Trust & Security at MentoCore
This page is maintained by Hospitality Mentors Inc to answer common security and privacy questions about MentoCore. It describes our current practices and is not an independent certification.
Platform & hosting
MentoCore runs on Lovable Cloud, a managed application platform backed by managed Postgres and an edge runtime. Traffic between your browser and MentoCore is encrypted in transit with TLS. Customer data is stored in a managed Postgres database with row-level security enforced per organization, so a user can only read or write the rows that belong to their workspace.
Access control
MentoCore supports email/password sign-in and Google sign-in. Inside an organization, users are assigned one of three roles — owner, admin, or member — and every privileged action is checked on the server, not just hidden in the UI. Sessions use secure, short-lived tokens and you can sign out at any time from your account menu.
Data we collect
We collect the information needed to operate the product: your account details (name, email, organization), the content your team creates in MentoCore (inspections, schedules, sensor readings, library items, uploaded files), and standard request logs used to keep the service running and secure. We do not sell personal data, and we do not use customer content to train third-party AI models.
Subprocessors & integrations
MentoCore relies on a small set of subprocessors to deliver the service:
- Lovable Cloud — application hosting, managed database, authentication, and file storage.
- Google — optional OAuth sign-in for users who choose “Continue with Google”.
- Lovable AI Gateway — used for AI-assisted features inside the product.
This list can change as the product evolves. Contact us if you need the current list for a vendor review.
Cookies & analytics
MentoCore uses first-party cookies that are strictly necessary to keep you signed in and to remember basic preferences. We do not run third-party advertising trackers or cross-site profiling scripts on the product.
Retention & deletion
You can request export or deletion of your account and workspace data at any time by contacting us. We honor deletion requests within a reasonable period and remove customer content from active systems; routine backups age out on their own schedule.
Privacy requests & security contact
To report a security issue, request data export or deletion, or ask a privacy question, contact us through the support address listed on our website or from inside the app. Please include enough detail to reproduce a security issue, and give us a reasonable window to respond before disclosing publicly.
Compliance
MentoCore does not currently claim formal certifications such as SOC 2, ISO 27001, HIPAA, or PCI DSS. We design and operate the platform with widely-accepted security practices — least-privilege access, encrypted transport, tenant isolation via row-level security, and server-side authorization — and we will update this page as our compliance posture changes.
Shared responsibility
Security on MentoCore is a shared effort. Hospitality Mentors Inc is responsible for the security of the platform itself. Each customer organization is responsible for managing its own users and roles, keeping credentials safe, and reviewing the content it uploads. The Lovable Cloud platform underneath us is responsible for the security of the hosting environment.
Last updated July 2026.