Overview
Mantis ("we," "us," or "our") operates the SEO auditing platform at usemantis.app. This Privacy Policy describes how we collect, use, store, and share information about you when you use our Service.
This policy applies to all users of usemantis.app, api.usemantis.app, and any related tools or communications. By using the Service, you agree to the practices described in this policy.
Short version: We collect what we need to run the Service and nothing more. We do not sell your personal data. We do not share it with advertisers. You can request deletion at any time.
Data We Collect
2.1 Account Data
When you create an Account, we collect:
- Email address — used for authentication, billing, and transactional notifications.
- Name — displayed in your profile and used in emails.
- Password (hashed) — stored using Node.js scrypt. We never store plaintext passwords.
- Avatar URL — optional profile image.
2.2 Billing Data
Payment processing is handled entirely by Paddle. Mantis does not store credit card numbers, CVVs, or bank account details. We retain:
- Paddle customer ID and subscription ID for account management.
- Plan tier, billing period start/end dates, and subscription status.
- Credit purchase amounts and transaction timestamps.
2.3 Usage & Activity Data
We log the following user activity with associated IP addresses and timestamps:
- Authentication events (logins, logouts, password resets, OTP requests).
- Site registrations and deletions.
- Scan jobs started, completed, or failed.
- Credits purchased and consumed.
- Fix approvals and dismissals.
- Plan upgrades, downgrades, and cancellations.
- JS snippet installations and verifications.
Activity logs are retained indefinitely for security, abuse prevention, billing disputes, and support purposes.
2.4 Crawl & Scan Data
When you initiate a scan, we collect and process:
- The URLs you submit for crawling.
- HTML content, meta tags, headings, link structures, and structured data extracted from crawled pages.
- Page performance metrics (load times, PageSpeed Insights scores).
- SEO issue types and severity scores assigned to each page.
- GEO readiness scores per AI search engine.
- AI-generated fix suggestions associated with each issue.
2.5 Technical Data
We automatically collect technical information to operate and improve the Service:
- IP address (logged on every request for security and activity tracking).
- Browser type, operating system, and device type (via User-Agent header).
- Request timestamps and API response codes.
- Session tokens (JWTs and refresh tokens stored server-side in Redis).
2.6 JS Snippet Data
If you install our JavaScript snippet on your website, the snippet pings our API on each page load. We receive the page URL, your site ID, your snippet token, and the visitor's IP address. The snippet also detects your CMS type (e.g., WordPress, Shopify). We do not track your website's visitors beyond this.
How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Performance of contract |
| Processing payments and managing subscriptions | Performance of contract |
| Sending transactional emails (OTP, welcome, billing, cancellation) | Performance of contract |
| Detecting and preventing fraud, abuse, and security incidents | Legitimate interests |
| Logging activity for billing disputes and support | Legitimate interests |
| Improving and developing the Service using aggregated, anonymized data | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Sending product update or promotional emails | Consent (opt-in only) |
Data Retention
| Data Type | Retention Period |
|---|---|
| Account profile data | Until account deletion request is fulfilled |
| Billing records | 7 years (legal / tax requirement) |
| Scan results & crawled page data | Indefinite (score history is a core feature); archived after inactivity |
| Activity logs & IP records | Indefinite (security & abuse prevention) |
| Session tokens (Redis) | 30 days (auto-expired) |
| OTP codes | 15 minutes (auto-expired) |
| Backups | 30 days rolling |
Upon account deletion, we remove your personal profile data and scan history within 30 days. Billing records and activity logs may be retained longer where required by law or to resolve outstanding disputes.
Security
We implement appropriate technical and organizational measures to protect your data:
- All data in transit is encrypted via TLS 1.2+.
- Passwords are hashed with Node.js scrypt — a memory-hard algorithm designed to resist brute-force attacks.
- Refresh tokens are single-use, rotated on every exchange, and revoked on logout.
- Authentication is rate-limited to prevent credential stuffing.
- Database access is restricted to the application layer; no public database endpoints are exposed.
- Redis is configured with
noevictionpolicy to prevent silent data loss.
No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly to security@usemantis.app.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Withdrawal of consent: Withdraw consent at any time where processing is based on consent (e.g., marketing emails).
To exercise any of these rights, contact us at privacy@usemantis.app. We will respond within 30 days.
Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@usemantis.app and we will delete it promptly.
International Transfers
Mantis operates servers in Europe (Contabo VPS) and uses services with global infrastructure (Stripe, OpenAI, Bright Data, Resend). Your data may be processed and stored in jurisdictions outside your own.
Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses or equivalent mechanisms as required by applicable data protection law.
Third-Party Services
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, billing details, subscription status |
| OpenAI | GPT-4o AI processing for issue detection and GEO scoring | Page content (HTML, meta, headings) extracted from crawled URLs |
| Bright Data | Residential proxy and Unlocker API for web crawling | Target URLs being crawled |
| Resend | Transactional email delivery | Email address, name, email content |
| Google PageSpeed Insights | Page performance scoring | Target URLs |
| Contabo | Cloud VPS hosting (EU) | All data stored on the platform |
| Vercel | Frontend hosting and CDN | Request metadata, IP addresses |
Each provider has their own privacy policy governing their use of data. We encourage you to review them if you have concerns about a specific provider.
AI Processing
Mantis uses OpenAI's GPT-4o model to generate SEO issue reports, fix suggestions, and GEO readiness scores. When you run a scan, the content extracted from your pages (HTML structure, meta tags, headings, visible text, link structure) is sent to the OpenAI API for processing.
We send only the structured page content necessary for analysis — we do not send your Account details, billing information, or other personal data to OpenAI. OpenAI's data usage policies apply to this processing. Mantis has opted out of OpenAI's data-training program for API calls.
Sensitive content: Avoid scanning pages that contain sensitive personal data (e.g., user-generated content with PII, private documents) unless you have the right to process and share that content with AI services.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where the changes are significant, notify you by email. Your continued use of the Service after the updated policy takes effect constitutes acceptance.
Contact
For privacy-related questions, data access requests, or to exercise your rights, contact us:
Mantis Privacy
Email: privacy@usemantis.app
General support: support@usemantis.app
Security disclosures: security@usemantis.app