Mockingbird

Privacy Policy

Last updated: 22 May 2026

1. Who we are

This Privacy Policy explains how Sancar Media (operating Mockingbird) collects and uses personal information about you when you use the service at mockingbirdhouse.com.

2. What we collect

  • Account data:email address, hashed password (when you don't sign in with Google), basic profile information from Google if you use Sign in with Google.
  • Brand inputs: the website URL, brand name, brand colours, product photos, and optional logo you upload during onboarding.
  • Voice profile: a derived JSON profile extracted from your website by our AI provider. You can edit it from the onboarding screen.
  • Usage: ad jobs you create, ads you heart, ads you upload, and metadata about each remake (timestamps, status, error messages).
  • Payment data: we use Stripe to process payments. We never see or store your full card number. We store Stripe customer and subscription identifiers so we can link your subscription state to your account.
  • Cookies: a session cookie for authentication (via Supabase) and an HttpOnly cookie indicating which brand you are currently working with.

3. How we use it

  • To operate the remake pipeline you signed up for
  • To bill you and manage your subscription
  • To send transactional emails (sign-in, billing, support)
  • To improve the service. Aggregate usage data may be used internally to debug, identify failure modes, and prioritise roadmap work.

4. Who we share it with

We share data with the following service providers, strictly as needed to deliver the service:

  • Supabase: database, authentication, file storage.
  • Vercel: hosting + serverless functions for the application.
  • Stripe: payment processing and subscription management. Stripe processes your card details under its own privacy policy.
  • OpenAI: image generation. We send your product photos, brand logo, and the remake prompt to OpenAI each time you trigger a remake.
  • Anthropic: brand voice extraction and cinematic prompt generation. We send public-facing text from your website and your brand voice profile.
  • Inngest: background job queue for the remake pipeline.
  • Resend / Supabase email: transactional emails (verification, billing notifications).
  • Sentry (when enabled): error tracking. May receive request metadata when something errors.

We do not sell your personal data and we do not share it with third parties for their independent marketing.

5. Retention

We keep account, brand, and usage data while your account is active and for up to 12 months after you delete your account or cancel your subscription, after which we anonymise or delete it. Stripe and other processors retain payment data according to their own retention policies and applicable law (typically 7 years for tax/compliance).

6. Your rights

If you are in the UK or EU, you have the right to:

  • Access the personal data we hold about you
  • Have it corrected if inaccurate
  • Have it deleted (subject to legal retention obligations)
  • Object to or restrict certain processing
  • Receive a portable copy of your data
  • Withdraw consent at any time where processing relies on consent
  • Complain to a data protection authority (in the UK, the Information Commissioner's Office)

To exercise any of these rights, email hello@mockingbirdhouse.com from the email address on your account.

7. Children

Mockingbird is not directed to or intended for use by anyone under 18. If you believe a child has provided personal data, email us and we'll delete it.

8. International transfers

Our infrastructure providers (Vercel, Supabase, OpenAI, Anthropic, Stripe) operate globally. Data may be processed in the United States, the European Union, the United Kingdom, or other jurisdictions in which they operate. They each maintain appropriate safeguards under their data-processing agreements.

9. Security

We use TLS in transit, encrypted database storage at rest, row-level security in the database to scope each user's data to their own account, HttpOnly cookies for sessions, and we do not store raw payment card details. No system is perfect — if we ever detect a breach affecting you we'll notify you within 72 hours as required by GDPR.

10. Changes

We may update this Policy. If we make material changes we'll notify you by email. Continued use of the service after notification means you accept the updated Policy.

11. Contact

Questions, complaints, or data requests? Email hello@mockingbirdhouse.com.