1. Who We Are
mocktomer is a product of MineledgerAI LLC (“MineledgerAI,” “we,” “us,” or “our”), a United States limited liability company. MineledgerAI LLC is the data controller for personal information processed through the mocktomer websites, applications, and related services (the “Service”). The Service lets site owners send AI customers through customer journeys on their own websites and receive experience feedback.
This Policy explains what we collect, how we use it, who we share it with, and the choices and rights you have. It is incorporated into our Terms of Service.
2. Information We Collect
Account and authentication data. When you create an account we collect your name, email address, and authentication identifiers. Authentication is provided by Firebase Authentication (Google); if you sign in with Google, we receive basic profile information from your Google account.
One-time Deep Audit purchases. If you purchase a Deep Audit without creating an account, we collect the website address and email address you submit at checkout. We use that email solely to confirm your order, deliver your report and re-run coupon, and send a limited number of follow-ups about that order; payment details are processed by Stripe and never stored by us.
Site data you submit. We collect the website URLs you submit and the publicly available content of those sites that our systems crawl and render in order to provide the Service, including page content, structure, and metadata.
Screenshots and journey records. While AI customers walk your site, we capture screenshots of the pages they encounter, along with journey events, reasoning narrations, and the resulting experience feedback reports. These may incidentally include content displayed on your site at the time of capture; you should not expose real end-user personal data to runs.
Usage and analytics data. We collect log and event data about how you use the Service — pages viewed, features used, runs launched, device and browser information, IP address, and approximate location derived from it.
Payment data. Payments are processed by Stripe, Inc. We receive limited billing information (such as plan, transaction status, and the last four digits and brand of your card) but we never receive or store your full card numbers.
Optional staging credentials. If you choose to provide credentials for a staging or test environment, they are stored encrypted in Google Secret Manager and used solely to operate AI customers on that environment at your direction. We never ask for, and you must not provide, real customer credentials.
Workspace branding assets. If you configure white-label reports, we store the workspace branding assets you provide — the brand name and logo URL — and use them solely to render the branded report exports you generate.
Free site check.If you use the free checker (no account required), we fetch a small number of the entered site's public pages to compute the result, cache the computed result briefly (about a day) so repeat checks of the same site are served instantly, and record the checked domain and coarse usage data (such as approximate request counts and rate-limit state) to operate and protect the feature. We do not store the content of the checked pages beyond what appears in the result.
Connected applications (MCP / OAuth). If you connect an external application to your workspace over our MCP server (for example, adding mocktomer as a connector in an AI assistant), we store the connecting application's registration details (its name and redirect URLs) and short-lived, revocable access and refresh tokens that let it act in your workspace at your direction. Tokens are stored hashed, expire automatically, and are revoked when you disconnect the connector or sign out of it. The connector receives only the access you grant — never your billing, members, API keys, or account settings.
3. How We Use Information
Share links you create.If you create a public replay link for a run, that run's screenshots, persona narrations, scores, and summary findings become viewable by anyone who has the link, without an account, until you revoke it. Replay pages are excluded from search indexing, but anyone holding the link can view and copy their contents.
Integrations and webhooks. If you connect Slack, Jira, or a webhook, we store the URLs and API tokens you provide and use them solely to deliver the alerts you configure. Once delivered, that data is governed by the receiving service.
We use the information described above to:
- provide, operate, and maintain the Service, including running AI customer journeys on the sites you submit and delivering experience feedback reports;
- create and secure your account and authenticate you;
- process payments, manage credits, and prevent fraud and abuse;
- communicate with you about your account, runs, billing, and changes to the Service or our terms;
- monitor, debug, and improve the Service, including in de-identified or aggregated form;
- comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use your data for third-party advertising.
4. AI Processing Disclosure
The Service is built on large language models. Content from the sites you submit — including page content, screenshots, and journey context — is processed by Anthropic to generate the simulated customer journeys and experience-feedback reports that make up the Service. For AI-shopper visibility checks we also query OpenAI and Google's Gemini API, but those receive only generic category questions — never your site's content, screenshots, or reports.
We do not use your data, your sites’ content, or your reports to train AI models. Our AI providers process this data as service providers under their commercial terms; we rely on commercial API arrangements under which provider-side training on our customers’ data is not permitted.
5. Subprocessors and Service Providers
We share personal information only with service providers that help us operate the Service, under contracts that restrict their use of it:
- Google Cloud Platform / Firebase — cloud infrastructure, hosting, authentication, database, file storage, and secret storage;
- Anthropic — AI model inference for journey simulation and report generation;
- OpenAI and Google (Gemini API) — AI model inference for AI-shopper visibility checks (generic category prompts only — no site content, screenshots, or reports);
- Stripe — payment processing and billing;
- Microsoft — transactional email delivery (verification and account emails) via Microsoft 365;
- Twilio / SendGrid — delivery of the run-completion email and SMS notifications you request;
- other cloud infrastructure and operational tooling used to run, monitor, and secure the Service.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case this Policy will continue to apply to previously collected data).
6. Legal Bases for Processing
Where the EU or UK General Data Protection Regulation applies, we process personal information on the following legal bases:
- Performance of a contract — providing the Service you signed up for, including accounts, runs, reports, and billing;
- Legitimate interests — securing and improving the Service, preventing abuse, and communicating with business users, balanced against your rights;
- Consent — where required, for example for optional analytics cookies; you may withdraw consent at any time;
- Legal obligation — where processing is necessary to comply with applicable law.
7. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service. Journey records, screenshots, and reports are retained so you can review runs over time. When you delete your account, we delete or de-identify your personal information within a reasonable period, except where retention is required for legal, billing, security, or dispute-resolution purposes. Staging credentials are deleted when you remove them or close your account.
8. Security
We use industry-standard measures designed to protect your information, including encryption in transit and at rest on Google Cloud infrastructure, encrypted secret storage for any credentials you provide, access controls and least-privilege service accounts, and isolation of the browser containers that run AI customers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, and the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at support@mocktomer.ai. We will verify your request and respond within the time required by applicable law. You can also delete individual sites and their stored credentials from your dashboard.
10. California Privacy Notice
If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) gives you rights to know, access, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising those rights. We do not sell personal information and we do not share personal information for cross-context behavioral advertising, so no opt-out is required. To exercise your rights, use the contact details in Section 9; you may use an authorized agent where permitted by law.
11. Cookies
We use cookies and similar technologies for two purposes: authentication and session cookies that keep you signed in and secure (strictly necessary), and analytics cookies — including Google Analytics — that help us understand how the Service is used so we can improve it (IP addresses are anonymized). You can control cookies through your browser settings; disabling strictly necessary cookies may prevent the Service from working.
12. Children
The Service is for business use by adults and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, contact us and we will delete it.
13. International Transfers
We are based in the United States and process data on servers located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses implemented by our service providers.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. The “Last updated” date above reflects the current version. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15. Contact
For privacy questions or requests, contact:
MineledgerAI LLC
support@mocktomer.ai