On this page
Privacy Policy
This policy explains what information Mend handles and why. Mend is made by Akira Patafio, an individual developer (“we” or “us”). It covers:
- the free Mend companion app for Mac, iPhone, and iPad (“the app”);
- this website, mend.solutions; and
- the Mend server software and browser SDK, including the pilot Mend service that we operate.
In short: the app sends no analytics or usage data to us and contains no advertising or tracking. This website sets no cookies and runs no analytics. A Mend server stores reduced, mostly numeric transition reports, and its Mend AI learns from verified outcomes and Claude’s checked corrections. When its operator turns cloud AI on, the server uses Anthropic (Claude) for layout checks and for transitions Mend AI is unsure about, and OpenAI only if the operator also enables that; those providers process what they receive under their own terms. Workspace owners and developers can each turn cloud AI and learning off, and an app that embeds the Mend SDK can offer the same switches to the people using it. When online checkout is open, Stripe handles payment and Mend keeps only subscription IDs, plan and status.
The Mend app
App Store privacy label: Data Not Collected. The app sends no analytics, usage data or diagnostics, calls no AI provider, and contains no tracking. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots. The sections below about servers, the SDK and AI describe software that runs elsewhere, not in the app.
No analytics or tracking
The app sends no analytics or usage data to us. It contains no analytics, advertising, crash-reporting, or tracking SDKs, does not track you across other companies’ apps or websites, and does not require an account with us. It has no in-app purchases. It contacts only the Mend server you enter; if that is the mend.solutions pilot we operate, we receive those requests as described below.
Offline features
The Try it tab runs a fixed sample entirely on your device and makes no network requests. Explore sample reports in the Reports tab shows example reports, example transition hotspots and sample server status that are bundled inside the app; loading them uses no network connection. They were produced by a Mend server from example transitions and contain no information about you.
Connecting to a server
The app contacts a server only after you enter its address and choose Connect and save. It then connects over HTTPS only to that address, sends the gateway username and password you entered so the server can authenticate you, and reads the server’s status, monthly usage counters, saved transition reports, and transition hotspots. It does not follow redirects to another address, and it turns off cookie, cache, and credential storage for these requests. The operator of that server—you, your organization, or us for the mend.solutions pilot—receives these requests along with your device’s IP address, as with any internet connection.
Stored on your device
After a successful connection, the app saves the server address, gateway username, and gateway password in this device’s Keychain, set to be available only on this device while it is unlocked. If you save a GitHub repository link, the app stores that link in its own preferences (UserDefaults) on the device. The app does not access the repository; Open GitHub passes the link to your browser. Reports and hotspots loaded from a server are kept in memory while the app is running and are not saved by the app. Copy snippet puts a hotspot’s code snippet on this device’s clipboard only when you choose it.
Apple
If you have chosen in your device settings to share analytics or crash data with app developers, Apple may provide us with aggregated usage statistics and crash reports. We use them only to fix and improve the app. Apple’s own handling of this data is described in Apple’s privacy policy.
This website
mend.solutions is a set of static pages. It sets no cookies, uses no browser storage, and loads no analytics, advertising, third-party scripts, fonts, or embedded content. Its content security policy prevents the pages from opening network connections after they load. Apart from the owner workspace, the only link the Mend server answers is the checkout link in the plan descriptions: it asks the server for a Stripe checkout page when online checkout is open, and otherwise only sends you back. It sets no cookies, and Mend writes nothing about it to disk; to limit abuse it counts these requests in memory for 10 minutes, without your IP address, and keeps only totals of turned-away requests until the server restarts.
The interactive demo runs entirely in your browser with fixed local actions. Its observations, and the signal latency you choose for it, stay in the page’s memory and are cleared when you refresh or leave the page. It makes no network requests and does not call an AI provider.
The site has no forms. If you use an email link, your email app sends the message only when you choose to send it.
Server logs
We serve https://mend.solutions from our own Raspberry Pi: HAProxy passes each encrypted connection to Caddy, which serves the pages. Their configuration does not record an entry for each visit: HTTP access logging and connection logging are not enabled, and the Mend server process does not log requests. To limit abuse, HAProxy counts each IP address’s open and recent connections in memory and drops the address about 60 seconds after its last connection; this count is never written to disk. HAProxy passes connections on without the visitor’s IP address, so Caddy and Mend see only a local address. Like most server software, these programs write operational messages—such as startup, certificate renewal, and errors—to the server’s system log. An error entry can include the request method, the requested page and request headers such as the browser’s user agent, but not your IP address; Caddy leaves login and cookie headers out of these entries by default. We use these messages only to operate and secure the service, and the system log discards the oldest messages automatically as it reaches its size limit.
Plain HTTP requests
Always use https://mend.solutions. An unencrypted http:// request for mend.solutions or www.mend.solutions that arrives from the internet (port 80) is answered by HAProxy with a permanent redirect to https://mend.solutions; it is not logged and never reaches Mend. Other plain-HTTP requests reach a separate network-onboarding service that runs on the same device: requests for other names arrive there through HAProxy with this device's address, and requests from the local network arrive directly, where that service can record the requesting IP address for network security. We do not use those records for Mend.
Owner workspace and links
The workspace at /workspace is not a public service. It requires a login issued by us; there is no public sign-up. When online checkout is open, someone who buys a plan receives their workspace login from us by email. Unlike the public pages, the workspace loads its fonts from Google Fonts, so Google receives the IP address and browser details of whoever opens it. Links to other sites, such as Apple, Anthropic, and OpenAI, lead to services governed by their own privacy policies.
The Mend service
Mend’s server software runs either on a developer’s own computer or on a server we operate for the pilot. Whoever operates a server decides how its data is used and kept; if you use a server run by you or your organization, its operator is responsible for it. This section describes what the software does and how we handle data on the mend.solutions pilot service, where we are the operator. Access to a server’s workspace and API requires the operator’s gateway login. Each server has a single workspace; there are no separate customer accounts.
In apps that use the Mend SDK
Developers add the Mend SDK to their own web apps. In the browser of a person using such an app, it measures only the screen changes and elements the developer marks, keeps its observations in the page’s memory, and sends layout findings only to the app’s own server, and only if the developer sets that up and cloud AI is on. If the person picks a signal latency or turns cloud AI or learning off, that choice is saved in that site’s browser storage, only after they choose. This is the app’s site, not mend.solutions.
What a Mend server receives and stores
- Received, then discarded. An app’s backend or the workspace can send complete screen-change records, including labels, element identifiers, event text and positions. The server reduces each one to fixed categories and numbers and discards the rest before anything is stored or sent to AI, except a failed transition’s developer source label and transition name, which it checks again and keeps for transition hotspots unless they are turned off.
- Transition reports. When an app that integrates the Mend SDK reports a failed screen transition, the server keeps a reduced report: a fixed failure category, the transition type, timing numbers including the signal latency in effect, numeric or categorical measurements of the expected screen (such as size, visibility, and opacity), the diagnosis, and the time. The expected screen element’s identifier is stored only as a one-way hash; because the hash is unsalted, someone who can guess an identifier could confirm it. Reports do not contain page text, form values, screenshots, URLs, or source code. For transition hotspots, a report can also keep the developer’s own source label and transition name from the app’s markup (a file path and line such as src/cart/CartButton.tsx:42 and a name such as “Open cart”), after the server checks that they contain no URL, absolute path, email address or long number; they are never sent to AI, and the workspace owner or the developer can turn them off. If the app registered a fallback screen, the report keeps a one-way hash of that screen’s element identifier. A report is marked when cloud AI or learning was off, or when it came from the workspace demo; a report made while cloud AI was off is not sent to cloud AI later.
- Recovery results. When an app checks a recovery, the server adds whether it succeeded, when it was recorded, a one-way hash of the browser observation, and the result of any independent AI review.
- Visual layout checks. Measurements of supported layout problems (problem type, severity, numeric measurements, and identifiers) are processed to suggest a repair. The server does not store them.
- Review summaries. The workspace owner can type summaries of App Store reviews, with an optional star rating and review ID. Owners are asked to leave out reviewer names and other personal information. Summaries stay on the server and are never sent to AI providers.
- Usage counters and the usage guardian. Counts of AI requests and tokens for the current month, and the usage guardian’s settings (including the optional revenue cap), current pause and last 20 pauses.
- Mend AI routing counts. For each month, how many transitions were diagnosed and whether an escalation rule, Mend AI, Claude or local rules handled them, Claude and Astra token totals, and verified fixes. Counts only.
- Workspace settings. The owner’s choices for cloud AI, learning, hotspot labels, and the default signal latency.
- Website subscribers. Only when online checkout is on: Stripe customer and subscription IDs, plan, status, payment time and onboarding status for each subscription bought on this website (see Online checkout on this website).
Mend AI learning memory
Each server runs Mend AI, a small outcome model. It keeps counts of browser-verified successes and failures for each recovery action (train) and counts of which action Claude chose when Mend AI was unsure and Claude’s answer passed Mend’s checks (fix), each keyed by a hash of the measurement pattern. Mend AI answers on its own once its verified-outcome counts make it confident and asks Claude about a transition only when they do not; correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Only action labels and counts are kept, never Claude’s text, and a correction never counts as a verified success. The memory stays on that server and is not shared. Mend AI is not a language model, and Mend never sends your data to train Anthropic’s or OpenAI’s models. Mend’s rules for Mend AI are improved by an automated job that uses only synthetic test transitions from Mend’s source code (iterate), never data from any server or app, and every change is reviewed before it ships. The workspace owner and developers can each turn learning off, an app that embeds the Mend SDK can offer that switch to the people using it, and the owner can delete learning data. Learning off stops the counters; the reports themselves are still kept until the owner deletes them.
How long data is kept
- the 500 most recent transition reports (older reports are replaced; fewer if the file would grow past 3 MB);
- up to 2,048 learned measurement patterns, for verified outcomes and for Claude corrections (today at most 160 distinct patterns can occur; the oldest is removed when the limit is reached);
- Mend AI routing counts for the newest 13 months;
- the 100 most recent review summaries;
- the last 20 usage-guardian pauses, and the workspace settings until they are changed; and
- AI usage counters for the current month (replaced when a new month starts); and
- website subscriber records, only when online checkout is on: up to 1,000, each removed 90 days after its subscription ends.
These records have no time-based expiry: they remain on the server’s disk until they are replaced as described above or removed by the operator. The workspace offers Delete learning data, which removes the learned counters, or the counters and every transition report; it does not yet offer per-item deletion. Backups, and records held by AI providers or Stripe, follow their own schedules.
Billing
Workspace usage billing, which meters a workspace’s AI usage to Stripe, is turned off by default and is not enabled on the mend.solutions service. If an operator enables it, Stripe-hosted Checkout collects payment details directly—Mend never receives card numbers—and Mend sends Stripe its workspace, customer, and plan identifiers and numeric usage amounts. Stripe’s notifications to Mend, which can include customer contact details, are processed in memory and not stored. Billing records are then kept on the server within the fixed limits described in the AI and data disclosure.
Online checkout on this website
When online checkout is open, a paid plan can be bought on Stripe’s hosted checkout page, which can offer Apple Pay, Google Pay and cards. Stripe collects your email address, your card or wallet details, the billing details it asks for, and device and browser data, under the Stripe Privacy Policy; Mend never receives card numbers. A checkout page left unpaid expires after about 30 minutes, and Mend keeps nothing about it. After a payment, Stripe sends Mend a signed notification; Mend checks it with Stripe and keeps only the subscription’s Stripe customer and subscription IDs, plan, test or live mode, status, start, payment-cleared, update and end times, and whether we have sent your workspace login. We look up your email address in our Stripe account to send that login within 1 business day and to answer you; the Mend server does not store it. The server keeps at most 1,000 subscriber records and removes each one 90 days after its subscription ends. Stripe keeps its own billing records under its terms. The companion app is free, has no in-app purchases and has no part in this.
AI providers
A Mend server works without cloud AI: local rules and Mend AI, its on-server learning memory, provide diagnoses. Cloud AI is used only when the server’s operator adds a provider’s API key and leaves cloud AI turned on.
- Anthropic Claude. With a Claude key configured, the server can send Anthropic the failure category, transition type, timing numbers, and numeric and categorical visibility measurements of a transition report when a cloud diagnosis is requested and Mend AI is not confident. Claude’s checked answer is kept as a Mend AI correction (the chosen action only) unless learning is off. For visual layout checks, which run automatically while cloud AI is on, it sends the problem type, severity, and numeric measurements, with identifiers replaced by placeholders. If the usage guardian pauses cloud AI, it can ask Claude for one short explanation from aggregate usage numbers only, at most 10 times a month.
- Mend AI improvement job. In Mend’s own source code repository, a scheduled job sends Anthropic the aggregate and per-case results of a benchmark on synthetic test transitions (synthetic case IDs, failure codes and counts) and the current rule thresholds, signed in with a short-lived token instead of a stored key, and opens a proposed change for review. It never uses data from any Mend server, app or person.
- OpenAI. The independent GPT-6 Astra review is off by default; it runs only when the operator adds a separate key and turns it on. It receives a recovery’s before-and-after measurements, the recovery action, and whether the browser verified it. An operator can also choose OpenAI instead of Claude for visual layout checks, which sends the same reduced data. Mend asks OpenAI not to store these requests (
store: false); this does not guarantee that OpenAI retains nothing.
Mend’s requests to AI providers do not include page text, form values, screenshots, repository code, URLs, element identifiers, source labels or transition names, review summaries, or your gateway login. API keys stay on the server. For the mend.solutions pilot, any AI processing uses our provider accounts. A developer who connects the SDK to a different diagnosis backend controls what that backend receives.
Under the providers’ terms
Anthropic and OpenAI process these requests under their own commercial or API terms and data controls, not this policy; those terms govern how long they keep the data and how they may use it. Anthropic’s Commercial Terms state that Anthropic may not train models on customer content from its services, and its privacy center explains how long API data is kept and the exceptions. OpenAI’s API data controls page states that API data is not used to train OpenAI’s models unless the customer opts in, and describes its own retention. Read the providers’ pages for their current terms:
- Anthropic Commercial Terms
- Anthropic: how long API data is kept
- Anthropic Privacy Policy
- OpenAI API data controls
- OpenAI Privacy Policy
Usage guardian and the free demo
A fixed set of rules checks every cloud AI request before it is sent, except the optional pause explanation described above, which is sent only after a pause and counts against the monthly Claude allowance rather than the hourly limits or website billing. It pauses cloud AI when requests or tokens in the last hour pass their limits, when a monthly allowance or budget is being used up much faster than the month is passing, after repeated provider failures, when a provider reports a credit or spend-limit problem, or, if the owner turns the revenue cap on, when this month’s estimated AI cost reaches a share of recent Stripe income. The decision never depends on an AI model. Local diagnosis continues while cloud AI is paused. The free demo on this website, the free demo in the workspace, and the app’s Try it tab use no AI tokens; only the private workspace playground can, and the guardian can cut it off.
What data Mend uses
This is every kind of data Mend’s software, this website, the app and our support mailbox handle, with where it comes from, why, where it is kept, for how long, who else receives it, and how to opt out. The same list, with live counts, appears in the workspace under Settings → Data & AI.
In an app that uses the Mend SDK
This stays in the browser of a person using an app whose developer added the Mend SDK. The mend.solutions website does not monitor its visitors; its demo watches only its own sample preview.
Screen-change observations
- Data
- For each control the developer marks: the transition name, from/to and group labels, the trigger and expected-screen element IDs, start and end times, duration, the signal latency in effect and where it came from, size, position, opacity and visibility before and after, up to 24 timeline steps, standard JavaScript error names (never messages) and an optional developer source label. For transition hotspots,
record.hotspotholds a checked copy of the developer’s source label and transition name (a repo-relative path and line such assrc/cart/CartButton.tsx:42and a plain name), or nothing when a label fails the checks. With a registered redirect, the recovery controller adds the fallback element ID (fallbackTargetId) to the record it passes to diagnosis - Source
- The Mend SDK in the person’s browser, only for elements the app’s developer marks
- Purpose
- Notice when a screen change is slow or stuck, measured against the signal latency
- Where stored
- Page memory only: 60 records by default, at most 200. Other scripts on the same page can read them through the
mend:transitionevent andwindow.Mend, and failed records are written to the browser console. - Retention
- Until the page is closed or reloaded
- Shared with
- Nobody, by the SDK itself. With automatic recovery, the app’s own code sends a failed record to the developer’s backend, which can pass it to a Mend server (see “Records as received”).
- How to opt out
- Developer: remove the
data-mend-transitionanddata-mend-motionattributes, or callMend.stop().data-mend-hotspots="off"on the page’s<html>or<body>, the connect tag, or any marked element or its container, orhotspots: falsefor the monitor or recovery controller, leavesrecord.hotspotempty; the recovery controller removes it before each diagnosis request whenever any of these is off. A person can turn cloud AI and learning off where the app offers it, but cannot switch off observation inside an app.
Layout findings
- Data
- For elements marked
data-mend: the element ID, check type, severity and measurements (widths, contrast ratio, opacity or image size) - Source
- The SDK’s layout checks in the browser
- Purpose
- Choose a supported, reversible repair
- Where stored
- Page memory: the current findings and the last 100 repairs. Other scripts on the same page can read them through the
mend:visualevent andwindow.Mend.visual. - Retention
- Until the page is closed or reloaded
- Shared with
- Only if the developer sets
data-mend-endpoint: up to 32 findings per request go to that same-origin address on the app’s own server. Never sent while cloud AI is off for the app or the person. - How to opt out
- Developer: leave out
data-mend-endpointor setdata-mend-cloud="off". Person: the app’s privacy controls orMend.setPrivacy({ cloudAi: false }).
A person’s own choices
- Data
- The signal latency the person picked (Fast, Balanced, Patient or a number of milliseconds) and which of the cloud AI and learning switches they turned off
- Source
- The person, through controls the developer mounts (
Mend.mountLatencyPicker,Mend.mountPrivacyControls) or the app’s own code - Purpose
- Apply and remember the choice on that site
- Where stored
- That site’s browser storage, keys
mend:signal-latency:v1andmend:privacy:v1, written only after the person makes a choice. If storage is blocked, the choice lasts for the page only. - Retention
- Until the person resets the choice (the stored entry is removed) or clears the site’s data
- Shared with
- Switches that are off travel as a
privacyflag with the SDK’s layout requests, and with diagnose and outcome calls where the app’s recovery code and backend pass them on; the latency in effect is recorded in each observation. - How to opt out
- Make no choice, reset to the app default, or clear the site’s data. Developer:
data-mend-user-latency="false"ignores any stored latency.
On a Mend server
Whoever operates a Mend server controls this data: we do for the mend.solutions pilot, and any other server is run by its own operator. Files sit in the server’s data directory with owner-only permissions.
Records as received, before reduction
- Data
- Complete screen-change records and layout findings as an app’s backend or the owner workspace sends them, including labels, element IDs, source labels, event text and positions, the
hotspotlabels and any fallback element ID, plus anyprivacyflags and the workspace demo marker - Source
- Requests to
/api/analyze,/api/transitions/diagnoseand/api/transitions/outcome - Purpose
- Reduce each request to fixed codes and numbers before anything is kept or sent to AI
- Where stored
- Not stored, apart from what transition reports keep. Labels, element IDs (apart from the hashes in transition reports), event text, source labels and positions are discarded during reduction. The one exception is a failed transition’s
hotspotsource label and transition name, kept after the server checks them again unless hotspot labels are off. Layout findings are answered and discarded. - Retention
- Only while the request is handled
- Shared with
- No one in this form
- How to opt out
- Developers can send fewer fields; nothing beyond the reduced form is kept
Transition reports
- Data
- Failure code and type, duration, the signal latency in effect (milliseconds, source and preset), before/after size, opacity and visibility measurements, the expected element’s ID stored only as a one-way hash (an unsalted SHA-256, so anyone who can guess an ID such as “account-panel” can confirm it) and, with a registered redirect, the same kind of hash of the fallback element’s ID, the developer’s source label and transition name for transition hotspots unless hotspot labels are off (a file path and line such as
src/cart/CartButton.tsx:42and a name such as “Open cart”, never the code itself), the diagnosis and its reason (Claude may have written it), how Mend AI routed it (an escalation rule, Mend AI itself, Claude or local rules, and why), a marker when Claude’s answer became a Mend AI correction with Mend AI’s earlier best guess, any notice, the browser verification result with a hash of that observation, the Astra review result and its token counts, and markers when cloud AI or learning was off or the request came from the workspace demo - Source
- Diagnose and outcome requests from the owner workspace or an app’s backend
- Purpose
- Show reports to the developer and suggest a recovery
- Where stored
transition-memory.jsonin the server’s data directory- Retention
- The newest 500 reports (fewer only if the file would pass 3 MB), with no time-based expiry, until the workspace owner deletes them
- Shared with
- The reduced measurements (not the hashes, the hotspot labels, the latency source, the routing or the markers) go to Anthropic Claude when a cloud diagnosis is requested and Mend AI is not confident, and to OpenAI Astra when the operator turns reviews on, unless cloud AI was off when the report was made: that marker keeps it from cloud AI later. Anyone with the gateway login can read reports and transition hotspots in the workspace or the companion app.
- How to opt out
- Workspace owner: Delete learning data → counters and every report; turn hotspot labels off in Settings → Data & AI, which also deletes the labels already stored. Developer: do not send failed records to a Mend server, or add
data-mend-hotspots="off"to keep the hotspot labels out (a registered redirect still sends its fallback ID). Learning off still keeps the report and its outcome, marked, for the developer, but never learns from it.
Mend AI learning (verified outcomes and Claude corrections)
- Data
- Per measurement pattern (a hash of the failure code, the transition type and four yes/no facts such as whether the screen was hidden) and recovery action: how many browser-verified recoveries succeeded and failed (train), and how many times Claude’s validated diagnosis chose that action while Mend AI was unsure (fix). Only the action label is counted, never Claude’s text
- Source
- Recovery outcomes: a success counts only when the browser verified it and, while Astra review is on, Astra agreed. Corrections: Claude diagnoses that passed Mend’s checks; they never count as verified successes.
- Purpose
- Let Mend AI, the small model on this server, answer on its own once verified outcomes make it confident and ask Claude about a transition only when they do not. Correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Mend never uses it to train Anthropic or OpenAI models.
- Where stored
transition-memory.json- Retention
- Up to 2,048 patterns (at most 160 can occur with today’s pattern key) of outcomes and of corrections, with no time-based expiry, until the workspace owner deletes learning data
- Shared with
- No one; never sent to AI providers
- How to opt out
- Workspace owner: turn learning off (no outcomes or corrections are recorded), turn cloud AI off (Claude is never asked, so nothing is corrected) or delete learning data. Developer: pass
{ learning: false }(or a person’s choice) as the recovery controller’sprivacyoption and have the app’s backend forwardprivacywith diagnose and outcome calls. A person’sMend.setPrivacy({ learning: false })and the connect tag’sdata-mend-learning="off"take effect only through that path; on their own they send nothing that is learned from.
Transition hotspots (owner only)
- Data
- Hotspots ranked from stored reports: per developer source label, transition name and type, failure counts, timing medians, verified recovery counts, and a recommendation (resolve, redirect or review) with steps and a code snippet to copy
- Source
- Computed by rules from stored transition reports and outcome counters on each
GET /api/hotspots; no AI is used - Purpose
- Show the developer where transitions fail in their code and whether Mend should resolve in place, redirect to a registered fallback or leave it for review
- Where stored
- Not stored: computed on each request
- Retention
- Only while the request is handled
- Shared with
- Anyone with the gateway login, in the workspace or the companion app; never sent to AI providers
- How to opt out
- Workspace owner: hotspot labels off groups hotspots by transition type only. Developer:
data-mend-hotspots="off".
Monthly AI usage counters
- Data
- Claude and Astra request and token counts for the current month
- Source
- Each cloud AI request
- Purpose
- Enforce the monthly request limits and the usage guardian
- Where stored
usage.jsonandastra-usage.json- Retention
- Replaced when a new month starts
- Shared with
- No one
- How to opt out
- Not needed: counts only, with no content
Mend AI routing counts
- Data
- Per month: transitions diagnosed; how many an escalation rule, Mend AI, Claude or local rules decided; why Mend AI asked Claude (unsure, a failed verification or not yet learned); Claude calls, answers, blocked calls and token totals; Astra reviews and tokens; correction counts and browser-verified outcomes by engine
- Source
- Each diagnosis and recorded outcome on this server, except workspace demo traffic
- Purpose
- Show the owner how often Mend AI handles transitions without Claude, Claude calls per 100 transitions and the estimated AI cost per verified fix
- Where stored
mend-ai-routing.json- Retention
- The newest 13 months
- Shared with
- No one; never sent to AI providers
- How to opt out
- Not needed: counts only, with no content
App Store review summaries
- Data
- Summaries the workspace owner types, with an optional star rating and review ID, and links to verified reports
- Source
- The owner, in Settings → Learn from App Store feedback
- Purpose
- Investigate reported problems
- Where stored
review-feedback.json- Retention
- The newest 100 summaries
- Shared with
- No one; never sent to AI providers
- How to opt out
- Do not add summaries; leave out reviewer names and other personal information
Usage guardian record
- Data
- Guardian settings (including the optional revenue cap: on or off, the share of income and the buffer), the current pause, the last 20 pauses with the figures that triggered them (for a revenue-cap pause, this month’s estimated AI cost and the cap), consecutive provider failure counts and this month’s explanation count
- Source
- The usage guardian and the owner’s settings. Whether a provider error was a credit or spend-limit error is read from at most 4 KB of an HTTP 400 or 429 error body, which is then discarded
- Purpose
- Stop runaway AI usage and keep cloud AI spend within a share of income
- Where stored
guardian.json(hourly call and token counts stay in memory and reset on restart)- Retention
- The last 20 pauses
- Shared with
- No one. An optional Claude Haiku explanation of a pause receives aggregate numbers only (see Anthropic Claude).
- How to opt out
- Not applicable: a safety record with no content
Workspace settings
- Data
- The owner’s cloud AI, learning, hotspot labels and default signal latency choices
- Source
- The owner, in Settings → Data & AI
- Purpose
- Apply those choices on this server
- Where stored
workspace-settings.json, written only after a setting changes- Retention
- Until changed
- Shared with
- No one
- How to opt out
- Change them in Settings → Data & AI
Billing records (only when website billing is on)
- Data
- Workspace billing ID, Stripe customer and subscription IDs, status, plan, billing-period usage, usage reservations and unsent meter events
- Source
- Stripe Checkout and verified Stripe webhooks
- Purpose
- Charge for included and extra AI usage
- Where stored
billing.json, only when billing is enabled- Retention
- The last 24 billing periods, 20 checkout attempts, 100 open reservations and 1,000 unsent meter events
- Shared with
- Stripe receives billing IDs, the plan, return addresses and usage amounts with event IDs and timestamps. Stripe-hosted pages collect card and contact details; Mend never receives card numbers. Webhook events, which can include customer contact details, are processed in memory and not stored.
- How to opt out
- Billing stays off unless the operator enables it; it is not enabled on mend.solutions
Money flow totals (owner only)
- Data
- Stripe balance transactions, subscriptions, invoices and payouts for the operator’s own Stripe account, reduced to totals by day, plan and month. No customer names, emails, addresses, card details, descriptions or raw Stripe IDs are kept or shown; payout IDs are shortened.
- Source
- Stripe, read with read-only requests and the server’s Stripe key when the owner opens Money flow, and every 6 hours while the owner’s revenue cap is on
- Purpose
- Show the owner income, fees, estimated AI and fixed costs, net contribution and AI funding advice, and set the revenue cap
- Where stored
- Not stored: the totals stay in server memory. For the revenue cap, the last 30 days’ net, its currency, test or live mode and the time it was read also stay in memory
- Retention
- Up to 60 seconds in memory; the 30-day net until the next read or a restart
- Shared with
- Only the signed-in owner sees the totals; Stripe receives the read requests
- How to opt out
- Not applicable: the operator’s own accounting view. It reads nothing until a Stripe key is configured
Website subscriber records (only when online checkout is on)
- Data
- For each website subscription: the Stripe customer and subscription IDs, the plan, test or live mode, Stripe’s subscription status, when it started, when its payment cleared, when it was last updated and ended, and whether the owner has sent the workspace login yet (and when). No names, email addresses, postal addresses or payment details.
- Source
- Signature-verified Stripe webhooks, each confirmed by a fresh request to Stripe before anything is kept
- Purpose
- Know who has paid, email each new subscriber a workspace login within 1 business day, and follow renewals and cancellations
- Where stored
customers.jsonin the server’s data directory, written only after the first verified subscription- Retention
- Up to 1,000 subscribers; an ended subscription is removed 90 days after it ends
- Shared with
- Only the signed-in owner, in Money flow. The owner opens each customer in the Stripe Dashboard, where Stripe keeps the contact and payment details.
- How to opt out
- Online checkout stays off unless the operator turns it on. Ask support@mend.solutions about the record we hold for you; it is needed while a subscription runs.
Gateway login
- Data
- The username and password sent with workspace, API and companion-app requests to a hosted server
- Source
- The person signing in
- Purpose
- Let only the owner reach the workspace and API
- Where stored
- On the mend.solutions pilot, the HTTPS proxy keeps only a bcrypt hash of the owner password in its protected configuration. It checks the login and removes it, with any cookies, before a request reaches Mend.
- Retention
- Until the operator changes the password
- Shared with
- No one
- How to opt out
- Not applicable: required for access
Server and proxy logs
- Data
- Operational messages such as startup, certificate renewal and errors. A proxy error entry can include the request method, page and headers, with login and cookie headers left out; the Mend process logs no requests.
- Source
- The Mend process and the HTTPS proxy on the server
- Purpose
- Operate and secure the service
- Where stored
- The server’s system log. On mend.solutions the ingress also counts each client IP address’s connections in memory, for about 60 seconds after its last connection, to limit abuse; that count is never written to disk.
- Retention
- The system log discards the oldest messages as it reaches its size limit
- Shared with
- No one
- How to opt out
- Not applicable
Sent to AI providers
From a Mend server, only when its operator adds a provider’s API key and cloud AI is on, and for transition diagnosis only when Mend AI is not confident. Each provider processes what it receives under its own terms and privacy policy. The improvement loop runs in Mend’s own repository on synthetic data. Mend never sends your data to train Anthropic’s or OpenAI’s models.
Anthropic Claude
- Data
- Layout checks: check type, severity and measurements, with placeholder IDs. Transition diagnosis: failure code, type, duration, signal latency in milliseconds and reduced before/after measurements. After a usage-guardian pause: aggregate usage numbers for an optional short explanation. Never page text, form values, element IDs, labels, URLs, screenshots, source code or review text.
- Source
- Layout checks run automatically when a Claude key is set and cloud AI is on; transition diagnosis only when requested (Ask Claude, or
useCloud: truefrom automatic recovery) and Mend AI is not confident; at most 10 pause explanations a month - Purpose
- Diagnose transitions Mend AI is unsure about and suggest a registered recovery, and explain a usage pause. A validated answer becomes a Mend AI correction unless learning is off
- Where stored
- Mend keeps only the reduced report, Claude’s short reason and, as a Mend AI correction, the action it chose. Anthropic processes requests under its own terms.
- Retention
- At Anthropic: as its terms and privacy pages describe
- Shared with
- Anthropic
- How to opt out
- Workspace owner: cloud AI off or no Claude key; pause explanations can be switched off. Developer:
data-mend-cloud="off"and the recovery controller’sprivacyoption. Person:Mend.setPrivacy({ cloudAi: false }). The usage guardian also pauses cloud AI on its own.
OpenAI GPT-6 Astra (off by default)
- Data
- Reduced before/after measurements of a recovery, the recovery action and whether the browser verified it, sent with
store: false - Source
- Recovery outcomes, only when the operator sets
MEND_AUDIT_ENABLED=1with a separate key - Purpose
- An independent review before a successful recovery is learned
- Where stored
- Mend keeps only the review result and its token counts in the report
- Retention
- At OpenAI: as its API data controls describe;
store: falsedoes not guarantee OpenAI keeps nothing - Shared with
- OpenAI
- How to opt out
- Leave Astra off (the default), turn cloud AI off, or turn learning off (no review is requested)
OpenAI layout path (legacy, off by default)
- Data
- Layout check type, severity and measurements with placeholder IDs, sent with
store: false - Source
- Layout checks, only when the operator sets
AI_PROVIDER=openai - Purpose
- Suggest layout repairs
- Where stored
- Not stored by Mend
- Retention
- At OpenAI: as its API data controls describe
- Shared with
- OpenAI
- How to opt out
- Keep the default
AI_PROVIDER=anthropic, or turn cloud AI off
Mend AI improvement loop (train → fix → iterate, in Mend’s own CI)
- Data
- Aggregate and per-case results (synthetic case IDs, failure codes and counts) of a benchmark on synthetic test transitions generated from a fixed seed in Mend’s source code (
scripts/mend-ai-corpus.mjs), with the current Mend AI rule thresholds and their bounds. Never data from a Mend server, an app or a person - Source
- A scheduled GitHub Actions job on Mend’s own repository, at most 2 Claude requests a night and none while an earlier proposal is still open
- Purpose
- Ask Claude to propose bounded threshold changes so Mend AI asks Claude less often or fixes more synthetic transitions, never with more wrong recoveries
- Where stored
- Not stored on any Mend server. An improving proposal becomes a pull request in Mend’s repository for the owner to review; nothing is merged automatically
- Retention
- Pull requests and job logs as GitHub keeps them; at Anthropic, as its terms and privacy pages describe
- Shared with
- Anthropic (Claude), with a short-lived token from workload identity federation instead of a stored key; GitHub
- How to opt out
- Not applicable: no personal or customer data is used
The website, the owner workspace and support email
mend.solutions and its free demo
- Data
- Page requests from visitors
- Source
- Visitors
- Purpose
- Explain Mend and run the free demo
- Where stored
- Nothing in your browser: no cookies, browser storage, analytics, or third-party scripts or fonts. The demo, including its signal latency choice, runs in page memory and sends nothing. Requests for the pages are covered by “Server and proxy logs”.
- Retention
- The demo clears when the page reloads
- Shared with
- No one. The free demo uses no AI tokens.
- How to opt out
- Not needed
Online checkout on Stripe (only when it is open)
- Data
- What you enter on Stripe’s checkout page: your email address, card or wallet (Apple Pay, Google Pay) details and the billing details Stripe asks for, plus device and browser data that Stripe collects under its own terms
- Source
- You, on Stripe’s hosted checkout page, when you start a website subscription
- Purpose
- Take the subscription payment and send the receipt
- Where stored
- Not stored by Mend. Stripe keeps it; Mend reads back only the IDs, plan and status listed under “Website subscriber records”. A checkout page left unpaid expires after about 30 minutes.
- Retention
- At Stripe: as Stripe’s privacy policy describes
- Shared with
- Stripe, the operator’s payment provider. Mend never receives card numbers. We use your email address only to send your workspace login and answer you.
- How to opt out
- Nothing is collected unless you start a subscription. The free demo and the companion app need no payment. Leaving Stripe’s page without paying ends it.
Owner workspace in the browser
- Data
- The dashboard’s reports, transition hotspots, settings and demo state
- Source
- The workspace owner
- Purpose
- Run the dashboard
- Where stored
- Page memory; no cookies or browser storage. Copy and export create files only when the owner chooses.
- Retention
- Until the page reloads
- Shared with
- Only the Mend server it came from. Its Live playground, and Ask Claude or Verify demo recovery on demo storefront transitions, can call cloud AI; the usage guardian’s demo cut-off stops that. Ask Claude on the dashboard’s own transitions is ordinary owner usage that the guardian still checks.
- How to opt out
- Settings → Data & AI: the demo cut-off switch, or cloud AI off
Google Fonts (owner workspace only)
- Data
- The IP address and browser details of whoever opens the owner workspace, as part of loading fonts
- Source
- Opening the owner workspace
- Purpose
- Load the DM Sans and Manrope fonts
- Where stored
- Google’s servers, under Google’s terms
- Retention
- Set by Google
- Shared with
- Google (fonts.googleapis.com and fonts.gstatic.com)
- How to opt out
- Block those domains; the workspace falls back to system fonts. The public website loads no third-party fonts.
Email to support
- Data
- Your email address and whatever you include
- Source
- You, when you email support@mend.solutions
- Purpose
- Answer you
- Where stored
- Our support mailbox, hosted by Microsoft 365 through GoDaddy
- Retention
- Only as long as needed to help you; deleted sooner if you ask
- Shared with
- Microsoft 365, as the mailbox provider
- How to opt out
- Leave out passwords, API keys and unredacted diagnostic exports, and ask us to delete your messages
The Mend companion app
App Store privacy label: Data Not Collected. The app sends no analytics or usage data and calls no AI provider. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots.
Server connection
- Data
- The server address, gateway username and password you enter, and an optional GitHub repository link
- Source
- You, in the app
- Purpose
- Read and show that server’s status, monthly usage, reports and transition hotspots
- Where stored
- The server address and login in this device’s Keychain (this device only, while unlocked); the GitHub link in the app’s preferences on the device; reports and hotspots in memory only. Copy puts a hotspot’s code snippet on this device’s clipboard only when you choose it.
- Retention
- Until you choose Disconnect and clear saved account. Keychain items can outlive the app, so clear them before deleting it.
- Shared with
- Only the server you enter, through HTTPS GET requests with your gateway login. Nothing goes to AI providers or analytics.
- How to opt out
- Use Try it and the sample reports without connecting, or choose Disconnect and clear saved account
App analytics from Apple (only if you opt in)
- Data
- Aggregated usage statistics and crash reports
- Source
- Apple, only if you chose in your device settings to share analytics with app developers
- Purpose
- Fix and improve the app
- Where stored
- Apple’s developer tools
- Retention
- Set by Apple
- Shared with
- No one
- How to opt out
- Turn off sharing with app developers in your device’s analytics settings
Your choices, opting out and deleting data
Every switch only reduces data use. A person can turn cloud AI or learning off for themselves but never back on when the app turned it off (the SDK enforces this), and no app or request can turn back on what the workspace owner turned off (the Mend server enforces this).
- A person using an app that includes Mend
- Use the app’s Mend privacy controls if its developer added them (or
Mend.setPrivacy({ cloudAi: false, learning: false })). Cloud AI off keeps layout findings in your browser. For screen-change diagnosis, both switches take effect only where the app passes your choice to its recovery code and its backend forwards it to the Mend server; if you are unsure, ask the app’s developer. - Pick Fast, Balanced, Patient or a custom signal latency in the app’s latency picker, or reset it to the app default.
- Your choices are remembered in that site’s browser storage; clearing the site’s data forgets them. If the app offers no controls, ask its developer.
- Use the app’s Mend privacy controls if its developer added them (or
- An app’s developer
data-mend-cloud="off"on the connect tag keeps layout findings in the browser. Give the recovery controller the same switch (itsprivacyoption) so diagnosis never asks for cloud AI.- Learning: give the recovery controller
privacy: { learning: false }(or a function returning a person’s choice, such as() => preferences.getPrivacy()withcreatePreferencesfrompreferences.js) and forward theprivacyobject with every diagnose and outcome call.data-mend-learning="off"on the connect tag sets the switch the connect API reports, but the tag itself sends nothing that is learned from. - Leave out
data-mend-endpointto keep layout findings in the browser, and adddata-mend-user-latency="false"to keep your own signal latency. data-mend-hotspots="off"on the page’s<html>or<body>or on the connect tag (the whole page, including a recovery controller), or on a marked element or its container, keeps your source labels and transition names out of the records sent for diagnosis, so none reaches a Mend server. In code:hotspots: falseforcreateTransitionRecovery, orprivacy: { hotspots: false }.
- A workspace owner or server operator
- Settings → Data & AI: turn cloud AI off (nothing goes to Anthropic or OpenAI; Mend AI and local diagnosis continue), learning off (new reports are marked, never learned from, Claude’s answers are not kept as Mend AI corrections, and no Astra review is requested) or hotspot labels off (new reports keep no source label or transition name, and the stored ones are deleted).
- Delete learning data: Mend AI’s outcome and correction counters only, or the counters and every transition report.
- Usage guardian: cut off cloud AI for the workspace demo and switch off Claude pause explanations. Or run with no provider keys, and leave Astra review and billing off (the defaults).
- A companion app user
- Use Try it and the sample reports without connecting. Server → Disconnect and clear saved account removes the saved server, login and GitHub link from the device.
- A visitor to mend.solutions
- Nothing to turn off: the website stores nothing in your browser, and its demo, including your signal latency choice, sends nothing.
Deleting data
- On your device: in the app, open Server and choose Disconnect and clear saved account. This removes the saved server address, gateway credentials, and GitHub link from the device and clears displayed reports. It does not delete anything on a server. Keychain items can remain after the app is deleted, so use this button before deleting the app.
- On this website: nothing is stored; refreshing the page clears the demo.
- In an app that uses Mend: clearing that site’s data removes your saved signal latency and privacy choices.
- On the mend.solutions pilot service: email support@mend.solutions to ask us to access or delete reports, review summaries, or other records we hold. Tell us which workspace you use, but do not include passwords or keys.
- On another operator’s server: contact that operator. Its owner can use Delete learning data in the workspace, and turning hotspot labels off deletes the stored source labels and transition names. Clearing the app does not delete server data or revoke a gateway password.
Email to support
If you email support@mend.solutions, we receive your email address and whatever you include, and we use them only to respond to you. Our support mailbox is hosted by Microsoft 365, provided through GoDaddy. Please do not send passwords, API keys, or unredacted diagnostic exports. We keep support correspondence only as long as we need it to help you, and delete it sooner if you ask.
Sharing
We do not sell or rent personal information and do not share it for advertising. Information leaves a Mend server only as described above: to an AI provider that the operator has turned on, or to Stripe when online checkout or workspace billing is on. For the mend.solutions pilot and our support mailbox, the service providers we use—Anthropic and OpenAI when turned on, Stripe for online checkout and billing when they are on, and Microsoft 365 for support email—process information on our behalf under contractual terms that require them to protect it at least as well as this policy describes. Separately, opening the owner workspace loads fonts from Google, which receives the visitor’s IP address and browser details under Google’s own terms.
Children
Mend is a tool for software developers. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information, contact support@mend.solutions and we will delete it.
Security
The app connects to servers only over HTTPS with a valid certificate and keeps credentials in the Keychain. Our server requires the owner login for every non-public page and API route except two that cannot carry it: the checkout link, which only redirects, and Stripe’s notifications, which Mend accepts only with a valid Stripe signature. AI and Stripe keys stay on the server. No system is perfectly secure; please report any problem to support@mend.solutions.
Changes to this policy
If our practices change, we will update this page and its effective date before the change takes effect, and summarize significant changes at the top of this page.
Contact
Akira Patafio, individual developer · support@mend.solutions
For more technical detail about the pilot’s AI use and limits, read the AI and data disclosure.