MetricMartianTerms draft

Draft — founder and legal approval required

PRIVACY POLICY · WORKING DRAFT

Your code and evidence deserve a clear boundary.

This page documents the intended MetricMartian privacy practices for review. It is not the final approved policy and must be approved before external beta.

Version: working-draft-2026-08-10 · Draft updated: August 10, 2026

On this pageWhat we collectWhat we avoidHow we use dataProvidersRetentionYour choicesSecurityContact

What we collect

MetricMartian may process account and organization membership, selected GitHub repositories, pull-request and commit metadata, reviews and checks, engineer identity and founder-entered cost context, analysis summaries, Mission Briefs, calibration history, billing identifiers, delivery status, and scrubbed operational logs.

Private stripped diffs may be used as bounded analysis input. They are stored separately from product analytics and are never promoted into the global reference library without explicit written customer consent.

Before an account exists, the early-access form collects a work email, company, active-engineer band, repository-readiness choice, requested participation path, acquisition-source category, and an explicit consent version and timestamp. It does not accept a repository URL, GitHub username, source code, employee name, compensation, phone number, payment data, or free-form response. Abuse controls store only a keyed one-way request fingerprint, never the raw IP address or user agent.

What we intentionally do not collect

MetricMartian does not collect keystrokes, screenshots, screen time, presence, private chats, IDE activity, or device surveillance. The product reads authorized repository evidence; it is not employee-monitoring software.

How we use information

We use authorized data to authenticate users, maintain organization boundaries, import delivery evidence, generate directional analysis, prepare weekly Mission Briefs, deliver requested email or Slack notifications, provide billing functions, prevent abuse, and improve reliability.

Product analytics and error monitoring are configured to exclude customer code, names, repository names, pull-request titles, rates, costs, diffs, tokens, and webhook URLs.

Service providers and AI processing

The working provider register maps GitHub, Supabase, Anthropic, Voyage AI, OpenAI as a controlled fallback, Inngest, Stripe, Resend, PostHog, Sentry, and Vercel. It identifies what is application-verified, what is only a published provider default, and which account settings remain unverified. MetricMartian does not claim that Voyage training opt-out, Anthropic zero data retention, or OpenAI zero data retention is enabled without account evidence.

Retention and deletion

Stripped diffs are scheduled for deletion 90 days after completed analysis. Protected raw model failures are scheduled for deletion 30 days after attachment. Account, organization, evidence, analysis, billing identifiers, and attributable audit records remain for the organization lifecycle or a documented legal and operational need. Organization owners can start a retry-safe deletion workflow that removes private storage objects, encrypted delivery secrets, GitHub provider links, database rows, and attributable operational records before retaining only a content-free receipt. A provider may retain residual backups, security records, or legally required payment records under its own documented terms.

Active early-access contact and qualification fields expire after 180 days without a new request. Unsubscribe immediately removes those fields and keeps only a one-way email suppression digest for up to 365 days. Short-lived abuse-control rows expire after 24 hours. The confirmation link requires a separate action so an email scanner cannot unsubscribe merely by opening it.

Your choices and data rights

Customers can disconnect providers and may request access, correction, export, restriction, objection, or deletion where applicable by contacting martin@metricmartian.com. Requests are logged, the requester's authority is verified, the affected systems and providers are searched, and legal exceptions are reviewed before fulfillment. The organization-deletion control requires the exact organization name plus a separate destructive confirmation; it runs server-side and does not expose deletion access to browser credentials. Final statutory timing, exceptions, and notice language still require legal approval.

Security

MetricMartian uses organization-keyed database policies, server-only credentials, signed webhooks, encrypted secrets, private storage, least-privilege provider scopes, and scrubbed telemetry. No internet service is risk-free; final incident, notification, and policy language requires legal approval.

Contact

Questions about this draft can be sent to martin@metricmartian.com. The legal operator is intended to be Daniel Son, LLC, United States; the final notice address and privacy contact must be confirmed before approval.

This is a working draft, not the final approved Privacy Policy.

Return homeProvider registerRead terms draft