Privacy & Data Protection

Privacy Policy

Effective Date: February 12, 2026

Last Updated: February 12, 2026

Version: 1.0

At Mention Pilot, we believe your data belongs to you. This Privacy Policy explains exactly what we collect, why we collect it, how we use it, and your rights over it. We have written this in plain English because privacy policies should be readable, not just legally sound.

1. Who We Are

Mention Pilot ("we," "our," or "us") is a real-time brand monitoring platform that helps businesses track conversations, mentions, and sentiment across multiple digital channels. Our service is accessible at mentionpilot.ai and through our application at app.mentionpilot.ai.

For the purposes of applicable data protection laws, Mention Pilot acts as the data controller of your personal information.

2. What Information We Collect

2.1 Account and Registration Information

When you create a Mention Pilot account, we collect:

  • Full name and professional title
  • Business email address
  • Company name and industry
  • Password (stored in encrypted, hashed form only)
  • Billing information (processed securely via our payment processor)

2.2 Usage and Service Data

As you use the platform, we collect:

  • Brand names, keywords, and competitors you configure for monitoring
  • Dashboard interactions, settings, and preferences
  • Alert configurations and notification preferences
  • Feature usage patterns and session activity
  • Reports you generate and data exports you request
  • Team member invitations and collaboration activity

2.3 Technical and Device Information

We automatically collect the following when you access our services:

  • IP address and approximate geographic location
  • Browser type, version, and language settings
  • Operating system and device type
  • Referring URL and pages visited within our platform
  • Timestamps of access, session duration, and click paths
  • Log data and error reports

2.4 Communications Data

  • Emails and messages you send to our support team
  • Feedback, survey responses, and product reviews you submit
  • Content of support tickets and chat transcripts

2.5 Payment Information

We do not store your full credit card details. Billing is handled via our PCI-compliant payment processor (Stripe). We retain only transaction identifiers, subscription status, and billing history.

3. How We Collect It

  • Directly from you when you register, fill out forms, or contact us
  • Automatically through cookies, analytics tools, and server logs as you use the platform
  • From third-party integrations you choose to connect (e.g., Slack, Salesforce, Zapier)
  • From payment processors to confirm and manage subscription status
  • From publicly available sources strictly for the brand monitoring service you have requested

4. Why We Use Your Information

We use your information for the following purposes:

Purpose What We Do
Service Delivery Create and manage your account, run your brand monitors, generate sentiment analysis, and deliver alerts.
Billing Process subscription payments, manage plan upgrades and downgrades, and issue invoices.
Communications Send transactional emails (account confirmations, alerts, invoices) and product update notifications.
Product Improvement Analyze usage patterns to fix bugs, improve features, and develop new capabilities.
Customer Support Respond to your queries, resolve issues, and provide onboarding assistance.
Security and Fraud Prevention Detect unauthorized access, prevent abuse, and protect platform integrity.
Legal Compliance Meet our obligations under applicable laws and respond to lawful requests.
Marketing (with consent) Send promotional content and feature announcements to users who have opted in.

If you are located in the European Economic Area (EEA) or the United Kingdom, our processing of your personal data is based on the following legal grounds under the General Data Protection Regulation (GDPR):

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide our service to you under our Terms of Service.
  • Legitimate interests (Art. 6(1)(f)): Improving our product, ensuring security, preventing fraud, and conducting analytics.
  • Legal obligation (Art. 6(1)(c)): Compliance with applicable laws, tax requirements, and regulatory obligations.
  • Consent (Art. 6(1)(a)): Marketing communications and optional tracking cookies, which you can withdraw at any time.

6. How We Share Your Information

We do not sell your personal data. We do not trade it. We share data only in these limited circumstances:

6.1 Service Providers (Sub-processors)

We work with trusted third-party vendors who process data strictly on our behalf, under binding data processing agreements. These include:

  • Cloud hosting and infrastructure providers
  • Payment processing (Stripe)
  • Email delivery services
  • Customer support tools
  • Analytics and error monitoring

6.2 Integrations You Authorize

When you connect third-party services (Slack, Teams, Salesforce, Zapier, etc.), you authorize us to share relevant data with those services to power the integration. We share only the minimum data necessary.

6.3 Business Transfers

If Mention Pilot is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

We may disclose your information when required by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

We may share data in any other way with your explicit, informed consent.

7. International Data Transfers

Mention Pilot operates globally. Your data may be processed in countries outside your own, including the United States. Where data is transferred from the EEA or UK to a country without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The EU-US Data Privacy Framework where applicable
  • Binding corporate rules or other approved transfer mechanisms

You can request a copy of the transfer safeguards we use by contacting us at the address below.

8. How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required by law. Typical retention periods are:

Data Type Retention Period
Account information For the duration of your account, plus 30 days after deletion
Brand monitoring data Per your subscription plan (Starter: 7 days, Growth: 1 year, Enterprise: unlimited)
Billing records 7 years (legal and tax requirements)
Support communications 3 years from last interaction
Analytics and log data 13 months (rolling)
Backup copies Purged within 90 days of account deletion

9. Data Security

We take the security of your data seriously. Our measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls limiting who can access production data
  • Regular third-party security audits and penetration testing
  • Multi-factor authentication (MFA) support for all accounts
  • Automated monitoring for suspicious access patterns

No method of transmission over the internet or electronic storage is 100% secure. While we implement industry-leading protections, we cannot guarantee absolute security. In the event of a data breach that affects your rights and freedoms, we will notify you and relevant authorities as required by law.

10. Your Privacy Rights

For All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Ask us to correct inaccurate or incomplete data.
  • Deletion: Request that we delete your personal data (subject to legal retention obligations).
  • Opt-out: Unsubscribe from marketing communications at any time via the unsubscribe link in any email.
  • Data portability: Receive your data in a structured, machine-readable format.

For EEA and UK Users (GDPR / UK GDPR)

  • Restriction of processing: Ask us to restrict how we process your data in certain circumstances.
  • Object to processing: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent at any time where processing is consent-based.
  • Lodge a complaint: File a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU).

For California Residents (CCPA / CPRA)

  • Right to know: Know what personal information is collected, used, shared, or sold.
  • Right to delete: Request deletion of personal information we have collected.
  • Right to opt-out: Opt-out of the sale or sharing of personal information (we do not sell data).
  • Right to non-discrimination: Not be discriminated against for exercising your privacy rights.
  • Right to limit: Limit the use of sensitive personal information.

To exercise any of these rights, contact us at support@mentionpilot.ai. We will respond within 30 days (or 45 days where permitted by applicable law). We may need to verify your identity before processing your request.

11. Children's Privacy

Mention Pilot is a business-to-business platform not directed at children. We do not knowingly collect personal information from any person under the age of 16. If we learn that we have inadvertently collected data from a minor, we will delete it promptly. If you believe we may have collected such data, please contact us immediately.

Our platform may contain links to third-party websites or services. This Privacy Policy does not cover those external services. We encourage you to review the privacy policies of any third-party service you connect to through Mention Pilot. We are not responsible for the privacy practices of those services.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to active account holders
  • Display a prominent notice within the platform for at least 30 days

Your continued use of Mention Pilot after the effective date of any update constitutes your acceptance of the revised policy.

14. Contact Us

For privacy-related questions, requests, or concerns, please reach out to:

Mention Pilot Privacy Team
Email: support@mentionpilot.ai
Website: mentionpilot.ai
Response time: Within 2 business days for general inquiries; within 30 days for formal data rights requests.

© 2026 Mention Pilot. All rights reserved. • Terms of ServiceCookie Policysupport@mentionpilot.ai