Privacy Policy

Last updated: August 24, 2026

This policy explains how MentionAudit (“we”) collects, uses, and shares personal data when you use our website, dashboard, and APIs (the “Service”). We do not sell personal data and we do not run advertising or marketing trackers.

1. Who we are

The data controller is Sam Miller, 1209 Mountain Road Pl NE Ste N, Albuquerque, NM 87110, United States. Contact: [email protected].

2. What we collect

  • Account data: email, name, profile image, password hash or OAuth provider ID, workspace name, plan, and billing name and address.
  • Audit content: the brand domains, keywords, competitor names, and briefs you submit, plus the AI responses and analysis we generate from them. Do not submit personal data of third parties as audit input.
  • Connected integrations: if you connect Google Analytics, Search Console, or Slack, we store an encrypted OAuth token and pull only the data you authorize. Disconnecting revokes the token.
  • Usage and technical data: pages viewed, features used, IP address, user agent, request URLs, and error reports.

3. How we use it

  • To provide the Service — run audits, store your history, send transactional email, process payments (legal basis: contract).
  • To secure and improve the Service — fraud and abuse prevention, error monitoring, product analytics (legal basis: legitimate interests; you may object at any time).
  • To comply with law — tax, accounting, and lawful requests (legal basis: legal obligation).
  • Product updates — only if you opt in; unsubscribe at any time (legal basis: consent).

We do not make automated decisions that produce legal or similarly significant effects on you.

4. Who we share it with

We share personal data only with the service providers below, each bound by a data-processing agreement, and with authorities where legally required.

RecipientPurposeDataLocation
ClerkAuthentication and account managementEmail, name, password hash, OAuth provider IDs, IP address, user agentUnited States
StripeSubscription billingEmail, name, billing address. Card details are entered on Stripe-hosted checkout and never reach our servers.United States, Ireland
CloudflareBot protection on the public audit formIP address, user agent, challenge tokenUnited States, global edge
PostHogProduct analyticsAnonymous ID, event names, page URL, IP address, user agent; linked to your account ID after sign-inUnited States
SentryError monitoringAccount ID, email, request URL, sanitized stack tracesUnited States
AI model providers (Google, OpenAI, Anthropic, Perplexity, xAI)Generate the AI responses your audit analyzesAudit inputs only (brand domain, keywords, competitor names). No account data.United States
Railway and VercelApplication, database, and frontend hostingAll stored account and audit data; server logs (IP address, user agent, request URL)United States
Google (Analytics, Search Console) and Slack — only if you connect themOptional integrations you authorize from your accountOAuth tokens (encrypted at rest), the metrics or channels you authorize, alert contentsUnited States

5. Cookies

We use only strictly necessary cookies: Clerk session cookies to keep you signed in, and a short-lived Cloudflare cookie for bot protection on the public audit form. Your light/dark preference is stored in browser local storage. We set no advertising or tracking cookies, so no consent banner is shown.

6. Retention

  • Account and audit data: while your account is active, and until you request erasure after closing it. Backups roll off within 35 days.
  • Billing records: 7 years, as required for tax purposes.
  • Server logs and error reports: up to 90 days.
  • Integration tokens: deleted within 24 hours of disconnection.

7. International transfers

We are located in the United States and our providers process data there. Where we transfer data of EEA, UK, or Swiss residents, we rely on Standard Contractual Clauses or the EU-US Data Privacy Framework as applicable.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to lodge a complaint with your local data-protection authority. To exercise any of these, email [email protected]; we respond within 30 days and may ask you to verify your identity. We do not discriminate against you for exercising your rights.

9. Security

We protect data with encryption in transit and at rest, access controls scoped to your workspace, and logging of sensitive actions. No system is perfectly secure; report suspected vulnerabilities to [email protected].

10. Children

The Service is for businesses and is not directed at children under 16. We do not knowingly collect their data; contact us to have it removed.

11. Changes

We will update this policy when our practices change and notify account owners of material changes by email or in-product notice.

12. Contact

[email protected]. See also our Terms of Service.