Privacy Policy
How MentorU handles personal information across the platform.
Last updated: August 15, 2026
Platform operator: Kahel Ventures LLC, an Oregon limited liability company, operating MentorU.
Policy Scope
This Privacy Policy explains how MentorU collects, uses, discloses, protects, and retains information when people visit MentorU public pages, create or use accounts, launch or administer workspaces, buy or access provider offerings, communicate through platform tools, or otherwise use MentorU services.
MentorU is a platform used by workspace owners, providers, admins, account users, customers, members, and visitors. Providers may also maintain their own privacy notices for the offerings, customer relationships, content, policies, and communications they control.
Connected Zoom Data
When a workspace owner connects Zoom, MentorU receives the authorizing user's Zoom account and host identifiers, display name, email, granted scopes, token expiration, and OAuth access and refresh tokens. The released integration requests the seven user-managed permissions needed to identify the authorizing user, create, read, update, and delete that user's meetings, obtain a short-lived Zoom Access Key for host start, and obtain a meeting-bound On Behalf Of token for an entitled member's embedded join.
When an authorized mentor schedules a Zoom-backed session, MentorU may process the meeting identifier, topic, scheduled time, duration, timezone, meeting settings, passcode, join URL, and host start information returned by Zoom. MentorU uses this information to keep the MentorU session and Zoom meeting synchronized and to render the exact meeting inside the authenticated MentorU experience.
OAuth access and refresh tokens are encrypted at rest and remain in server-side systems. They are not returned through customer-safe status APIs. For an exact embedded meeting, the authenticated browser may receive a short-lived Meeting SDK signature and either a short-lived, user-associated ZAK issued only after exact tenant, session, meeting, and host authorization, or a meeting-bound OBF token for an entitled member join. MentorU does not persist or log those short-lived credentials.
On a confirmed MentorU disconnect or valid Zoom deauthorization, MentorU immediately disables use of the connection and deletes its usable OAuth credentials and Zoom-derived account fields from active connection storage. Meeting records and secret-free lifecycle and security evidence follow the schedule in the Security and Data Protection Policy. Requests to access or delete retained personal information can be sent to support@mentoru.app and may require identity verification.
MentorU does not sell or rent Zoom-derived data, use it for advertising profiles or surveillance, or disclose it except to Zoom and infrastructure subprocessors that operate and secure the integration, or when legally required.
Information We Collect
We collect information you provide directly, information generated through platform activity, and information received from service providers that help operate MentorU. Depending on how you use the platform, this may include:
- Account and contact data, such as name, email address, phone number, organization, role, login status, profile details, and support requests.
- Provider and workspace data, such as workspace name, brand settings, public-site content, offerings, prices, setup status, admin users, and operational preferences.
- Customer and member data, such as package access, membership status, course or content progress, scheduling activity, form responses, comments, and relationship history within a workspace.
- Content, uploads, and communications submitted through MentorU, including files, images, messages, notes, announcements, comments, event details, and generated or edited workspace materials.
- Payment processor metadata from third-party processors such as Stripe, including customer IDs, connected account IDs, subscription or checkout status, invoice status, amounts, fees, refunds, disputes, and transaction identifiers. MentorU does not store complete payment card numbers.
- Technical and usage data, such as device and browser details, log data, IP-derived approximate location, cookie identifiers, page views, feature interactions, error diagnostics, and analytics events.
How We Use Information
We use information to provide, secure, operate, support, and improve MentorU. This includes using information to:
- Maintain accounts, authentication, workspace access, member access, admin permissions, and platform settings.
- Operate provider workspaces, public pages, checkout flows, content access, scheduling, comments, communications, reporting, and support workflows.
- Process platform subscriptions, provider offering payments, fees, refunds, disputes, invoices, compliance checks, and payment-related support through third-party processors.
- Send service notices, account messages, support responses, transactional email, workspace communications, and optional marketing where permitted.
- Monitor security, debug errors, prevent misuse, enforce terms, maintain audit records, and protect users, providers, customers, members, MentorU, and third parties.
- Measure usage, improve reliability, refine product features, develop new services, and understand how visitors and account users interact with MentorU.
Workspace and Customer Data
Workspace owners and providers control much of the workspace, offering, customer, member, content, and communication data submitted to their MentorU workspaces. MentorU processes that data to provide platform services, maintain tenant separation, support the workspace, and perform actions requested by authorized account users.
Customers and members should understand that information they submit inside a provider workspace may be visible to the applicable provider, workspace admins, invited team members, or other participants when the feature is designed for shared access.
Cookies and Analytics
MentorU may use cookies, local storage, pixels, analytics tools, and similar technologies to keep users signed in, remember preferences, secure sessions, measure page and feature usage, diagnose technical issues, and understand platform performance.
You can control some cookies through your browser settings. Blocking cookies may affect login, workspace access, checkout, personalization, or other platform features.
How We Share Information
MentorU does not sell personal information. We may share information when needed to operate the platform, support users, comply with law, or protect rights and security. This may include sharing with:
- Workspace owners, providers, admins, team members, customers, or members as directed by platform features and workspace permissions.
- Service providers and subprocessors that provide hosting, database, storage, authentication, email, payment processing, analytics, logging, security, customer support, and infrastructure services.
- Payment processors, banks, card networks, fraud-prevention services, tax or compliance providers, and connected-account platforms as needed for payments and financial administration.
- Professional advisors, legal authorities, regulators, or counterparties when required by law, legal process, compliance obligations, dispute handling, or protection of rights, safety, and platform integrity.
- Successors or participants in a business transaction involving MentorU or Kahel Ventures, subject to appropriate confidentiality or transfer safeguards.
Security
We use technical, administrative, and organizational safeguards designed to protect information, including access controls, tenant separation, secure infrastructure providers, monitoring, and restricted administrative access. No internet service can guarantee absolute security, but we work to reduce risk and respond to security concerns.
Additional controls, security-reporting instructions, and operational practices are described in the Security and Data Protection Policy.
Retention
We retain information for as long as reasonably needed to provide the platform, maintain accounts and workspaces, support provider and member relationships, comply with legal, tax, accounting, payment, security, audit, and dispute obligations, enforce agreements, and improve MentorU. Retention periods may vary by data type, workspace settings, legal requirements, and operational need.
When information is no longer needed, we may delete, de-identify, or aggregate it unless retention is required or permitted by law, legitimate business needs, security obligations, backup systems, or provider-controlled workspace requirements.
The current operational retention schedule, including Zoom credentials, short-lived authorization material, meeting metadata, security evidence, support records, and backups, appears in the Security and Data Protection Policy.
Your Choices and Privacy Requests
Depending on your location and relationship to MentorU, you may have rights to request access, correction, deletion, portability, restriction, objection, opt out of certain communications, or withdraw consent where processing depends on consent. You may also update some account information directly through platform tools.
To make a privacy request, contact support@mentoru.app. We may need to verify your identity, clarify the workspace or account involved, and coordinate with the applicable provider when the request concerns provider-controlled customer, member, content, or communication data.
Children and Sensitive Information
MentorU is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Do not submit sensitive personal information, regulated information, or confidential third-party information unless you have the legal right to do so and the platform feature is appropriate for that use.
Providers using MentorU for youth programs must also follow the Minors and Youth Program Policy.
Related Platform Policies
Provider communications, uploaded content, checkout activity, and AI-assisted tools may also be governed by MentorU's Communications and Email Policy, Copyright and Intellectual Property Policy, Customer Purchase Terms, and AI and Automation Policy, as well as the Security and Data Protection Policy.
International Use
MentorU is operated from the United States. If you access MentorU from another location, your information may be processed in the United States or other jurisdictions where MentorU or its service providers operate.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the date on this page and may provide additional notice when appropriate.
Contact
If you have questions about this Privacy Policy or how MentorU handles information, contact support@mentoru.app.