Privacy Policy

Last updated: July 17, 2026

1. Scope

This Privacy Policy explains how Mimetic Inc ("Mimetic", "we", "us", or "our") collects, uses, shares, and protects information when you visit our websites, request a site audit, view an audit report, use the Mimetic command-line interface ("CLI"), API, or Model Context Protocol ("MCP") server, connect third-party accounts, install our GitHub App, use our Rerun session replay and code-improvement tools, or otherwise interact with our services (the "Service").

Some features are optional and apply only if you choose to use them, such as Google Analytics, Google Search Console, Google Ads, PostHog, Klaviyo, the GitHub App, Slack notifications, session replay, PR previews, hosted analytics setup, AI-agent integrations, and payments.

2. Information We Collect

  • Contact and account information: business email, name, company, website URL, report access status, consent preferences, unsubscribe tokens, and messages you send us.
  • Site audit inputs: submitted domains, URLs, audit type, form data, and report unlock or booking details.
  • Public website and market data: publicly accessible page content, screenshots, DOM and page metadata, Lighthouse and browser-check results, SEO data, structured data, tracking tags, technology stack signals, public social/profile links, ad/creative observations, and other publicly available business information relevant to a report.
  • Report and workflow data: generated findings, rankings, recommendations, screenshots, code-context manifests, issue backlog items, fix requests, branch names, PR links, preview links, build/check status, acceptance/rejection status, and bounded diffs, prompts, and agent outputs.
  • Usage and device information: IP address, user agent, browser, device, approximate location, timestamps, pages viewed, referrers, UTM parameters, clicks, scroll activity, local identifiers, and error/debug information.
  • CLI, API, and MCP information: account and project identifiers, API-token metadata, client and version, commands and MCP tool names, request method, status, duration, trace identifiers, bounded diagnostic metadata, and the requests and results that must pass through Mimetic's hosted API to provide a command or tool call.
  • Third-party integration credentials: OAuth access and refresh tokens, granted scopes, token expiration, connected account or project identifiers, and connection-owner email for services you authorize. Provider credentials are encrypted at rest; Mimetic API tokens are stored server-side as hashes.
  • Third-party integration data: data from Google Analytics, Search Console, Google Ads, PostHog, Klaviyo, GitHub, Slack, Calendly, payment providers, or other services you connect or authorize. Depending on the feature, this can include traffic, conversion and revenue metrics, search queries, advertising performance, analytics events and properties, campaign and flow performance, list and segment metadata, and email-template content.

3. How We Use Information

  • Generate, store, unlock, and deliver site audit reports.
  • Prioritize issues, create backlog items, and suggest improvements based on audits, session evidence, and code context.
  • Authenticate CLI, API, and MCP requests; route authorized queries to connected providers; return results to you or your configured AI client; and maintain integration connections by refreshing credentials when necessary.
  • Run authorized code-improvement workflows, including creating branches, opening pull requests, running checks, deploying review previews, and notifying reviewers.
  • Operate authentication, admin access, report access, rate limiting, security, fraud prevention, abuse prevention, and debugging.
  • Send transactional emails, report links, workflow notifications, booking confirmations, and optional marketing communications.
  • Improve our products, prompts, evaluations, ranking logic, and automation quality, including by analyzing public, de-identified, aggregated, or access-controlled workflow outcomes, subject to the provider-specific restrictions below. We do not use Google user data to train or improve general-purpose AI models.
  • Comply with law, enforce our terms, and protect our rights and users.

4. Site Audits and Reports

When you submit a website, Mimetic may crawl and analyze publicly accessible pages and public business information. Reports may include screenshots, page text excerpts, detected tracking tools, technical checks, SEO findings, conversion findings, recommendations, and estimated business impact.

Reports may be stored in our application database and object storage, including Google Cloud Storage. Some reports are email-gated or manually unlocked after a booked call. We may record which report you accessed, the email used to access it, and whether findings were marked completed, dismissed, or sent to a fix workflow.

Do not submit websites or URLs you are not authorized to analyze if the resulting report may contain confidential business information.

5. Session Replay and Rerun

Where session replay is enabled, we use our Rerun SDK and collector to understand product usage and diagnose issues. Rerun may collect page URLs, viewport size, browser and device metadata, clicks, scrolls, navigation, timing information, rage-click signals, console or error information if enabled, and a masked representation of page structure.

Rerun is configured to mask text and inputs by default. For our current Mimetic site instrumentation, network body capture, canvas recording, font collection, console capture, error capture, resource capture, and web-vitals capture are disabled. The Rerun SDK and server also support bot filtering and server-side redaction of common PII and sensitive keys.

Replay data may be summarized into redacted narratives and issue rankings. Raw replay data is treated as sensitive operational data and is access-controlled. Hosted collectors use read/admin keys or GitHub OIDC for authorized access.

6. GitHub App, Code Agent, and PR Previews

If you install the Mimetic Code Agent GitHub App, we collect GitHub account, organization, installation, selected repository, permission, branch, commit, pull request, issue, check, and webhook metadata needed to operate the integration.

The GitHub App uses short-lived installation tokens at job time. We do not ask you to provide a personal access token. Depending on the permissions you approve, the app may read repository contents, create branches, push commits, open or update pull requests, read/write issues or PR comments, and trigger preview workflows.

When you ask Mimetic to fix a finding, we may send the selected issue, audit evidence, bounded code context, build/test instructions, and relevant replay summaries to our workflow system and AI coding tools. The workflow may store branch names, PR URLs, preview URLs, check results, bounded unified diffs, agent prompts, and agent outputs so you can review what happened and so we can improve our automation.

PR previews may be deployed to Google Cloud Run and may include review links comparing production and preview pages. Preview URLs are intended for review and may be accessible to anyone with the link unless additional access controls are configured.

7. AI and Automation Providers

Mimetic uses third-party AI providers to generate reports, summarize evidence, rank issues, produce content, and analyze technical context. Current text and code providers include Google Vertex AI (Gemini), Anthropic Claude, and OpenAI; image and video generation uses Replicate. Additional providers may be added or replaced as the Service evolves.

The data sent to each AI provider depends on the task and may include public website content, screenshots, audit findings, selected issue details, and bounded code context. We take reasonable steps to avoid sending secrets, payment data, private personal data, or unneeded sensitive content.

Google user data (data received from Google Analytics or Search Console under scopes you authorize) is transmitted only to the AI providers Mimetic uses to generate audit insights, summaries, and recommendations: currently Google Vertex AI (Gemini), Anthropic, and OpenAI. These providers are bound by their standard enterprise API terms, which prohibit the provider from using the data to train its general-purpose models or for the provider's own purposes, and limit retention to what is necessary to perform the requested processing and to meet the provider's safety, abuse-prevention, and legal obligations. Google user data is not transmitted to Replicate or to any other AI provider.

If you use Mimetic through Claude Code, Codex, or another MCP or AI client, information returned by the tools you invoke is provided to that client and may be processed by the AI provider and account you configured. That is a user-directed disclosure, separate from Mimetic's own AI-provider processing. Review your AI client's privacy, retention, and training settings before requesting connected data through an agent.

Some providers may offer prompt caching or similar performance features. We configure provider calls to support product functionality, cost control, and quality, and we rely on provider contractual and platform controls where available.

8. CLI, MCP, and Connected Data Sources (Optional)

8.1 Hosted Routing and Operator Access

The Mimetic CLI and MCP wrapper are clients for Mimetic's hosted API; they do not query Google, PostHog, or Klaviyo directly from your computer. Commands, MCP tool arguments, and connected-data results pass through Mimetic's servers. Mimetic therefore has technical access to the credentials and data needed to perform an authorized request. Access is restricted by account and connection ownership controls and by our internal access policies, but "read-only" describes what a connector may do at the provider; it does not mean the data is invisible to Mimetic.

The CLI and MCP wrapper send metadata-only usage events by default, including client version, project, command or tool name, request method, success or failure, duration, trace identifier, HTTP status, and bounded diagnostic metadata. These usage events are designed not to include access tokens, query text, MCP arguments, replay narratives, or provider results. You can disable them by setting MIM_TELEMETRY=0 or MIM_DISABLE_TELEMETRY=1. Disabling usage events does not prevent Mimetic from receiving the request and data required to provide a hosted command or MCP tool.

Unless you provide a token through an environment variable, CLI device login stores the bearer token locally in ~/.mim/config.json by default. On supported systems, the CLI applies restrictive permissions to both the credential directory and file on every save. The token is not encrypted locally or stored in the operating system keychain. Server-issued managed tokens expire after a configured lifetime (90 days by default). mim auth logout revokes the stored managed token before deleting the local configuration; mim auth logout --local-only only deletes the local copy, so that token remains usable until it expires or is otherwise revoked. Tokens supplied through environment variables are not changed by logout.

8.2 Google Analytics and Search Console

For a standard Google Analytics or Search Console connection, we request the scopes you authorize, currently analytics.readonly, webmasters.readonly, and your Google account email. This may provide available properties, traffic metrics, engagement metrics, traffic sources, device and geography data, page performance, conversion and revenue data, and Search Console queries and landing pages. Google incremental authorization may also return scopes you previously granted to the same Mimetic OAuth client; Mimetic limits its use of those credentials to the features you select.

We use this data to answer your queries, generate analytics insights, detect tracking gaps, benchmark performance, and produce recommendations specific to your property. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, do not sell it, and do not transfer it to other applications except (a) at your direction, including returning data to an AI client you configured; (b) to service providers acting on our behalf, currently Google Cloud Platform for hosting and Google Vertex AI / Gemini, Anthropic, and OpenAI for generating insights and recommendations, under applicable contractual and platform controls; (c) to comply with applicable law; (d) for security and abuse prevention; or (e) in a merger, acquisition, or sale of assets with appropriate notice.

We do not allow humans to read your Google user data except with your affirmative consent for specific support or transactions, for security purposes, to comply with law, or where the data is aggregated and used for internal operations. Mimetic may publicly display aggregated, non-identifiable statistics derived from connected Google integrations to describe the scale of our customer base; those statistics do not identify an individual user, property, account, or organization.

8.3 Hosted Analytics and Google Ads Setup

If you choose hosted analytics setup, Mimetic creates the GA4 property in a Mimetic-managed Google Analytics account, retains administrator access, and invites the designated site owner as a Viewer. Mimetic may install the measurement tag through an authorized GitHub pull request, Shopify pixel, or code snippet you or your agent apply. The setup may also verify Search Console ownership and submit sitemaps to Google, Bing, and IndexNow. Data collected by that property is accessible to Mimetic as the account administrator.

If you choose Google Ads setup, Mimetic creates or links an Ads account under Mimetic's Google Ads manager account, may link it to GA4 and enable auto-tagging, and invites the designated owner as an Administrator. Mimetic retains manager access unless and until that manager relationship is removed. Setup or management features may require broader Google permissions, such as analytics.edit, webmasters, siteverification, or adwords; those permissions are requested only when needed for a setup feature you select and are shown on the provider's consent screen.

8.4 PostHog

The PostHog connector requests query:read, project:read, and organization:read. It can list projects and run read-only HogQL, which may return event names, timestamps, distinct identifiers, user or event properties, funnels, and other data available to the connected PostHog account. Mimetic stores renewable OAuth credentials and the selected project and region so it can run queries you or your agent request.

8.5 Klaviyo

The Klaviyo connector requests read-only access to accounts, campaigns, flows, lists, metrics, segments, and templates. It can retrieve campaign and flow performance, attributed conversion value, list and segment metadata, and email-template HTML used for checks such as dead-link detection. The connector does not currently request Klaviyo profile or write scopes. Mimetic stores renewable OAuth credentials and connected-account metadata so it can run queries you or your agent request.

8.6 Revocation and Disconnection

You may revoke an OAuth connection through the provider and, where available, disconnect it within the Service. You may also contact contact@trymimetic.com to delete stored connection credentials. Revoking a personal Google OAuth grant does not by itself remove Mimetic's administrator or manager access to a Mimetic-hosted GA4 property or Google Ads account; contact us to disable hosted collection and request deletion, removal, or another available account action. Derived reports, snapshots, and workflow outputs may remain subject to the retention terms below.

9. Communications, Slack, and Bookings

  • Email: We send transactional emails such as report links and service updates. Marketing emails are optional and include unsubscribe options.
  • Calendly or booking tools: If you book a call, we may receive booking metadata such as name, email, company, domain, time, and responses you provide.
  • Slack: If a Slack integration is configured, we may send selected replay summaries, issue rankings, PR links, preview links, workflow status, and project names to configured Slack channels. We do not intentionally send raw replay event batches or secrets to Slack.

10. Payments

When payments are enabled, payment processors such as Stripe or x402-compatible payment providers may process billing details, transaction metadata, wallet or payment identifiers, fraud signals, and payment status. We do not store full payment card numbers.

11. Cookies, Analytics, and Similar Technologies

We use cookies, local storage, pixels, tags, and similar technologies for authentication, report access, preferences, analytics, attribution, performance measurement, product improvement, and abuse prevention.

Providers may include Google Analytics/Google Tag Manager, RB2B or similar B2B attribution tools, Calendly, email tools, and our own Rerun session replay. We do not currently use Microsoft Clarity on the Mimetic application.

12. Sharing and Service Providers

We do not sell personal information for money. We may share information with:

  • Infrastructure providers such as Google Cloud Platform, Cloud Run, Cloud Storage, database providers, CDN/DNS providers, and logging/monitoring tools.
  • AI and automation providers used to generate, summarize, rank, or implement recommendations.
  • GitHub, Slack, Google, PostHog, Klaviyo, Calendly, email, payment, analytics, and communication providers when you use or authorize those integrations.
  • AI clients and providers you configure, when you direct the CLI, API, or MCP tools to return information to those clients.
  • Professional advisors, security providers, and support vendors.
  • Authorities or third parties when required by law, to prevent abuse, to enforce agreements, or to protect rights, safety, and security.
  • Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets.

13. Data Security

We use technical and organizational safeguards such as access controls, account- and connection-level authorization, encryption of provider OAuth credentials at rest, hashing of Mimetic API tokens at rest, environment-separated secrets, short-lived GitHub installation tokens, masked replay capture, redaction, rate limiting, signed webhooks, OIDC where available, and encrypted transport. Credential encryption is reversible by the Service so it can call a provider on your behalf; authorized Mimetic systems therefore retain technical access while a connection is active. No system is perfectly secure, and you should avoid submitting secrets or highly sensitive data unless the feature specifically requires it.

14. Data Retention

We retain information for as long as needed to provide the service, maintain audit and workflow history, improve quality, comply with law, resolve disputes, and enforce agreements.

  • Local Rerun replay storage defaults to a 30-day retention window unless configured differently; hosted object storage may use bucket lifecycle policies.
  • Google, PostHog, Klaviyo, and other provider OAuth credentials are retained while the connection is active and are deleted when the connection is disconnected within the Service or when we fulfill a verified deletion request. Revoking access at the provider stops future API access but may not notify Mimetic immediately; contact us if you also want the stored credential record deleted.
  • Server-issued CLI/API bearer tokens expire after a configured lifetime (90 days by default). Hashed token records, revocation and last-use timestamps, account and project identifiers, and usage events may be retained after expiration or revocation as needed for security, abuse prevention, billing, support, and legal compliance. The current CLI's metadata-only telemetry can be disabled as described in Section 8.1.
  • Connected-data query results are returned through the Service. Results incorporated into reports, analytics snapshots, replay summaries, recommendations, agent outputs, or other workflows may be retained with those artifacts. Derived analytics snapshots are retained as needed to provide and improve the Service; you may request earlier deletion by contacting us.
  • Reports, audit artifacts, code-change attempts, diffs, PR metadata, and outcome labels may be retained while your account, project, or report remains active, or longer where needed for security, compliance, or product improvement.

15. Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also opt out of marketing emails, disable CLI/MCP usage telemetry, disconnect integrations, revoke third-party authorization, uninstall the GitHub App, remove an AI client configuration, or request deletion of credentials, connected-data artifacts, reports, or replay data.

To exercise privacy rights, contact contact@trymimetic.com. We may need to verify your identity or authority before acting on a request.

16. International Processing

Mimetic is based in the United States, and our service providers may process information in the United States and other locations. By using the service, you understand that information may be processed outside your jurisdiction, subject to applicable safeguards.

17. Children's Privacy

Our services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children.

18. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date above shows when the policy was last revised. If changes are material, we may provide additional notice through the service or by email.

19. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us:

Return to Home