Mend keeps only the review result and its token counts in the report
Retention
At OpenAI: as its API data controls describe; store: false does not guarantee OpenAI keeps nothing
Shared with
OpenAI
How to opt out
Leave Astra off (the default), turn cloud AI off, or turn learning off (no review is requested)

OpenAI layout path (legacy, off by default)

Data
Layout check type, severity and measurements with placeholder IDs, sent with store: false
Source
Layout checks, only when the operator sets AI_PROVIDER=openai
Purpose
Suggest layout repairs
Where stored
Not stored by Mend
Retention
At OpenAI: as its API data controls describe
Shared with
OpenAI
How to opt out
Keep the default AI_PROVIDER=anthropic, or turn cloud AI off

Mend AI improvement loop (train → fix → iterate, in Mend’s own CI)

Data
Aggregate and per-case results (synthetic case IDs, failure codes and counts) of a benchmark on synthetic test transitions generated from a fixed seed in Mend’s source code (scripts/mend-ai-corpus.mjs), with the current Mend AI rule thresholds and their bounds. Never data from a Mend server, an app or a person
Source
A scheduled GitHub Actions job on Mend’s own repository, at most 2 Claude requests a night and none while an earlier proposal is still open
Purpose
Ask Claude to propose bounded threshold changes so Mend AI asks Claude less often or fixes more synthetic transitions, never with more wrong recoveries
Where stored
Not stored on any Mend server. An improving proposal becomes a pull request in Mend’s repository for the owner to review; nothing is merged automatically
Retention
Pull requests and job logs as GitHub keeps them; at Anthropic, as its terms and privacy pages describe
Shared with
Anthropic (Claude), with a short-lived token from workload identity federation instead of a stored key; GitHub
How to opt out
Not applicable: no personal or customer data is used

The website, the owner workspace and support email

mend.solutions and its free demo

Data
Page requests from visitors
Source
Visitors
Purpose
Explain Mend and run the free demo
Where stored
Nothing in your browser: no cookies, browser storage, analytics, or third-party scripts or fonts. The demo, including its signal latency choice, runs in page memory and sends nothing. Requests for the pages are covered by “Server and proxy logs”.
Retention
The demo clears when the page reloads
Shared with
No one. The free demo uses no AI tokens.
How to opt out
Not needed

Online checkout on Stripe (only when it is open)

Data
What you enter on Stripe’s checkout page: your email address, card or wallet (Apple Pay, Google Pay) details and the billing details Stripe asks for, plus device and browser data that Stripe collects under its own terms
Source
You, on Stripe’s hosted checkout page, when you start a website subscription
Purpose
Take the subscription payment and send the receipt
Where stored
Not stored by Mend. Stripe keeps it; Mend reads back only the IDs, plan and status listed under “Website subscriber records”. A checkout page left unpaid expires after about 30 minutes.
Retention
At Stripe: as Stripe’s privacy policy describes
Shared with
Stripe, the operator’s payment provider. Mend never receives card numbers. We use your email address only to send your workspace login and answer you.
How to opt out
Nothing is collected unless you start a subscription. The free demo and the companion app need no payment. Leaving Stripe’s page without paying ends it.

Owner workspace in the browser

Data
The dashboard’s reports, transition hotspots, settings and demo state
Source
The workspace owner
Purpose
Run the dashboard
Where stored
Page memory; no cookies or browser storage. Copy and export create files only when the owner chooses.
Retention
Until the page reloads
Shared with
Only the Mend server it came from. Its Live playground, and Ask Claude or Verify demo recovery on demo storefront transitions, can call cloud AI; the usage guardian’s demo cut-off stops that. Ask Claude on the dashboard’s own transitions is ordinary owner usage that the guardian still checks.
How to opt out
Settings → Data & AI: the demo cut-off switch, or cloud AI off

Google Fonts (owner workspace only)

Data
The IP address and browser details of whoever opens the owner workspace, as part of loading fonts
Source
Opening the owner workspace
Purpose
Load the DM Sans and Manrope fonts
Where stored
Google’s servers, under Google’s terms
Retention
Set by Google
Shared with
Google (fonts.googleapis.com and fonts.gstatic.com)
How to opt out
Block those domains; the workspace falls back to system fonts. The public website loads no third-party fonts.

Email to support

Data
Your email address and whatever you include
Source
You, when you email support@mend.solutions
Purpose
Answer you
Where stored
Our support mailbox, hosted by Microsoft 365 through GoDaddy
Retention
Only as long as needed to help you; deleted sooner if you ask
Shared with
Microsoft 365, as the mailbox provider
How to opt out
Leave out passwords, API keys and unredacted diagnostic exports, and ask us to delete your messages

The Mend companion app

App Store privacy label: Data Not Collected. The app sends no analytics or usage data and calls no AI provider. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots.

Server connection

Data
The server address, gateway username and password you enter, and an optional GitHub repository link
Source
You, in the app
Purpose
Read and show that server’s status, monthly usage, reports and transition hotspots
Where stored
The server address and login in this device’s Keychain (this device only, while unlocked); the GitHub link in the app’s preferences on the device; reports and hotspots in memory only. Copy puts a hotspot’s code snippet on this device’s clipboard only when you choose it.
Retention
Until you choose Disconnect and clear saved account. Keychain items can outlive the app, so clear them before deleting it.
Shared with
Only the server you enter, through HTTPS GET requests with your gateway login. Nothing goes to AI providers or analytics.
How to opt out
Use Try it and the sample reports without connecting, or choose Disconnect and clear saved account

App analytics from Apple (only if you opt in)

Data
Aggregated usage statistics and crash reports
Source
Apple, only if you chose in your device settings to share analytics with app developers
Purpose
Fix and improve the app
Where stored
Apple’s developer tools
Retention
Set by Apple
Shared with
No one
How to opt out
Turn off sharing with app developers in your device’s analytics settings

Your choices, opting out and deleting data

Every switch only reduces data use. A person can turn cloud AI or learning off for themselves but never back on when the app turned it off (the SDK enforces this), and no app or request can turn back on what the workspace owner turned off (the Mend server enforces this).

Deleting data

Email to support

If you email support@mend.solutions, we receive your email address and whatever you include, and we use them only to respond to you. Our support mailbox is hosted by Microsoft 365, provided through GoDaddy. Please do not send passwords, API keys, or unredacted diagnostic exports. We keep support correspondence only as long as we need it to help you, and delete it sooner if you ask.

Sharing

We do not sell or rent personal information and do not share it for advertising. Information leaves a Mend server only as described above: to an AI provider that the operator has turned on, or to Stripe when online checkout or workspace billing is on. For the mend.solutions pilot and our support mailbox, the service providers we use—Anthropic and OpenAI when turned on, Stripe for online checkout and billing when they are on, and Microsoft 365 for support email—process information on our behalf under contractual terms that require them to protect it at least as well as this policy describes. Separately, opening the owner workspace loads fonts from Google, which receives the visitor’s IP address and browser details under Google’s own terms.

Children

Mend is a tool for software developers. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information, contact support@mend.solutions and we will delete it.

Security

The app connects to servers only over HTTPS with a valid certificate and keeps credentials in the Keychain. Our server requires the owner login for every non-public page and API route except two that cannot carry it: the checkout link, which only redirects, and Stripe’s notifications, which Mend accepts only with a valid Stripe signature. AI and Stripe keys stay on the server. No system is perfectly secure; please report any problem to support@mend.solutions.

Changes to this policy

If our practices change, we will update this page and its effective date before the change takes effect, and summarize significant changes at the top of this page.

Contact

Akira Patafio, individual developer · support@mend.solutions

For more technical detail about the pilot’s AI use and limits, read the AI and data disclosure.