Loading
Loading
Effective April 28, 2026 · Version 3.0
This Privacy Policy explains what personal data Mentorly collects, why we collect it, how we use and share it, and the rights you have over it. We aim to collect as little as possible and to be specific about what each piece is for.
This Privacy Policy applies to mentorly.io, its subdomains, and any service or feature that links to this policy (collectively, the "Platform").
For users in the European Economic Area, United Kingdom, and Switzerland, Mentorly is the data controller for personal data we collect about you. For data that mentors collect from their own students through their own external services (Whop, Discord, etc.), each mentor is an independent controller and Mentorly is not responsible for that processing.
Account & profile. Email address, hashed password (bcrypt), display name, headline, bio, niche, market focus, profile and banner images, social and pricing links, optional TOTP secret and hashed recovery codes if you enable 2FA, and the timestamp of your last sign-in.
Submitted performance data. CSV trade history files, derived performance metrics (total trades, net P&L, win rate, drawdown, profit factor, monthly consistency), and the file name of the most recent upload. Files are stored in private object storage (not publicly served) and only metrics are surfaced on your public profile.
Performance proof artifacts (mentors only). Broker statements, account summaries, CSV exports, tax documents, and trading-platform screenshots you upload during onboarding. Stored privately and accessed only via short-lived signed URLs minted for Mentorly admins. Never publicly displayed.
Identity verification result. A boolean "identity verified" flag, the Stripe Identity session id, the verification status, and timestamps. We do not receive, access, or store your government ID, selfie, or any biometric data, those remain with Stripe under their privacy policy.
Verification calls. Scheduled time, completion status, reviewer admin id, and free-text notes describing the consistency observed during the call. We do not record audio or video.
Agreement acceptance records. For each agreement you accept (Terms, Privacy, Mentor Agreement, Risk Disclosure, Non-Advisory, Post-Verification), we record: the agreement type, the version, the timestamp, a SHA-256 hash of your IP address (never the raw IP), and the user-agent string of your browser. This is required to prove informed consent in case of a dispute.
Reviews, leads, community posts. Author handle, optional email (kept private), the rating, title, body, source, and a hash of the submitter's IP address for spam detection.
Watchlist reports. The submitter (if signed in) or the submitted email, the named subject, optional aliases, evidence URLs, source links, free-text description, status, and dispute history. The IP address is hashed.
Operational data. Audit log entries (action, optional userId, raw or hashed IP, user-agent, JSON metadata) and admin action logs. Sessions store a hashed session token and last-seen timestamp.
Payments. Mentorly never sees your full card number. Stripe stores card data; we receive the Stripe customer id, subscription id, invoice metadata, and payout records.
Cookies & local storage. See Section 8.
We process personal data for the purposes below. Where the GDPR applies, the legal basis is shown in brackets.
We do not sell personal data, run advertising on the Platform, profile users for behavioural ads, or share personal data with third-party advertisers.
Mentorly uses a small set of vetted subprocessors. Each one is bound by a data-processing agreement and processes only the data necessary for its function.
We may share personal data with: (a) law enforcement or regulators when legally required; (b) professional advisers (lawyers, accountants, auditors) under confidentiality; (c) a successor entity in a merger, acquisition, or sale of assets, in which case affected users will be notified.
When a mentor begins identity verification, they are redirected to Stripe Identity. Stripe collects the government ID, selfie, and any related biometric data and processes them under Stripe's own privacy policy (stripe.com/privacy). Mentorly never sees and never stores those documents. We receive only:
identityVerified flag,If you wish Stripe to delete your identity records, follow Stripe's data-subject request process directly with them.
Proof documents and screenshots uploaded by mentors are validated (file-type magic-byte sniff, SVG/HTML/JS rejected, 25 MB cap), stored in a directory that is never served by the public web server, and accessed only via short-lived (5-minute) HMAC-signed URLs minted server-side for authenticated Mentorly admins. The signed URL contains the storage key and expiry encoded in a base64-url payload, signed with a server-side secret. Public users never see proof artifacts.
Mentors may delete their own proof artifacts from the dashboard. Admins may delete artifacts with reason logged in the admin action log.
Every acceptance of an agreement (Terms, Privacy, Mentor Agreement, Risk Disclosure, Non-Advisory, Post-Verification) is stored with: the agreement type, the version string, the timestamp, the SHA-256 hash of your IP address (the raw IP is never persisted), and the user-agent header sent by your browser. We retain these records for the lifetime of the account plus six (6) years to defend against contract disputes.
We keep personal data only as long as necessary for the purposes described in Section 3, or as required by law.
A daily retention sweep (npm run data-retention) enforces these timelines automatically.
Subject to applicable law you may have the right to:
California residents have additional rights under the CCPA/CPRA, including the right to know what categories of personal information have been collected and the right to opt out of the "sale" or "sharing" of personal information. Mentorly does not sell or share personal information as those terms are defined under the CCPA/CPRA.
To exercise any right, email privacy@mentorly.io from the address on your account, or use the in-product data export and delete tools (when enabled). We respond within 30 days.
Mentorly is operated from the United States. If you access the Platform from outside the US, your personal data is transferred to and processed in the US. For users in the EEA, UK, and Switzerland, Mentorly relies on the European Commission's Standard Contractual Clauses and equivalent UK and Swiss Addenda with our subprocessors to ensure an adequate level of protection. You may request a copy of the relevant clauses by emailing privacy@mentorly.io.
The Platform is not directed at children under 18 and we do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted personal data, contact privacy@mentorly.io and we will delete it.
We use industry-standard security measures: HTTPS in transit, encrypted database storage at rest, hashed passwords (bcrypt), HMAC-signed download URLs, IP-hashed audit trails, file-type validation, rate limiting, optional TOTP-based 2FA, and bot protection (Cloudflare Turnstile) on public submission forms.
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay. For security disclosures, see /.well-known/security.txt.
Mentor rankings and the "consistency review" that admins consult are generated algorithmically from self-reported data. No solely automated decision is made about you that produces legal or similarly significant effects. An admin reviews every onboarding decision (acceptance, proof approval, publication) before it takes effect. Algorithmic outputs are advisory only.
We may update this Privacy Policy. Material changes will be announced on the Platform or by email at least 14 days before they take effect. The version and effective date at the top of this page indicate the current version.
Privacy / data subject requests: privacy@mentorly.io
EU/UK representative: appointed on request, contact privacy@mentorly.io.
Postal address: provided on request to verified data subjects.
Mentorly is a neutral directory. We do not provide financial advice or endorsements. Read also our Terms, Privacy Policy, Mentor Agreement, Risk Disclosure, Non-Advisory Agreement, Cookies, and Refunds.