AI and data disclosure · October 11, 2026 · Developer pilot

What the AI does.
What the browser proves.

Mend monitors interfaces whose developers have integrated its SDK. It cannot inspect or repair arbitrary applications on your device. Our native companion displays reports; it does not bypass application sandboxing.

This public demo

The public landing page and its examples use self-contained static assets. After those files load, demo actions need no server or AI requests. The examples keep their observations, and the signal latency you choose, in page memory only; refreshing clears them. This page has no analytics scripts, account creation, review submission, or payment flow. Serving the site still involves ordinary network requests; the Privacy Policy describes exactly what the server records.

The rest of this disclosure describes the separate developer pilot. Its workspace requires an operator-issued gateway login. The public demo does not provide access to workspace reports, review feedback, provider credentials, or billing records. App Store release is pending.

Three separate components

Train, fix, iterate: how Mend AI learns

Mend AI is not a locally hosted Claude/Astra model and is not a language model. Mend never sends your data to train Anthropic’s or OpenAI’s models.

Signal latency

Signal latency is how long Mend waits after a screen change starts before it signals the change as slow or stuck and a recovery integration may start diagnosis. A developer sets an app-wide default and can give a control its own budget. A person using the app can choose Fast (500 ms), Balanced (1000 ms), Patient (3000 ms) or a custom value from 300 to 10,000 ms, unless the developer keeps the latency fixed. For a control with its own budget, a person’s choice can only add patience, never shorten it. The choice is saved in that site’s browser storage. Each stored report records the latency in effect and where it came from; only the number of milliseconds can be part of what is sent to an AI provider. The demo on this website lets you try it, in memory only.

Automatic transition recovery

Developers can opt in to the SDK’s automatic recovery controller inside their web app. When an instrumented transition misses its deadline, the controller requests a diagnosis from the developer’s configured backend. It accepts only a supported, sufficiently confident action with a recovery callback that the developer has registered, then observes a fresh transition to check the result. An unavailable diagnosis or unverified recovery remains unresolved and can be reported to the developer.

This integration requires setup; installing the native companion does not activate recovery in other apps. Automatic cloud diagnosis can consume provider tokens when enabled. Cancelling a browser operation does not necessarily cancel work already submitted to an AI provider. The public examples below use fixed local actions and make no AI requests.

Free local examples

The free interactive demo shows a hidden destination, a screen that opens slowly and an overflowing layout, applies fixed registered changes, and checks the rendered result. Its signal latency chooser shows when Mend would signal the slow screen. It needs no signup, card, AI credits, or GitHub connection. The public browser demo is served as static files and its actions need no backend or cloud connection. A local version is also included in the developer workspace. The native Demo tab works entirely offline without a server or account, and the native Reports tab’s sample reports are bundled with the app and load offline. These sample results do not prove that another app is repaired, and the samples do not train the server’s repair memory.

Usage guardian and the free demo

A deterministic usage guardian checks every cloud AI request first—Claude, Astra and the optional OpenAI layout path—before any allowance is reserved. The one exception is the optional pause explanation described below, which is sent only after a pause and counts against the monthly Claude allowance, not the hourly limits or website billing. It pauses cloud AI when requests or provider-reported tokens in the last hour pass their limits, when a monthly allowance or billing budget runs well ahead of the calendar, after repeated provider failures, when a provider reports a billing, credit or spend-limit problem (recognised from the provider’s error code; the error text is not kept), or, with the owner’s optional revenue cap, when this month’s estimated AI cost reaches a share of the last 30 days’ Stripe net. Stripe cannot pay Anthropic or OpenAI and Mend never moves money; the owner funds each provider in its own console. Hourly pauses resume on their own after a cooldown; the others wait for the workspace owner. Local diagnosis continues throughout. The pause itself is saved on the server; the hourly counts are kept in memory.

After an hourly, pace or budget pause, the guardian can ask Claude Haiku for one short explanation for the owner, at most 10 a month. It sends only the pause type, thresholds and aggregate counts—never transition, page or user data—and the explanation never decides or ends a pause. The owner can switch explanations off.

The free demo uses no AI tokens. The demo on this website, the free demo in the developer workspace and the companion app’s Try it tab run locally and send nothing to any AI provider. Only the private workspace playground can call cloud AI; the guardian can cut it off with a switch or once a share of a monthly allowance is used, without affecting real integrations. Ask Claude on the workspace dashboard’s own transitions is ordinary owner usage: the guardian checks it, but the demo cut-off does not apply.

App Store review feedback

Developers can manually add a summary of a genuine App Store review in Settings, with an optional star rating. Mend does not import or invent reviews. Leave out reviewer names, emails, account details, and other personal information. The separate public-rating preview remains unavailable until Mend has a published listing with real ratings.

Fixed English keyword rules suggest investigation topics and regression checks. They can misclassify a report and do not establish its cause. Review text is untrusted feedback, never instructions: adding it sends nothing to AI providers and makes no code, prompt, or model-weight changes. Star ratings describe customer feedback and are not labels of model quality.

A developer can link a summary to an existing recovery report only after successful browser verification and acceptance through the existing learning gates, including independent Astra review when enabled. “Evidence linked” records that manual association. It does not prove that the original reviewer encountered the same bug or that their problem is fixed, and it does not train the repair memory again. Reproduce and retest the original steps in the affected app before drawing that conclusion.

Data sent to AI providers

The built-in Mend server’s cloud requests exclude page text, form values, screenshots, repository code, URLs, source labels, transition names, element identifiers, and review feedback text. The server receives fuller records from an app’s backend, reduces them to fixed codes and numbers, and discards the rest before anything is stored or sent. The one exception is kept, not sent: for transition hotspots, a stored report can include the developer’s checked source label and transition name, unless the developer or workspace owner turns hotspot labels off. A developer-supplied diagnosis backend can have different data practices. API keys stay on the server. Local browser reports can include developer-supplied labels and source references. Copy/export includes the report you select.

Anthropic and OpenAI process cloud requests under the operator’s API account terms and data controls, linked in the AI notice above. Mend sets OpenAI requests to store: false; this does not promise that OpenAI keeps nothing.

What data Mend uses

Every kind of data Mend’s software, this website, the companion app and our support mailbox handle: what it is, where it comes from, why, where it is kept, for how long, who else receives it, and how to opt out. The developer workspace shows the same list with live counts under Settings → Data & AI.

In an app that uses the Mend SDK

This stays in the browser of a person using an app whose developer added the Mend SDK. The mend.solutions website does not monitor its visitors; its demo watches only its own sample preview.

Screen-change observations

Data
For each control the developer marks: the transition name, from/to and group labels, the trigger and expected-screen element IDs, start and end times, duration, the signal latency in effect and where it came from, size, position, opacity and visibility before and after, up to 24 timeline steps, standard JavaScript error names (never messages) and an optional developer source label. For transition hotspots, record.hotspot holds a checked copy of the developer’s source label and transition name (a repo-relative path and line such as src/cart/CartButton.tsx:42 and a plain name), or nothing when a label fails the checks. With a registered redirect, the recovery controller adds the fallback element ID (fallbackTargetId) to the record it passes to diagnosis
Source
The Mend SDK in the person’s browser, only for elements the app’s developer marks
Purpose
Notice when a screen change is slow or stuck, measured against the signal latency
Where stored
Page memory only: 60 records by default, at most 200. Other scripts on the same page can read them through the mend:transition event and window.Mend, and failed records are written to the browser console.
Retention
Until the page is closed or reloaded
Shared with
Nobody, by the SDK itself. With automatic recovery, the app’s own code sends a failed record to the developer’s backend, which can pass it to a Mend server (see “Records as received”).
How to opt out
Developer: remove the data-mend-transition and data-mend-motion attributes, or call Mend.stop(). data-mend-hotspots="off" on the page’s <html> or <body>, the connect tag, or any marked element or its container, or hotspots: false for the monitor or recovery controller, leaves record.hotspot empty; the recovery controller removes it before each diagnosis request whenever any of these is off. A person can turn cloud AI and learning off where the app offers it, but cannot switch off observation inside an app.

Layout findings

Data
For elements marked data-mend: the element ID, check type, severity and measurements (widths, contrast ratio, opacity or image size)
Source
The SDK’s layout checks in the browser
Purpose
Choose a supported, reversible repair
Where stored
Page memory: the current findings and the last 100 repairs. Other scripts on the same page can read them through the mend:visual event and window.Mend.visual.
Retention
Until the page is closed or reloaded
Shared with
Only if the developer sets data-mend-endpoint: up to 32 findings per request go to that same-origin address on the app’s own server. Never sent while cloud AI is off for the app or the person.
How to opt out
Developer: leave out data-mend-endpoint or set data-mend-cloud="off". Person: the app’s privacy controls or Mend.setPrivacy({ cloudAi: false }).

A person’s own choices

Data
The signal latency the person picked (Fast, Balanced, Patient or a number of milliseconds) and which of the cloud AI and learning switches they turned off
Source
The person, through controls the developer mounts (Mend.mountLatencyPicker, Mend.mountPrivacyControls) or the app’s own code
Purpose
Apply and remember the choice on that site
Where stored
That site’s browser storage, keys mend:signal-latency:v1 and mend:privacy:v1, written only after the person makes a choice. If storage is blocked, the choice lasts for the page only.
Retention
Until the person resets the choice (the stored entry is removed) or clears the site’s data
Shared with
Switches that are off travel as a privacy flag with the SDK’s layout requests, and with diagnose and outcome calls where the app’s recovery code and backend pass them on; the latency in effect is recorded in each observation.
How to opt out
Make no choice, reset to the app default, or clear the site’s data. Developer: data-mend-user-latency="false" ignores any stored latency.

On a Mend server

Whoever operates a Mend server controls this data: we do for the mend.solutions pilot, and any other server is run by its own operator. Files sit in the server’s data directory with owner-only permissions.

Records as received, before reduction

Data
Complete screen-change records and layout findings as an app’s backend or the owner workspace sends them, including labels, element IDs, source labels, event text and positions, the hotspot labels and any fallback element ID, plus any privacy flags and the workspace demo marker
Source
Requests to /api/analyze, /api/transitions/diagnose and /api/transitions/outcome
Purpose
Reduce each request to fixed codes and numbers before anything is kept or sent to AI
Where stored
Not stored, apart from what transition reports keep. Labels, element IDs (apart from the hashes in transition reports), event text, source labels and positions are discarded during reduction. The one exception is a failed transition’s hotspot source label and transition name, kept after the server checks them again unless hotspot labels are off. Layout findings are answered and discarded.
Retention
Only while the request is handled
Shared with
No one in this form
How to opt out
Developers can send fewer fields; nothing beyond the reduced form is kept

Transition reports

Data
Failure code and type, duration, the signal latency in effect (milliseconds, source and preset), before/after size, opacity and visibility measurements, the expected element’s ID stored only as a one-way hash (an unsalted SHA-256, so anyone who can guess an ID such as “account-panel” can confirm it) and, with a registered redirect, the same kind of hash of the fallback element’s ID, the developer’s source label and transition name for transition hotspots unless hotspot labels are off (a file path and line such as src/cart/CartButton.tsx:42 and a name such as “Open cart”, never the code itself), the diagnosis and its reason (Claude may have written it), how Mend AI routed it (an escalation rule, Mend AI itself, Claude or local rules, and why), a marker when Claude’s answer became a Mend AI correction with Mend AI’s earlier best guess, any notice, the browser verification result with a hash of that observation, the Astra review result and its token counts, and markers when cloud AI or learning was off or the request came from the workspace demo
Source
Diagnose and outcome requests from the owner workspace or an app’s backend
Purpose
Show reports to the developer and suggest a recovery
Where stored
transition-memory.json in the server’s data directory
Retention
The newest 500 reports (fewer only if the file would pass 3 MB), with no time-based expiry, until the workspace owner deletes them
Shared with
The reduced measurements (not the hashes, the hotspot labels, the latency source, the routing or the markers) go to Anthropic Claude when a cloud diagnosis is requested and Mend AI is not confident, and to OpenAI Astra when the operator turns reviews on, unless cloud AI was off when the report was made: that marker keeps it from cloud AI later. Anyone with the gateway login can read reports and transition hotspots in the workspace or the companion app.
How to opt out
Workspace owner: Delete learning data → counters and every report; turn hotspot labels off in Settings → Data & AI, which also deletes the labels already stored. Developer: do not send failed records to a Mend server, or add data-mend-hotspots="off" to keep the hotspot labels out (a registered redirect still sends its fallback ID). Learning off still keeps the report and its outcome, marked, for the developer, but never learns from it.

Mend AI learning (verified outcomes and Claude corrections)

Data
Per measurement pattern (a hash of the failure code, the transition type and four yes/no facts such as whether the screen was hidden) and recovery action: how many browser-verified recoveries succeeded and failed (train), and how many times Claude’s validated diagnosis chose that action while Mend AI was unsure (fix). Only the action label is counted, never Claude’s text
Source
Recovery outcomes: a success counts only when the browser verified it and, while Astra review is on, Astra agreed. Corrections: Claude diagnoses that passed Mend’s checks; they never count as verified successes.
Purpose
Let Mend AI, the small model on this server, answer on its own once verified outcomes make it confident and ask Claude about a transition only when they do not. Correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Mend never uses it to train Anthropic or OpenAI models.
Where stored
transition-memory.json
Retention
Up to 2,048 patterns (at most 160 can occur with today’s pattern key) of outcomes and of corrections, with no time-based expiry, until the workspace owner deletes learning data
Shared with
No one; never sent to AI providers
How to opt out
Workspace owner: turn learning off (no outcomes or corrections are recorded), turn cloud AI off (Claude is never asked, so nothing is corrected) or delete learning data. Developer: pass { learning: false } (or a person’s choice) as the recovery controller’s privacy option and have the app’s backend forward privacy with diagnose and outcome calls. A person’s Mend.setPrivacy({ learning: false }) and the connect tag’s data-mend-learning="off" take effect only through that path; on their own they send nothing that is learned from.

Transition hotspots (owner only)

Data
Hotspots ranked from stored reports: per developer source label, transition name and type, failure counts, timing medians, verified recovery counts, and a recommendation (resolve, redirect or review) with steps and a code snippet to copy
Source
Computed by rules from stored transition reports and outcome counters on each GET /api/hotspots; no AI is used
Purpose
Show the developer where transitions fail in their code and whether Mend should resolve in place, redirect to a registered fallback or leave it for review
Where stored
Not stored: computed on each request
Retention
Only while the request is handled
Shared with
Anyone with the gateway login, in the workspace or the companion app; never sent to AI providers
How to opt out
Workspace owner: hotspot labels off groups hotspots by transition type only. Developer: data-mend-hotspots="off".

Monthly AI usage counters

Data
Claude and Astra request and token counts for the current month
Source
Each cloud AI request
Purpose
Enforce the monthly request limits and the usage guardian
Where stored
usage.json and astra-usage.json
Retention
Replaced when a new month starts
Shared with
No one
How to opt out
Not needed: counts only, with no content

Mend AI routing counts

Data
Per month: transitions diagnosed; how many an escalation rule, Mend AI, Claude or local rules decided; why Mend AI asked Claude (unsure, a failed verification or not yet learned); Claude calls, answers, blocked calls and token totals; Astra reviews and tokens; correction counts and browser-verified outcomes by engine
Source
Each diagnosis and recorded outcome on this server, except workspace demo traffic
Purpose
Show the owner how often Mend AI handles transitions without Claude, Claude calls per 100 transitions and the estimated AI cost per verified fix
Where stored
mend-ai-routing.json
Retention
The newest 13 months
Shared with
No one; never sent to AI providers
How to opt out
Not needed: counts only, with no content

App Store review summaries

Data
Summaries the workspace owner types, with an optional star rating and review ID, and links to verified reports
Source
The owner, in Settings → Learn from App Store feedback
Purpose
Investigate reported problems
Where stored
review-feedback.json
Retention
The newest 100 summaries
Shared with
No one; never sent to AI providers
How to opt out
Do not add summaries; leave out reviewer names and other personal information

Usage guardian record

Data
Guardian settings (including the optional revenue cap: on or off, the share of income and the buffer), the current pause, the last 20 pauses with the figures that triggered them (for a revenue-cap pause, this month’s estimated AI cost and the cap), consecutive provider failure counts and this month’s explanation count
Source
The usage guardian and the owner’s settings. Whether a provider error was a credit or spend-limit error is read from at most 4 KB of an HTTP 400 or 429 error body, which is then discarded
Purpose
Stop runaway AI usage and keep cloud AI spend within a share of income
Where stored
guardian.json (hourly call and token counts stay in memory and reset on restart)
Retention
The last 20 pauses
Shared with
No one. An optional Claude Haiku explanation of a pause receives aggregate numbers only (see Anthropic Claude).
How to opt out
Not applicable: a safety record with no content

Workspace settings

Data
The owner’s cloud AI, learning, hotspot labels and default signal latency choices
Source
The owner, in Settings → Data & AI
Purpose
Apply those choices on this server
Where stored
workspace-settings.json, written only after a setting changes
Retention
Until changed
Shared with
No one
How to opt out
Change them in Settings → Data & AI

Billing records (only when website billing is on)

Data
Workspace billing ID, Stripe customer and subscription IDs, status, plan, billing-period usage, usage reservations and unsent meter events
Source
Stripe Checkout and verified Stripe webhooks
Purpose
Charge for included and extra AI usage
Where stored
billing.json, only when billing is enabled
Retention
The last 24 billing periods, 20 checkout attempts, 100 open reservations and 1,000 unsent meter events
Shared with
Stripe receives billing IDs, the plan, return addresses and usage amounts with event IDs and timestamps. Stripe-hosted pages collect card and contact details; Mend never receives card numbers. Webhook events, which can include customer contact details, are processed in memory and not stored.
How to opt out
Billing stays off unless the operator enables it; it is not enabled on mend.solutions

Money flow totals (owner only)

Data
Stripe balance transactions, subscriptions, invoices and payouts for the operator’s own Stripe account, reduced to totals by day, plan and month. No customer names, emails, addresses, card details, descriptions or raw Stripe IDs are kept or shown; payout IDs are shortened.
Source
Stripe, read with read-only requests and the server’s Stripe key when the owner opens Money flow, and every 6 hours while the owner’s revenue cap is on
Purpose
Show the owner income, fees, estimated AI and fixed costs, net contribution and AI funding advice, and set the revenue cap
Where stored
Not stored: the totals stay in server memory. For the revenue cap, the last 30 days’ net, its currency, test or live mode and the time it was read also stay in memory
Retention
Up to 60 seconds in memory; the 30-day net until the next read or a restart
Shared with
Only the signed-in owner sees the totals; Stripe receives the read requests
How to opt out
Not applicable: the operator’s own accounting view. It reads nothing until a Stripe key is configured

Website subscriber records (only when online checkout is on)

Data
For each website subscription: the Stripe customer and subscription IDs, the plan, test or live mode, Stripe’s subscription status, when it started, when its payment cleared, when it was last updated and ended, and whether the owner has sent the workspace login yet (and when). No names, email addresses, postal addresses or payment details.
Source
Signature-verified Stripe webhooks, each confirmed by a fresh request to Stripe before anything is kept
Purpose
Know who has paid, email each new subscriber a workspace login within 1 business day, and follow renewals and cancellations
Where stored
customers.json in the server’s data directory, written only after the first verified subscription
Retention
Up to 1,000 subscribers; an ended subscription is removed 90 days after it ends
Shared with
Only the signed-in owner, in Money flow. The owner opens each customer in the Stripe Dashboard, where Stripe keeps the contact and payment details.
How to opt out
Online checkout stays off unless the operator turns it on. Ask support@mend.solutions about the record we hold for you; it is needed while a subscription runs.

Gateway login

Data
The username and password sent with workspace, API and companion-app requests to a hosted server
Source
The person signing in
Purpose
Let only the owner reach the workspace and API
Where stored
On the mend.solutions pilot, the HTTPS proxy keeps only a bcrypt hash of the owner password in its protected configuration. It checks the login and removes it, with any cookies, before a request reaches Mend.
Retention
Until the operator changes the password
Shared with
No one
How to opt out
Not applicable: required for access

Server and proxy logs

Data
Operational messages such as startup, certificate renewal and errors. A proxy error entry can include the request method, page and headers, with login and cookie headers left out; the Mend process logs no requests.
Source
The Mend process and the HTTPS proxy on the server
Purpose
Operate and secure the service
Where stored
The server’s system log. On mend.solutions the ingress also counts each client IP address’s connections in memory, for about 60 seconds after its last connection, to limit abuse; that count is never written to disk.
Retention
The system log discards the oldest messages as it reaches its size limit
Shared with
No one
How to opt out
Not applicable

Sent to AI providers

From a Mend server, only when its operator adds a provider’s API key and cloud AI is on, and for transition diagnosis only when Mend AI is not confident. Each provider processes what it receives under its own terms and privacy policy. The improvement loop runs in Mend’s own repository on synthetic data. Mend never sends your data to train Anthropic’s or OpenAI’s models.

Anthropic Claude

Data
Layout checks: check type, severity and measurements, with placeholder IDs. Transition diagnosis: failure code, type, duration, signal latency in milliseconds and reduced before/after measurements. After a usage-guardian pause: aggregate usage numbers for an optional short explanation. Never page text, form values, element IDs, labels, URLs, screenshots, source code or review text.
Source
Layout checks run automatically when a Claude key is set and cloud AI is on; transition diagnosis only when requested (Ask Claude, or useCloud: true from automatic recovery) and Mend AI is not confident; at most 10 pause explanations a month
Purpose
Diagnose transitions Mend AI is unsure about and suggest a registered recovery, and explain a usage pause. A validated answer becomes a Mend AI correction unless learning is off
Where stored
Mend keeps only the reduced report, Claude’s short reason and, as a Mend AI correction, the action it chose. Anthropic processes requests under its own terms.
Retention
At Anthropic: as its terms and privacy pages describe
Shared with
Anthropic
How to opt out
Workspace owner: cloud AI off or no Claude key; pause explanations can be switched off. Developer: data-mend-cloud="off" and the recovery controller’s privacy option. Person: Mend.setPrivacy({ cloudAi: false }). The usage guardian also pauses cloud AI on its own.

OpenAI GPT-6 Astra (off by default)

Data
Reduced before/after measurements of a recovery, the recovery action and whether the browser verified it, sent with store: false
Source
Recovery outcomes, only when the operator sets MEND_AUDIT_ENABLED=1 with a separate key
Purpose
An independent review before a successful recovery is learned
Where stored
Mend keeps only the review result and its token counts in the report
Retention
At OpenAI: as its API data controls describe; store: false does not guarantee OpenAI keeps nothing
Shared with
OpenAI
How to opt out
Leave Astra off (the default), turn cloud AI off, or turn learning off (no review is requested)

OpenAI layout path (legacy, off by default)

Data
Layout check type, severity and measurements with placeholder IDs, sent with store: false
Source
Layout checks, only when the operator sets AI_PROVIDER=openai
Purpose
Suggest layout repairs
Where stored
Not stored by Mend
Retention
At OpenAI: as its API data controls describe
Shared with
OpenAI
How to opt out
Keep the default AI_PROVIDER=anthropic, or turn cloud AI off

Mend AI improvement loop (train → fix → iterate, in Mend’s own CI)

Data
Aggregate and per-case results (synthetic case IDs, failure codes and counts) of a benchmark on synthetic test transitions generated from a fixed seed in Mend’s source code (scripts/mend-ai-corpus.mjs), with the current Mend AI rule thresholds and their bounds. Never data from a Mend server, an app or a person
Source
A scheduled GitHub Actions job on Mend’s own repository, at most 2 Claude requests a night and none while an earlier proposal is still open
Purpose
Ask Claude to propose bounded threshold changes so Mend AI asks Claude less often or fixes more synthetic transitions, never with more wrong recoveries
Where stored
Not stored on any Mend server. An improving proposal becomes a pull request in Mend’s repository for the owner to review; nothing is merged automatically
Retention
Pull requests and job logs as GitHub keeps them; at Anthropic, as its terms and privacy pages describe
Shared with
Anthropic (Claude), with a short-lived token from workload identity federation instead of a stored key; GitHub
How to opt out
Not applicable: no personal or customer data is used

The website, the owner workspace and support email

mend.solutions and its free demo

Data
Page requests from visitors
Source
Visitors
Purpose
Explain Mend and run the free demo
Where stored
Nothing in your browser: no cookies, browser storage, analytics, or third-party scripts or fonts. The demo, including its signal latency choice, runs in page memory and sends nothing. Requests for the pages are covered by “Server and proxy logs”.
Retention
The demo clears when the page reloads
Shared with
No one. The free demo uses no AI tokens.
How to opt out
Not needed

Online checkout on Stripe (only when it is open)

Data
What you enter on Stripe’s checkout page: your email address, card or wallet (Apple Pay, Google Pay) details and the billing details Stripe asks for, plus device and browser data that Stripe collects under its own terms
Source
You, on Stripe’s hosted checkout page, when you start a website subscription
Purpose
Take the subscription payment and send the receipt
Where stored
Not stored by Mend. Stripe keeps it; Mend reads back only the IDs, plan and status listed under “Website subscriber records”. A checkout page left unpaid expires after about 30 minutes.
Retention
At Stripe: as Stripe’s privacy policy describes
Shared with
Stripe, the operator’s payment provider. Mend never receives card numbers. We use your email address only to send your workspace login and answer you.
How to opt out
Nothing is collected unless you start a subscription. The free demo and the companion app need no payment. Leaving Stripe’s page without paying ends it.

Owner workspace in the browser

Data
The dashboard’s reports, transition hotspots, settings and demo state
Source
The workspace owner
Purpose
Run the dashboard
Where stored
Page memory; no cookies or browser storage. Copy and export create files only when the owner chooses.
Retention
Until the page reloads
Shared with
Only the Mend server it came from. Its Live playground, and Ask Claude or Verify demo recovery on demo storefront transitions, can call cloud AI; the usage guardian’s demo cut-off stops that. Ask Claude on the dashboard’s own transitions is ordinary owner usage that the guardian still checks.
How to opt out
Settings → Data & AI: the demo cut-off switch, or cloud AI off

Google Fonts (owner workspace only)

Data
The IP address and browser details of whoever opens the owner workspace, as part of loading fonts
Source
Opening the owner workspace
Purpose
Load the DM Sans and Manrope fonts
Where stored
Google’s servers, under Google’s terms
Retention
Set by Google
Shared with
Google (fonts.googleapis.com and fonts.gstatic.com)
How to opt out
Block those domains; the workspace falls back to system fonts. The public website loads no third-party fonts.

Email to support

Data
Your email address and whatever you include
Source
You, when you email support@mend.solutions
Purpose
Answer you
Where stored
Our support mailbox, hosted by Microsoft 365 through GoDaddy
Retention
Only as long as needed to help you; deleted sooner if you ask
Shared with
Microsoft 365, as the mailbox provider
How to opt out
Leave out passwords, API keys and unredacted diagnostic exports, and ask us to delete your messages

The Mend companion app

App Store privacy label: Data Not Collected. The app sends no analytics or usage data and calls no AI provider. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots.

Server connection

Data
The server address, gateway username and password you enter, and an optional GitHub repository link
Source
You, in the app
Purpose
Read and show that server’s status, monthly usage, reports and transition hotspots
Where stored
The server address and login in this device’s Keychain (this device only, while unlocked); the GitHub link in the app’s preferences on the device; reports and hotspots in memory only. Copy puts a hotspot’s code snippet on this device’s clipboard only when you choose it.
Retention
Until you choose Disconnect and clear saved account. Keychain items can outlive the app, so clear them before deleting it.
Shared with
Only the server you enter, through HTTPS GET requests with your gateway login. Nothing goes to AI providers or analytics.
How to opt out
Use Try it and the sample reports without connecting, or choose Disconnect and clear saved account

App analytics from Apple (only if you opt in)

Data
Aggregated usage statistics and crash reports
Source
Apple, only if you chose in your device settings to share analytics with app developers
Purpose
Fix and improve the app
Where stored
Apple’s developer tools
Retention
Set by Apple
Shared with
No one
How to opt out
Turn off sharing with app developers in your device’s analytics settings

How to opt out

Every switch only reduces data use. A person can turn cloud AI or learning off for themselves but never back on when the app turned it off (the SDK enforces this), and no app or request can turn back on what the workspace owner turned off (the Mend server enforces this).

Optional website subscriptions

Workspace usage billing is disabled by default and is not enabled on the mend.solutions service. Checkout is unavailable until the operator configures Stripe credentials, subscription prices, persistent billing storage, and a verified webhook. The current deployment supports one authenticated workspace per server; it does not provide separate customer or team accounts.

Online checkout on the website is separate. It is off unless the operator sets MEND_PUBLIC_CHECKOUT=on with a Stripe key, prices and a webhook secret. When it is on, a visitor’s checkout link asks the Mend server to open a Stripe-hosted checkout page for the Personal or Developer plan, with a rate limit counted in memory; the page expires after about 30 minutes if unpaid. Stripe collects the email address, payment and billing details. Mend accepts Stripe’s webhook only with a valid signature, re-reads each subscription from Stripe, and records only the IDs, plan, status, payment time and onboarding status listed under “Website subscriber records”. The owner then emails each subscriber a workspace login by hand. The checkout link and that webhook are the only routes on mend.solutions that do not require the owner login.

When configured, a subscription has a monthly base fee and an included allowance measured in the retail dollar value of AI tokens. Provider-reported token usage consumes that allowance; usage above it is billed at the configured retail token rates. The monthly base applies even if no AI is used. Unused allowance does not roll over and is not cash or a provider credit.

The extra-spending limit starts at $0. Cloud requests stop when the included allowance cannot cover them unless the workspace owner increases that limit. Mend reserves an estimated amount before a request, so a request may be blocked before the displayed allowance is fully used. Local checks do not incur AI usage charges. A subscription does not mean every transition receives a cloud review.

Stripe-hosted Checkout collects payment details. Mend sends Stripe billing identifiers, the selected plan, and numeric usage values with event identifiers and timestamps. Stripe’s webhook events, which can include customer contact details, are verified and processed in memory; Mend keeps only the identifiers, status and billing periods listed in the inventory. Mend does not send Stripe AI diagnostic evidence, page content, or provider API keys, and does not collect card details itself. Stripe processes billing data under the operator’s Stripe account terms. The customer portal supports cancellation and payment-method updates when configured; plan changes require operator review. The native companion app is free and has no in-app purchases.

Local storage and retention

The server retains at most 500 reduced diagnosis reports and 2,048 local learning patterns (at most 160 distinct patterns can occur today) on its configured disk, plus current monthly provider usage counters, the usage guardian’s last 20 pauses and the owner’s workspace settings. These are separate from billing records. Browser-only observations disappear on refresh unless exported.

Review feedback has its own limit of the latest 100 summaries, with any supplied rating or source review ID, creation time, and linked recovery metadata. New entries replace the oldest. Duplicate text or source IDs reuse an existing item only while that item remains in retained history. The summaries stay on the configured Mend server and can be retrieved by its authorized workspace user; they are not sent to Stripe or AI providers. There is no per-item deletion interface yet.

When billing is enabled, persistent billing records include the workspace identity, spending limit, Stripe customer and subscription identifiers, subscription status, up to 24 billing periods, and up to 20 checkout attempts. They also retain up to 100 outstanding usage reservations and 1,000 usage events awaiting delivery to Stripe. Completed delivery removes an event from that queue; unresolved reservations or delivery may require operator reconciliation before more cloud use.

Local records survive restarts and remain until replaced through normal operation, removed with the workspace’s Delete learning data action, or removed through an operator-managed process. Do not erase billing state to reset an allowance or resolve a payment problem. Backups, exports, provider records, and Stripe billing records can have separate retention schedules; these local size limits do not define their retention.

Support

For Mend support, contact support@mend.solutions. See the support page for troubleshooting and what to include in a request. Do not email passwords, API keys, or unredacted diagnostic exports.

Choices and launch limits

Local diagnosis works without a provider key. When a Claude key is configured and cloud AI is on, analysis of supported visual findings can request cloud diagnosis automatically. Transition reports use the “Ask Claude” button, or useCloud: true from automatic recovery, to request a cloud diagnosis; Mend AI answers without Claude once it is confident for that measurement pattern. Astra review is disabled by default; the operator must configure a separate key and enable it. Both providers have separate request allowances, and the usage guardian can pause both. With website billing enabled, cloud work also requires an active paid subscription and available usage allowance; the optional usage-guardian pause explanation is the one exception, counted only against the monthly Claude allowance.

The companion app is free and has no in-app purchases. Website subscriptions, when online checkout is open, are paid on Stripe’s hosted checkout page and set up by hand during the pilot; the pilot still has no self-service accounts or team tenancy.

This disclosure describes the implemented pilot. It is not a complete privacy policy, service contract, commercial license, or guarantee of error-free AI output. Read the Privacy Policy for how Mend handles information.