Legal — Mentage LLC
MEVA Platform · Effective Date: April 8, 2026
Note: MEVA is a general wellness platform. It is not a medical device, clinical assessment tool, diagnostic instrument, or screening instrument, and is not intended to diagnose, treat, cure, mitigate, prevent, or monitor any disease or medical condition.
Contents
Section 1
This Privacy Policy ("Policy") describes how Mentage LLC ("Mentage," "we," "us," or "our") collects, uses, stores, discloses, and protects information in connection with your access to and use of the MEVA platform, including all associated websites, applications, and services (collectively, the "Service").
MEVA is a general wellness platform. It is not a medical device, clinical assessment tool, diagnostic instrument, or screening instrument, and is not intended to diagnose, treat, cure, mitigate, prevent, or monitor any disease or medical condition.
This Policy governs information collected through the Service. It does not apply to information collected by third parties, including third-party websites or services linked from or integrated with the Service.
By creating an account or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not create an account or use the Service.
Section 2
Mentage collects the following categories of information in connection with the Service:
Account Registration Information
When you create an account, we collect your email address and password. Account access is managed through an authentication service.
Technical Data
We collect limited technical data necessary to operate, maintain, and secure the Service. This includes: (a) IP address; (b) User Agent and browser details; and (c) error logs, collected automatically through standard server-side processes. Access logs are retained for security, fraud prevention, and operational purposes. See Section 8 for retention details.
Device and Session Data
When you sign in, the Service uses first-party browser storage scoped to the Mentage application domain to maintain your authenticated session. This information is used for authentication and session management only, not for behavioral advertising, analytics, or third-party tracking. You can clear this data at any time by signing out of the Service or clearing your browser's local storage.
Payment Transaction Data
Subscription and token purchases are processed through Stripe's hosted checkout, which operates on Stripe's own domain (checkout.stripe.com). You are redirected to Stripe's hosted checkout page to complete any purchase. No payment card data is transmitted through or processed on the Mentage application domain. Mentage does not directly receive or store your full payment card number. Mentage may receive from Stripe limited transaction metadata — including payment confirmation, transaction identifiers, card type, and the last four digits of your card number — for subscription management and recordkeeping.
User-Submitted Information
Depending on the features you use, you may submit information, responses, wellness data, or other content in the course of using the Service. See also Section 8A of the Terms of Service (User-Submitted Content).
Consent Records
When you complete the onboarding consent flow, Mentage records your acceptance, including the fact of your acceptance, the version of the terms accepted, and the date and time of acceptance. Certain consent records may be retained after account deletion for legal, contractual, research, or dispute-resolution purposes, as described in Section 8.
Provider-Originated Data — Business Associate Context
In certain arrangements where Mentage provides services on behalf of a healthcare provider or covered entity under a signed Business Associate Agreement ("BAA"), Mentage may receive, store, or transmit protected health information ("PHI") as defined under HIPAA. See Section 14 for details, including important disclosures regarding the current platform architecture.
Section 3
Mentage collects information in the following ways:
Directly from you: when you register for an account, make a purchase, use Service features, or communicate with us.
Automatically: when you access the Service, through standard server-side infrastructure, including IP address, User Agent and browser details, and server-side access logs
Through authentication session storage: when you sign in, session credentials are stored in your browser's local storage as described in Section 2.
From Stripe: Mentage receives limited transaction metadata from Stripe following a completed purchase as described in Section 2.
Within the authenticated MEVA application, Mentage does not embed third-party analytics tools, advertising trackers, or third-party behavioral data collection software. Mentage does not collect biometric identifiers or precise physical location data.
Section 4
Mentage uses collected information for the following purposes:
To provide, operate, maintain, and improve the Service;
To create and manage your account, authenticate your identity, and process transactions;
To process payments and manage subscriptions through Stripe;
To communicate with you about your account, transactions, service updates, and support inquiries;
To detect, investigate, and prevent fraud, unauthorized access, and other illegal or harmful activities;
To enforce our Terms of Service and other applicable agreements;
To comply with applicable legal obligations, respond to lawful requests, and protect the rights, property, or safety of Mentage, our users, or others; and
For any other purpose disclosed to you at the time of collection or with your consent.
Section 5
Mentage does not sell your personal information.
Mentage may disclose information in the following circumstances:
Service Providers
Mentage shares information with third-party service providers that perform functions on our behalf, including cloud infrastructure and hosting providers, an authentication service provider, and Stripe (payment processing). These providers access information only as necessary to perform their functions and are subject to contractual obligations regarding the protection of your information.
Legal and Regulatory Compliance
Mentage may disclose information as required by applicable law, regulation, legal process, or valid governmental request, or where Mentage reasonably believes disclosure is necessary to prevent or investigate fraud, enforce these Terms, or protect the rights, property, or safety of Mentage, our users, or others.
Corporate Transactions
In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, your information may be transferred or disclosed as part of that transaction, subject to customary confidentiality arrangements.
With Your Consent
Mentage may share information when you direct us to do so or otherwise provide your consent.
Section 6
Subscription and token purchases are processed exclusively through Stripe's hosted checkout, operating on Stripe's own domain (checkout.stripe.com). When you initiate a purchase, you are redirected from the Mentage application to Stripe's domain to complete the transaction. No payment processing code from Stripe runs on the Mentage application domain, and no Stripe-originated cookies or storage entries are set on the Mentage application domain.
Stripe may set its own cookies or storage entries on checkout.stripe.com in accordance with Stripe's own privacy policy. Those technologies are scoped to Stripe's domain and are not accessible to or controlled by Mentage. For information about Stripe's privacy and security practices, visit stripe.com/privacy.
Mentage may receive from Stripe limited transaction metadata for subscription management and recordkeeping: payment confirmation status, transaction identifiers, card type, and the last four digits of your card number.
Section 7
The Service is hosted using reputable third-party cloud infrastructure located in the United States. Mentage uses backup and recovery processes designed to protect against accidental data loss. Mentage selects infrastructure providers that maintain industry-recognized security certifications and practices.
Section 8
Mentage retains personal information for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal, contractual, research, and operational requirements.
Account and Profile Information. Mentage retains account information for the duration of your account and for a reasonable period following account closure, sufficient to resolve disputes, fulfill contractual obligations, respond to legal requests, and complete security and fraud investigations.
Activity and Engagement Data. Engagement records are retained for the duration of the user relationship and for a reasonable period thereafter, consistent with longitudinal reporting purposes, research obligations, and applicable legal requirements.
Authentication and Access Records. Authentication and access records are retained for as long as reasonably necessary to protect account security, investigate suspected misuse, prevent fraud, comply with legal obligations, and resolve disputes.
Consent and Authorization Records. Certain consent records may be retained after account deletion when reasonably necessary to document your acceptance, comply with legal or research obligations, resolve disputes, or enforce agreements. Where appropriate, Mentage may reduce or remove identifying information associated with those records.
Technical and Log Data. Server-side access logs and diagnostic data are retained for security, operational, and fraud-prevention purposes. Log data is treated as a distinct retention category from account data.
Payment Records. Transaction metadata received from our payment processor is retained consistent with applicable accounting and tax requirements.
Backup and Recovery Data. Personal information may remain temporarily in backup and recovery systems after deletion from active systems. Backup data is retained for disaster recovery and business continuity purposes and is deleted or overwritten according to Mentage's backup retention schedule.
Research Data. Where Mentage collects data in connection with an IRB-approved research study, that data is governed by the applicable research protocol, consent form, and any applicable regulatory requirements, which may require retention periods that differ from standard account data.
Legal Holds. Data subject to a legal hold, pending litigation, regulatory investigation, or other legal obligation will be retained for the duration of that obligation regardless of otherwise applicable retention periods.
To request deletion of your account or personal information, contact info@mentage.com. Mentage will process verified deletion requests in accordance with applicable law, subject to the retention exceptions described in this Section.
Section 9
These measures include encryption of data in transit and at rest, authentication and access controls, continuous threat monitoring, security event logging and audit trails, web application firewall protections, backup and recovery procedures, and administrative controls governing access to personal information.
No method of electronic transmission or storage is completely secure. Although Mentage uses safeguards designed to protect personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and should notify us promptly if you suspect unauthorized account access.
Section 10
Within the authenticated MEVA application, Mentage does not embed third-party analytics tools, advertising trackers, or third-party behavioral data collection software.
Authentication Session Storage
When you sign in, the Service uses first-party browser storage scoped to the Mentage application domain to maintain your authenticated session. This information is used for authentication and session management only, not for behavioral advertising, analytics, or third-party tracking. Session data is cleared when you sign out.
Stripe Checkout
Subscription and token purchases are processed through Stripe's hosted checkout, which operates exclusively on Stripe's own domain (checkout.stripe.com). When you are redirected to Stripe's checkout page, Stripe may set its own cookies or storage entries on its domain in accordance with Stripe's privacy policy. Those technologies are scoped to Stripe's domain and are not accessible to or controlled by Mentage. No Stripe cookies or storage entries are set on the Mentage application domain.
Server-Side Technical Data
The Service collects limited technical data through standard server-side processes as described in Section 2, including IP address, User Agent and browser details, and server-side access logs. This data is collected server-side and does not involve browser cookies or client-side tracking technologies.
Website Analytics
The Mentage public marketing website (mentage.com) uses Google Analytics (GA4) and Google Tag Manager (GTM) for website traffic analysis and marketing optimization. These tools may set cookies or use similar technologies on the marketing website to collect information such as pages visited, referral sources, browser type, device type, and general geographic region. This information is used to understand how visitors interact with the marketing website, to improve the website, and to measure the effectiveness of communications.
Google Analytics and Google Tag Manager operate only on the public marketing website. They are not embedded in the authenticated MEVA application.
Google may process this information in accordance with Google's privacy policy. You can opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on or by adjusting your browser's cookie settings.
Mentage does not use website analytics data gathered through cookies or similar technologies to sell personal information or to share personal information for cross-context behavioral advertising as those terms are defined under applicable state privacy laws.
Section 11
The Service is not directed to children under 13 years of age. Mentage does not knowingly collect personal information from children under 13. If Mentage learns that a child under 13 has provided personal information through the Service, Mentage will take commercially reasonable steps to delete that information promptly. If you believe a child under 13 has provided personal information to Mentage, contact us at info@mentage.com.
Section 12
Account Information
You may review and update certain account information by accessing your account settings or by contacting info@mentage.com.
Deletion Requests
You may request deletion of your account and associated personal information by contacting info@mentage.com. Mentage will process verified deletion requests in accordance with applicable law, subject to the retention exceptions described in Section 8.
Communications
You may opt out of promotional communications by following the unsubscribe instructions in those messages. You may not opt out of transactional or account-related communications necessary for account management and service delivery.
Section 13
Certain U.S. state privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), and the Connecticut Data Privacy Act ("CTDPA"), among others — may provide residents of those states with specific rights regarding their personal information, including the right to know what personal information is collected, to request correction or deletion, to opt out of the sale or sharing of personal information for targeted advertising, and to not be discriminated against for exercising these rights.
Mentage does not sell personal information as that term is defined under applicable state privacy laws.
If you are a resident of a state with an applicable privacy law and wish to exercise rights available to you, contact us at info@mentage.com. Mentage will respond in accordance with applicable law.
Section 14
This Section applies only in arrangements where Mentage acts as a Business Associate under a signed Business Associate Agreement.
In certain provider-facing arrangements, Mentage may receive, store, or transmit PHI on behalf of a covered entity pursuant to a signed BAA. In those limited circumstances, Mentage acts as a Business Associate as defined under HIPAA and will use and disclose PHI only as permitted under the applicable BAA and HIPAA.
The direct-to-consumer MEVA platform is not presented as HIPAA-regulated by default. Information submitted by a direct-to-consumer user who is not associated with a covered entity's BAA arrangement is not intended to be treated as PHI under HIPAA solely because it is submitted through the Service.
Nothing in this Policy is intended to expand or limit Mentage's HIPAA obligations beyond what is required by applicable law and any applicable BAA.
Section 15
Mentage may update this Policy from time to time. If Mentage makes material changes, it will post the updated Policy on the Service with a new Effective Date and may provide additional notice by email or in-app notification. Your continued use of the Service after the effective date of any revised Policy constitutes your acknowledgment of the revised practices.
Section 16
Questions or concerns regarding this Policy should be directed to:
Mentage LLC
Email: info@mentage.com