This Privacy Policy explains how fromzeroagain OÜ, registry code 17447933, Sepapaja tn 6, 15551 Tallinn, Estonia handles personal data when you use CheckMention. We are the controller for the account and website data described below. Contact hello@checkmention.com with privacy questions or requests.
1. Data we handle
We handle account and authentication data such as your email address, authentication identity, session records, account status, and account creation time.
We handle service-control data such as accepted Terms, acknowledged Privacy Policy versions, trial and membership status, payment-provider customer and subscription references, billing event status, and registered device records. A device record includes the Mac hostname reported by macOS, macOS and app versions, registration and last-seen times, and whether access is active or removed.
When you connect Threads, our server handles the authorization exchange and stores the long-lived access token as an authenticated encrypted envelope. The encryption key is kept separately from the account database, and the token is not sent to or stored in the Mac app. We store Threads connection metadata, including the provider account identifier, username, granted access level and scopes, token expiry, and a keyed non-plain-text reference used to process Meta deauthorization and data-deletion callbacks.
For always-on Hacker News monitoring, we handle an account-scoped catalog containing product names, domains, handles, aliases, matching terms, selected competitor identifiers, Hacker News source selections, and tracked Hacker News post IDs. Our worker reads public Hacker News API items and compares them with the catalog. New items that have never matched any account and are not tracked are not retained as source-content records. For matched or tracked items, we store allowlisted normalized fields such as the public author name, title or excerpt, links, publication time, matching evidence, classification, and account-product delivery records.
Matched Hacker News and Threads results are synchronized to the Mac app for offline use. For Threads, we centrally derive search queries from your account-scoped product names, domains, handles, aliases, and competitor identifiers; call the official recent keyword-search API; and store allowlisted normalized matched content, matching evidence, classification, scheduling and delivery records. We do not store raw provider response payloads. Saved, Completed, and human-feedback state remains in the local account workspace.
2. Why we handle it
We use account and service-control data to create and secure your account, provide the trial and paid service, keep legal records, process billing, manage device access, run always-on Hacker News and Threads matching and result synchronization, process source deauthorization and deletion requests, respond to support requests, prevent misuse, and comply with legal obligations.
Depending on the context, our legal bases include performing our contract with you, taking steps at your request before entering a contract, complying with legal obligations, and our legitimate interests in securing and operating the service. Where consent is legally required, you may withdraw it for future processing.
3. Service providers
We use Supabase for authentication and account database services, and Cloudflare to run the collection workers that connect to the source APIs and our database. We use Stripe when you choose to activate a paid Monthly membership. These providers process relevant data on our behalf or, where their own terms apply, under their stated roles and privacy terms.
We do not sell personal data. This version of CheckMention does not state that it uses advertising profiles or website analytics, and we do not use those purposes as a basis for this Policy.
4. International processing
Our service providers may process data outside your country. Where required, transfers are protected through an applicable legal transfer mechanism and provider safeguards.
5. Retention
We retain account and service-control data while your account is active and as reasonably needed for security, billing, legal recordkeeping, dispute resolution, and applicable legal obligations. The server-side Hacker News catalog, matched or tracked normalized content, projections, and delivery records are retained while reasonably needed to provide and synchronize Hacker News monitoring, subject to account deletion and source-specific deletion requirements. Retention periods depend on the record and legal requirement. We do not claim a fixed deletion period that the current service does not enforce.
If the Hacker News API reports that a stored item is deleted, dead, or unavailable, the server removes the corresponding source record and sends a purge event to connected Macs. The Mac applies that purge to the local source item, projections, and associated user state before acknowledging the event.
A Threads data-deletion request for the currently connected provider identity immediately stops that connection, clears the centrally stored token envelope, removes centrally stored Threads source content and projections, and creates a completed status receipt. A request for a previously connected identity also removes the account-scoped stored Threads content, but does not stop a different provider identity that is currently connected. A purge event removes the mirrored Threads content from each local workspace when that Mac next synchronizes. A deauthorization request clears and stops the matching current connection without deleting previously collected content, and does not stop a different current identity. We retain keyed references for current and previously connected Threads identities while the CheckMention account remains active so later Meta lifecycle requests can be attributed, plus the minimum request and completion records reasonably needed to show that a request was handled.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on consent. You may also complain to the Estonian Data Protection Inspectorate or another competent supervisory authority.
Send requests to hello@checkmention.com. We may need to verify your identity before completing a request.
7. Security
We use access controls and service boundaries intended to protect account and billing records. Threads access tokens are encrypted with authenticated encryption, bound to account and connection context, versioned for key rotation, and available to a least-privilege collection worker only through restricted database operations. No system is completely secure, so you should protect access to your email account and device.
8. Changes to this Policy
We may update this Policy when our data practices, providers, or legal obligations change. The current version and effective date are published on this page. A Privacy Policy update is presented as a notice and does not by itself represent consent to unrelated processing.
See also the Terms of Service.