Privacy Policy
Last updated: August 2, 2026
1. Who We Are
Metera, a company organized under the laws of Brazil, is the controller of personal data processed through the Metera platform ("Metera", "we", "us").
Contact for privacy matters: hello@metera.xyz
Data Protection Officer / Encarregado (LGPD Art. 41): [NAME AND CONTACT]
This Policy explains what personal data we process, why, on what legal basis, and what rights you have. It applies to the website at metera.xyz, the API, the dashboard, and all related services (the "Service").
2. Two Very Different Kinds of Data
This distinction matters throughout this Policy.
Account data — yours. Data about you as a user of the Service: your identity, your usage, your billing. We are the controller of this data and this Policy governs it.
Delivered data — third-party content. Data that the Service retrieves from third-party sources at your request and delivers to you. This may include personal data about other people, for example public social media profiles. We do not choose what this data contains; you do, by making the request.
For delivered data, you are the controller and we act as your processor. You decide what to request and why. You are responsible for having a lawful basis for that processing, for honouring the rights of the individuals concerned, and for complying with the terms of the originating platform. See Section 8.
3. Personal Data We Process
Data you provide
| Data | Purpose |
|---|---|
| Name, email address | Account creation, authentication, support, service notices |
| Billing details (processed by our payment provider) | Payment, invoicing, tax compliance |
| Agent configurations and chat descriptions | Providing the Service |
| Support correspondence | Responding to you |
Data generated by your use
| Data | Purpose |
|---|---|
| API keys (stored hashed) | Authentication |
| Request logs: timestamp, endpoint, canonical type, parameters, source selected, verification level, cost, latency | Delivering the Service, billing, security, debugging |
| Traces of routing decisions | Providing the audit trail that is a core feature of the Service |
| Agent execution records and collected results | Providing the Service |
| Aggregate reliability measurements about sources | Operating the verification engine |
Data collected automatically
IP address, browser and device information, and pages visited, collected through server logs and, where you consent, analytics cookies.
Data we do not collect
We do not intentionally collect special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation) about our users. Do not submit such data in agent descriptions or support requests.
We do not knowingly collect data from anyone under 18. See Section 11.
4. Legal Bases
Where the GDPR applies, we rely on:
- ·Contract (Art. 6(1)(b)) — account management, delivering the Service, billing, support
- ·Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, debugging, improving the Service, measuring source reliability. We have assessed that these interests are not overridden by your rights
- ·Legal obligation (Art. 6(1)(c)) — tax, accounting, and regulatory record-keeping
- ·Consent (Art. 6(1)(a)) — analytics cookies and marketing communications, where applicable. You may withdraw consent at any time
Where the LGPD applies, we rely on the corresponding bases in Art. 7: execution of contract (VI), legitimate interest (IX), compliance with legal obligation (II), and consent (I).
5. How We Use Data
- ·Providing, operating, and maintaining the Service
- ·Authenticating you and securing your account
- ·Metering usage and charging credits
- ·Producing the traces and verification levels that the Service delivers
- ·Measuring the reliability of data sources
- ·Detecting and preventing fraud, abuse, and security incidents
- ·Complying with legal obligations
- ·Communicating with you about the Service
- ·Improving the Service, including through aggregated and de-identified analysis
We do not sell personal data. We do not serve advertising and we do not share personal data with advertisers.
Automated decision-making. The Service makes automated decisions about which data sources to use and how to label results. These decisions concern data sources, not people, and do not produce legal or similarly significant effects on individuals. We do not use automated decision-making to evaluate users.
7. International Transfers
Metera is established in Brazil. Our infrastructure providers may process data in [REGIONS]. If you access the Service from outside Brazil, your personal data will be transferred to and processed in Brazil and in those regions.
For users in the European Economic Area and the United Kingdom: Brazil has not received an adequacy decision from the European Commission. Transfers of your personal data to us therefore rely on Standard Contractual Clauses adopted by the European Commission, together with supplementary measures where necessary. You may request a copy of the relevant clauses at hello@metera.xyz.
For users in Brazil: transfers outside Brazil are made in accordance with LGPD Art. 33, relying on standard contractual clauses or the other mechanisms provided in that article.
8. Delivered Data and Your Responsibilities
This section applies to data the Service retrieves and delivers to you.
We act as processor. We process delivered data on your documented instructions, which are the requests you or your agents make. We do not use delivered data for our own purposes, except in aggregated and de-identified form to measure the reliability of sources.
You are the controller, and this carries obligations. If you use the Service to retrieve personal data — including publicly available personal data such as social media profiles, posts, or engagement metrics — you are responsible for:
- ·Having a valid legal basis for that processing under the law applicable to you and to the individuals concerned
- ·Providing any required notice to those individuals
- ·Honouring their rights, including access, rectification, erasure, and objection
- ·Complying with the terms of the originating platform
- ·Assessing whether your processing requires a data protection impact assessment
- ·Retaining the data no longer than necessary
Publicly available does not mean unrestricted. Personal data that is publicly accessible remains personal data. Both the GDPR and the LGPD apply to it.
Retention of delivered data. We retain collected results for the period necessary to provide the Service, and delete them on your instruction or on account closure. You may delete collected results at any time through the dashboard.
We will assist you in responding to requests from individuals concerning delivered data, to the extent technically feasible and at your cost where the effort is more than trivial.
9. Retention
| Category | Period |
|---|---|
| Account data | For the life of the account, then 12 months, then deleted or anonymised |
| Billing and tax records | 5 years, as required by Brazilian law |
| Request logs and traces | 12 months, then aggregated or deleted |
| Agent configurations and collected results | Until deleted by you or 30 days after account closure |
| Source reliability measurements | Retained indefinitely in aggregated form; these concern sources, not individuals |
| Security logs | 12 months |
Where law requires longer retention, we retain for the required period only.
10. Your Rights
Subject to applicable law, you have the right to:
- ·Access the personal data we hold about you
- ·Rectify inaccurate or incomplete data
- ·Erase your data, where no overriding obligation or interest applies
- ·Restrict or object to processing based on legitimate interests
- ·Portability — receive your data in a structured, machine-readable format
- ·Withdraw consent at any time, without affecting prior processing
- ·Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects
Under the LGPD you additionally have the right to confirmation of processing, to information about data sharing, and to information about the consequences of refusing consent (Art. 18).
Exercising your rights. Contact hello@metera.xyz. We will respond within 30 days, extendable where the request is complex, and will tell you if we need more time. We may need to verify your identity.
Complaints. You may lodge a complaint with a supervisory authority. In Brazil, the Autoridade Nacional de Proteção de Dados (ANPD). In the EEA, your local supervisory authority. In the UK, the Information Commissioner's Office.
Requests about delivered data. If your request concerns data the Service retrieved on behalf of a customer, we will forward it to that customer, who is the controller.
11. Age Restriction
The Service is for users 18 and over. We do not knowingly collect personal data from anyone under 18.
If we learn that we have collected data from someone under 18, we will delete it promptly. If you believe this has occurred, contact hello@metera.xyz.
12. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, hashed storage of API keys and passwords, access controls, and monitoring.
No system is perfectly secure. We cannot guarantee absolute security.
Breach notification. If a breach is likely to result in a high risk to your rights, we will notify you and the relevant authorities without undue delay, as required by the GDPR (Arts. 33–34) and the LGPD (Art. 48).
Your part. Keep your credentials confidential. Report suspected compromise to hello@metera.xyz.
14. Changes
We may update this Policy. Where a change is material, we will notify you by email or through the Service at least 30 days before it takes effect. The "Last updated" date indicates the most recent revision.
15. Contact
Privacy matters: hello@metera.xyz
Data Protection Officer / Encarregado: [NAME AND CONTACT]
Security: hello@metera.xyz
This Policy is drafted in English. Any translation is provided for convenience; the English version prevails.