Privacy Policy
Last updated: 21 July 2026
Who we are
whereamimentioned ("we", "us", the "Service") is an AI-visibility monitoring service available at whereamimentioned.com, operated from Greece. We are the data controller for the personal data described in this policy. For any privacy question or request, contact hello@whereamimentioned.com.
What we collect
Account data. Your email address, hashed password (or OAuth identity from GitHub), and organization/workspace names you create. Legal basis: performance of a contract.
Billing data. Subscription tier, invoices, and payment status. Card details are processed and stored by Stripe — we never see or store your card number. Legal basis: performance of a contract and legal obligations.
Service content. The brand profiles, prompts, competitor lists, and scan results you create in the product, including AI-model answers and citations we retrieve on your behalf. Legal basis: performance of a contract.
Usage data. Product analytics events (pages viewed, features used) via PostHog — collected only if you accept analytics cookies, and otherwise held in memory for the session without persistent identifiers. Legal basis: consent. Error reports (which may include your IP address and browser details) via Sentry. Legal basis: legitimate interest in keeping the Service working.
Free checker. The brand URL and optional description you submit, plus your IP address for rate limiting. Legal basis: legitimate interest.
What we do not do
We do not sell personal data. We do not use your data to train AI models. We do not run third-party advertising or share data with ad networks.
Sub-processors
We share data with the following processors, only as needed to run the Service:
| Provider | Purpose | Region / transfer |
|---|---|---|
| Supabase | Database, authentication, and storage | EU/US (SCCs) |
| Vercel | Application hosting and delivery | EU/US (SCCs) |
| Stripe | Payment processing and billing | EU/US (SCCs) |
| OpenRouter | Routing AI-model probe requests | US (SCCs) |
| Inngest | Background job orchestration (scans) | US (SCCs) |
| Upstash | Rate limiting and caching | EU/US (SCCs) |
| Resend | Transactional email delivery | US (SCCs) |
| PostHog | Product analytics (only with your consent) | EU/US (SCCs) |
| Sentry | Error monitoring | EU/US (SCCs) |
Where a provider processes data outside the EEA, transfers rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework.
Retention
Account and service content are kept while your account is active and deleted within 30 days of account deletion, except invoices and billing records we must keep for tax law (up to 10 years). Free-checker submissions and rate-limit records are kept no longer than 30 days. Analytics data is kept per PostHog's standard retention.
Your rights (GDPR)
You have the right to access, rectify, erase, and export your personal data, to restrict or object to processing, and to withdraw consent at any time (this does not affect processing before withdrawal). To exercise any right, email hello@whereamimentioned.com from the address on your account — we respond within 30 days. You also have the right to lodge a complaint with your supervisory authority; in Greece, that is the Hellenic Data Protection Authority (dpa.gr).
Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production data is limited to what is needed to operate the Service. Passwords are hashed by Supabase Auth; API keys you bring (BYOK) are stored encrypted and never shown back in full.
Data processing agreement
If your organization needs a signed DPA covering the data you process through the Service, contact hello@whereamimentioned.com.
Changes
We will post any changes to this policy here and update the date above. Material changes affecting registered users will also be announced by email. See also our Terms of Service and Cookie Policy.