What the AI does.
What the browser proves.
Mend monitors interfaces whose developers have integrated its SDK. It cannot inspect or repair arbitrary applications on your device. Our native companion displays reports; it does not bypass application sandboxing.
This public demo
The public landing page and its examples use self-contained static assets. After those files load, demo actions need no server or AI requests. The examples keep their observations, and the signal latency you choose, in page memory only; refreshing clears them. This page has no analytics scripts, account creation, review submission, or payment flow. Serving the site still involves ordinary network requests; the Privacy Policy describes exactly what the server records.
The rest of this disclosure describes the separate developer pilot. Its workspace requires an operator-issued gateway login. The public demo does not provide access to workspace reports, review feedback, provider credentials, or billing records. App Store release is pending.
Three separate components
- Mend AI: the small outcome model on each Mend server. It learns from browser-verified recoveries and from Claude’s checked corrections, answers on its own once its verified outcomes make it confident, and asks Claude about a transition only when they do not.
- Local checks and repairs: fixed browser checks detect supported layout and transition failures. Registered recovery code runs in the integrated app, with a fresh browser observation checking the result.
- Claude: Mend AI’s optional reasoning engine (Anthropic) receives fixed diagnostic categories and reduced numeric measurements for layout checks and for transitions Mend AI is unsure about. Its suggestions can be incorrect. It cannot execute generated code, change the Pi, or permanently edit an app’s source.
- Astra: optional OpenAI GPT-6 Astra reviews reduced before/after evidence independently. “Supported” is an AI assessment, not proof. Failed browser verification always remains failed. If a review is unavailable or disagrees, successful outcomes are held out of local learning.
Train, fix, iterate: how Mend AI learns
- Train: each recovery the browser verifies, or sees fail, updates Mend AI’s success and failure counts for that measurement pattern on that server.
- Fix: when Mend AI is unsure, or its recovery failed verification, it asks Claude. A Claude answer that passes Mend’s checks is recorded as a correction count for the action Claude chose. Only the action label is kept, never Claude’s text, and a correction never counts as a verified success: corrections only suggest an action, below automatic recovery, when Claude is unavailable. Learning off or cloud AI off means no corrections are made.
- Iterate: a nightly job in Mend’s own repository benchmarks Mend AI on synthetic test transitions generated from a fixed seed, asks Claude to propose changes to its thresholds, and opens a pull request only if the benchmark improves. It uses no data from any Mend server or app, signs in with a short-lived federated token, makes at most 2 Claude requests (none while its earlier proposal is still open), and never merges a change by itself.
Mend AI is not a locally hosted Claude/Astra model and is not a language model. Mend never sends your data to train Anthropic’s or OpenAI’s models.
Signal latency
Signal latency is how long Mend waits after a screen change starts before it signals the change as slow or stuck and a recovery integration may start diagnosis. A developer sets an app-wide default and can give a control its own budget. A person using the app can choose Fast (500 ms), Balanced (1000 ms), Patient (3000 ms) or a custom value from 300 to 10,000 ms, unless the developer keeps the latency fixed. For a control with its own budget, a person’s choice can only add patience, never shorten it. The choice is saved in that site’s browser storage. Each stored report records the latency in effect and where it came from; only the number of milliseconds can be part of what is sent to an AI provider. The demo on this website lets you try it, in memory only.
Automatic transition recovery
Developers can opt in to the SDK’s automatic recovery controller inside their web app. When an instrumented transition misses its deadline, the controller requests a diagnosis from the developer’s configured backend. It accepts only a supported, sufficiently confident action with a recovery callback that the developer has registered, then observes a fresh transition to check the result. An unavailable diagnosis or unverified recovery remains unresolved and can be reported to the developer.
This integration requires setup; installing the native companion does not activate recovery in other apps. Automatic cloud diagnosis can consume provider tokens when enabled. Cancelling a browser operation does not necessarily cancel work already submitted to an AI provider. The public examples below use fixed local actions and make no AI requests.
Free local examples
The free interactive demo shows a hidden destination, a screen that opens slowly and an overflowing layout, applies fixed registered changes, and checks the rendered result. Its signal latency chooser shows when Mend would signal the slow screen. It needs no signup, card, AI credits, or GitHub connection. The public browser demo is served as static files and its actions need no backend or cloud connection. A local version is also included in the developer workspace. The native Demo tab works entirely offline without a server or account, and the native Reports tab’s sample reports are bundled with the app and load offline. These sample results do not prove that another app is repaired, and the samples do not train the server’s repair memory.
Usage guardian and the free demo
A deterministic usage guardian checks every cloud AI request first—Claude, Astra and the optional OpenAI layout path—before any allowance is reserved. The one exception is the optional pause explanation described below, which is sent only after a pause and counts against the monthly Claude allowance, not the hourly limits or website billing. It pauses cloud AI when requests or provider-reported tokens in the last hour pass their limits, when a monthly allowance or billing budget runs well ahead of the calendar, after repeated provider failures, when a provider reports a billing, credit or spend-limit problem (recognised from the provider’s error code; the error text is not kept), or, with the owner’s optional revenue cap, when this month’s estimated AI cost reaches a share of the last 30 days’ Stripe net. Stripe cannot pay Anthropic or OpenAI and Mend never moves money; the owner funds each provider in its own console. Hourly pauses resume on their own after a cooldown; the others wait for the workspace owner. Local diagnosis continues throughout. The pause itself is saved on the server; the hourly counts are kept in memory.
After an hourly, pace or budget pause, the guardian can ask Claude Haiku for one short explanation for the owner, at most 10 a month. It sends only the pause type, thresholds and aggregate counts—never transition, page or user data—and the explanation never decides or ends a pause. The owner can switch explanations off.
The free demo uses no AI tokens. The demo on this website, the free demo in the developer workspace and the companion app’s Try it tab run locally and send nothing to any AI provider. Only the private workspace playground can call cloud AI; the guardian can cut it off with a switch or once a share of a monthly allowance is used, without affecting real integrations. Ask Claude on the workspace dashboard’s own transitions is ordinary owner usage: the guardian checks it, but the demo cut-off does not apply.
App Store review feedback
Developers can manually add a summary of a genuine App Store review in Settings, with an optional star rating. Mend does not import or invent reviews. Leave out reviewer names, emails, account details, and other personal information. The separate public-rating preview remains unavailable until Mend has a published listing with real ratings.
Fixed English keyword rules suggest investigation topics and regression checks. They can misclassify a report and do not establish its cause. Review text is untrusted feedback, never instructions: adding it sends nothing to AI providers and makes no code, prompt, or model-weight changes. Star ratings describe customer feedback and are not labels of model quality.
A developer can link a summary to an existing recovery report only after successful browser verification and acceptance through the existing learning gates, including independent Astra review when enabled. “Evidence linked” records that manual association. It does not prove that the original reviewer encountered the same bug or that their problem is fixed, and it does not train the repair memory again. Reproduce and retest the original steps in the affected app before drawing that conclusion.
Data sent to AI providers
The built-in Mend server’s cloud requests exclude page text, form values, screenshots, repository code, URLs, source labels, transition names, element identifiers, and review feedback text. The server receives fuller records from an app’s backend, reduces them to fixed codes and numbers, and discards the rest before anything is stored or sent. The one exception is kept, not sent: for transition hotspots, a stored report can include the developer’s checked source label and transition name, unless the developer or workspace owner turns hotspot labels off. A developer-supplied diagnosis backend can have different data practices. API keys stay on the server. Local browser reports can include developer-supplied labels and source references. Copy/export includes the report you select.
Anthropic and OpenAI process cloud requests under the operator’s API account terms and data controls, linked in the AI notice above. Mend sets OpenAI requests to store: false; this does not promise that OpenAI keeps nothing.
What data Mend uses
Every kind of data Mend’s software, this website, the companion app and our support mailbox handle: what it is, where it comes from, why, where it is kept, for how long, who else receives it, and how to opt out. The developer workspace shows the same list with live counts under Settings → Data & AI.
In an app that uses the Mend SDK
This stays in the browser of a person using an app whose developer added the Mend SDK. The mend.solutions website does not monitor its visitors; its demo watches only its own sample preview.
Screen-change observations
- Data
- For each control the developer marks: the transition name, from/to and group labels, the trigger and expected-screen element IDs, start and end times, duration, the signal latency in effect and where it came from, size, position, opacity and visibility before and after, up to 24 timeline steps, standard JavaScript error names (never messages) and an optional developer source label. For transition hotspots,
record.hotspotholds a checked copy of the developer’s source label and transition name (a repo-relative path and line such assrc/cart/CartButton.tsx:42and a plain name), or nothing when a label fails the checks. With a registered redirect, the recovery controller adds the fallback element ID (fallbackTargetId) to the record it passes to diagnosis - Source
- The Mend SDK in the person’s browser, only for elements the app’s developer marks
- Purpose
- Notice when a screen change is slow or stuck, measured against the signal latency
- Where stored
- Page memory only: 60 records by default, at most 200. Other scripts on the same page can read them through the
mend:transitionevent andwindow.Mend, and failed records are written to the browser console. - Retention
- Until the page is closed or reloaded
- Shared with
- Nobody, by the SDK itself. With automatic recovery, the app’s own code sends a failed record to the developer’s backend, which can pass it to a Mend server (see “Records as received”).
- How to opt out
- Developer: remove the
data-mend-transitionanddata-mend-motionattributes, or callMend.stop().data-mend-hotspots="off"on the page’s<html>or<body>, the connect tag, or any marked element or its container, orhotspots: falsefor the monitor or recovery controller, leavesrecord.hotspotempty; the recovery controller removes it before each diagnosis request whenever any of these is off. A person can turn cloud AI and learning off where the app offers it, but cannot switch off observation inside an app.
Layout findings
- Data
- For elements marked
data-mend: the element ID, check type, severity and measurements (widths, contrast ratio, opacity or image size) - Source
- The SDK’s layout checks in the browser
- Purpose
- Choose a supported, reversible repair
- Where stored
- Page memory: the current findings and the last 100 repairs. Other scripts on the same page can read them through the
mend:visualevent andwindow.Mend.visual. - Retention
- Until the page is closed or reloaded
- Shared with
- Only if the developer sets
data-mend-endpoint: up to 32 findings per request go to that same-origin address on the app’s own server. Never sent while cloud AI is off for the app or the person. - How to opt out
- Developer: leave out
data-mend-endpointor setdata-mend-cloud="off". Person: the app’s privacy controls orMend.setPrivacy({ cloudAi: false }).
A person’s own choices
- Data
- The signal latency the person picked (Fast, Balanced, Patient or a number of milliseconds) and which of the cloud AI and learning switches they turned off
- Source
- The person, through controls the developer mounts (
Mend.mountLatencyPicker,Mend.mountPrivacyControls) or the app’s own code - Purpose
- Apply and remember the choice on that site
- Where stored
- That site’s browser storage, keys
mend:signal-latency:v1andmend:privacy:v1, written only after the person makes a choice. If storage is blocked, the choice lasts for the page only. - Retention
- Until the person resets the choice (the stored entry is removed) or clears the site’s data
- Shared with
- Switches that are off travel as a
privacyflag with the SDK’s layout requests, and with diagnose and outcome calls where the app’s recovery code and backend pass them on; the latency in effect is recorded in each observation. - How to opt out
- Make no choice, reset to the app default, or clear the site’s data. Developer:
data-mend-user-latency="false"ignores any stored latency.
On a Mend server
Whoever operates a Mend server controls this data: we do for the mend.solutions pilot, and any other server is run by its own operator. Files sit in the server’s data directory with owner-only permissions.
Records as received, before reduction
- Data
- Complete screen-change records and layout findings as an app’s backend or the owner workspace sends them, including labels, element IDs, source labels, event text and positions, the
hotspotlabels and any fallback element ID, plus anyprivacyflags and the workspace demo marker - Source
- Requests to
/api/analyze,/api/transitions/diagnoseand/api/transitions/outcome - Purpose
- Reduce each request to fixed codes and numbers before anything is kept or sent to AI
- Where stored
- Not stored, apart from what transition reports keep. Labels, element IDs (apart from the hashes in transition reports), event text, source labels and positions are discarded during reduction. The one exception is a failed transition’s
hotspotsource label and transition name, kept after the server checks them again unless hotspot labels are off. Layout findings are answered and discarded. - Retention
- Only while the request is handled
- Shared with
- No one in this form
- How to opt out
- Developers can send fewer fields; nothing beyond the reduced form is kept
Transition reports
- Data
- Failure code and type, duration, the signal latency in effect (milliseconds, source and preset), before/after size, opacity and visibility measurements, the expected element’s ID stored only as a one-way hash (an unsalted SHA-256, so anyone who can guess an ID such as “account-panel” can confirm it) and, with a registered redirect, the same kind of hash of the fallback element’s ID, the developer’s source label and transition name for transition hotspots unless hotspot labels are off (a file path and line such as
src/cart/CartButton.tsx:42and a name such as “Open cart”, never the code itself), the diagnosis and its reason (Claude may have written it), how Mend AI routed it (an escalation rule, Mend AI itself, Claude or local rules, and why), a marker when Claude’s answer became a Mend AI correction with Mend AI’s earlier best guess, any notice, the browser verification result with a hash of that observation, the Astra review result and its token counts, and markers when cloud AI or learning was off or the request came from the workspace demo - Source
- Diagnose and outcome requests from the owner workspace or an app’s backend
- Purpose
- Show reports to the developer and suggest a recovery
- Where stored
transition-memory.jsonin the server’s data directory- Retention
- The newest 500 reports (fewer only if the file would pass 3 MB), with no time-based expiry, until the workspace owner deletes them
- Shared with
- The reduced measurements (not the hashes, the hotspot labels, the latency source, the routing or the markers) go to Anthropic Claude when a cloud diagnosis is requested and Mend AI is not confident, and to OpenAI Astra when the operator turns reviews on, unless cloud AI was off when the report was made: that marker keeps it from cloud AI later. Anyone with the gateway login can read reports and transition hotspots in the workspace or the companion app.
- How to opt out
- Workspace owner: Delete learning data → counters and every report; turn hotspot labels off in Settings → Data & AI, which also deletes the labels already stored. Developer: do not send failed records to a Mend server, or add
data-mend-hotspots="off"to keep the hotspot labels out (a registered redirect still sends its fallback ID). Learning off still keeps the report and its outcome, marked, for the developer, but never learns from it.
Mend AI learning (verified outcomes and Claude corrections)
- Data
- Per measurement pattern (a hash of the failure code, the transition type and four yes/no facts such as whether the screen was hidden) and recovery action: how many browser-verified recoveries succeeded and failed (train), and how many times Claude’s validated diagnosis chose that action while Mend AI was unsure (fix). Only the action label is counted, never Claude’s text
- Source
- Recovery outcomes: a success counts only when the browser verified it and, while Astra review is on, Astra agreed. Corrections: Claude diagnoses that passed Mend’s checks; they never count as verified successes.
- Purpose
- Let Mend AI, the small model on this server, answer on its own once verified outcomes make it confident and ask Claude about a transition only when they do not. Correction counts only suggest an action, below automatic recovery, when Claude is unavailable. Mend never uses it to train Anthropic or OpenAI models.
- Where stored
transition-memory.json- Retention
- Up to 2,048 patterns (at most 160 can occur with today’s pattern key) of outcomes and of corrections, with no time-based expiry, until the workspace owner deletes learning data
- Shared with
- No one; never sent to AI providers
- How to opt out
- Workspace owner: turn learning off (no outcomes or corrections are recorded), turn cloud AI off (Claude is never asked, so nothing is corrected) or delete learning data. Developer: pass
{ learning: false }(or a person’s choice) as the recovery controller’sprivacyoption and have the app’s backend forwardprivacywith diagnose and outcome calls. A person’sMend.setPrivacy({ learning: false })and the connect tag’sdata-mend-learning="off"take effect only through that path; on their own they send nothing that is learned from.
Transition hotspots (owner only)
- Data
- Hotspots ranked from stored reports: per developer source label, transition name and type, failure counts, timing medians, verified recovery counts, and a recommendation (resolve, redirect or review) with steps and a code snippet to copy
- Source
- Computed by rules from stored transition reports and outcome counters on each
GET /api/hotspots; no AI is used - Purpose
- Show the developer where transitions fail in their code and whether Mend should resolve in place, redirect to a registered fallback or leave it for review
- Where stored
- Not stored: computed on each request
- Retention
- Only while the request is handled
- Shared with
- Anyone with the gateway login, in the workspace or the companion app; never sent to AI providers
- How to opt out
- Workspace owner: hotspot labels off groups hotspots by transition type only. Developer:
data-mend-hotspots="off".
Monthly AI usage counters
- Data
- Claude and Astra request and token counts for the current month
- Source
- Each cloud AI request
- Purpose
- Enforce the monthly request limits and the usage guardian
- Where stored
usage.jsonandastra-usage.json- Retention
- Replaced when a new month starts
- Shared with
- No one
- How to opt out
- Not needed: counts only, with no content
Mend AI routing counts
- Data
- Per month: transitions diagnosed; how many an escalation rule, Mend AI, Claude or local rules decided; why Mend AI asked Claude (unsure, a failed verification or not yet learned); Claude calls, answers, blocked calls and token totals; Astra reviews and tokens; correction counts and browser-verified outcomes by engine
- Source
- Each diagnosis and recorded outcome on this server, except workspace demo traffic
- Purpose
- Show the owner how often Mend AI handles transitions without Claude, Claude calls per 100 transitions and the estimated AI cost per verified fix
- Where stored
mend-ai-routing.json- Retention
- The newest 13 months
- Shared with
- No one; never sent to AI providers
- How to opt out
- Not needed: counts only, with no content
App Store review summaries
- Data
- Summaries the workspace owner types, with an optional star rating and review ID, and links to verified reports
- Source
- The owner, in Settings → Learn from App Store feedback
- Purpose
- Investigate reported problems
- Where stored
review-feedback.json- Retention
- The newest 100 summaries
- Shared with
- No one; never sent to AI providers
- How to opt out
- Do not add summaries; leave out reviewer names and other personal information
Usage guardian record
- Data
- Guardian settings (including the optional revenue cap: on or off, the share of income and the buffer), the current pause, the last 20 pauses with the figures that triggered them (for a revenue-cap pause, this month’s estimated AI cost and the cap), consecutive provider failure counts and this month’s explanation count
- Source
- The usage guardian and the owner’s settings. Whether a provider error was a credit or spend-limit error is read from at most 4 KB of an HTTP 400 or 429 error body, which is then discarded
- Purpose
- Stop runaway AI usage and keep cloud AI spend within a share of income
- Where stored
guardian.json(hourly call and token counts stay in memory and reset on restart)- Retention
- The last 20 pauses
- Shared with
- No one. An optional Claude Haiku explanation of a pause receives aggregate numbers only (see Anthropic Claude).
- How to opt out
- Not applicable: a safety record with no content
Workspace settings
- Data
- The owner’s cloud AI, learning, hotspot labels and default signal latency choices
- Source
- The owner, in Settings → Data & AI
- Purpose
- Apply those choices on this server
- Where stored
workspace-settings.json, written only after a setting changes- Retention
- Until changed
- Shared with
- No one
- How to opt out
- Change them in Settings → Data & AI
Billing records (only when website billing is on)
- Data
- Workspace billing ID, Stripe customer and subscription IDs, status, plan, billing-period usage, usage reservations and unsent meter events
- Source
- Stripe Checkout and verified Stripe webhooks
- Purpose
- Charge for included and extra AI usage
- Where stored
billing.json, only when billing is enabled- Retention
- The last 24 billing periods, 20 checkout attempts, 100 open reservations and 1,000 unsent meter events
- Shared with
- Stripe receives billing IDs, the plan, return addresses and usage amounts with event IDs and timestamps. Stripe-hosted pages collect card and contact details; Mend never receives card numbers. Webhook events, which can include customer contact details, are processed in memory and not stored.
- How to opt out
- Billing stays off unless the operator enables it; it is not enabled on mend.solutions
Money flow totals (owner only)
- Data
- Stripe balance transactions, subscriptions, invoices and payouts for the operator’s own Stripe account, reduced to totals by day, plan and month. No customer names, emails, addresses, card details, descriptions or raw Stripe IDs are kept or shown; payout IDs are shortened.
- Source
- Stripe, read with read-only requests and the server’s Stripe key when the owner opens Money flow, and every 6 hours while the owner’s revenue cap is on
- Purpose
- Show the owner income, fees, estimated AI and fixed costs, net contribution and AI funding advice, and set the revenue cap
- Where stored
- Not stored: the totals stay in server memory. For the revenue cap, the last 30 days’ net, its currency, test or live mode and the time it was read also stay in memory
- Retention
- Up to 60 seconds in memory; the 30-day net until the next read or a restart
- Shared with
- Only the signed-in owner sees the totals; Stripe receives the read requests
- How to opt out
- Not applicable: the operator’s own accounting view. It reads nothing until a Stripe key is configured
Website subscriber records (only when online checkout is on)
- Data
- For each website subscription: the Stripe customer and subscription IDs, the plan, test or live mode, Stripe’s subscription status, when it started, when its payment cleared, when it was last updated and ended, and whether the owner has sent the workspace login yet (and when). No names, email addresses, postal addresses or payment details.
- Source
- Signature-verified Stripe webhooks, each confirmed by a fresh request to Stripe before anything is kept
- Purpose
- Know who has paid, email each new subscriber a workspace login within 1 business day, and follow renewals and cancellations
- Where stored
customers.jsonin the server’s data directory, written only after the first verified subscription- Retention
- Up to 1,000 subscribers; an ended subscription is removed 90 days after it ends
- Shared with
- Only the signed-in owner, in Money flow. The owner opens each customer in the Stripe Dashboard, where Stripe keeps the contact and payment details.
- How to opt out
- Online checkout stays off unless the operator turns it on. Ask support@mend.solutions about the record we hold for you; it is needed while a subscription runs.
Gateway login
- Data
- The username and password sent with workspace, API and companion-app requests to a hosted server
- Source
- The person signing in
- Purpose
- Let only the owner reach the workspace and API
- Where stored
- On the mend.solutions pilot, the HTTPS proxy keeps only a bcrypt hash of the owner password in its protected configuration. It checks the login and removes it, with any cookies, before a request reaches Mend.
- Retention
- Until the operator changes the password
- Shared with
- No one
- How to opt out
- Not applicable: required for access
Server and proxy logs
- Data
- Operational messages such as startup, certificate renewal and errors. A proxy error entry can include the request method, page and headers, with login and cookie headers left out; the Mend process logs no requests.
- Source
- The Mend process and the HTTPS proxy on the server
- Purpose
- Operate and secure the service
- Where stored
- The server’s system log. On mend.solutions the ingress also counts each client IP address’s connections in memory, for about 60 seconds after its last connection, to limit abuse; that count is never written to disk.
- Retention
- The system log discards the oldest messages as it reaches its size limit
- Shared with
- No one
- How to opt out
- Not applicable
Sent to AI providers
From a Mend server, only when its operator adds a provider’s API key and cloud AI is on, and for transition diagnosis only when Mend AI is not confident. Each provider processes what it receives under its own terms and privacy policy. The improvement loop runs in Mend’s own repository on synthetic data. Mend never sends your data to train Anthropic’s or OpenAI’s models.
Anthropic Claude
- Data
- Layout checks: check type, severity and measurements, with placeholder IDs. Transition diagnosis: failure code, type, duration, signal latency in milliseconds and reduced before/after measurements. After a usage-guardian pause: aggregate usage numbers for an optional short explanation. Never page text, form values, element IDs, labels, URLs, screenshots, source code or review text.
- Source
- Layout checks run automatically when a Claude key is set and cloud AI is on; transition diagnosis only when requested (Ask Claude, or
useCloud: truefrom automatic recovery) and Mend AI is not confident; at most 10 pause explanations a month - Purpose
- Diagnose transitions Mend AI is unsure about and suggest a registered recovery, and explain a usage pause. A validated answer becomes a Mend AI correction unless learning is off
- Where stored
- Mend keeps only the reduced report, Claude’s short reason and, as a Mend AI correction, the action it chose. Anthropic processes requests under its own terms.
- Retention
- At Anthropic: as its terms and privacy pages describe
- Shared with
- Anthropic
- How to opt out
- Workspace owner: cloud AI off or no Claude key; pause explanations can be switched off. Developer:
data-mend-cloud="off"and the recovery controller’sprivacyoption. Person:Mend.setPrivacy({ cloudAi: false }). The usage guardian also pauses cloud AI on its own.
OpenAI GPT-6 Astra (off by default)
- Data
- Reduced before/after measurements of a recovery, the recovery action and whether the browser verified it, sent with
store: false - Source
- Recovery outcomes, only when the operator sets
MEND_AUDIT_ENABLED=1with a separate key - Purpose
- An independent review before a successful recovery is learned
- Where stored
- Mend keeps only the review result and its token counts in the report
- Retention
- At OpenAI: as its API data controls describe;
store: falsedoes not guarantee OpenAI keeps nothing - Shared with
- OpenAI
- How to opt out
- Leave Astra off (the default), turn cloud AI off, or turn learning off (no review is requested)
OpenAI layout path (legacy, off by default)
- Data
- Layout check type, severity and measurements with placeholder IDs, sent with
store: false - Source
- Layout checks, only when the operator sets
AI_PROVIDER=openai - Purpose
- Suggest layout repairs
- Where stored
- Not stored by Mend
- Retention
- At OpenAI: as its API data controls describe
- Shared with
- OpenAI
- How to opt out
- Keep the default
AI_PROVIDER=anthropic, or turn cloud AI off
Mend AI improvement loop (train → fix → iterate, in Mend’s own CI)
- Data
- Aggregate and per-case results (synthetic case IDs, failure codes and counts) of a benchmark on synthetic test transitions generated from a fixed seed in Mend’s source code (
scripts/mend-ai-corpus.mjs), with the current Mend AI rule thresholds and their bounds. Never data from a Mend server, an app or a person - Source
- A scheduled GitHub Actions job on Mend’s own repository, at most 2 Claude requests a night and none while an earlier proposal is still open
- Purpose
- Ask Claude to propose bounded threshold changes so Mend AI asks Claude less often or fixes more synthetic transitions, never with more wrong recoveries
- Where stored
- Not stored on any Mend server. An improving proposal becomes a pull request in Mend’s repository for the owner to review; nothing is merged automatically
- Retention
- Pull requests and job logs as GitHub keeps them; at Anthropic, as its terms and privacy pages describe
- Shared with
- Anthropic (Claude), with a short-lived token from workload identity federation instead of a stored key; GitHub
- How to opt out
- Not applicable: no personal or customer data is used
The website, the owner workspace and support email
mend.solutions and its free demo
- Data
- Page requests from visitors
- Source
- Visitors
- Purpose
- Explain Mend and run the free demo
- Where stored
- Nothing in your browser: no cookies, browser storage, analytics, or third-party scripts or fonts. The demo, including its signal latency choice, runs in page memory and sends nothing. Requests for the pages are covered by “Server and proxy logs”.
- Retention
- The demo clears when the page reloads
- Shared with
- No one. The free demo uses no AI tokens.
- How to opt out
- Not needed
Online checkout on Stripe (only when it is open)
- Data
- What you enter on Stripe’s checkout page: your email address, card or wallet (Apple Pay, Google Pay) details and the billing details Stripe asks for, plus device and browser data that Stripe collects under its own terms
- Source
- You, on Stripe’s hosted checkout page, when you start a website subscription
- Purpose
- Take the subscription payment and send the receipt
- Where stored
- Not stored by Mend. Stripe keeps it; Mend reads back only the IDs, plan and status listed under “Website subscriber records”. A checkout page left unpaid expires after about 30 minutes.
- Retention
- At Stripe: as Stripe’s privacy policy describes
- Shared with
- Stripe, the operator’s payment provider. Mend never receives card numbers. We use your email address only to send your workspace login and answer you.
- How to opt out
- Nothing is collected unless you start a subscription. The free demo and the companion app need no payment. Leaving Stripe’s page without paying ends it.
Owner workspace in the browser
- Data
- The dashboard’s reports, transition hotspots, settings and demo state
- Source
- The workspace owner
- Purpose
- Run the dashboard
- Where stored
- Page memory; no cookies or browser storage. Copy and export create files only when the owner chooses.
- Retention
- Until the page reloads
- Shared with
- Only the Mend server it came from. Its Live playground, and Ask Claude or Verify demo recovery on demo storefront transitions, can call cloud AI; the usage guardian’s demo cut-off stops that. Ask Claude on the dashboard’s own transitions is ordinary owner usage that the guardian still checks.
- How to opt out
- Settings → Data & AI: the demo cut-off switch, or cloud AI off
Google Fonts (owner workspace only)
- Data
- The IP address and browser details of whoever opens the owner workspace, as part of loading fonts
- Source
- Opening the owner workspace
- Purpose
- Load the DM Sans and Manrope fonts
- Where stored
- Google’s servers, under Google’s terms
- Retention
- Set by Google
- Shared with
- Google (fonts.googleapis.com and fonts.gstatic.com)
- How to opt out
- Block those domains; the workspace falls back to system fonts. The public website loads no third-party fonts.
Email to support
- Data
- Your email address and whatever you include
- Source
- You, when you email support@mend.solutions
- Purpose
- Answer you
- Where stored
- Our support mailbox, hosted by Microsoft 365 through GoDaddy
- Retention
- Only as long as needed to help you; deleted sooner if you ask
- Shared with
- Microsoft 365, as the mailbox provider
- How to opt out
- Leave out passwords, API keys and unredacted diagnostic exports, and ask us to delete your messages
The Mend companion app
App Store privacy label: Data Not Collected. The app sends no analytics or usage data and calls no AI provider. Its only network requests are HTTPS GET requests to the Mend server address you enter, to read that server’s status, usage, reports and transition hotspots.
Server connection
- Data
- The server address, gateway username and password you enter, and an optional GitHub repository link
- Source
- You, in the app
- Purpose
- Read and show that server’s status, monthly usage, reports and transition hotspots
- Where stored
- The server address and login in this device’s Keychain (this device only, while unlocked); the GitHub link in the app’s preferences on the device; reports and hotspots in memory only. Copy puts a hotspot’s code snippet on this device’s clipboard only when you choose it.
- Retention
- Until you choose Disconnect and clear saved account. Keychain items can outlive the app, so clear them before deleting it.
- Shared with
- Only the server you enter, through HTTPS GET requests with your gateway login. Nothing goes to AI providers or analytics.
- How to opt out
- Use Try it and the sample reports without connecting, or choose Disconnect and clear saved account
App analytics from Apple (only if you opt in)
- Data
- Aggregated usage statistics and crash reports
- Source
- Apple, only if you chose in your device settings to share analytics with app developers
- Purpose
- Fix and improve the app
- Where stored
- Apple’s developer tools
- Retention
- Set by Apple
- Shared with
- No one
- How to opt out
- Turn off sharing with app developers in your device’s analytics settings
How to opt out
Every switch only reduces data use. A person can turn cloud AI or learning off for themselves but never back on when the app turned it off (the SDK enforces this), and no app or request can turn back on what the workspace owner turned off (the Mend server enforces this).
- A person using an app that includes Mend
- Use the app’s Mend privacy controls if its developer added them (or
Mend.setPrivacy({ cloudAi: false, learning: false })). Cloud AI off keeps layout findings in your browser. For screen-change diagnosis, both switches take effect only where the app passes your choice to its recovery code and its backend forwards it to the Mend server; if you are unsure, ask the app’s developer. - Pick Fast, Balanced, Patient or a custom signal latency in the app’s latency picker, or reset it to the app default.
- Your choices are remembered in that site’s browser storage; clearing the site’s data forgets them. If the app offers no controls, ask its developer.
- Use the app’s Mend privacy controls if its developer added them (or
- An app’s developer
data-mend-cloud="off"on the connect tag keeps layout findings in the browser. Give the recovery controller the same switch (itsprivacyoption) so diagnosis never asks for cloud AI.- Learning: give the recovery controller
privacy: { learning: false }(or a function returning a person’s choice, such as() => preferences.getPrivacy()withcreatePreferencesfrompreferences.js) and forward theprivacyobject with every diagnose and outcome call.data-mend-learning="off"on the connect tag sets the switch the connect API reports, but the tag itself sends nothing that is learned from. - Leave out
data-mend-endpointto keep layout findings in the browser, and adddata-mend-user-latency="false"to keep your own signal latency. data-mend-hotspots="off"on the page’s<html>or<body>or on the connect tag (the whole page, including a recovery controller), or on a marked element or its container, keeps your source labels and transition names out of the records sent for diagnosis, so none reaches a Mend server. In code:hotspots: falseforcreateTransitionRecovery, orprivacy: { hotspots: false }.
- A workspace owner or server operator
- Settings → Data & AI: turn cloud AI off (nothing goes to Anthropic or OpenAI; Mend AI and local diagnosis continue), learning off (new reports are marked, never learned from, Claude’s answers are not kept as Mend AI corrections, and no Astra review is requested) or hotspot labels off (new reports keep no source label or transition name, and the stored ones are deleted).
- Delete learning data: Mend AI’s outcome and correction counters only, or the counters and every transition report.
- Usage guardian: cut off cloud AI for the workspace demo and switch off Claude pause explanations. Or run with no provider keys, and leave Astra review and billing off (the defaults).
- A companion app user
- Use Try it and the sample reports without connecting. Server → Disconnect and clear saved account removes the saved server, login and GitHub link from the device.
- A visitor to mend.solutions
- Nothing to turn off: the website stores nothing in your browser, and its demo, including your signal latency choice, sends nothing.
Optional website subscriptions
Workspace usage billing is disabled by default and is not enabled on the mend.solutions service. Checkout is unavailable until the operator configures Stripe credentials, subscription prices, persistent billing storage, and a verified webhook. The current deployment supports one authenticated workspace per server; it does not provide separate customer or team accounts.
Online checkout on the website is separate. It is off unless the operator sets MEND_PUBLIC_CHECKOUT=on with a Stripe key, prices and a webhook secret. When it is on, a visitor’s checkout link asks the Mend server to open a Stripe-hosted checkout page for the Personal or Developer plan, with a rate limit counted in memory; the page expires after about 30 minutes if unpaid. Stripe collects the email address, payment and billing details. Mend accepts Stripe’s webhook only with a valid signature, re-reads each subscription from Stripe, and records only the IDs, plan, status, payment time and onboarding status listed under “Website subscriber records”. The owner then emails each subscriber a workspace login by hand. The checkout link and that webhook are the only routes on mend.solutions that do not require the owner login.
When configured, a subscription has a monthly base fee and an included allowance measured in the retail dollar value of AI tokens. Provider-reported token usage consumes that allowance; usage above it is billed at the configured retail token rates. The monthly base applies even if no AI is used. Unused allowance does not roll over and is not cash or a provider credit.
The extra-spending limit starts at $0. Cloud requests stop when the included allowance cannot cover them unless the workspace owner increases that limit. Mend reserves an estimated amount before a request, so a request may be blocked before the displayed allowance is fully used. Local checks do not incur AI usage charges. A subscription does not mean every transition receives a cloud review.
Stripe-hosted Checkout collects payment details. Mend sends Stripe billing identifiers, the selected plan, and numeric usage values with event identifiers and timestamps. Stripe’s webhook events, which can include customer contact details, are verified and processed in memory; Mend keeps only the identifiers, status and billing periods listed in the inventory. Mend does not send Stripe AI diagnostic evidence, page content, or provider API keys, and does not collect card details itself. Stripe processes billing data under the operator’s Stripe account terms. The customer portal supports cancellation and payment-method updates when configured; plan changes require operator review. The native companion app is free and has no in-app purchases.
Local storage and retention
The server retains at most 500 reduced diagnosis reports and 2,048 local learning patterns (at most 160 distinct patterns can occur today) on its configured disk, plus current monthly provider usage counters, the usage guardian’s last 20 pauses and the owner’s workspace settings. These are separate from billing records. Browser-only observations disappear on refresh unless exported.
Review feedback has its own limit of the latest 100 summaries, with any supplied rating or source review ID, creation time, and linked recovery metadata. New entries replace the oldest. Duplicate text or source IDs reuse an existing item only while that item remains in retained history. The summaries stay on the configured Mend server and can be retrieved by its authorized workspace user; they are not sent to Stripe or AI providers. There is no per-item deletion interface yet.
When billing is enabled, persistent billing records include the workspace identity, spending limit, Stripe customer and subscription identifiers, subscription status, up to 24 billing periods, and up to 20 checkout attempts. They also retain up to 100 outstanding usage reservations and 1,000 usage events awaiting delivery to Stripe. Completed delivery removes an event from that queue; unresolved reservations or delivery may require operator reconciliation before more cloud use.
Local records survive restarts and remain until replaced through normal operation, removed with the workspace’s Delete learning data action, or removed through an operator-managed process. Do not erase billing state to reset an allowance or resolve a payment problem. Backups, exports, provider records, and Stripe billing records can have separate retention schedules; these local size limits do not define their retention.
Support
For Mend support, contact support@mend.solutions. See the support page for troubleshooting and what to include in a request. Do not email passwords, API keys, or unredacted diagnostic exports.
Choices and launch limits
Local diagnosis works without a provider key. When a Claude key is configured and cloud AI is on, analysis of supported visual findings can request cloud diagnosis automatically. Transition reports use the “Ask Claude” button, or useCloud: true from automatic recovery, to request a cloud diagnosis; Mend AI answers without Claude once it is confident for that measurement pattern. Astra review is disabled by default; the operator must configure a separate key and enable it. Both providers have separate request allowances, and the usage guardian can pause both. With website billing enabled, cloud work also requires an active paid subscription and available usage allowance; the optional usage-guardian pause explanation is the one exception, counted only against the monthly Claude allowance.
The companion app is free and has no in-app purchases. Website subscriptions, when online checkout is open, are paid on Stripe’s hosted checkout page and set up by hand during the pilot; the pilot still has no self-service accounts or team tenancy.
This disclosure describes the implemented pilot. It is not a complete privacy policy, service contract, commercial license, or guarantee of error-free AI output. Read the Privacy Policy for how Mend handles information.