Privacy

What is processed and retained.

MonetizeMentions is copy-only, but “not published” does not mean “not processed.” This notice describes the service’s current behavior.

Effective August 2, 2026.

Data you submit

The service processes YouTube URLs, fetched captions, pasted or uploaded transcript text, filenames, and the approved affiliate URLs you enter. For signed-in creators, eligible product mentions are saved to the durable opportunity workspace with their video or transcript source, quote, timestamp, matched program, application status, and any approved affiliate URL you choose to save.

Accounts and usage enforcement

Clerk handles authentication and its session cookies. The analysis API stores keyed hashes derived from a Clerk user ID or, for guests, Cloudflare’s client-IP header plus browser attributes. Resource IDs are also hashed. The usage database does not store raw IP addresses, raw user agents, or transcript text. These pseudonymous records enforce distinct-analysis quotas and short-window rate limits.

External processors

TranscriptAPI may receive a YouTube video ID to retrieve captions. OpenRouter or Anthropic receives transcript text to extract product mentions. AffiliateDataset receives extracted brand names for program lookup. Clerk processes account and session data. Cloudflare provides hosting, network security, operational metrics, logs, and the durable usage database. Stripe processes checkout, payment, and subscription records. PostHog receives page views, a pseudonymous anonymous ID or Clerk user ID, and allowlisted product events such as plan, source type, counts, timing, and error category. PostHog does not receive transcript text, affiliate URLs, raw YouTube URLs, video quotes, creator email, or API keys. Autocapture and session replay are disabled. LogRocket receives privacy-filtered production session interaction, performance, and error telemetry. The application masks page text, images, and form values; removes URL query strings and network bodies and headers; and disables LogRocket IP capture. Signed-in sessions are associated only with the immutable Clerk user ID, not a name or email. Each provider handles data under its own terms and privacy notice.

Retention

Successful fetched transcripts and normalized model extraction results may remain in the application cache without an automatic expiration so repeat analyses avoid another billable upstream request. Failed upstream responses are not cached. Usage-resource hashes are retained for up to 400 days; rate-limit buckets are retained for up to 30 days. Saved opportunities remain associated with your account so you can continue the workflow across sessions, including when marked Dismissed, until a deletion request is completed. LogRocket keeps session and analytics data according to the retention period configured for this project. Hosting, authentication, and upstream providers may keep operational or security logs under their own retention schedules.

Publishing and link review

The service does not connect to your YouTube account, modify a video, or publish a description. Copying a generated draft requires explicit review. Program application pages are never inserted as creator tracking links, and unrelated tracking domains are blocked.

Account and deletion requests

Account controls are available through the Clerk profile menu. Use the contact channel provided with your account for a privacy or deletion request, including deletion of saved opportunities and approved links. Some cached records use only non-reversible hashes and may not be linkable back to an account.