Terms of Service

Last updated: July 17, 2026

1. Acceptance of Terms

By accessing or using Mimetic (the "Service"), operated by Mimetic Inc ("Mimetic", "we", "us", or "our"), you agree to be bound by these Terms of Service ("Terms") and all applicable laws and regulations. If you do not agree, do not use the Service. Your use of the Service is also governed by our Privacy Policy.

2. Description of the Service

Mimetic provides automated growth analysis for websites through its web application, command-line interface ("CLI"), API, and Model Context Protocol ("MCP") tools. The Service crawls publicly available pages, optionally connects to third-party data sources you authorize, and generates audit reports, answers, recommendations, setup workflows, and prioritized issue lists.

2.1 Site Audits and Reports

The Service includes website audits in which a submitted URL is crawled and analyzed for technical, conversion, and growth signals. A report is generated and delivered by email or via a unique report URL. Free audits are subject to per-email rate limits. Reports may be email-gated.

2.2 CLI, API, and MCP Tools

The Mimetic CLI and MCP wrapper call Mimetic's hosted API. Unless a feature expressly states otherwise, commands, tool arguments, and results pass through Mimetic's systems. Some connector tools only read data, while other tools may connect accounts, create or configure analytics and advertising resources, install tracking, modify authorized settings, return checkout links, or propose code changes. A "read-only" label describes a particular connector's permissions at the third-party provider and does not mean that Mimetic cannot access data routed through the Service.

You are responsible for reviewing a tool's description, arguments, scopes, and output before you or an automated agent invokes or approves an action. Server-issued managed CLI/API tokens expire after a configured lifetime and can be revoked by mim auth logout; the --local-only option removes only the local copy. Tool availability and capabilities may change as the Service evolves.

When you use the Service through Claude Code, Codex, or another MCP or AI client, results returned by Mimetic are provided to the AI client and account you configured and may be processed under that provider's terms and privacy settings.

2.3 Connected Data Sources (Optional)

If you connect Google Analytics 4 ("GA4") or Google Search Console, the Service uses the scopes you authorize, ordinarily analytics.readonly, webmasters.readonly, and your Google account email, to retrieve analytics and search-performance data. If you connect PostHog, the Service requests read access to queries, projects, and organizations and may return events, distinct identifiers, and event or user properties available to the connected project. If you connect Klaviyo, the Service requests read access to accounts, campaigns, flows, lists, metrics, segments, and templates and may retrieve performance data, metadata, and email-template content. Current Klaviyo access does not include profile or write scopes.

Mimetic stores renewable provider credentials in encrypted form and uses them to run queries you or your agent request. Because the Service must decrypt those credentials and proxy the resulting data, Mimetic has technical access while a connection is active, subject to our account controls and internal access policies.

You may revoke access at the provider and, where available, disconnect within the Service. Contact contact@trymimetic.com to request deletion of stored credentials or connected-data artifacts. See our Privacy Policy for details about data categories, routing, telemetry, retention, and disconnection.

2.4 Hosted Analytics and Google Ads Setup (Optional)

If you choose hosted analytics setup, Mimetic creates the GA4 property in a Mimetic-managed Google Analytics account, retains administrator access, and invites the designated site owner as a Viewer. The Service may install the measurement tag using an authorized GitHub pull request, Shopify pixel, or code snippet and may configure Search Console and sitemap submission. Mimetic can access data collected by that property as its account administrator.

If you choose Google Ads setup, Mimetic creates or links an Ads account under Mimetic's Google Ads manager account, may link the account to GA4 and enable auto-tagging, and invites the designated owner as an Administrator. Mimetic retains manager access until that manager relationship is removed. These setup features may request broader Google scopes, including analytics, Search Console, site-verification, or advertising-management permissions, when required for the feature you select.

2.5 GitHub App and Code Agent (Optional)

If you install the Mimetic Code Agent GitHub App, the Service can access selected repositories under the permissions you approve. Depending on those permissions, the Service may:

  • Read repository contents to build a bounded code context for the issue being fixed.
  • Create branches, push commits, and open or update pull requests proposing fixes for findings from your audit.
  • Read and write pull-request and issue comments, and trigger preview deployment workflows where configured.

The Service uses short-lived GitHub installation tokens and does not request personal access tokens. You retain full ownership of your code and full control over which pull requests are merged. You may uninstall the GitHub App at any time from your GitHub account settings.

3. Google API Services User Data Policy and Limited Use

Mimetic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.1 Permitted Use

Mimetic uses Google user data only to provide and improve the user-facing features of the Service that you select: for example, answering your CLI or MCP queries, generating analytics insights from your GA4 and Search Console data, producing audit reports, detecting tracking gaps, and performing an analytics or advertising setup you authorize. Google user data is not used for any purpose unrelated to providing or improving these user-facing features.

Mimetic may publicly display aggregated, non-identifiable statistics derived from authorized integrations (for example, total annual visitors or revenue tracked across all connected customer properties) to describe the scale of its customer base. Such aggregate statistics do not identify any individual user, property, account, or organization.

3.2 No Advertising

Mimetic does not use Google user data to serve advertisements, including personalized, retargeted, contextual, or interest-based advertising, and does not use Google user data to build or enrich advertising audiences, profiles, or lookalike segments.

3.3 No Sale of Google User Data

Mimetic does not sell, rent, license, or otherwise monetize Google user data to data brokers, advertisers, or any other third parties.

3.4 No Transfer of Google User Data Except for Permitted Purposes

Mimetic does not transfer Google user data to other applications, parties, or services except as strictly necessary for one of the following permitted purposes:

  • Providing or improving user-facing features. Where required to deliver a feature you are using, Mimetic may transmit limited Google user data to (a) infrastructure providers acting on Mimetic's behalf, such as Google Cloud Platform, on which the Service is hosted, and (b) the AI providers Mimetic uses to generate audit insights, summaries, and recommendations from your data: currently Google Vertex AI (Gemini), Anthropic, and OpenAI. These providers are bound by contractual obligations under their standard enterprise API terms that (i) prohibit the provider from using the data to train its general-purpose models or for the provider's own purposes, and (ii) limit retention to what is necessary to perform the requested processing and to meet the provider's safety, abuse-prevention, and legal obligations. Mimetic does not transmit Google user data to image- or video-generation providers or to any other third party.
  • User-directed AI clients. When you invoke a Mimetic tool through an MCP or AI client you configured, Mimetic returns the requested data to that client to provide the feature you requested. The AI provider and account you select may process that data under its terms, retention rules, and privacy or training settings.
  • Compliance with applicable law. Where required by valid legal process or applicable law.
  • Merger, acquisition, or sale of assets. In connection with a merger, acquisition, or sale of assets, only after providing notice to affected users and an opportunity to consent or to delete their data, in accordance with applicable law.
  • Security and abuse prevention. As reasonably necessary to detect, investigate, or prevent fraud, abuse, or threats to the security of the Service or its users.

3.5 No Human Reading Except for Permitted Purposes

Mimetic does not allow humans to read your Google user data except in the following narrowly limited cases:

  • With your affirmative agreement, for specific support, troubleshooting, or transactional purposes you have requested.
  • Where necessary for security purposes, such as investigating abuse, fraud, or a security incident.
  • To comply with applicable law.
  • Where the data has been aggregated and used for internal operations in accordance with applicable privacy and other legal requirements (for example, aggregate usage analytics that do not identify individual users or properties).

3.6 Scope Minimization

For connected-data queries, Mimetic ordinarily requests read-only OAuth scopes. Setup and management features may request broader scopes only when needed for a feature you select. Google incremental authorization may return scopes that you previously granted to the same Mimetic OAuth client; Mimetic limits its use of the credentials to the selected Service features. Mimetic does not retain usable access after the applicable OAuth connection is revoked or disconnected, although separate hosted-account access may continue as described below.

3.7 Revocation and Deletion

You may revoke a personal Google OAuth connection by disconnecting within the Service or by visiting your Google Account permissions page. When you disconnect within the Service, Mimetic promptly deletes the stored OAuth access and refresh tokens. Revoking personal OAuth does not by itself remove Mimetic's administrator access to a Mimetic-hosted GA4 property, remove Mimetic's manager relationship with a Google Ads account, or stop a separately installed measurement tag. Contact contact@trymimetic.com to request removal, hosted-collection changes, or deletion. Retention of historical snapshots and related artifacts is governed by our Privacy Policy.

3.8 Relationship to Google's Terms

Your use of the Google APIs and the underlying Google services through Mimetic is also governed by the Google APIs Terms of Service, the Google Analytics Terms of Service, and the Google Privacy Policy. You are responsible for ensuring your authorization for Mimetic to access your Google data is consistent with those terms and with any obligations you owe to the end users whose data is contained in your Google properties.

4. User Obligations and Acceptable Use

You agree to:

  • Provide accurate information, including a valid business email address.
  • Only submit websites, analytics or advertising properties, customer or event data, email-marketing accounts, and repositories that you own or are authorized to analyze, connect, access, or modify.
  • Provide all notices and obtain all rights and consents required for Mimetic and your selected AI clients to process data you make available through the Service.
  • Protect your access tokens and connected accounts, review the actions an AI agent proposes, and approve only actions you intend to authorize.
  • Comply with the terms of all third-party services you connect, including Google, GitHub, PostHog, Klaviyo, and any AI client you configure.
  • Not use the Service for any unlawful, fraudulent, or abusive purpose, including violation of any third party's intellectual property, privacy, or contractual rights.
  • Not attempt to reverse engineer, scrape, decompile, or otherwise extract the source code, models, or proprietary logic of the Service, except as expressly permitted by law.
  • Not interfere with, abuse, or attempt to overwhelm the Service or its underlying infrastructure.

5. Reports, Recommendations, and No Professional Advice

Audits, reports, recommendations, rankings, fix proposals, and any other Service output are generated through automated analysis and AI tooling. You acknowledge that:

  • Output is informational and is not financial, legal, tax, accounting, security, or other professional advice.
  • Output may contain errors, omissions, or inaccuracies, and should be evaluated in the context of your specific business.
  • Business and technical outcomes depend on many factors beyond the Service's analysis. We make no guarantee of any specific result.
  • You should consult qualified professionals before making material business, technical, or financial decisions based on Service output.

6. Intellectual Property and Data Ownership

The Service, including its software, models, prompts, audit methodology, ranking logic, UI, and brand, is owned by Mimetic Inc and is protected by copyright, trademark, and other intellectual property laws. We grant you a limited, non-exclusive, non-transferable, revocable license to use the Service in accordance with these Terms.

You retain full ownership of all data and content you submit to the Service or that the Service accesses through integrations you authorize, including your website content, Google Analytics, Search Console, Google Ads, PostHog, and Klaviyo data, and source code. By using the Service, you grant Mimetic a non-exclusive, worldwide license to access, store, process, transmit, and analyze that data solely as needed to provide, secure, and improve the user-facing Service features you use, in accordance with these Terms, our Privacy Policy, and applicable provider-specific restrictions.

7. Service Tiers

The Service offers free and paid features. Rate limits, feature availability, and pricing may change without notice. Material changes affecting paid features will be communicated through the Service.

8. Service Availability and Modifications

We aim to keep the Service available but do not guarantee uninterrupted access. We may add, modify, suspend, or discontinue features at any time, and may impose, modify, or remove rate limits without notice.

9. Disclaimer of Warranties

The Service is provided "as is" and "as available" without warranties of any kind, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, or uninterrupted operation. We make no warranty that the Service or any output, recommendation, or fix will meet your requirements or produce any particular business outcome.

10. Limitation of Liability

To the maximum extent permitted by law:

  • Mimetic Inc shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, revenue, data, goodwill, or business opportunity.
  • Our total cumulative liability for any claim arising out of or related to the Service shall not exceed the greater of (i) one hundred US dollars ($100) or (ii) the total fees you paid to Mimetic for the Service in the twelve (12) months preceding the event giving rise to the claim.
  • We are not responsible for business, technical, security, or other decisions made by you based on Service output, including any code change merged into your repositories.

11. Indemnification

You agree to defend, indemnify, and hold harmless Mimetic Inc, its officers, employees, and agents from any claims, damages, liabilities, losses, and expenses (including reasonable attorneys' fees) arising out of your use of the Service, your violation of these Terms, your violation of any third-party right (including any website, analytics property, or repository you submit), or your breach of any third-party service's terms.

12. Privacy

Use of the Service is governed by our Privacy Policy, which describes how we collect, use, share, and retain information. By using the Service, you acknowledge that you have read and understand the Privacy Policy.

13. Termination

You may stop using the Service at any time, revoke third-party OAuth access, use any available disconnection controls, uninstall the GitHub App, and request deletion of your data as described in the Privacy Policy. Revoking OAuth does not necessarily remove a hosted analytics property, installed measurement tag, or Mimetic's separate administrator or manager relationship; contact us to request those changes. We may suspend or terminate your access to the Service at any time, with or without notice, for any reason, including suspected breach of these Terms, abuse of the Service, or risk to other users.

14. Changes to These Terms

We may modify these Terms from time to time. The "Last updated" date above shows when these Terms were last revised. If a change is material, we may provide additional notice through the Service or by email. Your continued use of the Service after a change becomes effective constitutes acceptance of the modified Terms.

15. Governing Law and Disputes

These Terms are governed by the laws of the State of Delaware, without regard to conflict-of-law provisions. Any dispute arising out of or related to these Terms or the Service shall be resolved in the state or federal courts located in Delaware, and you consent to personal jurisdiction in those courts.

16. Contact

For questions about these Terms, please contact us:

Return to Home