Last updated: July 17, 2026
This Privacy Policy explains how Mimetic Inc ("Mimetic", "we", "us", or "our") collects, uses, shares, and protects information when you visit our websites, request a site audit, view an audit report, use the Mimetic command-line interface ("CLI"), API, or Model Context Protocol ("MCP") server, connect third-party accounts, install our GitHub App, use our Rerun session replay and code-improvement tools, or otherwise interact with our services (the "Service").
Some features are optional and apply only if you choose to use them, such as Google Analytics, Google Search Console, Google Ads, PostHog, Klaviyo, the GitHub App, Slack notifications, session replay, PR previews, hosted analytics setup, AI-agent integrations, and payments.
When you submit a website, Mimetic may crawl and analyze publicly accessible pages and public business information. Reports may include screenshots, page text excerpts, detected tracking tools, technical checks, SEO findings, conversion findings, recommendations, and estimated business impact.
Reports may be stored in our application database and object storage, including Google Cloud Storage. Some reports are email-gated or manually unlocked after a booked call. We may record which report you accessed, the email used to access it, and whether findings were marked completed, dismissed, or sent to a fix workflow.
Do not submit websites or URLs you are not authorized to analyze if the resulting report may contain confidential business information.
Where session replay is enabled, we use our Rerun SDK and collector to understand product usage and diagnose issues. Rerun may collect page URLs, viewport size, browser and device metadata, clicks, scrolls, navigation, timing information, rage-click signals, console or error information if enabled, and a masked representation of page structure.
Rerun is configured to mask text and inputs by default. For our current Mimetic site instrumentation, network body capture, canvas recording, font collection, console capture, error capture, resource capture, and web-vitals capture are disabled. The Rerun SDK and server also support bot filtering and server-side redaction of common PII and sensitive keys.
Replay data may be summarized into redacted narratives and issue rankings. Raw replay data is treated as sensitive operational data and is access-controlled. Hosted collectors use read/admin keys or GitHub OIDC for authorized access.
If you install the Mimetic Code Agent GitHub App, we collect GitHub account, organization, installation, selected repository, permission, branch, commit, pull request, issue, check, and webhook metadata needed to operate the integration.
The GitHub App uses short-lived installation tokens at job time. We do not ask you to provide a personal access token. Depending on the permissions you approve, the app may read repository contents, create branches, push commits, open or update pull requests, read/write issues or PR comments, and trigger preview workflows.
When you ask Mimetic to fix a finding, we may send the selected issue, audit evidence, bounded code context, build/test instructions, and relevant replay summaries to our workflow system and AI coding tools. The workflow may store branch names, PR URLs, preview URLs, check results, bounded unified diffs, agent prompts, and agent outputs so you can review what happened and so we can improve our automation.
PR previews may be deployed to Google Cloud Run and may include review links comparing production and preview pages. Preview URLs are intended for review and may be accessible to anyone with the link unless additional access controls are configured.
Mimetic uses third-party AI providers to generate reports, summarize evidence, rank issues, produce content, and analyze technical context. Current text and code providers include Google Vertex AI (Gemini), Anthropic Claude, and OpenAI; image and video generation uses Replicate. Additional providers may be added or replaced as the Service evolves.
The data sent to each AI provider depends on the task and may include public website content, screenshots, audit findings, selected issue details, and bounded code context. We take reasonable steps to avoid sending secrets, payment data, private personal data, or unneeded sensitive content.
Google user data (data received from Google Analytics or Search Console under scopes you authorize) is transmitted only to the AI providers Mimetic uses to generate audit insights, summaries, and recommendations: currently Google Vertex AI (Gemini), Anthropic, and OpenAI. These providers are bound by their standard enterprise API terms, which prohibit the provider from using the data to train its general-purpose models or for the provider's own purposes, and limit retention to what is necessary to perform the requested processing and to meet the provider's safety, abuse-prevention, and legal obligations. Google user data is not transmitted to Replicate or to any other AI provider.
If you use Mimetic through Claude Code, Codex, or another MCP or AI client, information returned by the tools you invoke is provided to that client and may be processed by the AI provider and account you configured. That is a user-directed disclosure, separate from Mimetic's own AI-provider processing. Review your AI client's privacy, retention, and training settings before requesting connected data through an agent.
Some providers may offer prompt caching or similar performance features. We configure provider calls to support product functionality, cost control, and quality, and we rely on provider contractual and platform controls where available.
The Mimetic CLI and MCP wrapper are clients for Mimetic's hosted API; they do not query Google, PostHog, or Klaviyo directly from your computer. Commands, MCP tool arguments, and connected-data results pass through Mimetic's servers. Mimetic therefore has technical access to the credentials and data needed to perform an authorized request. Access is restricted by account and connection ownership controls and by our internal access policies, but "read-only" describes what a connector may do at the provider; it does not mean the data is invisible to Mimetic.
The CLI and MCP wrapper send metadata-only usage events by default, including client version, project, command or tool name, request method, success or failure, duration, trace identifier, HTTP status, and bounded diagnostic metadata. These usage events are designed not to include access tokens, query text, MCP arguments, replay narratives, or provider results. You can disable them by setting MIM_TELEMETRY=0 or MIM_DISABLE_TELEMETRY=1. Disabling usage events does not prevent Mimetic from receiving the request and data required to provide a hosted command or MCP tool.
Unless you provide a token through an environment variable, CLI device login stores the bearer token locally in ~/.mim/config.json by default. On supported systems, the CLI applies restrictive permissions to both the credential directory and file on every save. The token is not encrypted locally or stored in the operating system keychain. Server-issued managed tokens expire after a configured lifetime (90 days by default). mim auth logout revokes the stored managed token before deleting the local configuration; mim auth logout --local-only only deletes the local copy, so that token remains usable until it expires or is otherwise revoked. Tokens supplied through environment variables are not changed by logout.
For a standard Google Analytics or Search Console connection, we request the scopes you authorize, currently analytics.readonly, webmasters.readonly, and your Google account email. This may provide available properties, traffic metrics, engagement metrics, traffic sources, device and geography data, page performance, conversion and revenue data, and Search Console queries and landing pages. Google incremental authorization may also return scopes you previously granted to the same Mimetic OAuth client; Mimetic limits its use of those credentials to the features you select.
We use this data to answer your queries, generate analytics insights, detect tracking gaps, benchmark performance, and produce recommendations specific to your property. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, do not sell it, and do not transfer it to other applications except (a) at your direction, including returning data to an AI client you configured; (b) to service providers acting on our behalf, currently Google Cloud Platform for hosting and Google Vertex AI / Gemini, Anthropic, and OpenAI for generating insights and recommendations, under applicable contractual and platform controls; (c) to comply with applicable law; (d) for security and abuse prevention; or (e) in a merger, acquisition, or sale of assets with appropriate notice.
We do not allow humans to read your Google user data except with your affirmative consent for specific support or transactions, for security purposes, to comply with law, or where the data is aggregated and used for internal operations. Mimetic may publicly display aggregated, non-identifiable statistics derived from connected Google integrations to describe the scale of our customer base; those statistics do not identify an individual user, property, account, or organization.
If you choose hosted analytics setup, Mimetic creates the GA4 property in a Mimetic-managed Google Analytics account, retains administrator access, and invites the designated site owner as a Viewer. Mimetic may install the measurement tag through an authorized GitHub pull request, Shopify pixel, or code snippet you or your agent apply. The setup may also verify Search Console ownership and submit sitemaps to Google, Bing, and IndexNow. Data collected by that property is accessible to Mimetic as the account administrator.
If you choose Google Ads setup, Mimetic creates or links an Ads account under Mimetic's Google Ads manager account, may link it to GA4 and enable auto-tagging, and invites the designated owner as an Administrator. Mimetic retains manager access unless and until that manager relationship is removed. Setup or management features may require broader Google permissions, such as analytics.edit, webmasters, siteverification, or adwords; those permissions are requested only when needed for a setup feature you select and are shown on the provider's consent screen.
The PostHog connector requests query:read, project:read, and organization:read. It can list projects and run read-only HogQL, which may return event names, timestamps, distinct identifiers, user or event properties, funnels, and other data available to the connected PostHog account. Mimetic stores renewable OAuth credentials and the selected project and region so it can run queries you or your agent request.
The Klaviyo connector requests read-only access to accounts, campaigns, flows, lists, metrics, segments, and templates. It can retrieve campaign and flow performance, attributed conversion value, list and segment metadata, and email-template HTML used for checks such as dead-link detection. The connector does not currently request Klaviyo profile or write scopes. Mimetic stores renewable OAuth credentials and connected-account metadata so it can run queries you or your agent request.
You may revoke an OAuth connection through the provider and, where available, disconnect it within the Service. You may also contact contact@trymimetic.com to delete stored connection credentials. Revoking a personal Google OAuth grant does not by itself remove Mimetic's administrator or manager access to a Mimetic-hosted GA4 property or Google Ads account; contact us to disable hosted collection and request deletion, removal, or another available account action. Derived reports, snapshots, and workflow outputs may remain subject to the retention terms below.
When payments are enabled, payment processors such as Stripe or x402-compatible payment providers may process billing details, transaction metadata, wallet or payment identifiers, fraud signals, and payment status. We do not store full payment card numbers.
We use cookies, local storage, pixels, tags, and similar technologies for authentication, report access, preferences, analytics, attribution, performance measurement, product improvement, and abuse prevention.
Providers may include Google Analytics/Google Tag Manager, RB2B or similar B2B attribution tools, Calendly, email tools, and our own Rerun session replay. We do not currently use Microsoft Clarity on the Mimetic application.
We do not sell personal information for money. We may share information with:
We use technical and organizational safeguards such as access controls, account- and connection-level authorization, encryption of provider OAuth credentials at rest, hashing of Mimetic API tokens at rest, environment-separated secrets, short-lived GitHub installation tokens, masked replay capture, redaction, rate limiting, signed webhooks, OIDC where available, and encrypted transport. Credential encryption is reversible by the Service so it can call a provider on your behalf; authorized Mimetic systems therefore retain technical access while a connection is active. No system is perfectly secure, and you should avoid submitting secrets or highly sensitive data unless the feature specifically requires it.
We retain information for as long as needed to provide the service, maintain audit and workflow history, improve quality, comply with law, resolve disputes, and enforce agreements.
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also opt out of marketing emails, disable CLI/MCP usage telemetry, disconnect integrations, revoke third-party authorization, uninstall the GitHub App, remove an AI client configuration, or request deletion of credentials, connected-data artifacts, reports, or replay data.
To exercise privacy rights, contact contact@trymimetic.com. We may need to verify your identity or authority before acting on a request.
Mimetic is based in the United States, and our service providers may process information in the United States and other locations. By using the service, you understand that information may be processed outside your jurisdiction, subject to applicable safeguards.
Our services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. The "Last updated" date above shows when the policy was last revised. If changes are material, we may provide additional notice through the service or by email.
If you have questions about this Privacy Policy or our privacy practices, contact us: