Privacy Policy | MentionFox
What we collect, where it goes and what you can do about it
Last updated 2026-09-30
This page explains, in plain English, what mentionfox.com and the MentionFox app collect, where it goes and what you can do about it. It describes what our code does today. We do not sell personal data.
Cookies and tracking on mentionfox.com
The cookie banner has two choices: Accept All and Essential Only. Closing it with the X is the same as Essential Only. It appears at the bottom of every page on mentionfox.com until you choose (it is not shown if your browser sends Global Privacy Control or Do Not Track, or when one of our pages is shown inside another site's frame). Your choice is saved in your browser (localStorage, key mentionfox_cookie_consent) and applies to every page on mentionfox.com after that. On any page, until you have pressed Accept All, you are treated as if you had not agreed: nothing optional runs.
- Google Ads tag (Google). We use it to measure whether our Google ads lead to sign-ups and paid orders. The script loads from Google on our pages with every consent signal set to "denied". Until you press Accept All it sets no cookies and Google receives only consent-denied, cookieless signals (for example that a page was viewed, that a checkout was started, or that an order was paid, with its amount and our order number). After Accept All it may set advertising cookies such as _gcl_au, and Google may set its own cookies. We send Google the page address with only ad-click and campaign parameters kept (gclid, gbraid, wbraid and utm tags); every other parameter is removed. Enhanced conversions are off: we never send Google your name, email address or account details.
- Microsoft Clarity (Microsoft). Page analytics that show how people use our pages. It loads only after you press Accept All, never inside another site's frame, and it sets its own cookies (such as _clck and _clsk); Microsoft sets its own cookies too. Opening any page with ?clarity_optout=1 at the end of the address turns Clarity off for your browser even after Accept All (?clarity_optout=0 turns it back on).
- Umami (Umami Software). Simple visit counts on about a hundred of our pages and in the app. It sets no cookies and stores nothing in your browser. It receives the page address and title, the referring page, your screen size and browser language and, like any web server, your IP address and browser type. It is not controlled by the banner, because it sets nothing on your device; it does not load at all if your browser sends Global Privacy Control or Do Not Track.
- Essential Only means no advertising cookies and no optional analytics: the Google tag stays in consent-denied mode, Clarity does not load, and an ad click id is not kept (see below). Our own page-view records become a cookieless count, and no click or event record is sent (see below). If you choose Essential Only in another tab, a Clarity already running is told to stop.
- Global Privacy Control and Do Not Track are honoured. If your browser sends either signal, the Google tag, Clarity and Umami do not load at all, whatever you choose on the banner, no ad channel or click id is kept, our own click and event records (below) send nothing, and a page view is only a cookieless count.
- Essential storage in your browser: your sign-in session (sb-...-auth-token), your banner choice, and the small first-party records described below. See the Cookie Policy for the full list.
- To change your choice later, clear this site's data in your browser (or remove the
mentionfox_cookie_consent entry). The banner will appear again on the next page you open.
Our own first-party visit records
These are written to our own database, not to an analytics company, and use no cookies:
- Page views. One record per public page view: the page path, the referring page (its address without any query string), a random visitor id and a session id kept in your browser (localStorage), and any
utm_source, utm_medium, utm_campaign or ref word in the link. No IP address, no user agent and no email are stored with it. Pages behind a sign-in and pages shown inside another site's frame send nothing. This record is kept before you choose and after Accept All. If your browser sends Global Privacy Control or Do Not Track, or you chose Essential Only, it is not kept: no visitor id or session id is created (ones kept earlier are removed), and each page view only adds one to a daily count for that page.
- Cookieless page count. For a browser sending Global Privacy Control or Do Not Track, or a visitor who chose Essential Only, a page view sends only the page path and a channel worked out from that page's own address and referring page (paid, organic, other, direct, or a click inside our site). Our server adds one to the count for that page, day and channel. Nothing else is stored: no id, no IP address, no browser details, no time of day, and nothing is kept in your browser for it.
- Where you first came from. Your browser keeps the first outside page that sent you, the campaign tags and the first page you landed on (localStorage, keys
mf_first_touch and mf_last_touch). If you create an account, this and the random visitor id (when one exists) are attached to it so we know which channel brought you. An invite link you followed is kept for 30 days so the invite can be credited.
- Clicks and events. When you press a tracked button or open a box such as the Order Full Report box, we record the page address, which element it was, a session id, the first-touch record above, the referring website's host, and, on our servers, a salted one-way hash of your IP address and a rough device class (desktop, mobile, tablet) taken from your browser's user-agent. If you are signed in, your account id is included. Nothing is sent if your browser sends Global Privacy Control or Do Not Track, if you chose Essential Only, or if the browser is driven by an automated script.
- Ad channel and click id. Your browser keeps where you came from as a channel (paid, organic, direct or other) for 90 days (localStorage, key
mf_acq), together with the campaign tags of the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the first page you landed on and when. Campaign tags name our ad or link, not you. Our click and order records include the channel and the campaign tags. If you arrive from one of our Google ads, the Google ad click id (gclid, gbraid or wbraid) is kept and added to our records only if you have pressed Accept All. Before a choice, or with Essential Only, it is never stored in your browser and never sent to us; a click id kept earlier is removed. Your browser also notes the time of an ad click (not its id) so Google's consent-denied conversion signals can be sent.
- The help chat ("Foxy"). The chat on our pages is GetFoxChat, our sister product, loaded from its own server; what you type there is handled as GetFoxChat's privacy page describes. If you are signed in to MentionFox, we pass your email address and name to it so it knows who you are.
Emails you ask for on our company pages
Our company, funding, layoff, IPO, ownership and executive-change pages offer three things you can ask for with only an email address. None of them adds you to a mailing list. All are sent through Resend, and a copy of each email sent is kept in our sent-mail log. Limits per address and per connection stop anyone from using them to mail other people.
- "Email me a sample report". We send one email with a link to our sample reports and a link back to the page. We store your email address, the page and company, the time and the exact wording you agreed to, a salted one-way hash of your IP address, a rough device class, and whether the email was sent.
- "Email me this snapshot". We send the snapshot of that company to you once. We store the same details as above, plus the snapshot lines exactly as mailed and a session id.
- "Watch this company". We first send one confirmation email. Nothing else is sent unless you click its link to confirm; an unconfirmed request stops after 7 days (the request is marked stopped, not deleted). Once confirmed, we email you only when something new happens to that company, at most one email a day, and every email has a one-click stop link. We store your email address, the page and company, the time and wording you agreed to, a salted one-way hash of your IP address, a rough device class, a session id, the first-touch record above, the random link codes for confirming and stopping, and for each alert when it was sent and whether its link was clicked.
If you create an account or order a report
- Account. Your email address and password, or Google sign-in, handled by Supabase Auth. Google sign-in passes through Lovable's sign-in service on its way to Google. Your research, scans, reports, contacts, drafts and settings are stored in our Supabase database (hosted in Sydney, Australia).
- Full Report orders. We store the company ordered, the page it was ordered from, your email address, the order and payment status, the ad channel, the campaign tags and landing page kept in your browser (see Ad channel and click id) and, only if you pressed Accept All, the ad click id. The same channel, campaign tags, landing page and (only after Accept All) click id are attached to the order at Stripe, our payment processor, so a payment can be matched to the ad that led to it. We send a receipt email and one email when the report is ready, through Resend.
- Success-story permission. The order form has one optional box, unticked unless you tick it: "You may feature my use of MentionFox in an anonymised success story (no company names without my OK)". We store your choice with the order and, if you ticked it, when. Nothing is published from it automatically, and no company name is used without your OK.
- Sending a report to a colleague. If you make a private link to your finished report, we store the link's random code, the report it opens, when it was made, when it expires (30 days later) and, if your account has a name, your first name, which the shared page shows as "Shared by (first name) · MentionFox". The shared page never shows your email address or account details. You can turn the link off at any time and it stops working at once. "Email it" opens your own email app with the link filled in: we send nothing to the people you share with. When someone opens the link or presses its order button, we count it like our other visit records, without a name or email.
- Payments are handled by Stripe. We receive your plan, subscription or order status and billing email; we never see or store your full card number.
- Research you run. When you research a person or company, MentionFox gathers information about them from web pages, search results, public records and specialist data providers, and keeps the results in your account. The names, companies and questions you enter are sent to those providers and to the AI providers listed below so they can do the work.
- Services you connect. If you connect a mailbox (Gmail), social accounts or other tools, we use the access you grant only for the features you use. Emails to your contacts are sent only after you preview them and press send. Phone calls you place from the CRM go through Twilio. You can disconnect a service at any time; deleting your account also revokes Gmail access.
- Emails to you. Account emails such as password resets come from Supabase Auth. Product emails you asked for (for example a report is ready) are sent through Resend.
Claude Connector data handling
When you connect MentionFox to Claude through Anthropic's Connectors directory:
- Access tokens. We store only one-way (SHA-256) hashes of the tokens that let Claude call MentionFox for you. You can revoke a connection at any time in MentionFox under Settings, MCP (Active connections), or in Claude under Settings, Connectors. A revoked token stops working at once.
- Tool calls. For each tool call we log which tool was called, the details you passed to it (for example the name you asked about), the credits charged, whether it worked and when. Anthropic does not share your Claude conversation with us, and we do not see it.
- Results. Dossiers, company research and other results are saved to your MentionFox account, just as if you had run them in the app, and are charged to your normal credit balance.
- Anthropic sees only what the tools you call return to Claude.
Reference: connector documentation · pricing · connectors@mentionfox.com
Service providers we use
- Vercel hosts mentionfox.com and runs part of our server code. Cloudflare provides our domain name service.
- Supabase hosts our database, sign-in, file storage and server functions (Sydney, Australia).
- Stripe handles payments. Resend sends email. Twilio carries phone calls you place from the CRM. Lovable runs the Google sign-in step.
- AI providers. Anthropic writes and checks most research, reports and drafts. OpenAI, Google, DeepSeek and Perplexity also handle parts of research, analysis and drafting. For AI-visibility checks, we ask assistants from OpenAI, Google, Anthropic, Perplexity, xAI, Mistral, Groq and Cohere questions about the brand you track.
- Research data. Specialist providers of web search, social media posts, company and public records, and email-address checks receive the names, companies, domains and addresses needed to run the research you ask for.
- Google (Ads tag), Microsoft (Clarity) and Umami, as described above.
- GetFoxChat, our sister product, runs the help chat.
People and companies on our public pages
Our public pages about companies, funds, filings, layoffs and executive changes are built from public records and filings. If you are named on one of these pages and want something corrected or removed, email privacy@mentionfox.com.
Keeping and deleting data
We keep account data while your account is in use. The only automatic time limits are the ones stated on this page (the 30-day ad channel and 30-day invite in your browser, and the 7-day limit on unconfirmed watches).
- Delete your account yourself in Settings, under Danger Zone. It deletes your account, your data and your uploaded files. If it cannot finish, your account keeps working and it tells you what happened. It will ask you first to cancel an active paid subscription or to remove the other members of a team you own. Payment records we must keep for tax law stay, with your name and email removed.
- Everything else, including a copy of your data, a correction, stopping or deleting a sample, snapshot or watch request, or a request about a page that names you: email privacy@mentionfox.com.
Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you can ask to see the personal data we hold about you, get a copy of it, have it corrected or deleted, limit or object to how we use it, and complain to your data protection authority. To use any of these rights, email privacy@mentionfox.com.
Security
Everything between your browser and our servers travels over encrypted connections (HTTPS). Access to our database is restricted, and the request records described on this page are readable only by our own server code.