Responsible AI - How we work with AI at Mentimeter

At Mentimeter, our approach to integrating Artificial Intelligence (AI) is based on crafting a seamless and intuitive experience for our users. At the same time, we are cautious about the risks the use of AI can pose, ensuring that ethical considerations and user privacy are at the forefront of our development process.

Start with AI

Table of contents

  • The role of AI at Mentimeter
  • Core principles guiding Mentimeter's use of AI
  • Alignment with global frameworks and regulations
  • FAQ

The role of AI at Mentimeter

AI at Mentimeter is an umbrella term that refers to the strategic implementation of artificial intelligence technologies within the Mentimeter platform.

Mentimeter AI brings intelligent support into our users’ workflows - helping users design fit-for-purpose interactions, interpret audience input, and guide meaningful actions. AI capabilities are woven into familiar Mentimeter experiences, making preparation and facilitation faster, more engaging, and more impactful.

Whether generating ideas, refining questions, summarising responses, or offering context-aware recommendations, Mentimeter AI is designed to make our users more confident and sessions more impactful.

Core principles guiding Mentimeter's use of AI

Mentimeter follows a clear set of principles guiding our use of AI

  • Privacy-by-design & data minimisation. We only send the minimum information required for an AI capability to work. We do not include user identity, workspace structure, billing information, or audience identities.
  • Security-by-design. All AI data is protected by Mentimeter’s broader security program, including AES-256 encryption at rest, TLS-encrypted transport, and ISO 27001:2022-aligned controls.
  • Human oversight & user control. AI supports the presenter, but never replaces their decisions. Suggestions are optional, editable, and fully under user control.
  • No model training on customer data. Mentimeter does not train models on customer content, and our third-party model providers are not permitted to train on Mentimeter data.
  • Transparency & simplicity. We design AI experiences that are easy to understand, predictable, and aligned with Mentimeter’s product principles.

Alignment with responsible AI frameworks and global regulations

Mentimeter’s AI approach aligns with established AI governance practices and international regulatory expectations, including the General Data Protection Regulation (EU 2016/679) (GDPR) and its fundamental principles, ISO 27001:2022 information security standards, and emerging frameworks such as the EU AI Act. We continuously monitor changes in regulation and model-provider practices to ensure our AI capabilities remain responsible, compliant, and safe.

You can read more about our internal compliance routines and our continuous work to secure GDPR compliance within Mentimeter here.

FAQ

General questions

What is Mentimeter AI, and which features use it?

Mentimeter AI refers to the set of capabilities in the product that use machine learning or large language models to help users create, analyse, or enhance content more easily. Examples include generating or refining questions or entire Mentimeter presentations, summarizing or grouping responses by theme, and offering guidance or suggestions on what to do next. 

How does Mentimeter’s AI work in practice?

Mentimeter’s AI operates within defined product flows. When an AI capability is used, we send only the information required for that feature to our model provider, process the returned output within Mentimeter, and then surface it to the user inside the product’s normal workflows.

Can I choose whether to use AI features in my workspace?

Individual users cannot turn AI features on or off, and some AI capabilities may appear automatically as part of the product experience. However, workspace-level controls to disable AI features are available on relevant plans for organisations that prefer not to use AI. Even when AI capabilities are active, users always decide whether to act on, edit, or ignore any AI-generated suggestion - AI never changes the contents of a user’s Mentimeter presentation automatically.

Are there usage guidelines for Mentimeter’s AI features?

Mentimeter AI is designed to help users save time and improve the outcomes of their interactions, not to replace user judgement. We encourage users to review AI suggestions before using them in a session. Due to the nature of the Service, Mentimeter does not expect personal data in input fields, but users are reminded not to enter personal or sensitive information into free-text prompts. AI suggestions are always optional, and users decide whether to apply them.

Data use & privacy

Does Mentimeter use customer data to train AI models?

No. User and customer content is never used to train models. Mentimeter does not train in-house models, and does not permit third-party AI providers to utilise Mentimeter customer data for model training purposes.

Who owns the content generated by Mentimeter’s AI features?

Any AI-generated content you choose to use in Mentimeter — such as suggested questions, summaries, or recommendations — becomes part of your User Data. You retain ownership of this content under our Terms. Mentimeter does not claim ownership of AI-generated outputs and does not use customer content to train models.

What data is shared with third-party model providers?

Mentimeter uses data minimisation by design, meaning we only share the information an AI capability needs in order to work. Depending on the functionality, this may include:

  • The prompt or other information the user directly provides to an AI feature
  • Content from Menti presentations – such as question text, choices, and other slide content, when the AI needs that context to generate relevant suggestions or insights
  • Audience responses, but only when the AI functionality is designed to analyse or work with those responses

Across all AI functionality, we do not share:

  • User identity (name, email, full profile data)
  • Workspace or organisation structure
  • Billing or payment information
  • Audience identities or device information

Third-party providers process the data only to generate the Output. They are not permitted to use this data to train models.

Will Mentimeter share my content with third parties?

No. Mentimeter does not share user content with third parties for marketing or advertising purposes. Data is shared only with our model provider when needed for an AI capability to function, and always under strict data-minimisation and security controls.

Where is AI-related data processed and stored, and in which region?

Mentimeter currently uses OpenAI as our third-party model provider. When an AI capability is used, the relevant data is sent to OpenAI and processed within their infrastructure in the United States. OpenAI may retain this data for up to 30 days for abuse-monitoring and operational security purposes, after which it is deleted. They are not permitted to use this data to train models.

AI-related processing by OpenAI is separate from Mentimeter’s own storage. All customer content stored within Mentimeter — including any AI-generated output — remains in our established hosting regions, as described in our Security Policy.

How long is this data retained, and can I request deletion?

When data is sent to our third-party model provider (OpenAI), it may be retained for up to 30 days for abuse-monitoring and operational security purposes, after which it is deleted. OpenAI is not permitted to use this data to train models.

Within Mentimeter, AI-related data is stored and retained in line with our general data handling practices as described in our Security Policy and Privacy Policy. You may request deletion of your User Data under GDPR, and we will handle your data accordingly.

Does Mentimeter anonymize or protect data before it’s sent to model providers?

Mentimeter applies data minimisation before sending data to a model provider. We only include the information required for an AI capability to work and do not attach user identity details, workspace information, billing data, or audience identities. All data is encrypted in transit, and access to data within Mentimeter follows strict least-privilege controls. Third-party providers are not permitted to use this data to train models.

Security & compliance

What security measures protect AI data and interactions?

AI data and interactions are protected using the same security measures that apply across the Mentimeter platform. We apply data minimisation, meaning we only send the information an AI capability needs in order to work. Requests sent to model providers do not include user identity details, workspace information, billing data, or audience identities. All data is encrypted in transit, and access to data inside Mentimeter follows strict least-privilege controls. Our broader security program — including continuous monitoring, vulnerability scanning, and independent assessments — also applies to all AI-related processing.

How does Mentimeter prevent unsafe or inappropriate AI outputs?

Mentimeter reduces the risk of unsafe or inappropriate AI outputs in three ways:

  1. Model-provider safety systems: We rely on the built-in safety and moderation systems of our model provider (OpenAI), which are designed to block harmful or sensitive content.
  2. Scoped usage: AI features in Mentimeter operate only within clearly defined product contexts, ensuring that the model is used in controlled and predictable ways.
  3. Continuous refinement: We continuously evaluate AI behaviour and adjust prompts, constraints, and feature design to help ensure outputs remain relevant and appropriate for typical Mentimeter use cases.

These measures work together to reduce the likelihood of harmful, sensitive, or irrelevant content being shown to users.

What standards and regulations (e.g., GDPR, SOC 2, EU AI Act) does Mentimeter comply with?

Mentimeter's information security management system is certified under ISO 27001:2022, meaning it meets internationally recognised standards for protecting data. We comply with the EU General Data Protection Regulation (GDPR) and apply its principles across all data processing activities, including AI-related processing.

Our hosting provider, Amazon Web Services (AWS), maintains certifications such as ISO 27001, SOC 1, SOC 2, PCI Level 1, and FISMA Moderate. Our third-party model provider, OpenAI, is SOC 2 Type 2 compliant.

Mentimeter continuously monitors developments in relevant regulations, including the EU AI Act, and will adapt our practices as required.

Model providers & governance

Which model providers does Mentimeter use?

Mentimeter currently uses OpenAI as our third-party model provider for AI capabilities. We use the OpenAI API, which is SOC 2 Type 2 compliant, and we ensure that only the data required for an AI capability to work is shared. OpenAI is not permitted to use Mentimeter data to train models.

How does Mentimeter assess and monitor third-party AI providers for security and compliance?

As subprocessors, our third-party model providers are subject to the same vendor-risk and security review processes applied across our platform. This includes assessing their security certifications, data-handling practices, privacy commitments, and contractual safeguards, as well as reviewing their published documentation for compliance with standards such as SOC 2 and GDPR. Mentimeter also monitors provider updates and security advisories on an ongoing basis to ensure continued alignment with our security and privacy requirements. Read more about OpenAI’s security and compliance here.

How often are Mentimeter’s AI systems reviewed or updated?

AI features follow Mentimeter’s standard secure development and review processes. This includes continuous monitoring, regular refinement of prompts and feature behaviour, ongoing security assessments, and updates aligned with our broader secure software development practices. As model providers release improvements or safety updates, we evaluate and incorporate them in line with product needs and our security policies.

Does Mentimeter perform testing or bias evaluation of AI outputs?

Mentimeter reviews AI behaviour as part of our product development and quality assurance processes. We test AI outputs for relevance, usefulness, and alignment with typical Mentimeter use cases, and we refine prompts or constraints when outputs do not meet expectations. We also rely on the safety, moderation, and bias-mitigation mechanisms built into our model provider’s platform. While we do not conduct formal bias audits, we continuously monitor performance and adjust our implementations to help ensure a consistent and appropriate user experience. Read more about OpenAI’s safety approach here.

Ethical & environmental responsibility

What principles guide Mentimeter’s use of AI?

Mentimeter uses AI to augment, not replace, human interaction. Our approach is guided by principles of data minimisation, security-by-design, and user control, ensuring AI features support clarity, insight, and accessibility without introducing unnecessary complexity or risk. We evaluate new AI capabilities against our product principles, privacy obligations, and security standards before releasing them.

What is Mentimeter’s stance on the environmental impact of AI?

Generative AI and machine learning require meaningful computing resources, and we recognize the environmental impact associated with running these workloads. Mentimeter offsets the emissions from the use of AI in our product and continues to collaborate with vendors and partners who are working to improve the efficiency and sustainability of their infrastructure. This approach is part of our broader climate strategy, which has enabled us to remain carbon negative since 2022. Read more about our climate work here.

At Mentimeter, our approach to integrating Artificial Intelligence (AI) is based on crafting a seamless experience for our users. We also ensure that ethical considerations and user privacy are at the forefront of our development process. - Mentimeter