Legal
Privacy Policy
Last updated: 2026-05-22
This policy explains what we collect when you use MentionLayer, what we do with it, who we share it with, and the rights you have over your data. We try to keep it readable. If something isn't clear, email [email protected].
1. Who we are
MentionLayer is operated by Miji Australia Pty Ltd (ACN to be added), trading as MentionLayer ("we", "us", "our"). Registered office in New South Wales, Australia.
For privacy enquiries, contact our founder Joel House at [email protected]. We respond within 30 days as required by the GDPR, CCPA, and Australian Privacy Principles.
2. What we collect
We collect three categories of data:
- Account data — the name, email address, agency name, and password hash you provide at signup. Required to create your account.
- Brand workspace data — the client brand briefs, website URLs, keywords, competitor names, and team-member emails you add inside the product. This is the working content of your subscription.
- Operational telemetry — usage events, IP address, browser type, error logs, and pages visited. Used to keep the service running and to diagnose problems. Marketing-attribution events (ad clicks, signups, conversions) are sent to Google Ads / Analytics via our cookie banner.
We do not collect special-category data (health, ethnicity, religion, biometric identifiers, etc.). The Reddit, Quora, and Facebook Group content the platform discovers is public-web content and is not associated with any private user account on our side.
3. Why we collect it (lawful basis)
Under the GDPR Art. 6, our lawful bases are:
- Contract — we need account and workspace data to deliver the service you've subscribed to.
- Legitimate interests — operational telemetry, fraud prevention, and product analytics. We've weighed these against your rights and consider them proportionate.
- Consent — advertising and marketing cookies fire only after you accept them via the cookie banner. You can withdraw consent at any time from the cookie settings in the footer.
- Legal obligation — certain billing and tax records are retained for compliance with Australian Taxation Office and EU VAT rules.
4. Who we share it with (subprocessors)
We use the third-party services below to deliver MentionLayer. Each handles a specific slice of your data and is contractually bound to protect it. By using MentionLayer you authorise these subprocessors.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | US, EU |
| Vercel | Application hosting, edge functions | Global (regional) |
| Cloudflare | DNS, CDN, bot mitigation (Turnstile) | Global |
| Stripe | Payment processing, subscription billing | US, EU, AU |
| Anthropic (Claude) | AI processing — brand briefs, classification, response generation | US |
| OpenAI | AI probing — ChatGPT citation discovery | US |
| Perplexity | AI probing — citation discovery, keyword research | US |
| Google (Gemini, GA4, Ads, GTM) | AI probing, analytics, advertising attribution | Global |
| Apify | Web scraping for SERP, Reddit, Quora content | EU |
| SerpApi | Search results, AI Overviews monitoring | US |
| Moz | Backlink and domain authority data | US |
| SpyFu | Competitor traffic signals | US |
| Resend | Transactional email delivery | US, EU |
| Inngest | Background job orchestration | US |
| Sentry | Error monitoring | US, EU |
| PostHog | Product analytics | US, EU |
| Instantly | Email outreach delivery (PressForge) | US |
International transfers to subprocessors outside the EEA / UK rely on Standard Contractual Clauses. We do not sell personal data to any third party.
6. How long we keep it
- Account data — kept while your subscription is active. Deleted within 90 days of account closure unless we are required to retain it for legal reasons.
- Workspace data — same as account data; deleted within 90 days of closure.
- Billing records — retained for 7 years to satisfy ATO and EU VAT requirements.
- Telemetry & logs — retained for 30 days, then aggregated. Sentry error events follow Sentry's 30-day default.
7. Your rights
You have the right to:
- Access the data we hold about you.
- Correct data that's inaccurate or incomplete.
- Delete your data ("right to be forgotten" / GDPR Art. 17). Cancels your subscription and removes all workspace data within 90 days.
- Export your data in a portable format (GDPR Art. 20).
- Restrict or object to processing.
- Withdraw consent for marketing or analytics cookies.
- Lodge a complaint with a supervisory authority. For Australia: the OAIC. For the EU: your local Data Protection Authority.
To exercise any of these, email [email protected]. We will verify your identity and respond within 30 days.
8. Security
Workspace data is stored in Supabase with row-level security policies that isolate each agency. All connections are TLS 1.2+. Passwords are hashed with bcrypt. Service-role credentials are scoped to server-side processes only.
We do not currently hold SOC 2 certification ourselves. Our primary infrastructure providers (Supabase, Vercel, Cloudflare, Stripe, Anthropic) are independently SOC 2 Type II audited.
9. Children
MentionLayer is a B2B product. We do not knowingly collect data from anyone under 18. If you believe a child has registered, email us and we will delete the account.
10. Changes to this policy
We will update this page when we materially change how we handle data, and the "Last updated" date above will change with it. For account holders, material changes will also trigger an email.
11. Contact
Privacy enquiries: [email protected]
Postal: Miji Australia Pty Ltd, New South Wales, Australia (postal address available on request).
See also: Terms of Service.