MetriqualMETRIQUAL

Privacy policy

Last updated: February 11, 2026

How we collect, use, disclose, and safeguard your information when you use the Metriqual AI gateway.

At a glance

Request logs kept
90 days, for analytics and billing. Billing records are kept 7 years for tax compliance.
Encryption
API keys and sensitive data are encrypted at rest with AES-256-GCM. Traffic uses TLS 1.3.
Your prompts
Forwarded to the AI provider you route to. We do not sell your data.
Your rights
Access, correct, delete, export, or withdraw consent by emailing privacy@metriqual.com.

1. Introduction

Metriqual is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your information when you use our AI gateway platform and services.

2. Information we collect

2.1 Information you provide

  • Account information (name, email address, password)
  • Organization details (company name, size, industry)
  • Payment information, processed securely through our payment providers
  • API keys and configuration data for AI providers
  • Support and communication data

2.2 Automatically collected information

  • API usage data (requests, responses, latency, costs)
  • Device and browser information
  • IP addresses and location data
  • Cookies and similar tracking technologies
  • Log data (timestamps, errors, performance metrics)

2.3 AI request data

  • Prompts and responses sent through our proxy
  • Model selection and configuration
  • Token usage and pricing data
  • Performance and analytics metrics

3. How we use your information

We use the collected information to:

  • Provide and maintain our AI gateway services
  • Process API requests and route them to AI providers
  • Generate analytics and usage reports
  • Bill for services and process payments
  • Detect and prevent fraud or abuse
  • Improve our products and develop new features
  • Send service updates and technical notices
  • Provide customer support
  • Comply with legal obligations

4. Data storage and security

Encryption. All API keys and sensitive data are encrypted at rest using AES-256-GCM. Data in transit is protected using TLS 1.3.

Storage. Your data is stored on secure servers provided by Supabase (PostgreSQL) and Cloudflare. API request logs are retained for 90 days for analytics purposes.

Access control. We implement strict access controls and regularly audit our security practices. Only authorized personnel have access to user data.

5. Data sharing and disclosure

We may share your information with:

5.1 Third-party services

  • AI providers: OpenAI, Anthropic, Google, Mistral and others receive your prompts and API requests
  • Authentication: Supabase, for account data and authentication
  • Payment processing: Razorpay, including international cards via PayPal
  • Email: SendGrid, for transactional email
  • Infrastructure: Cloudflare and Digital Ocean, for hosting and CDN

5.2 Legal requirements

We may disclose your information if required by law or court order, or to protect our rights, property, or safety.

6. Your privacy rights

Depending on your location, you may have the following rights:

  • Access: request a copy of your personal data
  • Correction: update or correct inaccurate information
  • Deletion: request deletion of your account and data
  • Data portability: export your data in a portable format
  • Opt out: unsubscribe from marketing communications
  • Withdraw consent: revoke consent for data processing

To exercise these rights, contact privacy@metriqual.com.

7. Cookies and tracking

We use cookies and similar technologies for:

  • Authentication and session management
  • Preference storage (theme, settings)
  • Analytics and performance monitoring
  • Security and fraud prevention

You can control cookies through your browser settings. Disabling them may affect functionality.

8. Data retention

  • Account data: retained until account deletion
  • API request logs: 90 days, for analytics and billing
  • Billing records: 7 years, for tax compliance
  • Support tickets: 2 years

9. International data transfers

Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place to protect it in accordance with this policy and applicable laws.

10. Children's privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information immediately.

11. Changes to this policy

We may update this policy from time to time. We will notify you of significant changes by email or through the platform. Continued use after changes constitutes acceptance of the updated policy.

12. Contact us

Questions about this policy or our data practices: