Legal
Privacy Notice
What we collect, why we collect it, and how long we keep it. Last updated 15 August 2026.
1. Who is responsible
Can Özdoğan, sole proprietor, Türkiye is the controller for the personal data described here. Contact: can@metriqmto.com.
For payments, Paddle.com Market Ltd is the merchant of record and an independent controller of the billing data you give it. We never see or store your card number.
2. What we collect
- Account data — email address, display name, hashed password, role, and sign-in timestamps. Passwords are stored only as a salted scrypt hash; we cannot read them.
- The models you upload and everything derived from them — take-off rows, evidence reports, workbooks, scope decisions and calibration corrections.
- Operational records — processing status, errors, usage counters, and server logs needed to run and debug the service.
- Billing status — subscription state and the Paddle customer and subscription identifiers. Card details stay with Paddle.
3. Why, and on what basis
- To provide the service you have subscribed to — performance of a contract.
- To keep the service secure and diagnose faults — legitimate interests.
- To meet accounting and tax obligations — legal obligation.
We do not sell personal data, and we do not use your models to train models for other customers.
4. Who processes data for us
- Vercel — application hosting (region: Frankfurt).
- Supabase — database and file storage.
- Autodesk Platform Services — cloud translation of models you choose to process in the cloud.
- Anthropic — the AI features (Ask-the-Data, diagnosis). Content sent for these features is not used to train their models.
- Paddle — payment processing and invoicing.
- Google Analytics 4 (Google Ireland Limited) — visit statistics on the public pages only, and only if you accept analytics cookies. It is not loaded on any page behind sign-in, so it never sees your models, take-offs or run identifiers.
Some of these providers operate outside your country. Transfers rely on the providers’ standard contractual clauses.
5. How long we keep it
- Uploaded model files — kept while your account is active so re-runs and 3D verification stay possible; deleted on request at any time.
- Take-offs and reports — kept while your account is active, so you can return to a past tender.
- Account and billing records — kept for as long as the account exists, then for the period required by tax law.
- Server logs — short-lived, kept only for operational debugging.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. Write to can@metriqmto.com and we will respond within 30 days. You can export your take-offs yourself at any time from inside the app — that path stays open even after a subscription ends.
7. Cookies
We use a single essential cookie to keep you signed in, plus small preference cookies for language and theme. These are necessary for the service and are not optional.
On the public pages only — the product page, guides and these legal pages — we ask before setting any analytics cookie. Until you accept, Google Analytics runs in consent-denied mode and writes no cookie. If you decline, nothing changes about how the site works. Your choice is stored for a year in a first-party cookie named metriq_consent; clear it in your browser to be asked again. Analytics is never loaded on pages behind sign-in. No advertising cookies are set, and Google Signals and ad personalisation are switched off.
8. Changes
If this notice changes materially we will email the account owner. The date at the top always reflects the current version.