MENTAT PRIVACY POLICY
1. Two roles.
For the data your organization's users put into Mentat, we act as a processor on your organization's behalf, and that data is governed by the Cloud Service Agreement and the Data Processing Addendum. For our own account, billing, and website data, we act as a controller.
2. Data we process as a processor, on your organization's behalf.
Handled only to deliver the service, under your organization's instructions and the DPA:
- Technician voice input, the audio memo itself, which contains the technician's voice and may contain spoken job or customer details.
- Transcripts of that audio, plus confidence and duration.
- The recommendations extracted from the transcript.
- Technician identifiers: name for attribution and phone number for matching call-in recordings.
- Job and estimate data synced with your field-service system.
3. Data we process as a controller, for our own purposes.
- Authorized-user account data: names and work emails, and authentication handled through our identity provider.
- Billing and contract contacts.
- Support communications you send us.
- Website analytics on mentathq.com: cookieless, no cross-site tracking.
4. AI processing.
Mentat's recommendations are generated by a large language model and always pass through human operator review before they become a customer-facing estimate. We do not train models on identifiable customer data.
5. Subprocessors.
We use a small set of service providers that process personal data on our behalf to deliver the service. The current list, including each provider's role and the categories of data it touches, is maintained at mentathq.com/subprocessors. We update that page when the list changes and give organizations with a signed Data Processing Addendum advance notice per its terms.
Your field-service system, such as Jobber or ServiceTitan, is your own system that Mentat connects to under your authorization. It is not our subprocessor.
6. Retention.
- Voice audio: we delete the raw recording 30 days after capture. It is kept only to complete processing and provide a short quality-and-dispute buffer. We keep no long-term audio archive.
- Transcripts and structured data: retained for the term of your subscription, returned or deleted on termination as set out in the DPA.
- Account data: retained while your account is active and for a reasonable period afterward for legal and administrative purposes.
7. Security.
Data is encrypted in transit. Access to your data is scoped and tenant-isolated. Every AI output passes a human review gate before it acts on anything.
8. Your rights and your users' rights.
For service data, where we act as a processor, requests from individuals are directed to your organization as the controller, and we assist you in responding. For account data, where we are the controller, contact us at the address below.
9. International transfers.
We operate in the United States, and our service is built for US businesses. If any personal data originates in the EU or UK, transfers are handled under the DPA and its standard contractual clauses. We expect this to be minimal.
10. Children.
Mentat is a business tool, not directed to children, and we do not knowingly collect their data.
11. Changes and contact.
We version this policy and date each version. Material changes are announced and, for in-product acceptance, re-accepted at sign-in. Contact: [email protected]. Fieldcraft Systems, Inc.