Mention Reminder
Back to home

Privacy Policy

Last updated: 23 September 2026

This Privacy Policy explains what data Mention Reminder processes when you use our bot, panel, and website, on what legal basis, and what rights you have. We built Mention Reminder to help teams follow up on mentions - not to monetize your conversations. We do not sell personal data or the content of your servers and workspaces.

1. Who we are

Mention Reminder is operated by Webalize sp. z o.o., with its registered office in Warsaw (Plac Bankowy 2, 00-095 Warszawa, Poland), entered in the Polish National Court Register (KRS) under number 0000822439, NIP PL5252811769, REGON 385278470, share capital PLN 5,000 (“Mention Reminder”, “we”, “us”). We provide a bot and related services that help teams track and resolve unanswered mentions in chat platforms - currently Discord and Slack.

For data protection questions, contact privacy@mentionreminder.com.

2. Controller vs processor

For content from your Discord servers and Slack workspaces (mentions, message excerpts, reminders) we generally act as a processor on behalf of your organization - the workspace admin decides why and how Mention Reminder is used. Your organization is then responsible for informing team members and for having an appropriate legal basis.

For the customer relationship - panel accounts, billing data, form submissions, website analytics - we act as a controller.

The data processing terms (DPA) required by Art. 28 GDPR form an integral part of our Terms and Conditions (section 7) and need no separate document or signature. Art. 28(9) GDPR expressly allows a processing agreement to be concluded in electronic form, so accepting the Terms in the web panel, which is required before the bot starts processing anything, concludes it. If your organization needs those provisions as a standalone file for its records, we will send them on request - email privacy@mentionreminder.com.

3. What data we process

Account and configuration data: Discord server and Slack workspace identifiers, organization name, reminder hours and time zone, the primary-server selection, and the per-user “observed” (seat) flag.

Mention data: user, channel, and message identifiers, message URLs, author identifier, timestamps, and a short message excerpt needed to render the “to reply” list. We do not store the full text of every message to provide reminders.

Automatic credential removal: before an excerpt is stored, text that looks like an API key, token, password, or private key is automatically replaced with a placeholder. Such data reaches neither our database nor the AI model provider. Detection is heuristic, so we cannot guarantee every case is caught - it does not replace care when sharing secrets in chat.

Installation tokens: for OAuth installs (Slack) we store the app authorization token so the bot can operate in your workspace.

Identity matching: when more than one Slack workspace is linked to a single account, the same person has a different identifier in each. To recognize that they are the same person, we store the email address from their Slack profile purely as a matching key between those identifiers. Where the workspace admin hides the address, no match is made. We never match identities across platforms.

Panel sign-in data: when you sign in via OAuth we read your identifier on that platform and the list of servers or workspaces where you are an admin, solely to check whether you may access that account’s panel. We do not store that list.

Billing data: company name, address, tax/VAT number, invoice email, and subscription and payment-status identifiers. Payment card data is processed solely by Stripe - we neither see nor store the full card number.

Form submissions: data you provide in the contact form (first name, last name, email, company, message), waitlist sign-ups (email, selected platforms), and the feedback form available from the bot (category, message, the submitter’s identifier and platform).

Technical data: IP address, browser and device type, error reports, and events needed for security and diagnostics. Panel sign-in uses essential, signed cookies only - they are listed in section 7.

4. Purposes and legal bases

Providing the service (Art. 6(1)(b) GDPR): detecting mentions, maintaining private reminders, sending them on schedule, panel sign-in, and handling subscriptions.

Legitimate interests (Art. 6(1)(f) GDPR): security, abuse prevention, diagnostics, privacy-preserving aggregate website analytics, and product improvement.

Legal obligation (Art. 6(1)(c) GDPR): retaining invoices and tax records.

Consent (Art. 6(1)(a) GDPR): where we require it, e.g. optional marketing emails. You can withdraw consent at any time.

5. AI features

AI classification is optional. When enabled, short message excerpts may be sent to a model provider (currently OpenAI) solely to assess whether a mention needs action or whether a reply resolves it. Excerpts are not used to train the provider’s models.

The context for that assessment is the mention itself plus a few preceding messages from the same channel - without them there is no way to tell whether someone has already replied. Before anything is sent to the model provider, the automatic credential removal described above is applied to both the message and that context, so detected keys, tokens, and passwords are stripped first.

AI can be turned off - Mention Reminder then runs on simple rules. Enterprise (self-hosted) deployments can use local models so content never leaves the customer’s infrastructure.

6. Subprocessors and recipients

The following act as processors on our behalf: Hetzner (server infrastructure in Germany), Vercel (website and panel hosting, plus analytics), OpenAI (optional AI classification), and inFakt (issuing VAT invoices and filing them with KSeF, Poland’s national e-invoicing system). Processing is entrusted under the data processing terms that form part of our agreements with those providers.

Stripe handles payments. For billing data processed on our instructions it acts as a processor, while at the same time - for fraud prevention and its own payment and regulatory obligations - it acts as an independent controller under its own privacy policy.

Discord and Slack are not our processors. They are independent controllers of their own platforms; we receive data from them through their APIs, within the permissions granted by the admin of your server or workspace. Their processing of your conversations - which happens whether or not you use Mention Reminder - is governed by their own privacy policies and by the agreements you concluded directly with them.

Beyond that, data may reach professional advisers (accounting, legal) and public authorities where the law requires it - in particular, invoices are filed with KSeF, operated by the Polish Ministry of Finance. We do not sell data and do not share it for advertising. We give advance notice before changing or adding a subprocessor, and send the current list on request at privacy@mentionreminder.com.

7. Cookies and analytics

We use only cookies that are essential to running the panel, and none of them is used for tracking or advertising: mention_reminder_session (the signed session cookie that keeps you signed in), mention_reminder_signed_in (tells the interface that a session exists), and short-lived technical cookies that keep the sign-in and installation flows secure (including the language the installation was started in). The latter expire when the operation or session ends.

For website analytics we use Vercel Analytics, which works without cookies and without profiling - it collects aggregate, anonymized visit statistics (such as page views, country, and device type) and does not identify individuals. For that reason we do not show a cookie-consent banner. If we later add tools that require consent, we will ask for it before enabling them.

8. International transfers

The application database and the bot process run on servers in Germany, inside the European Economic Area. Invoices are issued by a Polish provider.

Some providers (Stripe, OpenAI, and Vercel) may process data outside the European Economic Area, including in the US. In those cases we rely on appropriate safeguards - the European Commission’s Standard Contractual Clauses or participation in the Data Privacy Framework where applicable.

9. Retention

We keep mention and configuration data for as long as your workspace uses Mention Reminder. Unlinking a single server or workspace deletes its mention data immediately.

When the bot is removed from the last linked server or workspace, the account goes “dormant”: data is retained for a grace period (currently 12 months) so an accidental removal can be undone, after which it is permanently deleted. Re-adding the bot within that window restores the account.

Closing the account from the panel (the danger zone on the company page) works differently and has no grace period: we immediately and irreversibly delete connections, settings, seats, mentions, identities, and installation tokens, and cancel the subscription with immediate effect. This cannot be undone.

Closing the account does not delete accounting documents: issued VAT invoices and the billing data attached to them are retained for the period required by tax law, because we are legally obliged to keep them and cannot waive that. We also retain the content of product feedback you have submitted. Contact-form and waitlist submissions are kept until the matter is handled and for a reasonable period afterward. You can ask us to delete data subject to your rights sooner at any time.

10. Security

We apply appropriate technical and organizational measures - encryption in transit, restricted access to data, signed sessions, and separation of secrets. No method of transmission or storage is 100% secure, but we treat data protection as a priority and respond to incidents in line with applicable law.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing and withdraw consent. You also have the right to lodge a complaint with a supervisory authority (in Poland: the President of the UODO).

To exercise your rights, email privacy@mentionreminder.com. Where we act as a processor on behalf of your organization, we may route the request to the workspace admin. We may need to verify your identity or admin authority.

12. Children’s data

Mention Reminder is a tool for teams and is not directed at children. Use requires meeting the minimum age set by Discord’s and Slack’s terms and by applicable law. We do not knowingly collect data from anyone below that age.

13. Changes and contact

We may update this policy as our product or legal obligations change. We will post the new version on this page and update the “Last updated” date. Material changes affecting workspace admins may also be communicated by email or in-product notice.

Privacy questions: privacy@mentionreminder.com.

Stop letting things vanish in the scroll

Add Mention Reminder to Discord or Slack - two minutes, once. After that it runs in the background and nobody on the team has to do anything else. Starter is free, no card.

Free · no card · no extra app