Privacy Policy
Effective 27 September 2026
We collect what Mantis needs to work and nothing more. There is no analytics, no advertising and no tracking. This policy explains what we collect, why, how long we keep it, who else sees it, and the rights you have under the GDPR, UK GDPR and US state privacy laws.
1. Who we are
Mantis is a product of Tamam Labs Limited Liability Co., 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA (“Mantis”, “we”, “us”). We are the controller of the personal data described in this policy, except where section 4 says we act for our customers. For anything about your data, email [email protected].
2. What this policy covers
This policy covers people who visit our website, people who create a Mantis account, and people who contact us. If you are a user of an app that is built with Mantis, section 4 explains who is responsible for your data.
3. What we collect, and why
When you visit the site
Our servers receive technical information with each request: your IP address, the date and time, the page you asked for, the page you came from, and your browser's user agent.
- Why: to deliver the site, keep it secure, and find and fix errors.
- Legal basis: our legitimate interest in running a secure, working website (Article 6(1)(f) GDPR).
- How long: up to 30 days, unless we need a specific log to investigate a security incident.
When you create an account or sign in
We store:
- your name, your email address, and the team you create (its name and URL);
- your password, only as an Argon2id hash. We never store the password itself, and you don't need one if you sign in with a code, GitHub or Google;
- the 6-digit codes we email you, only as hashes. A code works for 15 minutes and is deleted about a day after it was sent. While a sign-up waits for its code, the name and password hash you gave wait with it, and are deleted with it if you never finish;
- your sessions: a random token, stored as a hash, and when it started. A session ends when you sign out or two months after you signed in, and is deleted within an hour of ending;
- how many wrong codes or passwords were entered for your account, so that we can stop someone guessing them.
To slow down attacks, we also count sign-in requests per IP address. Those counts are kept in memory for no more than 10 minutes.
- Why: to create your account, sign you in, and keep your account secure.
- Legal basis: performing our contract with you (Article 6(1)(b) GDPR), and our legitimate interest in stopping unauthorised access (Article 6(1)(f) GDPR) for the attempt counts.
- How long: until you delete your account. Codes and sessions are deleted as described above.
When you sign in with GitHub or Google
We send you to GitHub or Google, and they tell us your account ID with them, your name, your email address, and whether they have verified that email. We use the email only if they have verified it. We don't receive your GitHub or Google password, and we don't keep the access token they give us. GitHub and Google handle your sign-in with them under their own privacy policies.
When you connect an app to Mantis
The Mantis package runs inside your app. For each AI call your app makes through it, the package sends us:
- an identifier for the user who made the call, chosen by you. We recommend an internal ID rather than a name or an email address;
- the AI provider and model, the number of tokens used, and the estimated cost;
- the route or feature name your app gives the call, and the time of the call.
We never receive the prompts your app sends, the responses it gets back, or your API keys for OpenAI, Anthropic, Stripe or any other provider. They stay on your server.
- Why: to count usage, apply the limits and caps you set, and send you alerts.
- Legal basis: performing our contract with you (Article 6(1)(b) GDPR). For the data about your own users, see section 4.
- How long: until you delete the app or your account.
When you pay us
If you buy a paid plan, Stripe processes your payment. Stripe receives your card details; we don't. We receive your name, email address, billing address, the type and last four digits of your card, your plan, and your invoices.
- Why: to charge you, send invoices, and meet our tax and accounting duties.
- Legal basis: performing our contract with you (Article 6(1)(b) GDPR) and our legal obligations (Article 6(1)(c) GDPR).
- How long: for as long as tax and accounting law requires, which is usually up to seven years.
When you email us
We use your email address and your message to reply. Legal basis: our legitimate interest in answering you (Article 6(1)(f) GDPR). We keep the conversation for as long as we need it to deal with your request.
4. Data about your users
When you connect an app to Mantis, you decide which of your users' data the package sends us, and why. For that data you are the controller and we are your processor: we process it only to provide Mantis to you, following your instructions and our Terms of Service. You are responsible for telling your users about it in your own privacy policy and for having a legal basis to share it with us. We sign a data processing agreement with any customer who asks; email [email protected].
If you are a user of an app built with Mantis, please contact that app's owner about your data. If you contact us instead, we will pass your request to them.
5. What we don't do
- No cookies beyond the ones that keep you signed in, described below.
- No analytics, advertising, tracking pixels or session recording.
- No third-party requests while you browse. Our fonts are served from our own domain, so your browser doesn't contact Google Fonts.
- No reading of your prompts, your AI responses or your API keys.
- We don't sell or share personal information, including as those terms are defined in US state privacy laws such as the CCPA.
- No automated decision-making that has legal or similarly significant effects on you.
6. Cookies
We set only cookies that are strictly necessary to sign you in:
mantis_sessionkeeps you signed in. Scripts on the page can't read it, and it expires when your session ends, two months after you signed in at the latest.JSESSIONIDis set only while you sign in with GitHub or Google, to check that the sign-in comes back to the same browser. It lasts until you close the browser, and stops meaning anything once the sign-in finishes.
Strictly necessary cookies don't need consent, which is why there is no cookie banner. If we ever add another kind, we will update this policy first and ask for your consent wherever the law requires it.
7. Who receives your data
These providers process data for us, under contracts that oblige them to protect it and use it only for us (Article 28 GDPR):
- hosting and infrastructure providers, which run our servers and databases and store server logs, account data and usage data;
- Resend (Resend, Inc.), which delivers our emails, such as sign-in codes and alerts. It receives your email address and the message;
- Stripe (Stripe, Inc.), which processes payments for paid plans.
When you choose to sign in with GitHub (GitHub, Inc.) or Google (Google LLC), they share the data described in section 3 with us. We don't send them anything about your use of Mantis.
We also disclose data to professional advisers such as lawyers and accountants when we need their help, to authorities when the law requires it, and to a buyer or successor if our business is sold or merged, in which case this policy continues to protect your data.
8. International transfers
We are based in the United States, and our providers may process data in the United States and other countries. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision, such as the EU-US Data Privacy Framework where the recipient is certified under it, or on the European Commission's Standard Contractual Clauses and their UK equivalent.
9. Your rights
Under the GDPR and UK GDPR you have the right to:
- get a copy of the personal data we hold about you (access);
- have it corrected if it's wrong (rectification);
- have it deleted (erasure);
- have its use restricted (restriction);
- receive it in a portable format (portability);
- object to processing based on our legitimate interests (objection);
- withdraw consent at any time, where we rely on consent.
To use any of these rights, email [email protected]. We reply within one month. For complex requests we may extend that by up to two more months, and we will tell you if we do. We may ask you to confirm your identity first.
You can also complain to a data protection authority, in particular in the country where you live, work, or where you think the problem happened. In the UK, that is the Information Commissioner's Office (ICO).
10. Rights under US state laws
If you live in California or another US state with a consumer privacy law, you have the right to know what personal information we collect and how we use it, to get a copy of it, to have it corrected or deleted, and not to be treated differently for using these rights. This policy describes the categories we collect (identifiers, account and billing details, and technical data), where they come from, and why. We don't sell or share personal information and don't use sensitive personal information to infer anything about you. To make a request, email [email protected]; you can also ask someone to make it for you.
11. Security
The site is served only over HTTPS. Passwords, codes and session tokens are stored only as hashes, sign-in attempts are limited, each team's data is separated from every other team's in the database, and access to account data and server logs is limited to the people who need it to run Mantis. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
12. Children
Mantis is a tool for building software and isn't directed at children under 16. We don't knowingly collect their personal data. If you think a child has sent us personal data, email [email protected] and we will delete it.
13. Deleting your account
To delete your account, email [email protected] from the address you signed up with. We delete your account and the data linked to it within one month, except billing records we must keep by law.
14. Changes to this policy
We will post any change on this page and update the effective date. If a change matters for how we use your data, we will also tell you by email or with a notice on the site before it takes effect.
15. Contact
Tamam Labs Limited Liability Co., 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA. Email: [email protected].