MetricMartianPrivacy draft

Draft — founder and legal approval required

DATA PRACTICES · WORKING REGISTER

Where MetricMartian data goes.

This register separates verified application controls, published provider defaults, verified account controls, and settings that still need action or confirmation. An unverified or pending control is never presented as a privacy guarantee.

Reviewed: August 11, 2026

GitHub

Status: Application control verified

Purpose: Source repository, GitHub App authorization, webhooks, and API evidence.

Data: GitHub App installation identifiers; selected repository, pull-request, commit, review, check, author, and bounded diff data.

Location: GitHub-operated global service; MetricMartian does not select a GitHub storage region.

Retention: GitHub retains source/account data under its account, contractual, and legal policies. MetricMartian copies follow the application periods described below.

Training: Not applicable to the GitHub App/API service used by MetricMartian; GitHub Copilot is not part of this flow.

Configuration evidence: Selected-repository access and the server-side disconnect/deletion path are implemented and verified.

Read the provider source

Supabase

Status: Application control verified

Purpose: Authentication, Postgres database, private Storage, Vault, and pgvector.

Data: Accounts, organization membership, GitHub evidence, cost context, analyses, private diffs, protected failures, encrypted delivery secrets, and operational records.

Location: Production project: AWS us-east-1.

Retention: Active records follow the organization lifecycle. Private diffs expire after 90 days; protected AI failures after 30 days. Supabase documents daily backups for paid plans, while Free projects are advised to make their own exports.

Training: Not an AI model-training service in this use.

Configuration evidence: Production project and US East (North Virginia) region were verified. The project is recorded as Free; re-check backup settings after the planned Pro upgrade.

Read the provider source

Anthropic

Status: Published provider default verified

Purpose: PR classification, AI-assisted baseline bands, and weekly narratives.

Data: Bounded stripped diff and trusted pull-request metadata for classification/baselines; structured weekly evidence for narratives.

Location: MetricMartian uses a United States Anthropic workspace; provider processing may use its approved infrastructure.

Retention: Anthropic says commercial API inputs and outputs are deleted within 30 days by default, subject to usage-policy and legal exceptions.

Training: Anthropic says commercial inputs and outputs are not used for model training by default unless feedback is submitted or the customer opts in.

Configuration evidence: Commercial API defaults are verified from Anthropic's Privacy Center. No zero-data-retention agreement is verified or claimed.

Read the provider source

Voyage AI

Status: Account setting verified; required control pending

Purpose: Primary vector embeddings for retrieval.

Data: A bounded embedding document containing trusted PR statistics, classification labels, and an AI-generated change summary; not the raw stored diff object.

Location: Provider-controlled processing; an account-specific residency setting has not been verified.

Retention: Voyage promises immediate post-processing deletion for content submitted after its account opt-out is enabled. Opt-out is not enabled for MetricMartian, so no bounded provider retention is claimed.

Training: Voyage's terms permit use of customer content to train and improve the service unless the account-level opt-out is enabled. Current MetricMartian account status: Opted In, and the application defaults customer embedding input to denied before any provider or telemetry call.

Configuration evidence: The authenticated MetricMartian organization currently shows Opted In. The opt-out switch is disabled until a payment method is on file; no opt-out or zero-retention claim is made.

Read the provider source

OpenAI

Status: Published provider default verified

Purpose: Controlled whole-corpus embedding fallback only.

Data: The same bounded embedding document used for Voyage if the whole corpus is deliberately migrated to the fallback provider.

Location: Default API processing; no account-specific regional residency configuration is verified.

Retention: OpenAI documents up to 30 days of default abuse-monitoring logs for embeddings and no application-state retention for the embeddings endpoint.

Training: OpenAI says API data is not used to train models by default unless the customer opts in.

Configuration evidence: Fallback is not active in production. Zero Data Retention or Modified Abuse Monitoring approval is not verified or claimed.

Read the provider source

Inngest

Status: Application and account controls verified

Purpose: Durable backfill, analysis, retention, deletion, billing, and notification jobs.

Data: Organization, repository, pull-request, scorecard, request, and installation identifiers; normalized webhook events; workflow step inputs and structured results.

Location: Inngest states that all data is hosted on AWS databases located in the United States.

Retention: The verified Hobby/Free account retains trace and log history for 24 hours. Durable application records remain in Supabase under MetricMartian's own retention controls.

Training: Not an AI model-training service in this use.

Configuration evidence: Event names and payload shapes are application-verified. The dashboard shows Hobby/Free, 50,000 runs per month, five concurrent steps, and 24-hour trace/log history; Inngest's Security page locates all database data in the United States.

Read the provider source

Stripe

Status: Application control verified

Purpose: Test checkout, subscription state, customer portal, and eventual payment processing.

Data: Organization identifier and plan metadata from MetricMartian; contact, billing, payment, fraud, and transaction data entered into Stripe-hosted surfaces.

Location: Stripe may process globally, including in the United States, under its DPA and transfer mechanisms.

Retention: Stripe processes data for the service term and post-termination or legal obligations. MetricMartian stores only customer/subscription identifiers and webhook state, removed with organization deletion where permitted.

Training: Not an AI model-training service in this use.

Configuration evidence: Checkout uses Stripe-hosted collection. Production remains configured with a test-mode publishable key; live payments and tax settings remain disabled pending founder approval.

Read the provider source

Resend

Status: Application and account controls verified

Purpose: Welcome, backfill-complete, and weekly Mission Brief email delivery.

Data: Recipient email address, first-name greeting, message subject/body, delivery metadata, and links to MetricMartian.

Location: Verified sending domain region: us-east-1 (North Virginia), with transfers described in the Resend DPA.

Retention: Resend says customer data is deleted within 90 days after account termination and production backups are retained for 30 days.

Training: Not an AI model-training service in this use.

Configuration evidence: Application payloads are verified and contain only recipient details and transactional template content. The verified metricmartian.com domain is in us-east-1, and dashboard open/click tracking is not configured.

Read the provider source

PostHog

Status: Application and account controls verified

Purpose: Pseudonymous activation-funnel analytics only.

Data: Fourteen allowlisted activation event names, six allowlisted low-risk properties, and SDK-added anonymous device/browser/session metadata.

Location: US cloud (Virginia).

Retention: The verified Pay-as-you-go plan retains data for seven years. Monthly free allowances still apply, but usage above them can be charged because product billing limits are not set; MetricMartian traffic therefore remains disabled until capped Free is verified.

Training: No PostHog AI feature is enabled for MetricMartian event data.

Configuration evidence: The isolated US project is verified and currently has no events. The organization is Pay-as-you-go with no billing limits set for Product Analytics or Session Replay. The application requires NEXT_PUBLIC_POSTHOG_ENABLED=true in addition to a project key, and that release flag stays denied until capped Free is verified; autocapture, pageview/pageleave capture, session recording, and identify remain disabled in application code.

Read the provider source

Sentry

Status: Application and account controls verified

Purpose: Error reporting and operational health alerts.

Data: Scrubbed exception messages, stack traces, route/runtime metadata, and a 5% performance trace sample; stable operational alert codes only.

Location: Verified organization storage region: United States of America (US).

Retention: The verified Developer/Free plan uses Sentry's published 30-day error-event retention.

Training: Sentry Seer is not enabled by MetricMartian application code.

Configuration evidence: Default PII is disabled and application scrubbing removes user context, request bodies/cookies, sensitive headers, extras, and breadcrumb data. The organization is on Developer/Free with no billing details or payment method on file.

Read the provider source

Vercel

Status: Application and account controls verified

Purpose: Web hosting, builds, server execution, TLS, and runtime logs.

Data: Application source/build artifacts, encrypted environment variables, requests, runtime output, deployment metadata, and platform logs.

Location: Vercel global platform; no application function region is pinned in repository configuration.

Retention: Verified project policy: runtime logs 1 day; Canceled 30 days; Errored 90 days; Pre-Production 180 days; Production 1 year. Vercel keeps protected recent/aliased deployments under documented exceptions and offers a recovery window after policy deletion.

Training: Team-level Data Preferences are disabled, and the project confirms that Vercel will not share code and chat data going forward for model-provider training.

Configuration evidence: The isolated MetricMartian project is verified on the team's Pro plan. Data Preferences disabled is inherited from the team, so Vercel does not share project code/chat data for model training going forward.

Read the provider source

This is a working register, not a final approved legal notice.

Return homeRead privacy draft