Skip to content
Home

Privacy Policy

Last updated: August 6, 2026. This policy describes data handled by the Mentioned site, app, updates list, subscriptions, source-dependent features, and aggregate mention-data pipeline.

Who operates Mentioned

Stromatic Labs operates Mentioned and is accountable for its privacy practices. Contact the Stromatic Labs Privacy Lead at mentioned@stromaticlabs.com for privacy requests.

Data you provide

  • The email address on your Mentioned account is used for sign-in, account communication, and alert delivery when an alert-capable source lane is available and you enable that delivery method.
  • Supabase processes the one-time sign-in code or optional account password you use to authenticate. Mentioned does not retain those credentials in readable form. Never send a one-time code or password to Mentioned support.
  • If you separately join the website updates list, the email address you submit there is used to send product updates. You can leave that list using the instructions in the message or by contacting us.
  • Watchlist tickers, any saved alert thresholds, delivery preferences, and other settings you choose to save to your account. Saving an alert setting does not mean every source lane currently supports alert evaluation.
  • Optional profile fields you provide for onboarding or support.
  • On the website, an optional webhook endpoint and server-generated signing key if you configure Premium webhook alerts while that feature is available.
  • On the website, trader profile or tier interest if you submit those optional fields.
  • Messages you send to us by email, forms, or support channels.
  • Subscription and purchase records handled by Apple and RevenueCat in the iOS app, or by Stripe on the website, when you use paid access. Mentioned does not receive your full payment-card or bank-account details.
  • If you use referrals, your account's random referral code, referral attribution, qualification status, reward status, and the provider transaction identifiers needed to prevent duplicate, refunded, disputed, or fraudulent rewards. Referral summaries do not disclose either person's email address.

Technical data

  • Account and customer identifiers used to authenticate requests, keep entitlements attached to the correct account, and sync saved features.
  • IP address, coarse request region, and request metadata for rate limiting, security, logs, diagnostics, and abuse prevention.
  • Device, browser, request-region, referral, page, and event data used for security, operational diagnostics, performance measurements, and privacy-conscious aggregate analytics. Vercel Analytics and Speed Insights run on the website, not in the iOS app.
  • Cookie or local storage values needed for site preferences, such as theme choice.
  • The iOS app keeps Firebase Messaging token generation off until you explicitly enable push. After opt-in, Firebase processes an installation identifier and device/app configuration; the resulting push token is linked to your account so Mentioned can deliver alerts from compatible source lanes that you enable for that account. Enabling push does not cause an unsupported source lane to generate alerts. For supported tracked stocks, Mentioned's separate GDELT aggregate alert authority evaluates only while it is explicitly active and its source baseline is complete and current. Crypto mention alerts are not currently available.
  • If you enable push on the website, your browser's push service creates a subscription endpoint and delivery encryption keys. Mentioned stores that subscription with your account and sends encrypted alert payloads through the push service operated by Google, Mozilla, Microsoft, or Apple, as applicable to your browser when a compatible alert lane is available. For supported tracked stocks, the separate GDELT aggregate alert authority creates alert events only while it is explicitly active and its source baseline is complete and current. Crypto mention alerts are not currently available. Turning website push off removes the linked server record before asking the browser to unsubscribe. Account deletion also removes the linked server record. A browser-side subscription may remain until the browser finishes unsubscribing or you clear it in site settings, but Mentioned cannot deliver to it without the server record.

App Lock and on-device security

App Lock is optional. The app stores a one-way salted hash of the app passcode and its retry state on your device; the passcode itself is not retained or sent to Mentioned. Face ID or Touch ID is evaluated by iOS. Mentioned does not receive or store your face, fingerprint, biometric template, or Apple Account credentials. On iOS, the signed-in session is stored in the device Keychain.

Ticker searches and market quotes

When you use add-ticker search, the ticker or company text you enter is sent to Mentioned and to Yahoo's public symbol-search service to return matching listings. When a website surface displays current market quotes, the ticker symbols in that surface are sent to Mentioned, which requests the corresponding quote data from Yahoo's public market-data service. Search and quote responses may be retained briefly in provider or infrastructure caches under configured revalidation and eviction policies; a stale cache entry may remain longer if refresh is delayed or fails. Infrastructure request logs may retain the search term or requested ticker symbols with technical metadata such as IP address, user agent, and request region for security, diagnostics, and abuse prevention. Yahoo receives the search query or ticker symbols from Mentioned's server, not your Mentioned email address, account identifier, or push token.

Source and aggregate mention data

The current mention lane uses 15-minute GKG 2.1 data published by the GDELT Project. A collector transiently examines normalized entity and theme fields in each source record to find exact matches for the configured stock and crypto target mapping. It also transiently uses a source-domain key to calculate numeric publisher-diversity measures, then discards the domain value. For matched targets, it also counts service-allowlisted GKG topic labels while excluding the target's own identity and match theme. It sends Mentioned only per-target aggregate counts, per-topic matched-record counts, numeric diversity measures, and interval-level operational and integrity metadata. The GDELT lane does not store article content, article URLs, source domains, article titles, or publisher identities. Those fields are not displayed to customers either.

Stored GDELT interval records can include the source interval, aggregate record totals, per-target matched-record counts, mapping revision and digest, aggregate allowlisted topic-label counts, archive generation and checksums, collection timing, and validation results. Customer output is limited to aggregate ticker counts, 90-minute timing buckets, source attribution, freshness, and—for Premium—up to four recurring aggregate topic labels that appear in at least two matched records across the complete window. Free responses strip those labels. This lane does not derive or store article excerpts, raw keywords, sentiment, or explanations of why an entity appeared.

Separate source lanes operated in the past, or enabled in the future under provider authorization, can have different inputs and retention controls. A compatible public-discussion lane may process post IDs, timestamps, scores, titles, body text, and source labels for deduplication and filtering without separately collecting source-profile usernames or post permalinks. Any raw public text in such a lane is kept private, is not republished as a customer post or quotation, and is subject to the short retention rule below. We will update this policy before materially expanding what an active source lane collects or displays.

How we use data

  • Operate product updates and send confirmation emails.
  • Run available parts of the Mentioned site, app, aggregate source views, compatible alerts and summaries, and support.
  • Detect duplicate submissions, investigate abuse, and improve data quality controls.
  • Measure aggregate usage and improve the product.
  • Comply with legal, security, tax, accounting, or platform obligations.

Legal grounds and your choices

Where applicable law requires a legal basis, we process account, watchlist, alert, and subscription data to provide the service you request and perform our agreement with you. We process security, abuse-prevention, reliability, and limited aggregate analytics data for our legitimate interests in protecting and improving Mentioned, balanced against your rights. We use consent where required, including when you enable push notifications or separately join the website updates list. We also process limited records when necessary to comply with legal, tax, accounting, fraud-prevention, or platform obligations.

You can withdraw an optional consent at any time by disabling the related feature, changing your device permission, leaving the updates list, or contacting us. Withdrawal does not affect processing that was lawful before it took effect. Core account and security processing is necessary to provide a signed-in service; you can stop that processing by deleting your account.

Model providers

If a compatible ticker-summary feature uses a third-party model provider, Mentioned sends only the ticker symbol, an aggregate mention count, and, when a compatible source lane supplies them, a short list of service-allowlisted normalized aggregate themes rather than arbitrary source tokens. The current GDELT lane may supply up to four recurring aggregate topic labels that meet its minimum matched-record threshold. It supplies no article text, article URLs, domains, titles, publisher identities, or raw source keywords to a model provider. Email addresses, watchlists, payment details, private account credentials, and service-role keys are not included in a ticker-summary request.

Mentioned does not train or fine-tune models on source mention data. If that changes, we will update this policy before the change ships.

Under Anthropic's standard commercial API policy, API inputs and outputs are deleted from its backend within 30 days, subject to its safety, legal, and contractual exceptions. Mentioned does not opt API data into model training.

Service providers

We use Supabase for authentication and database services, Vercel for hosting, aggregate website analytics, and performance measurements, Firebase and Apple for native notifications, Google, Mozilla, Microsoft, or Apple browser push services for website notifications as applicable, RevenueCat and Apple for iOS subscriptions, Stripe for web subscriptions, Resend for email, Yahoo for symbol and market-quote lookup, Cloudflare Turnstile for abuse prevention on protected forms and the iOS sign-in challenge, and model providers for the compatible summary processing described above. The GDELT Project publishes the source data used by the current aggregate mention lane; GDELT is not given your Mentioned account, watchlist, billing, or push-token data for that collection. Service providers process data to provide services to us. We do not sell personal data and do not share product-update emails with advertisers.

We require service providers that handle personal data on our behalf to use it only for the contracted service and to protect it consistently with this policy and applicable law. We review the data sent to integrated providers and remain responsible for configuring our integrations appropriately.

When a protected form or the iOS sign-in screen shows Turnstile, Cloudflare processes the one-time challenge token, IP address, coarse request region, browser or device information, and request metadata needed to distinguish people from abusive automated traffic. The iOS challenge does not receive your sign-in email or password.

In the iOS app, RevenueCat receives your pseudonymous Mentioned account identifier and Apple purchase and entitlement status so Premium can follow the correct account across devices. Mentioned clears the email attribute rather than sending your account email to RevenueCat. RevenueCat also processes subscription analytics used to understand purchase, renewal, cancellation, and entitlement activity.

For website checkout, Mentioned sends Stripe your account email and Mentioned account identifier so the subscription can be attached to the correct account. Stripe Checkout directly processes the contact or billing information, payment method, transaction, device or network information, and fraud-prevention data needed to complete and protect the payment under the terms of the Stripe Privacy Center. Mentioned receives customer, subscription, transaction-status, and entitlement records, but not your full payment-card or bank-account details.

International processing

Stromatic Labs operates from Canada. Mentioned and its service providers may process data in Canada, the United States, and other countries where they operate. Privacy laws in those countries may differ from those where you live. Where required, we rely on provider contractual commitments and other lawful transfer safeguards. Contact us if you want more information about safeguards relevant to your data.

No advertising or cross-app tracking

Mentioned does not include an advertising SDK, sell personal data, share personal data with data brokers, or combine app activity with other companies' data for targeted advertising or advertising measurement. The iOS app does not request App Tracking Transparency permission because Mentioned does not perform that kind of tracking.

Retention

Product-update and account data is kept until deletion is requested or it is no longer needed for product, legal, or operational reasons. Mentioned and its billing providers may retain limited pseudonymous transaction, entitlement, and event records after account deletion for purchase restoration, entitlement integrity, tax, accounting, referral integrity, fraud or security prevention, and other legal obligations. Billing providers may also retain payment, account, transaction, and security records under their own policies.

Current GDELT interval receipts, per-entity aggregate counts, and topic-label aggregates become eligible for deletion after 72 hours and are removed by the lane's successful-ingest cleanup. If source ingestion stops, that cleanup can be delayed until ingest or maintenance resumes. Deleting an interval receipt also removes its linked count and topic-label rows. The lane never retains article content, article URLs, source domains, article titles, or publisher identities. Derived non-user-identifying feed snapshots and ticker summaries are retained for no more than 30 days unless a source agreement or operational control requires a shorter period.

In a separate provider-authorized public-discussion lane that accepts raw titles or post text, those fields become eligible for deletion at 48 hours and are removed by a five-minute cleanup, ordinarily within minutes after that point. A row already undergoing an exact-source check may remain until that lease ends. The lease cannot exceed 30 minutes or be renewed once the row is over-age; the next five-minute cleanup then removes it, ordinarily within 35 minutes after the boundary. Maintenance on other rows never delays cleanup. Product reads and compatible alert calculations never use raw text beyond the 48-hour window. Such a lane does not retain source-profile usernames or post permalinks.

Account-linked alert state and notification-queue status, where an alert-capable lane is available, are kept for no more than 30 days unless account deletion removes them sooner; queue events expire after one hour so old work is not delivered. The separate GDELT aggregate alert authority creates supported tracked-stock alert events only while it is explicitly active and its source baseline is complete and current; crypto mention alerts are not currently available. Mentioned's aggregate ticker-summary cache is removed after 30 days if it has not already been replaced by a current summary. Logs may be kept for security and debugging.

Deletion and access requests

Email mentioned@stromaticlabs.com to request access, correction, or deletion of personal data you provided. Signed-in users can also delete their account from the app's You tab. We may need to verify your identity. Some records may be retained where required for legal, security, fraud-prevention, accounting, backup, or operational reasons.

The Privacy Choices page explains how to manage alerts, push permission, App Lock, subscriptions, and account data.

Deleting a Mentioned account deletes the linked Stripe customer and cancels any website subscription, so web Premium access may end immediately; account deletion does not itself issue a refund. Deleting the Mentioned account is permanent, and the deleted account cannot be recovered. Before deleting, cancel any active App Store subscription in your Apple Account. Deletion does not cancel Apple billing, so Apple may continue billing until you cancel it. While the subscription is active, Premium remains tied to that Mentioned account and cannot be restored automatically to a different account. Contact support for ownership-verified subscription help. After the subscription fully expires and is no longer active, a later purchase or Restore Purchases may transfer it to a different Mentioned account.

Depending on where you live, you may also have rights to receive a copy of your data, correct it, restrict or object to certain processing, request portability, withdraw consent, and complain to your privacy regulator. These rights can have legal exceptions. We will not discriminate against you for making a privacy request.

Security

We use reasonable technical and administrative safeguards. No online service is perfectly secure. Do not send secrets, brokerage credentials, seed phrases, private keys, wallet keys, tax records, or other sensitive financial information to Mentioned.

Children

Mentioned is not intended for children under 18. Do not use Mentioned or submit data if you are under 18.

Changes

We may update this policy as the product changes. The updated date shows when the current version was posted.

Home / Terms / Privacy choices / Disclaimer