What we store
Brand data and test results, not your customers' personal data.
mentionedin.ai stores your account details, your brand profile and truth file, your competitors, your prompts, the answers the engines return with their cited sources, page grades and your intervention log. It reads public pages of the sites you add. It does not need access to your website admin, your analytics or your customer data.
How it is protected
The measures that apply to every account.
- Hosting in the EU, in Germany.
- All traffic to the site, the app and the API is encrypted with TLS.
- Passwords are stored as hashes, never in plain text. You can also sign in with Google.
- Access to production data is limited to the people and systems that need it.
- Card details are handled by Stripe and never touch our servers.
- Shared reports use long random links, so a report is only visible to people you give the link to.
What we never do with your data
Limits that hold for every plan.
- We do not sell your data or share it with advertisers.
- We do not publish your results. A report is visible only to people you share its link with.
- We do not send anything to third party sites on your behalf. Source gaps are a list for your team, not an outreach tool.
- We do not log in to your website, and we only read pages that are public.
- We do not use one customer's brand data in another customer's account.
Who else processes data
Every vendor on our credentials is listed, with its country and purpose.
The AI engines we measure, the search data provider, hosting, email, payments and support tools are listed on /subprocessors/. Before a new sub-processor sees customer data we update that page and email customers at least 14 days in advance. The Data Processing Agreement at /dpa/ covers customers who need one, and the privacy policy at /privacy-policy/ explains the rest.
Deleting your data
Gone within 30 days of deleting your account.
When you delete your account, your brands, prompts, results and reports are deleted within 30 days. Invoices are kept for 7 years because Dutch tax law requires it.
Reporting a security issue
Tell us and we answer quickly.
If you find a vulnerability, email hi@mentionedin.ai with the details and how to reproduce it. Please give us a reasonable time to fix it before you share it publicly.