← Back to app

Legal

Privacy Policy

Last updated: June 2026  ·  Effective date: June 2026

Mentorise is operated from the United Kingdom. This policy explains what personal data we collect, why we collect it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are based in California, additional rights under CCPA are described in our Data & Compliance page.

1. Who we are

Mentorise ("we", "us", "our") is a career-mentorship platform that turns professional CVs into interactive, AI-powered profiles. We are the data controller for the personal data described in this policy.

Contact: hello@mentorise.co.uk

2. Data we collect and why

Account information

DataPurposeLegal basis
UsernameIdentify your accountContract performance
Email addressPassword reset, weekly digest emailsContract performance / Consent (digest)
4-digit PIN (bcrypt hash — never stored in plain text)Authenticate youContract performance
Invite code used at registrationAccess controlContract performance
Onboarding answers (goals, interests)Personalise your experienceLegitimate interests
Email digest opt-in preferenceDetermine whether to send weekly summariesConsent

CV and career profile data

DataPurposeLegal basis
CV file (PDF)Extract career history for your profileContract performance
Extracted career timeline, education, skillsGenerate AI clarification questions and your public profileContract performance
Your answers to AI-generated questionsBuild your public career profileContract performance
Profile corrections and supplementary Q&AKeep your profile accurateContract performance
Privacy exclusions (topics you want hidden)Honour your privacy preferences in profile responsesContract performance

Conversation data

DataPurposeLegal basis
Questions you ask other profiles; answers returnedPersonalise your experience; improve signal matchingLegitimate interests
Questions others ask your profile; answers returnedProvide the mentorship service; generate weekly digestContract performance
Inferred interest signals from conversation patternsSurface relevant profiles and career insightsLegitimate interests

Analytics

DataPurposeLegal basis
Anonymous session ID (stored in browser localStorage, not a cookie)Understand aggregate usage without identifying individualsLegitimate interests
Page visit timestamps, session duration, last screen viewedProduct analytics and improvementLegitimate interests
Your user ID associated to page visits once logged inUnderstand how registered users navigate the productLegitimate interests

Support and bug reports

If you submit a bug report, we store the text you provide along with your username. We use this solely to investigate and resolve the issue.

3. Cookies and local storage

NameTypeDurationPurpose
user_idHTTP cookie (HttpOnly, Secure, SameSite=Lax)7 daysKeeps you signed in
_anon_idBrowser localStorageUntil clearedAnonymous analytics identifier

We do not use advertising cookies, third-party tracking cookies, or any cookies from Google, Meta, or other ad networks.

4. How we use AI (OpenAI)

We use OpenAI's API (model: GPT-4o-mini) to:

To do this, we send relevant parts of your CV content, answers, and conversation context to OpenAI's API. OpenAI is based in the United States. We rely on OpenAI's Data Processing Agreement and Standard Contractual Clauses as the legal basis for this international transfer. OpenAI's privacy practices are described at openai.com/privacy.

We do not use your data to train OpenAI models. OpenAI's API terms prohibit training on API-submitted data by default.

5. Email communications

We send two types of email:

6. Data retention

Data categoryRetention period
Account and profile dataUntil you request deletion of your account
Uploaded CV (PDF file)Until your account is deleted
Conversation logsUntil your account is deleted
Analytics (page visits)Retained indefinitely in aggregated form
PIN reset tokens7 days (tokens expire and are invalidated after use)
Bug reportsUntil resolved or account deleted

7. Your rights under UK GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, email hello@mentorise.co.uk. We will respond within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

8. Data security

We implement appropriate technical and organisational measures to protect your personal data, including:

9. Children

Mentorise is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or by a notice on the platform. Continued use of Mentorise after changes take effect constitutes acceptance of the revised policy.

11. Contact

For any privacy-related questions or requests: hello@mentorise.co.uk