Legal
Privacy Policy
This policy explains what personal data Mentalist collects, why we collect it, who we share it with, and the choices you have. It covers the trymentalist.com website, the Mentalist application, and the data we process from accounts you connect to it.
Last updated 29 July 2026
Scope & roles
Mentalist (“Mentalist”, “we”, “us”) provides an AI prospecting agent for sales teams: it researches your market, builds lists of relevant people and companies, and sends outreach from accounts you connect.
Two different kinds of personal data flow through the product, and our role differs for each:
- Your data as a user — your account, your workspace, your billing details and the credentials of the mailboxes and LinkedIn accounts you connect. For this data we act as the controller, and this policy is our notice to you.
- Data about the prospects you target — the people your workspace sources, enriches and contacts. For this data your organisation decides who is contacted and why, so your organisation is the controller and Mentalist acts as a processor on your instructions. You are responsible for having a lawful basis for that outreach.
Data we collect
Account and workspace data
When you sign in with your Google Workspace account we receive your name, email address, profile picture and Google account identifier. We create an organisation for you and store your role in it, the teammates you invite (their email addresses), and your invitation status.
Onboarding and configuration data
What you tell us about your company and your ideal customer profile: your website, your market, your personas and targeting filters, your campaigns, and the knowledge you give the agent. Some of this is enriched from public web sources (see AI processing).
Connected account data
OAuth tokens and account identifiers for the mailboxes and LinkedIn accounts you connect, plus the message content required to send outreach and show you replies. Details are in the two sections below.
Usage, billing and technical data
- Activity — the actions the agent and your team take in the product (leads sourced, messages sent, credits spent), kept as an audit trail in your workspace.
- Billing— plan, subscription status and credit balance. Card details are entered on Stripe’s hosted pages and never reach our servers; we store only Stripe’s customer and subscription identifiers.
- Technical logs — IP address, browser/user-agent, timestamps and error traces generated by our hosting and authentication providers, used for security and debugging.
Google user data
Signing in uses only identity scopes (openid, email, profile). The Gmail, Calendar and Postmaster permissions are requested separately, later, when you choose to connect a mailbox — and only for the purposes listed here:
You can disconnect a mailbox from Mentalist at any time in Settings → Connections, and revoke our access entirely at myaccount.google.com/permissions. Revoking access stops all sending immediately; we delete the stored tokens and the synced message content associated with that mailbox.
LinkedIn account data
If you connect a LinkedIn account, that connection is operated through our provider Unipile. We receive an account identifier and the session credentials Unipile holds on your behalf, your basic LinkedIn profile, and the connection invitations and messages sent through Mentalist together with their status.
We use this only to send the invitations and messages you or the agent approve, to record them in your workspace, and to show you their outcome. You can disconnect the account at any time in Settings → Connections, and change your LinkedIn password to invalidate the session.
Prospect data
To do its job the agent builds and enriches records about potential buyers: name, job title, employer, professional location, public profile URLs, business email addresses where available, and the public signals that make them relevant now (for example a job posting, a funding announcement or a leadership change).
This data comes from publicly available and commercially available sources — company websites, public professional profiles, news, job boards and our search and enrichment providers — and from data you or your teammates enter or import. It is business contact data used for business-to-business outreach.
Prospect records are stored per organisation and isolated by row-level security so one workspace cannot read another’s. Where a person or company has already been researched, we may reuse the de-duplicated public record across workspaces to avoid re-collecting the same public information; the campaigns, notes, messages and enrichment tied to your use of it stay private to your workspace.
How we use data
- Provide the service: authenticate you, run your workspace, source and enrich leads, draft and send outreach, and show you replies and results.
- Meter usage: count credits, enforce plan limits, and apply referral or bonus credits.
- Bill you: create and manage subscriptions and invoices through Stripe.
- Keep the service safe and working: prevent abuse and fraud, investigate incidents, debug failures, and maintain audit trails.
- Support you: answer your questions and, when you ask us to look into something, inspect the relevant part of your workspace.
- Improve the product: understand aggregate usage patterns and failures. We do not use your connected mailbox content to train generalised AI models.
- Comply with law: meet our legal, tax and accounting obligations and respond to lawful requests.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
AI processing
Mentalist is an AI product: it uses large language models and web search to research companies, build ICP personas, decide who is worth contacting, and draft messages in your own words.
- OpenAI — used through its API to synthesise company and ICP research and to draft outreach copy. Data sent through the OpenAI API is not used by OpenAI to train its models.
- EXA — a web search and content API used to gather the public web context behind our research and signals.
The inputs we send are the research prompts, the company and prospect context needed for the task, and the knowledge you gave the agent. AI output is generated automatically and can be wrong; outreach is reviewable, and you remain responsible for what your workspace sends. No automated decision with legal or similarly significant effects on an individual is made by the product.
Legal bases (EEA/UK)
- Contract — to give you the service you signed up for, including running your workspace and sending from the accounts you connect.
- Legitimate interests — to secure the service, prevent abuse, keep audit trails, and understand aggregate usage. For prospect data used in B2B outreach, your organisation relies on its own legitimate interest as controller.
- Consent — for the Google Workspace and LinkedIn permissions you grant, and for any optional communications. Withdrawable at any time.
- Legal obligation — for accounting, tax and responses to lawful requests.
International transfers
Some providers above are established in the United States. Where personal data leaves the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), or on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified. You can ask us for details of the safeguards in place.
Retention
- Account, workspace and configuration data: while your account is active, then deleted or anonymised within 90 days of account closure.
- Connected-account tokens: until you disconnect the account or revoke access, then deleted.
- Synced message content: while the connected account remains connected; deleted with the connection.
- Prospect records and campaign history: while your workspace needs them, and deleted on request or with the workspace.
- Billing records: as long as tax and accounting law requires (typically 10 years).
- Security and technical logs: typically up to 12 months.
Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Every application table is isolated per organisation with Postgres row-level security, and privileged operations run through audited server-side functions rather than from the browser. Secrets and provider keys are held in server-side environment configuration and are never exposed to the client. Access to production data is limited to the people who need it.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority as required by law.
Your rights
Depending on where you live you may have the right to access, correct, delete, port or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents additionally have the rights to know, delete, correct and opt out of “sale” or “sharing” — which we do not do — and not to be discriminated against for exercising them.
Write to privacy@trymentalist.com and we will respond within one month. You can also complain to your local data protection authority. If your organisation administers your workspace, we may forward your request to it.
If Mentalist contacted you
If you received an email or LinkedIn message sent through Mentalist, the sender is the customer whose name appears on it — they chose to contact you and they control the data behind it. Reply to them to unsubscribe, object, or ask what data they hold.
You can also write to privacy@trymentalist.com with the message you received. We will identify the customer responsible, pass on your request, and — where we are able to act ourselves — suppress your details so they are not sourced again.
Children
Mentalist is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes. The date at the top always reflects the current version, and we will notify account owners by email or in-product before a change that materially reduces your rights takes effect.
Contact
Mentalist — privacy questions and data requests: privacy@trymentalist.com. Everything else: legal@trymentalist.com.
See also our Terms of Service.