← Back to MentoCore

Trust & Security at MentoCore

This page is maintained by Hospitality Mentors Inc to answer common security and privacy questions about MentoCore. It describes our current practices and is not an independent certification.

Platform & hosting

MentoCore runs on Lovable Cloud, a managed application platform backed by managed Postgres and an edge runtime. Traffic between your browser and MentoCore is encrypted in transit with TLS. Customer data is stored in a managed Postgres database with row-level security enforced per organization, so a user can only read or write the rows that belong to their workspace.

Access control

MentoCore supports email/password sign-in and Google sign-in. Inside an organization, users are assigned one of three roles — owner, admin, or member — and every privileged action is checked on the server, not just hidden in the UI. Sessions use secure, short-lived tokens and you can sign out at any time from your account menu.

Data we collect

We collect the information needed to operate the product: your account details (name, email, organization), the content your team creates in MentoCore (inspections, schedules, sensor readings, library items, uploaded files), and standard request logs used to keep the service running and secure. We do not sell personal data, and we do not use customer content to train third-party AI models.

Subprocessors & integrations

MentoCore relies on a small set of subprocessors to deliver the service:

  • Lovable Cloud — application hosting, managed database, authentication, and file storage.
  • Google — optional OAuth sign-in for users who choose “Continue with Google”.
  • Lovable AI Gateway — used for AI-assisted features inside the product.

This list can change as the product evolves. Contact us if you need the current list for a vendor review.

Cookies & analytics

MentoCore uses first-party cookies that are strictly necessary to keep you signed in and to remember basic preferences. We do not run third-party advertising trackers or cross-site profiling scripts on the product.

Retention & deletion

You can request export or deletion of your account and workspace data at any time by contacting us. We honor deletion requests within a reasonable period and remove customer content from active systems; routine backups age out on their own schedule.

Privacy requests & security contact

To report a security issue, request data export or deletion, or ask a privacy question, contact us through the support address listed on our website or from inside the app. Please include enough detail to reproduce a security issue, and give us a reasonable window to respond before disclosing publicly.

Compliance

MentoCore does not currently claim formal certifications such as SOC 2, ISO 27001, HIPAA, or PCI DSS. We design and operate the platform with widely-accepted security practices — least-privilege access, encrypted transport, tenant isolation via row-level security, and server-side authorization — and we will update this page as our compliance posture changes.

Shared responsibility

Security on MentoCore is a shared effort. Hospitality Mentors Inc is responsible for the security of the platform itself. Each customer organization is responsible for managing its own users and roles, keeping credentials safe, and reviewing the content it uploads. The Lovable Cloud platform underneath us is responsible for the security of the hosting environment.

Last updated July 2026.