ItalianoEnglishFrançaisDeutschEspañolPortuguêsNederlandsΕλληνικάPolskiRomânăDanskSvenskaNorskSuomiMagyarGaeilgeLëtzebuergesch Mentup

Privacy policy

Last updated: 6 September 2026 · Version 1.1

This policy explains what personal data Mentup collects, why it collects it, who it shares it with and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the « GDPR ») and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018.

We wrote it to be understood. Where a technical word is unavoidable, we explain it.

1. Who the data controller is

Mentup Solutions
Via Romana 75 · 42028 Poviglio (RE) · Italia
VAT no. 03156100350
Email: privacy@mentup.eu
PEC: mentup@pec.it

2. Who Mentup is for

Mentup may be used by people aged 16 or over.

If you are 16 or 17, activating your account requires the consent of a parent or of whoever holds parental responsibility: without that consent the account stays inactive and you cannot use the service. How it works is explained in section 6.

Italian law would allow consent to data processing from the age of 14 (Art. 8 GDPR and Art. 2-quinquies of the Italian Privacy Code). We chose a higher threshold for two reasons: Mentup processes health data, and a subscription is a contract that a minor cannot enter into alone. The 16-year threshold matches the one set by the GDPR where no different national rule applies, and the one in force in Germany and the Netherlands. Where the law of your country sets a higher age, that age applies.

3. What data we collect

3.1 Data you give us when you create the account

First name, last name, email address, password (which we keep only in encrypted form and which none of us can read), date of birth, gender, phone number, preferred language, country and — if you choose to upload one — a profile picture.

We need your date of birth for one precise reason: to determine whether you are a minor and start the parental consent procedure.

3.2 Data about your wellbeing — the most sensitive part

By using Mentup you record:

This is data concerning your health, and it falls within the « special categories of personal data » of Art. 9 GDPR. It is the most protected data the Regulation knows, and we process it only on the basis of your explicit consent, which you can withdraw at any time (section 5).

3.3 Parent or guardian data (only for users who are minors)

First name, last name and email address of the parent or guardian, collected for the sole purpose of requesting, receiving and keeping proof of consent.

3.4 Technical data

IP address, browser or device type (user agent) and the date and time at which you gave or withdrew each consent. We keep these so we can demonstrate, if needed, that a consent was actually obtained: this is an obligation the GDPR places on us (Art. 7.1).

3.5 Payment data

Mentup does not see and does not store your card details. The subscription is purchased through the Apple App Store, Google Play or — on the website — through Stripe. From the provider we receive only the information needed to keep your subscription active: whether it is active, when it expires, whether it has been renewed or cancelled, and a transaction identifier.

3.6 What we do NOT collect — and this is not a formality

As at the date of this policy, Mentup:

If any of these points changes in the future, this policy will be updated before the change takes effect, and you will be asked for fresh consent where required.

4. Why we process your data and on what legal basis

PurposeData usedLegal basis
Creating and managing your account, letting you sign in3.1Performance of the contract — Art. 6.1.b
Letting you use the wellbeing features (actions, journal, anxiety, anger, satisfaction, statistics)3.2Explicit consent — Art. 9.2.a
Verifying your age and obtaining parental consent if you are a minor3.1, 3.3Legal obligation — Art. 6.1.c and Art. 8
Managing the subscription, renewals, receipts and support3.1, 3.5Performance of the contract — Art. 6.1.b
Showing your data to the health professional you have designated3.2Explicit and specific consent — Art. 9.2.a
Producing aggregated, anonymous statistics for your company or your school3.2 in aggregated formExplicit consent — Art. 9.2.a
Recording and keeping proof of consents3.4Legal obligation — Art. 6.1.c
Sending you service messages (email verification, security alerts, subscription deadlines)3.1Performance of the contract — Art. 6.1.b
Sending you promotional messages about MentupEmailConsent — Art. 6.1.a, withdrawable with one click in every message
Keeping the service secure and preventing abuse3.4Legitimate interest — Art. 6.1.f
Establishing or defending a legal claimas applicableLegitimate interest / Art. 9.2.f

Service messages are not advertising and cannot be switched off while you have an active account: without them we could not tell you that your subscription is about to be charged or that someone has asked to reset your password.

5. Consent to wellbeing data, and how to withdraw it

Consent to Art. 9 data is explicit, separate and specific: it is not buried in your acceptance of the Terms, it is not pre-ticked, and it covers one purpose at a time.

You can withdraw it at any time, from the app's Settings, without having to explain why and at no cost to you. Withdrawal:

It has to be said honestly: wellbeing data is the service. If you withdraw that consent, the journal, statistics and tracking features stop working, and the account is left with basic features only.

6. If you are 16 or 17

  1. When you register we ask for the email address of a parent or of whoever holds parental responsibility.
  2. Your account is created but stays inactive: you cannot sign in and no wellbeing data is collected.
  3. We send the parent a message containing the consent request and a link to this policy.
  4. The account is activated only once the parent confirms.
  5. If consent does not arrive within 30 days, the request expires and the data collected up to that point is deleted.

The parent can withdraw consent at any time by writing to the address given in section 1, whereupon the account is deactivated and the data deleted.

We do not advertise to minors and we do not profile users who are minors for any purpose.

7. Who we share your data with

We share nothing by default. Every kind of sharing below happens only if you switch it on, and it can be revoked.

7.1 With your professional (psychologist, doctor, coach)

If you link your account to a professional, they can see your daily satisfaction scores and how they change over time, your anxiety and anger releases — date, intensity and also the text you wrote — and receive an alert if you stop using the app.

7.2 With your company

Your company never sees your individual data. Never. This is not a promise: it is how the system is built.

The company receives only the average satisfaction of all its employees and how it changes over time. No data per person, per department or per any group smaller than the whole company. The average is calculated only if at least 3 employees are enrolled: with fewer people, an « aggregated » figure would still point back to someone. For the same reason a company can only activate Mentup with at least 3 employees. You can also ask to be excluded from the average as well.

Mentup and your company are joint controllers under Art. 26 GDPR, on the basis of a written agreement, a copy of which you can request at the address given in section 1.

7.3 With your school

The same rule applies: the school receives only aggregated, anonymous data — average satisfaction and the number of releases recorded — per class and for the school as a whole, never per individual student. A class figure is shown only if at least 3 students in that class are enrolled. Participation is voluntary and has no bearing whatsoever on school assessment. For students who are minors, the procedure in section 6 applies.

7.4 With our providers

See section 8. They act as processors and are bound by contract under Art. 28 GDPR.

7.5 With the authorities

Only if and to the extent the law requires it.

7.6 Charities

The charities receiving the donations receive the donation, not your data. They do not know who you are.

8. The providers we rely on

ProviderWhat it doesWhereRole
Netsons S.r.l.Application and database serversEU (Italy)Processor, Art. 28
Netsons S.r.l.Sending service emails (SMTP)EU (Italy)Processor, Art. 28
Apple — App StorePurchase and renewal of the subscription on iOS—Independent controller for the payment
Google — Google PlayPurchase and renewal of the subscription on Android—Independent controller for the payment
StripePayments made from the websiteEU / USAProcessor, Art. 28
RevenueCatChecking that a subscription bought on the stores is activeUSAProcessor, Art. 28

We never pass your wellbeing data to providers. They receive only what their function requires: a user identifier and the status of the subscription.

9. Cookies, and data kept on your device

9.1 On our websites

The details of our cookies — name, purpose, duration and who sets each one — are in the Cookie Policy. Today we use a single, technical cookie. If we were to introduce non-technical cookies in the future, they would be set only after your consent, which you could change or withdraw at any time.

9.2 In the app

There are no cookies in the Mentup app. Cookies are a web technology and talking about cookies in a native app is technically wrong. The app does, however, keep some information on your device:

InformationWhat it is forWhere
Authentication token, user identifierKeeping you signed in without asking for your password every time you open the appEncrypted store of the operating system
Interface language, countryShowing you the app in the right language and the charities of your countryLocal storage of the app
Display preferencesRemembering what you have already closed or hiddenLocal storage of the app

All of this stays on your phone. It is erased by uninstalling the app or signing out of the account.

10. How long we keep the data

DataRetention
Account and profile dataFor as long as the account exists. Deleted within 30 days of a deletion request
Wellbeing data (journal, releases, ratings, photos)As above: deleted with the account
Data from a relationship with a health professionalFor the duration of the relationship and 10 years after it ends, in line with obligations in the health field
Log of the professional's accesses10 years
Proof of consents (date, time, IP, document version)10 years from withdrawal or termination
Data under a corporate welfare programmeFor the duration of the programme; anonymised within 90 days of its end, save for legal obligations
Tax and accounting data for subscriptions10 years, as required by law
Aggregated, anonymous statistical dataNo limit: it can no longer be traced back to a person

11. Your rights, and how to exercise them

At any time you can:

How to do it. In the app's Settings you will find export and account deletion. You can also write to the address given in section 1, and the website has a public page for requesting account deletion without having to sign in: mentup.eu/cancella-account.

We reply within one month. If the request is complex we may take up to two further months, and we will tell you.

If you believe your data is being handled improperly you can lodge a complaint with the Garante per la protezione dei dati personali, the Italian data protection authority (Piazza Venezia 11, 00187 Rome — garante@gpdp.it — www.garanteprivacy.it), or with the authority of the country where you live, and you can go to the courts.

12. How we protect the data

Encrypted communications (HTTPS/TLS); passwords kept only as hashes and never in the clear; access tokens held in the device's encrypted store; access to data limited to the people who genuinely need it; every access by a professional traced and retained; regular backups.

No system is absolutely secure. Should a breach occur that entails a high risk to your rights, we will tell you and we will inform the supervisory authority within the time limits set by law (Arts. 33 and 34 GDPR).

13. Where the data is held

Data is kept on servers located in the European Union.

Some of the providers listed in section 8 (Apple, Google, Stripe, RevenueCat) may also process data outside the European Economic Area. In those cases the transfer takes place on the basis of the safeguards set out in Chapter V of the GDPR: an adequacy decision or Standard Contractual Clauses approved by the European Commission.

Wellbeing data does not leave the European Union.

14. Changes to this policy

If we change it, we publish the new version on this page with a new date and a new version number. Where the change is significant — new purposes, new recipients, new measurement tools — we tell you before it takes effect, and where necessary we ask for fresh consent.

Previous versions remain available on request.

This policy is drawn up in Italian. In the event of any discrepancy between the Italian version and a translation, the Italian version prevails.

Privacy policy Terms of service Cookie policy privacy@mentup.eu

Mentup is a digital tool for everyday wellbeing. It is not a medical device and it does not replace the opinion, diagnosis or treatment of a doctor, psychologist or other qualified health professional. The content and features of the app are for information and personal wellbeing support only. If you are experiencing psychological distress or mental health difficulties, please speak to a qualified professional. In an emergency call 112.

© 2025–2026 Mentup