Privacy policy
Between you and MentionMachine.ai. Last updated August 2026.
The short version: we store what you give us, what we crawl from the sites you scan, and what AI engines answer. We do not sell any of it. The detail below matters most if you are a business named in someone else's scan.
1. Who we are
MentionMachine.ai is the data controller for the personal data described here. Reach us through the contact form, which is open whether or not you have an account.
2. What we collect about you
- Account: your email address, name if you give one, and a hashed password. If you sign in with Google we receive your email, name and profile picture.
- Billing: handled by Stripe. We store their customer and payment identifiers and the tier you bought. We never see or store your card details.
- Usage: the domains you scan, the questions you track, your scans, reports and credit ledger.
- Free scans: the domain, a hashed IP address for rate limiting, and your email if you give one to unlock the detail.
- Account security: when you sign in, we record the IP address and browser you signed in from, and whether the attempt succeeded. It is what lets you see where your account is signed in and end a session you do not recognise, and what lets us spot somebody trying passwords against your address.
- Product analytics: self-hosted, on our own infrastructure. Not shared with an advertising network. We record which pages were viewed and which actions were taken, against a random id stored in your browser rather than against your name or address, plus the marketing channel you arrived through if there was one. We also record the country a visit came from, as a two letter code our network provider attaches and we keep nothing else of, and the name of the website that sent you here, never the full address of the page you were on. No IP address, and no device fingerprint.
Lawful basis: contract for everything needed to provide the service, legitimate interests for security, abuse prevention and product analytics, and consent for marketing email, which you can withdraw from any message.
3. Data about businesses that are not our customers
This is the part most privacy policies in our category leave out, so we will be explicit.
To answer “what do AI engines say about this market”, we store the text those engines return. That text names businesses: competitors, directories, and companies who have never heard of us. We also crawl publicly available pages of any domain that is scanned and extract business information from them, which for a sole trader can include a name, a phone number and an address that are personal data.
Our lawful basis is legitimate interests: analysing a public market to tell a business how it is represented in it. We have assessed this against the rights of those individuals and limit it accordingly. We collect only what is already published on a public web page or returned by a public AI service, we do not build profiles of individuals, we do not sell or share this data as a product, and we do not use it to contact anyone without their consent.
If you are a business or sole trader whose details we hold and you want them removed, tell us and we will remove them and suppress the domain from future crawls. You do not need to be a customer to ask.
4. The shared answer index
Answers to general, category-style questions are cached and may be served to another customer who asks the same question, which is why most scans cost far fewer credits than the questions they cover. Questions naming a specific business, and anything relating to your own account, site, reports or generated content, are never shared. The terms set out the same position.
5. Who we share data with
Only the processors needed to run the service: AI providers, payment, email, hosting and infrastructure. They are listed individually, with what each receives, on the subprocessor page. We do not sell personal data, and we do not share it for advertising.
When we send a question to an AI provider, that question and your domain name go to them under their own terms. We send the minimum needed to get an answer.
6. How long we keep it
- Your scans and reports: indefinitely, on purpose. The product's core promise is showing change over time, and a before/after loses its meaning if the before is deleted. You can delete a scan at any time, and deleting your account removes all of it.
- The answer index: indefinitely. It is what makes cached answers free. It records what an engine said about a market on a date, and is not tied to your account.
- Free-scan records: 24 months, then deleted.
- Sign-in records: 90 days, then deleted automatically. That includes the IP addresses and browsers above.
- Billing records: seven years, because tax law requires it.
7. Your rights
You can ask for a copy of your data, correction, deletion, or restriction of processing, and you can object to processing based on legitimate interests. Ask us and we will respond within one month.
Deleting your account deletes your scans, reports, generated artifacts and personal details. Entries in the shared answer index are not tied to you and remain, as do billing records we are legally required to keep.
If you are in the UK or EU and think we have handled your data badly, you can complain to your data protection authority (in the UK, the Information Commissioner's Office).
8. Security
Transport encryption throughout, passwords hashed, provider credentials encrypted at rest, and access to production limited to the operator. Backups are encrypted and stored off the server they protect. No system is perfectly secure, and we will notify you and the regulator as required if a breach affects your data.
9. Cookies
A session cookie when you are signed in, and a preference cookie for your theme. If you arrive through a link carrying campaign tags (a utm_source, or the click id a search advert appends), we store those tags and the site you came from in a first-party cookie called aeo_attr for 90 days, so we can tell which of our own adverts and articles are worth writing. It holds nothing else: no identifier for you, nothing that follows you to another website, and if you arrive without campaign tags it is never set at all.
Product analytics are first-party and self-hosted. We record the country a visit came from and the site that referred it, and nothing that could identify you or follow you to another website. No advertising or cross-site tracking cookies, which is why there is no consent banner in your way.
10. International transfers
Our servers are in the EU. Some processors, notably the AI providers, are in the United States, and those transfers rely on the appropriate safeguards under UK and EU law. Each is named on the subprocessor page.
Questions about any of this? The documentation explains the practical side in plainer language.