Metorite

Privacy Policy

Last updated: 16 September 2026

Please review before relying on this. This policy describes how the Metorite service actually behaves, but the operator of this service must confirm the company details, the contact address and the retention periods below are correct for their business, and should take legal advice before treating it as final.

Metorite is a company operating system provided as software as a service. This policy explains what personal data we collect, why we collect it, who we share it with, and what rights you have. It applies to metorite.com, app.metorite.com and the Metorite application.

1. Who we are

Metorite is operated by Hathi Labs ("we", "us"). We are the data controller for account and billing data. For the content our customers put into the product, the customer organisation is the controller and we act as a processor on their instructions.

Questions about this policy: privacy@metorite.com.

2. What we collect

Account and sign-in data

Organisation and billing data

Content you put into the product

Metorite stores the work you do in it. Depending on which parts you use, that can include tasks and projects, notes, calendar entries, meeting records and transcripts, customer records, and messages and attachments from accounts you choose to connect. We do not inspect this content except as needed to run, support and secure the service.

What we do not collect

3. Why we use it, and on what basis

PurposeDataLawful basis
Give you an account and let you sign inEmail, name, sign-in recordsPerformance of a contract
Run the product for your organisationContent you enter or connectPerformance of a contract
Bill you and meet tax obligationsOrganisation, seats, GSTIN, usageContract, and legal obligation
Keep the service secure and availableSign-in records, technical logsLegitimate interests
Answer your support requestsWhatever you send usLegitimate interests

4. Who we share it with

We share personal data only with the suppliers that run the service for us. Each one is bound by contract and may use the data only to provide their service to us.

SupplierWhat they handle
Supabase (on Amazon Web Services)Database hosting
HostingerApplication server hosting
ResendSending sign-in codes and product email
GoogleSign in with Google, if you choose it
AI model providersProcessing the prompts that AI features send

We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is sold or merged, account data may transfer to the buyer, and we will tell you before that happens.

5. Where your data is held

Our databases and application servers are hosted in India. Some suppliers named above process data outside India. Where they do, transfers rely on the supplier's standard contractual protections.

6. How long we keep it

7. How we protect it

8. Your rights

Subject to local law, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also complain to your data protection authority.

If your data sits inside a customer organisation's workspace, send your request to that organisation first. We will help them answer it.

To make a request, write to privacy@metorite.com. We answer within one month.

9. Children

Metorite is a product for businesses. It is not meant for children, and we do not knowingly collect data from anyone under 16.

10. Changes

If we change this policy we will update the date at the top. If a change materially affects you, we will tell account administrators by email.