Trust & security
Small surface, honest posture.
What we store, where it lives, who touches it, and how to reach us. Updated whenever any of it changes.
What we collect, and what we deliberately do not
A scan needs your company name, website, market description and email. We never ask for access to your analytics, your CRM, your ad accounts or your codebase. Scan results are reachable only through an unguessable 64-character token or your logged-in account. Passwords are stored as salted scrypt hashes; login links are single-use and expire in 20 minutes.
Where data lives
Application data is stored with Supabase (EU-hosted Postgres) and served through Vercel. Payments are processed entirely by Stripe; card details never touch our systems. Transactional email is sent through Resend. AI engine calls are made to the providers listed below with your buyer questions only, never with your account data.
Sub-processors
Vercel (hosting and edge network), Supabase (database), Stripe (payments), Resend (email), and the AI engine providers queried during scans: OpenAI, Anthropic, Google, Perplexity, xAI and OpenRouter. We add nothing to this list without updating this page.
GDPR
We act as controller for the account data you give us and process it to deliver what you bought. You can request export or deletion of everything tied to your email at any time by writing to hello@saymetry.com; deletion is completed within 30 days. A signable DPA is available on request for agency and enterprise customers.
Certifications
SOC 2 is on our roadmap as the company scales; we are honest about not holding it yet, and equally honest that our surface area is deliberately small: no analytics access, no stored payment data, no third-party JavaScript beyond first-party analytics.
Reporting a vulnerability
Write to hello@saymetry.com with "security" in the subject. We reply within 48 hours, we do not pursue good-faith researchers, and we credit fixes if you want the credit.