Privacy policy

Mentionkit Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains how Nazare Studios Pty Ltd (ABN 18 695 273 995), a company incorporated in Victoria, Australia, collects, uses, stores, and shares information when you use Mentionkit.

In this policy, “Mentionkit,” “we,” “our,” and “us” refer to Nazare Studios Pty Ltd and the Mentionkit website, application, APIs, Model Context Protocol (“MCP”) server, and related services.


1. Information We Collect

The information we collect depends on how you use Mentionkit.

1.1 Account and workspace information

When you create or use an account, we may collect:

  • Your name, email address, profile image, and account settings.
  • Your organization name, workspace membership, role, invitations, and active workspace.
  • Login and security information, such as authentication records, session information, IP address, browser, device, and user agent.
  • Project details, website information, keywords, monitoring settings, notification settings, reports, and comments you add to Mentionkit.
  • Support messages and any screenshots, error messages, or other information you choose to send us.

1.2 Billing information

We use Stripe to process subscriptions and payments. We may receive and store billing-related information such as your Stripe customer and subscription identifiers, plan, subscription status, billing period, and payment status.

Stripe processes your payment card and other payment details under its own privacy policy. Mentionkit does not store your full payment card number.

1.3 Public social and web content

Mentionkit monitors public sources based on the keywords and settings you choose. We may collect and process:

  • Public post, comment, video, profile, or page text.
  • Public author names or handles.
  • Platform and source identifiers.
  • Source URLs, publication dates, and timestamps.
  • Keywords that matched the content.
  • Language, tags, relevance scores, summaries, classifications, and other analysis created by Mentionkit.
  • Your review status, notes, comments, and actions related to a mention.

This content may come from sources such as Reddit, X, LinkedIn, Hacker News, YouTube, Bluesky, TikTok, Medium, GitHub, and other public sources we support.

1.4 API, MCP, OAuth, and integration information

If you use our API, MCP server, webhooks, or another integration, we may process:

  • API requests, MCP tool inputs, webhook settings, and integration configuration.
  • API keys, OAuth scopes, authorization grants, token metadata, client identifiers, callback details, and connection timestamps.
  • The user, organization, and project connected to the request.
  • Request, usage, error, and security logs needed to operate and protect the service.
  • Data returned in response to a request.

Depending on the tool you call, MCP responses may include project names and identifiers, keyword values and settings, mention identifiers, public author handles, post text, source URLs, platforms, timestamps, relevance scores, tags, and review or comment status.

Mentionkit stores sensitive OAuth records using appropriate security measures. Short-lived authorization records expire automatically, and revoking a connection invalidates its grant.

1.5 Connected AI services

When you connect Mentionkit to ChatGPT, Claude, or another AI service, that service may send requests to Mentionkit on your behalf. We return the information needed to complete the request you approved.

For example, if you ask ChatGPT to find recent opportunities, Mentionkit may return matching public post text, author handles, source URLs, keywords, projects, relevance scores, and related metadata. If you approve a write action, the connected service may send a keyword and its settings to Mentionkit for creation.

Information sent to a connected service is also handled under that service’s terms and privacy policy. Review the privacy settings of a connected service before using it with Mentionkit. You can revoke an OAuth connection to stop future access.

1.6 Usage and analytics information

We use PostHog on our website and application. We may collect:

  • Pages and features you use.
  • Actions you take in the service.
  • Referral information.
  • Browser, device, approximate location, IP address, and similar technical information.
  • Cookies, local storage, and similar technologies used for login, preferences, analytics, and service operation.

2. How We Collect Information

We collect information:

  • Directly from you when you create an account, configure Mentionkit, contact support, or make a payment.
  • From members or administrators of your organization.
  • Automatically when you use our website, application, API, or MCP server.
  • From public websites and social platforms that Mentionkit monitors.
  • From connected services and providers when you authorize an integration.

3. How We Use Information

We use information to:

  • Create, authenticate, and manage your account and workspace.
  • Monitor keywords and provide mentions, alerts, reports, analysis, and other product features.
  • Respond to API, MCP, webhook, and integration requests.
  • Process subscriptions and manage billing.
  • Send account, security, billing, support, and service messages.
  • Send product or marketing messages where permitted. You can unsubscribe from marketing messages.
  • Provide customer support and investigate problems.
  • Measure and improve the reliability, performance, and usability of Mentionkit.
  • Detect fraud, abuse, unauthorized access, and security incidents.
  • Enforce our Terms and comply with legal obligations.
  • Protect the rights, safety, and property of Mentionkit, our users, and others.

4. How We Share Information

We may share information in the following situations.

4.1 With your organization

Information in a Mentionkit workspace may be visible to other authorized members and administrators of that organization.

4.2 With connected services at your direction

When you connect or use ChatGPT, Claude, Slack, Discord, Telegram, a webhook, or another integration, we share the information needed to complete the request or deliver the integration.

4.3 With service providers

We use providers that help us operate Mentionkit, including:

  • Hosting, infrastructure, database, and storage providers.
  • Stripe for billing and payments.
  • Resend for email delivery.
  • PostHog for product and website analytics.
  • OpenRouter and AI model providers for selected AI-assisted features.
  • Security, monitoring, and customer support providers.

These providers may process information only as needed to provide their services to us and are subject to their own legal and privacy obligations.

For AI-assisted features, we may send relevant project details, keyword settings, instructions, and public mention content to an AI provider to create classifications, relevance analysis, summaries, or drafts.

We may disclose information if we reasonably believe it is necessary to:

  • Comply with a law, regulation, court order, or lawful government request.
  • Protect the security or integrity of Mentionkit.
  • Investigate fraud, abuse, or a violation of our Terms.
  • Protect the rights, safety, or property of our users, the public, or another person.

4.5 Business changes

If Mentionkit or Nazare Studios Pty Ltd is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be shared as part of that transaction. We will continue to protect personal information and provide notice where required.


5. Overseas Processing

Mentionkit is operated from Australia. Some service providers and connected services may process or store information outside Australia, including in the United States and other countries where they operate.

Privacy laws in those countries may differ from Australian law. Where required, we take reasonable steps to use providers and arrangements that protect personal information.


6. Data Retention

We keep information for as long as needed to:

  • Provide Mentionkit and maintain your account.
  • Complete the purpose for which the information was collected.
  • Meet billing, tax, accounting, security, fraud prevention, and legal requirements.
  • Resolve disputes and enforce our agreements.

Account, workspace, project, keyword, and mention data is generally kept while your account is active. Some records may remain for a limited period after deletion in backups, security logs, billing records, or where retention is required by law.

OAuth authorization records and connection grants expire or are removed according to their configured lifetime. Revoked grants cannot be used for future access.

Public content collected from third-party sources may remain in Mentionkit after it changes or is removed at the source. You can contact us if you believe personal information should be corrected or removed.


7. Data Security

We use reasonable technical and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, or disclosure.

No online service can guarantee complete security. You are responsible for keeping your password, API keys, OAuth connections, and other account credentials secure. Contact us promptly if you believe your account or credentials have been compromised.


8. Your Choices and Rights

Depending on where you live, you may have rights to:

  • Access personal information we hold about you.
  • Ask us to correct inaccurate or incomplete information.
  • Ask us to delete personal information, subject to legal and operational retention requirements.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Unsubscribe from marketing messages.
  • Revoke an OAuth connection or remove an integration.
  • Delete your Mentionkit account.

You can update some information in your account settings. For other requests, email shash@mentionkit.com. We may need to verify your identity before completing a request.


9. Public Content and Removal Requests

Mentionkit processes public content to provide social monitoring services. If you are the author of public content shown in Mentionkit and believe it contains personal information that should be corrected or removed, contact shash@mentionkit.com.

Please include the source URL, a description of the content, and enough information for us to review the request. We may ask you to confirm that you are the person concerned or are authorized to act for them.


10. Children

Mentionkit is not directed to children under 13. If you believe a child under 13 has provided personal information to us, contact us so we can review and remove it where appropriate.


11. Privacy Questions and Complaints

If you have a privacy question, request, or complaint, email shash@mentionkit.com.

Please explain what happened and include any relevant account email, dates, or screenshots. Do not send passwords, API keys, access tokens, or OAuth tokens.

We will review your request and respond within a reasonable time. If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner.


12. Changes to This Policy

We may update this Privacy Policy when our services, providers, or legal obligations change. We will post the updated policy on this page and change the “Last updated” date.

If a change materially affects how we handle personal information, we may provide additional notice through the service or by email where appropriate.