Privacy Policy
Effective date: 2026-08-17.
Mentrox is built by BunBun Labs Limited (“we”, “us”), a company registered in the United Kingdom. This policy explains what we collect, why, and what you control. We wrote it to be read.
1. What Mentrox is
Mentrox is a non-clinical follow-through assistant. You send a daily voice note describing your plan; Mentrox runs check-ins and shows you what you said versus what you did. It is not a medical device, does not diagnose, and does not provide treatment advice.
2. What we collect
- Your messages and voice notes. Plan notes, check-in replies, and chats with the assistant. Voice notes are transcribed to text; audio is processed to produce the transcript.
- Your plan and follow-through ledger. The blocks you planned, when you confirmed starting, and outcomes (done / rolled / split). This is the core of the product.
- Account basics. Your Telegram account identifier, contact email, time zone, and subscription status. We do not collect your date of birth, biometrics, or precise location.
- Wearable data — only if you connect a wearable and only summaries. Sleep duration and score, readiness or recovery score, resting heart rate, heart-rate variability. Never raw waveforms. Used for one purpose: adapting the timing and load of your own planned blocks, and showing you your own trends.
- Safety signals. See section 5.
3. Health data and your choice (UK/EU GDPR Article 9)
Plan and follow-through patterns can reveal information about your health. Where required by law, this is “special category” data and we process it only with your explicit opt-in consent. Declining is fully allowed: the core product (planning, check-ins, the ledger) keeps working — you just won’t receive commentary about your patterns or state.
One exception we disclose plainly: every inbound message runs a simple, fixed crisis-language check that looks for explicit self-harm phrasing and, if found, shows you crisis support resources for your region. This check assesses nothing about you, stores nothing, and cannot be used to profile you. It is a safety net, and it runs regardless of your consent choice, because responding to “I want to kill myself” with a scheduling message is not acceptable to us.
4. Where data lives and who processes it
- Stored encrypted at rest (AES-256) on servers in the EU/US; encrypted in transit.
- Messages arrive via Telegram; standard Telegram infrastructure handles transit.
- To generate replies, summary context about your plan and day may be sent to language-model providers under zero-data-retention agreements — they are contractually prohibited from storing your data or using it for training.
- We never sell your data, share it with advertisers, or use it to train models ourselves.
5. Safety records
If the crisis check triggers, we record the date and the action taken — nothing else. A human reviews the flag within 24 hours; the assistant does not resume on its own after a crisis event.
6. Retention
Your ledger and transcripts are kept while your account is active — that memory is the product. Delete your account and everything personal is destroyed within 30 days, confirmed by email.
7. Your rights (GDPR)
Access, export (complete JSON ledger, on request), correction, deletion, withdrawal of consent (affects pattern commentary, not the core loop), and complaint to a supervisory authority. To exercise any: yahia@bunbunlabs.com. No dark patterns — deletion is as easy as subscription.
8. Changes
If this policy materially changes, we notify you in-chat before it takes effect. Previous versions available on request.
9. Contact
BunBun Labs Limited, Glasgow, UK — yahia@bunbunlabs.com