Privacy Policy
Last updated: 29 September 2026
This document describes how Mendi actually works today and is pending formal legal review. If anything here conflicts with your rights under UK GDPR or your local law, your rights take precedence — write to us and we will fix the wording.
1. What we collect
To provide the service, we collect limited information:
- Identity. Your email address, and your name if you sign in with Google, to manage your account and subscription.
- Posts and comments you ask us to work on. When you give Mendi a post to reply to, we fetch that post’s public text and public comments related to it so a draft can be grounded in what people actually said.
- Drafts you generate. The replies Mendi writes for you, and the comments each draft drew on, so you can review and trace them later.
- Billing records. Your subscription tier and a ledger of every credit charged or refunded. Card details are handled by Stripe and never reach our servers.
- Technical data. Anonymised interaction logs used to keep the service working.
2. Third-party comments and public posts
Mendi reads public content: posts you point it at, and public comments on or about them. We do not log into anyone’s account to obtain it, and we do not collect private messages, follower lists, or anything behind a login.
Raw comment text and commenter handles are working memory, not a permanent archive. They are deleted after 30 days. What survives past that is the draft you generated and the derived, non-identifying analysis behind it.
Mendi never posts on your behalf. There is no path in the product that publishes a reply to any third-party platform, on any trigger, automatic or manual. Drafts are yours to copy and post yourself.
3. The Mendi browser extension
The Mendi extension for Chrome works on x.com and twitter.com. It acts only on the post you have open.
- What it reads on the page. On a post page it reads that post’s text, author, images and link preview, and the replies already visible under it, so the side panel can show you what you are replying to. It also reads your own X handle from the page, only to recognise your own replies, and keeps it in your browser.
- What it sends to us. Only when you ask for drafts: the post’s link, text and author handle, and links to up to four of its images. These are handled like any other post you give Mendi (sections 1 to 4), including describing the images with an AI provider. The visible replies and your X handle are not sent.
- What it does not touch. Your direct messages, your timeline, other tabs, websites other than X and the Mendi web app, or your browsing history. It does not scan your timeline or choose posts for you, and it never calls X’s own APIs or asks for access to your X account.
- What it stores in your browser. Your Mendi sign-in tokens and basic account details (id, email and name) in Chrome’s local extension storage, so you stay signed in; signing out removes them. Your drafting preset (reply modes, angles, tones and number of drafts) in Chrome’s sync storage, which Chrome may copy to other browsers where you are signed in to Chrome. Removing the extension deletes what it stored.
- Signing in. On app.commentverdict.com the extension exchanges sign-in tokens with the Mendi web app, so signing in once covers both.
- It never presses Post. When you pick a draft, the extension types it into X’s reply box. You read it and press Post yourself.
4. How we handle your prompts and drafts
Generating a reply sends the post’s text, the related public comments, and any style or instruction you supplied to third-party AI providers (currently OpenAI, Anthropic, Google, and specialist model hosts such as DeepInfra, Together, Fireworks, Groq and OpenRouter) so a draft can be produced.
- What is not sent: your name, email address, or payment details are never forwarded to an AI provider.
- No training use: we do not use your prompts, drafts or account content to train or fine-tune AI models.
- Retention: your drafts are kept for as long as your account is active, so you can return to them. You can delete any draft at any time.
5. Google API Limited Use
Mendi’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Email you receive from us
Service messages about your own account and money — a failed payment, a refund, credits running low or resetting — are transactional, and you receive them while you hold an account.
Marketing email (product updates, tips) is separate and off unless you turn it on. You can withdraw marketing consent at any time in notification settings without affecting the service messages above — the two are deliberately not bundled.
7. Your rights
Under UK GDPR you can, at any time:
- Get a copy of your data. Settings gives you a machine-readable export of your account, subscription, credit ledger and preferences.
- Delete your account, which removes your account and its associated records.
- Correct anything inaccurate, or ask us to restrict or object to a particular use.
If you think we have handled your data badly, you can complain to the UK Information Commissioner’s Office at ico.org.uk.
8. Changes
If this policy changes in a way that materially affects you, we will say so rather than quietly updating the date at the top.
Questions about this policy? support@commentverdict.com