mantıs
Sign inTry it out

Legal

Privacy Policy

This policy explains what personal data Mantis processes, why, on what legal basis, who we share it with, and the rights you have — under the EU/UK GDPR and similar laws.

Last updated: 7 July 2026

1. Who we are

Mantis (“Mantis,” “we,” “us”) operates the AI investor-intelligence service at www.heymantis.ai. For the personal data described here, Mantis is the data controller.

For any privacy question or to exercise your rights, contact us at contact@heymantis.ai.

2. The data we process

2.1 Data you give us

  • Account & identity: your email address and name, obtained when you sign in with a magic link or Google sign-in.
  • Workspace & configuration: your workspace, default timezone, and delivery preferences.
  • Watchlists: the companies, people/founders, markets/topics, and URLs you choose to monitor, plus schedules.
  • Channel data: your connected delivery channels (login email and, if you connect it, Slack) and the messages you exchange with the Mantis agent by email or Slack.
  • Payment data: if you subscribe, your billing details and subscription status. Card payments are handled by Stripe; we receive tokens and status, not your full card number.
  • Attribution & support:your optional answer to “how did you hear about us,” and any correspondence you send us.

2.2 Data collected automatically

  • Essential cookies & session: a strictly-necessary authentication cookie keeps you signed in; a short-lived cookie protects the Slack connection flow. On our public site we also use Google Analytics, but only if you accept it in the cookie banner — reject it and no analytics cookies are set. See the Cookie Policy. We do not use advertising or cross-site tracking cookies.
  • Technical logs: our hosting and network providers process request metadata such as IP address and timestamps to serve the site securely.

2.3 Public information about the subjects you monitor

This is central to how Mantis works, so we are explicit about it. When you add a company, founder, or other person to a watchlist, Mantis collects publicly available information about that subject — for example public posts on X, and web/news articles — in order to build your briefs. Where the subject is an individual, this can include personal data drawn from public sources (such as their public statements and activity). Mantis only processes information that is already public; it does not access private accounts or non-public content.

3. How and why we use data, and our legal bases

Under Article 6 GDPR we rely on the following legal bases:

  • To provide the Service (contract, Art. 6(1)(b)): creating your account, running your watchlists, generating and delivering briefs, and processing your commands.
  • Payments & records (contract / legal obligation, Art. 6(1)(b),(c)): billing you and keeping the tax and accounting records we are required to keep.
  • Security, reliability, and improvement (legitimate interests, Art. 6(1)(f)): protecting the Service against abuse, enforcing rate limits, debugging, and improving quality. We balance these interests against your rights.
  • Consent (Art. 6(1)(a)): where we ask for it — for example, optional Google Analytics cookies on our public site, or any optional product or marketing email. You can withdraw consent at any time.
  • Collecting public information about monitored subjects (legitimate interests, Art. 6(1)(f)): see section 4.

4. Third-party public data — our legitimate-interest basis

When Mantis collects publicly available information about a company or person you monitor, our legal basis is our and our users’ legitimate interest in delivering investor intelligence about subjects that are already in the public domain. We have considered the interests and rights of those individuals:

  • we process only information that is already public and that a user has a genuine professional reason to monitor;
  • we summarize and deliver it privately to the specific user who requested it — we do not publish it, sell it, or build cross-user profiles for sale;
  • we retain source records only as long as needed for deduplication and delivery (see retention below);
  • an individual can object and request removal, as described in section 8.

5. Who we share data with (sub-processors)

We do not sell your personal data. We share it with the service providers below, who process it only on our instructions to run Mantis. Each is bound by a data-processing agreement.

Sub-processorPurposeData involvedLocation / transfer
SupabaseDatabase, authentication, and application data storageAccount, workspaces, watchlists, settings, brief history, auth sessionHosting region we select; SCCs where outside the EEA
VercelApplication hosting, serving, and edge/CDN deliveryRequest metadata, IP address, technical logsUSA (SCCs)
StripeSubscription payments and billingBilling contact, subscription status, payment-method tokens (Stripe stores full card data; we do not)USA (SCCs)
ResendOutbound email delivery and inbound email-command processingRecipient email address, message content of briefs and your email repliesUSA (SCCs)
SlackBrief delivery and two-way commands via the Slack integrationWorkspace/channel identifiers, message content you exchange with the botUSA (SCCs)
Anthropic (Claude)LLM processing — filtering, deduplication, and brief synthesisWatchlist context and collected public-source snippets (no payment data)USA (SCCs); not used to train their models on our data
xAI (Grok)Collection of public posts on X and web/news searchSearch queries derived from your watchlist subjectsUSA (SCCs)
Google (Gemini)Market and news collection with search groundingSearch queries derived from your watchlist markets/topicsUSA (SCCs)
CloudflareDNS and network/proxy layerRequest metadata, IP addressGlobal edge network (SCCs)
Google AnalyticsAggregate usage analytics for our public marketing site — loaded only with your consentAnonymous usage events (page views, device/browser, approximate location) from the public site; never app or watchlist dataUSA (SCCs)

We may also disclose data where required by law, to establish or defend legal claims, or in connection with a business transfer, subject to this policy.

6. International transfers

Several sub-processors are based in the United States or operate global infrastructure. Where personal data is transferred outside the European Economic Area or the UK, we rely on appropriate safeguards — primarily the European Commission’s Standard Contractual Clauses (and the UK Addendum) — or another lawful transfer mechanism such as an adequacy decision. You can request more detail on the safeguards for a specific provider at contact@heymantis.ai.

7. How long we keep data

  • Account & workspace data: for as long as your account is active. If your workspace is paused for non-payment, we retain it so you can reactivate; we may delete data from long-paused or closed accounts.
  • Brief history: retained in your account so you can revisit past briefs, until you delete it or close your account.
  • Collection/deduplication records (internal records of which source items have already been seen, and source snapshots): retained on a rolling basis of up to roughly 60 days and then automatically purged.
  • Billing records: kept for the period required by tax and accounting law.
  • Backups & logs: kept for a limited period, then rotated out.

8. Your rights

Subject to applicable law, you have the right to access your personal data, to rectify inaccurate data, to request erasure, to restrict or object to certain processing, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email contact@heymantis.ai; we will respond within the timeframes required by law. You also have the right to complain to your local data-protection authority.

Account deletion. You can request full deletion of your account and associated data by emailing contact@heymantis.ai. A self-serve “delete my account” option in the dashboard is planned; until it ships, the email route above is the documented path.

8.1 Individuals who appear in briefs

If you are a person whom a Mantis user has chosen to monitor and your public information appears in briefs, you may object to that processing or request removal by emailing contact@heymantis.ai. Tell us the identifier(s) you use publicly (for example, an X handle or a company name) so we can act on your request. We will assess it and, where your rights require, suppress the relevant data from future collection to the extent it is within our control.

9. How we protect data

  • Tenant isolation:database row-level security scopes every workspace’s data to its owner, so users cannot see each other’s data.
  • Encryption in transit: traffic to and from the Service is encrypted with HTTPS/TLS.
  • Least-privilege access: sensitive server operations use scoped, server-only credentials; secrets such as integration tokens are never exposed to the browser.
  • Provider security: our sub-processors maintain their own industry-standard security and compliance programs.

No system is perfectly secure, but we work to protect your data using measures appropriate to the risk.

10. Cookies

Mantis uses only strictly-necessary cookies. Details of each cookie, its purpose, and its duration are in the Cookie Policy.

11. Children

The Service is for business/professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact contact@heymantis.ai and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, take reasonable steps to notify you.

13. Contact

Privacy questions and data-subject requests: contact@heymantis.ai. General enquiries: contact@heymantis.ai.

mantıs
ProblemHow it worksUse casesSolutionPricing
contact@heymantis.ai
© 2026 Mantis. All rights reserved.
TermsPrivacyCookies