MontrusLegal

Privacy Policy

Montrus Technologies LLC Last updated: 19 September 2026


This policy explains what Montrus knows about you, why, who else sees it, and what you can make us do about it. We have tried to write it in plain English and to say the awkward parts out loud rather than bury them.

If anything here does not match what the product actually does, that is a bug and we want to know: muhammad-abdou@outlook.com.


1. Who we are

Montrus is operated by Montrus Technologies LLC, a limited liability company registered in the State of Wyoming, United States (filed 6 July 2026).

Registered address 30 N Gould St, STE R Sheridan, WY 82801 United States

For anything in this policy, write to muhammad-abdou@outlook.com.

Where the GDPR or UK GDPR applies to you, Montrus Technologies LLC is the controller of the personal data described in this policy — except for the workplace data described in section 14, where we act as a processor for your employer.


2. There are two ways to be in Montrus, and it matters

This is the most important thing to understand, because it decides what you can delete.

Your personal Montrus account is yours. You created it, you own what is in it, and you can export it or erase it entirely at any time from Settings. Your capability passport lives here, and it outlives any employer.

A workplace account is created for you by an organisation that bought Montrus — normally your employer. That record belongs to them, not to us and not, strictly, to you. If you ask us to delete it we will pass you to them, because they are the controller of it. We can remove your access; we cannot erase their record of your role, your assessments or your development plan without their instruction.

You can have both at once. When you do, they are deliberately kept apart: your personal conversations, your wellbeing sessions and your private career exploration are not visible to your employer, and nothing crosses from one to the other unless you explicitly grant it (section 14).


3. What we collect

Things you tell us

  • Account details — name, email address, and a password or social login, handled by our authentication provider (section 9). We never see your password.
  • Your profile — current role, the role you are aiming at, career stage, industry, country, and any goals you type in.
  • Your roles — the roles you tell us you have held, with the dates you give and the kind of experience (a job, volunteering, a family business and so on), kept as the career history on your passport. Changing your role keeps the previous one; you can correct a role in Settings.
  • A photo, if you upload one. It is resized in your browser and stored as an image on your profile. You can remove it.
  • A CV or a LinkedIn profile, if you give us one. We read it once to suggest your roles, courses and certificates, and the capabilities they built. Only what you choose to add is kept, as your career history, with those capabilities marked as claimed until they are measured. We do not keep the file, or the text you paste. If you tell your Mentor about your work instead, that conversation is kept with your other Mentor conversations, and the same applies: only what you choose to add becomes your career history.
  • Capabilities you tell us you want to grow. Their names, and which kind each is, so we can show them on your passport and build a plan for them. They carry no level until Montrus measures them. You can remove them, and they are deleted with your account.
  • What you write to support. When you contact support from Help in the product, we keep your request, the messages you send, our replies and their dates, so that the conversation can be followed and the reply times we promise can be measured (section 11).

Things you create by using Montrus

This is the bulk of it, and it is the part that matters most to you:

  • Assessments — the questions you were asked, the answers you gave, how long you took, and the capability levels those answers produced.
  • Conversations with the Mentor — the full text of what you and the Mentor said to each other, kept so the conversation can be resumed and so the Mentor can remember you.
  • Mentor memory — short factual notes the Mentor extracts from your conversations ("is preparing for a move into quality assurance"), so it does not ask you the same thing twice.
  • Development plans — the sessions scheduled for you, what you completed, and the reflections you wrote during activities.
  • Steps you set aside. When you press Not now on a suggested next step, we keep which step it was and when it comes back - a week later - so it stays set aside on every device. Nothing else is kept with it, and it is deleted with your account.
  • Career Compass journeys — the three coaching conversations, the paths you explored, the one you chose, and the plan produced.
  • Interview preparation — the job descriptions you paste in, the analysis produced, and the practice answers you typed.
  • Community posts and reports, if you use the community.
  • Anything you send us when you report a bad AI answer, including your note and the reply you reported.

Things we observe

  • Sign-in and usage events — that you signed in, completed an assessment, started a plan. Used to work out your streak, your progress, and whether the product is working.
  • Device and browser information sent automatically by your browser when it makes a request.
  • A one-way fingerprint of your network address, used only to stop one visitor flooding us with requests, and only counted for the current day. We do not store your IP address itself. (Being straight about the limit: a fingerprint made with a secret is not the same as anonymous data — someone holding that secret could confirm a guessed address. It identifies nobody on its own and we never use it for anything but that daily cap.)

What we deliberately do not collect

We want this list on the record, because most of it is unusual:

  • No analytics products. No Google Analytics, no Mixpanel, no Amplitude, no Segment.
  • No advertising or marketing trackers. No pixels, no ad networks, no remarketing tags. We do not sell or share your data with advertisers, and we never will.
  • No third-party session recorders or heatmaps.
  • No fonts loaded from someone else's server — they are served from ours, so no font provider sees your visits.
  • No card details. Payments go directly to Stripe; card numbers never reach our systems.
  • No video. See section 6.
  • No stored audio. If you speak to the Mentor, the speech-to-text happens in your browser where your browser supports it. Nothing is recorded or kept.
  • No CV files, as above.

4. Sensitive information

Some of what you may choose to put into Montrus is sensitive by any reasonable definition, and under the GDPR some of it may be special category data.

Wellbeing conversations. The Mentor has a wellbeing mode. If you use it, what you write may touch your mental or physical health. We want to be exact about how it is handled:

  • These conversations are never visible to your employer, and are excluded by design from every organisation-facing screen, report and export.
  • They are never mined into Mentor memory, so nothing from a wellbeing conversation is quietly carried into a career conversation later.
  • They are never used to rate, score, flag or rank you.
  • The Mentor is not a therapist or a clinician, and says so on screen.
  • If what you write contains explicit signals of immediate danger, the product stops the AI and shows a supportive message pointing you to real help. That check runs on our server, on the text of the message. We do not log which words matched, and we do not build a record of it.

Our legal basis for handling this is your explicit consent, given by choosing to use the wellbeing mode. You can delete any conversation with your account at any time.

Nothing else in Montrus is intended to hold special category data. Please do not put health details, political opinions, religious beliefs, trade union membership, sexual orientation, biometric or genetic data into assessments, plans, community posts or workplace conversations.


5. Legal bases (if you are in the UK or EEA)

WhatWhy we are allowed to
Running your account, delivering the product you asked forPerformance of a contract
Keeping the service secure, preventing abuse, fixing faultsOur legitimate interests
Understanding whether features work, at an aggregate levelOur legitimate interests
Camera, engagement sensing, wellbeing conversations, marketing emailYour consent — withdrawable at any time
Keeping records we are required to keepLegal obligation
Workplace data used by your employerTheir basis, as controller (section 14)

6. The camera, and "engagement sensing"

The live Mentor can show your own camera to you, and can read how engaged you seem. Both are off until you switch them on, and each asks separately.

The self-view camera. The picture is drawn in your browser. It is never uploaded, never recorded, and never sent to us or to anyone else. It exists so a live conversation feels like one.

Engagement sensing. If you turn it on, a face model runs inside your browser — the video never leaves your device. What reaches our server is a single coarse word: engaged, unsure or neutral. That word is put into the Mentor's prompt so it can adjust its pace, and then it is gone. We do not store it. The Mentor is explicitly told it cannot see you and must never comment on your appearance.

The face model runs on your device, but the model files have to be downloaded to get there. The first time you switch this on, your browser fetches the software library from a public code network (jsDelivr) and the model file itself from Google Cloud Storage. Both of those services therefore see a request coming from your browser, including your network address, as they would for any file your browser fetches. Nothing about you is sent with the request, no account information is included, and none of it happens unless you turn engagement sensing on.

You can withdraw either consent at any time in Settings → Mentor.


7. How we use what we hold

  • To run the product: score assessments, keep your passport current, build and reschedule plans, hold conversations, generate your CV.
  • To make the Mentor useful: your role, your gaps, your goals and your Mentor memory are put into the Mentor's prompt so its advice is about you rather than about nobody.
  • To keep you moving: streaks, reminders on screen, suggestions for what to do next, and — only if you switch it on — one email a day when a session in your plan is waiting. You choose the days it may arrive, it is never sent on a day you did not choose, and it is not sent at all if you have already been in Montrus that day or if nothing is actually waiting. Every one of them carries a link that switches it off, and switching it off does not change any other preference.
  • To keep the product honest: several AI outputs are checked by a second model before you see them, and what a checker rejected is recorded so we can find weak spots.
  • To keep it safe and affordable: daily and weekly usage limits, abuse prevention, moderation.
  • To bill you, if you are a paying customer.
  • To improve Montrus, in aggregate.

We do not use your data to train AI models. Not ours, and not anyone else's. See section 9.


8. Decisions Montrus makes about you automatically

Montrus is a measurement product, so it makes judgements. You should know which ones are made without a human involved.

  • Your capability levels are calculated from your assessment answers. A level above Proficient cannot be reached by answering questions alone — it requires demonstrated evidence that a person has reviewed, or a manager's attestation.
  • How much evidence sits behind a level is calculated, and shown next to it, so a level built on one question is not presented as though it were built on eight.
  • A capability index is calculated for workplace users from assessments, learning activity and engagement. That part is always on.
  • A "talent signal" goes further: once that index passes a threshold it flags you individually as high potential — to your manager, to HR, and in the recruitment module. It is off unless your employer switches it on. If they have, two things we think you should know: it is generated automatically with no manual override, and you are not told when you are flagged. If you would like to know your status, ask your administrator, or write to us and we will help you get it. Where you work changes what you can ask for. Several countries give employees additional rights over automated profiling at work — in Germany, for example, a works council normally has to be involved before a tool that rates staff in this way is used on them. Those rights follow the employment law that applies to you and the agreement between us and your employer. They cannot be signed away by that agreement, and it is your employer who has to satisfy them. An administrator can switch the signal off at any time in the organisation's own settings, which also clears any flags already set.
  • Succession readiness and internal candidate matching are suggested automatically, but a person in HR decides and can overrule them.
  • A hiring interview score, if you take a Montrus interview as a job candidate. It is produced by AI from what you said, checked by a second model, and dropped entirely rather than shown if that check finds it unsupported or inconsistent. A human recruiter makes the decision.
  • Community moderation. Posts are screened before they appear. If the check cannot run, the post is held rather than published. A person reviews anything held.

If a decision like this affects you and you disagree with it, you have the right to ask for a human to look at it. Write to muhammad-abdou@outlook.com and we will.


9. Who else sees your data

We use other companies to run Montrus. Each one only receives what it needs.

WhoWhat forWhat reaches them
AnthropicThe Mentor, assessment generation, all main AI featuresThe text of the relevant conversation or task, plus your role and goals as context
OpenAIBackup when Anthropic is unavailable; duplicate-detection in our capability libraryThe same, only when the backup is used
ClerkSign-in, passwords, sessionsYour name, email, and authentication data
StripePaymentsYour email and payment details. Card numbers go to Stripe, never to us
ResendSending emailYour email address and the message
ElevenLabsThe Mentor's voiceThe text to be spoken. Not your voice
LiveAvatar (HeyGen)The Mentor's video avatarAudio of the Mentor speaking. Not your camera, not your microphone
VercelHostingRequests your browser makes, including your IP address in transit
NeonThe databaseEverything stored, encrypted at rest
jsDelivr and Google Cloud StorageDeliver the on-device face-reading library and modelOnly that a browser requested a file, and only if you turned engagement sensing on

On the AI providers specifically. Anthropic and OpenAI process your text under their business API terms. Under those terms they do not use it to train their models, and they retain it only briefly for abuse monitoring. Neither is given your name or email; they receive the conversation and the professional context needed to answer.

We also share data:

  • With your employer, if you have a workplace account — see section 14.
  • Not with your employer when you ask us for help. What you send Montrus support stays between you and Montrus. It is answered by the Montrus team and, for a request from an organisation they look after, by that organisation's Montrus account manager or partner. A request about your rights over your data, and a security report, are only ever handled by Montrus itself.
  • With whoever you choose, when you publish your passport or send someone a share link. That is your decision, and you can revoke it.
  • With LinkedIn or X, if you use the share buttons on your passport. Those are plain links — they set nothing and send nothing until you click one, at which point you are on that company's site under its terms.
  • If the law requires it, or to protect someone's safety or our rights.
  • If Montrus is ever sold or merged, in which case we will tell you before your data moves.

We do not sell your personal data.


10. Where your data is held

Montrus runs on infrastructure in the United States. Our providers may process data in other countries as part of running their services.

If you are in the UK or EEA, transfers out are covered by the European Commission's Standard Contractual Clauses and, where relevant, the UK Addendum, together with our providers' own transfer terms.

We do not currently offer a choice of region. If your organisation needs data held in a specific country, contact us before you buy — we would rather tell you no than promise something the product does not do.


11. How long we keep it

What you make is not on a timer. Your assessments, capability levels, plans, Mentor conversations, passport and account stay until you or your organisation removes them. Nothing you created is deleted because time passed.

What using Montrus leaves behind does expire. Counters, analytics events and logs are byproducts: useful for a while, and then not. From 21 September 2026 they are deleted automatically once they pass the periods below. We are publishing them ahead of that date because the previous version of this policy promised we would tell you before they first apply.

What it isKept forWhy that long
Wellbeing conversations with the Mentor30 daysThe shortest period here, because it is the most sensitive thing we hold and it serves no purpose once the conversation ends. A wellbeing conversation is never resumed, never enters the Mentor's memory, is never shown to your employer, and is not listed among your past conversations.
Daily AI usage counters90 daysThe counter is only needed for the day it covers. A quarter is long enough to investigate a cost spike or a billing question, and nothing beyond that.
Live Mentor minute counters90 daysThe same kind of counter as the one above, kept for the same reason and therefore for the same length.
AI quality reports12 monthsKept to answer whether a part of the product actually improved after we changed it, which takes a year. They can carry up to 500 characters of your own words when you report a bad answer, so they are not kept longer.
Signup and activation events14 monthsFourteen rather than twelve. A year exactly is the one length that breaks the comparison you would use it for: on 1 January you could no longer compare December with December.
Records of who viewed whose data24 monthsKept longer than everything else, and deliberately so — this is the record that protects you rather than us. A workplace dispute often surfaces a year or more after the fact, and this log is what settles what actually happened. Two years covers that. Forever is not a retention policy.
Records of administrative changes24 monthsKept as long as the access records above, and for the same reason: evidence of who changed what is only useful if it outlives the dispute.
A half-finished organisation setup30 days from its last changeLong enough to come back to after a fortnight away, short enough that a setup somebody abandoned does not sit here for ever. It holds the shape of the organisation and the people its administrator meant to invite, never job descriptions or a logo.
Your requests to Montrus support24 months after the request is closedLong enough to pick up an earlier conversation if the same problem comes back, and to show how we handled it if you complain. A request marked solved closes itself after 7 days without a reply.
Requests about your rights, and security reports5 years after the request is closedOur evidence that we met a legal obligation to you, so it is kept longer than anything else here. If you delete your account, your name and email address are removed and only the request itself remains.

Support requests are a record of your dealings with us, not a byproduct, which is why they are kept longer than the counters above. Their periods run from when a request is closed, never while it is still open.

Two things follow from this:

  • Anything left behind by a closed account is removed once it is 30 days old, whatever the period above would otherwise allow. When an account is closed we release the identity it used, so a record still naming it belongs to nobody, and there is no window in which keeping it is right. The 30 days exist only so that we never sweep up somebody who is halfway through signing up. The one exception is a request about your rights or a security report you sent to support: it is kept as the table says, without your name or email address.
  • An account nobody has used for 24 months is deleted — and we write to you first. This is the period we promised to publish here before it applies, and it takes effect on 7 November 2026. Thirty days before anything happens we email the address on the account. Signing in is enough to stop it — you do not have to do anything else, and the timer starts again. If you would rather keep a copy, you can export your data from Settings at any time before the date in that email.

What you can do at any time, without waiting for a timer:

  • Delete your personal account from Settings, which removes almost everything at once (section 13).
  • Ask your administrator to remove a workplace record.
  • Ask us to delete specific things — a single Mentor memory, one conversation, your photo — and we will.

12. Your rights

Wherever you live, you can ask us to:

  • Show you what we hold. Settings → Data has an export that produces a single file containing your profile, your capabilities, your assessments including the questions and your answers, your Mentor conversations, your Career Compass sessions, your plans and the reflections you wrote, your interview preparation and practice, and your community activity.
  • Correct anything wrong. Most of it you can edit yourself.
  • Delete your account, as in section 13.
  • Withdraw a consent — camera, engagement sensing, marketing email — without losing the rest of the product.
  • Object to us relying on legitimate interests, or ask us to restrict what we do.
  • Take your data elsewhere, using the same export.
  • Ask for a human to review an automated decision (section 8).

Write to muhammad-abdou@outlook.com, or use Help → Contact support in the product and choose My data & privacy. We will reply within 30 days, and we will not charge you.

If you are in the EEA or UK, you may complain to your national data protection authority. We would rather you told us first, but it is your right either way.


13. What deleting your account actually removes

When you delete your personal account from Settings, we remove — in one transaction — your profile, your capabilities and their evidence, every assessment and the answers in it, every Mentor conversation and everything the Mentor remembered about you, your plans and your reflections, your Career Compass journeys, your interview preparation and practice answers, your passport share links, your community membership, posts and reports, your photo, your usage counters, your signup and activation events, any AI-quality report you filed, and your sign-in account itself. It is irreversible. Export first if you want a copy.

A small number of things survive, and you should know exactly what and why:

  • Security and administration logs. A record that an administrator viewed sensitive data, or changed something, stays. Erasing it would destroy the evidence that protects you.
  • A hiring screening, if you took a Montrus interview as a candidate for an employer. That is the employer's record of their own hiring decision, and it is theirs to keep or delete. The link from it to your deleted profile is severed.
  • Your workplace record, if an employer created one. It belongs to them (section 2).
  • An anonymous reference in someone else's record, if you referred a friend. Once your profile is gone it is a bare identifier that points to nothing and names nobody.
  • A request about your rights, or a security report, that you sent to support. It is our evidence that we met a legal obligation to you. Your name and email address are removed from it, and it is kept for 5 years after it closed (section 11). Your other support requests are deleted with your account.

14. If your employer gave you Montrus

What your organisation can see: your role and the capabilities it requires, your assessment results and capability levels, your development plans and progress, your learning activity, and aggregate views of the team and organisation. Depending on their internal permissions, HR and administrators may see more than your line manager does.

What your organisation cannot see: your personal Montrus account, your personal passport, your wellbeing conversations, your private career exploration, and any personal Mentor conversation. These are architecturally separate, not merely hidden.

Your passport is only shared if you share it. An organisation can ask, and you get a screen showing exactly what would be shared. You choose which parts, and you can revoke it later. Every time someone in that organisation looks at it, that is recorded.

Workplace questions in Help. If you ask Help about your workplace - leave, a policy, who approves what - the answer comes only from documents your organisation has published in Montrus, and it says which one it used. If none answers it, Help names the HR contact your organisation set. If there is none, you can choose to send the question to your organisation's administrators, who then see it and your name. Montrus does not answer workplace questions itself and does not read them.

When you leave. Removing your access does not delete your workplace record — that stays with your employer as their data. Your personal account and your passport are unaffected and remain yours.

For anything about workplace data, your employer is the controller and their privacy policy applies alongside ours. Ask them first; we will help them answer.


15. Children

Montrus is not for children. You must be at least 16 to use it, or older if the law where you live sets a higher age for consenting to online services.

We ask you to confirm you are 16 or older before you can create an account. That is a declaration, not proof of age — we do not ask for identity documents and we do not store a date of birth. If you believe someone under 16 has an account, tell us at muhammad-abdou@outlook.com and we will remove it.


16. How we protect it

Encrypted in transit and at rest. Access controlled by role, with sensitive views recorded. Passwords handled by a specialist provider, never by us. Permissions checked on the server on every request, not just hidden in the interface. Secrets kept out of the codebase.

No system is perfect. If you find a weakness, please tell us at muhammad-abdou@outlook.com rather than publishing it, and we will work with you.

If a breach puts you at risk, we will tell you and the relevant regulator without undue delay, and within 72 hours of becoming aware where the law requires it.


17. Changes to this policy

We will update this page when the product changes. If a change materially affects you, we will tell you in the product or by email before it takes effect, rather than quietly changing the date at the top.


18. Contact

In the product: Help → Contact support Privacy and your rights: muhammad-abdou@outlook.com Security: muhammad-abdou@outlook.com Anything else: muhammad-abdou@outlook.com

Montrus Technologies LLC 30 N Gould St, STE R, Sheridan, WY 82801, United States

Privacy Policy · Version 1.6 · 19 September 2026

Every change we publish is listed on the legal index. We do not change these documents quietly.