Privacy Policy
Last updated: 16 September 2026
Please review before relying on this. This policy describes how the Metorite service actually behaves, but the operator of this service must confirm the company details, the contact address and the retention periods below are correct for their business, and should take legal advice before treating it as final.
Metorite is a company operating system provided as software as a service. This policy explains what personal data we collect, why we collect it, who we share it with, and what rights you have. It applies to metorite.com, app.metorite.com and the Metorite application.
1. Who we are
Metorite is operated by Hathi Labs ("we", "us"). We are the data controller for account and billing data. For the content our customers put into the product, the customer organisation is the controller and we act as a processor on their instructions.
Questions about this policy: privacy@metorite.com.
2. What we collect
Account and sign-in data
- Your email address, and your display name if your sign-in provider supplies one.
- A one-time sign-in code, or an authentication token from Google if you sign in with Google. We never receive or store your Google password.
- Records of sign-in events, used for security and support.
Organisation and billing data
- Your organisation name and its short identifier.
- Your registered state and, if you supply one, your GSTIN, both used for tax purposes.
- The number of seats you ask for, the seats assigned to you, your plan, and your subscription status.
- Usage counts for billing, including AI usage recorded against your organisation.
Content you put into the product
Metorite stores the work you do in it. Depending on which parts you use, that can include tasks and projects, notes, calendar entries, meeting records and transcripts, customer records, and messages and attachments from accounts you choose to connect. We do not inspect this content except as needed to run, support and secure the service.
What we do not collect
- We do not use advertising trackers, and this marketing site sets no cookies and runs no scripts.
- We do not sell personal data, and we never have.
- We do not collect special category data on purpose. Please do not put it into free text fields.
3. Why we use it, and on what basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Give you an account and let you sign in | Email, name, sign-in records | Performance of a contract |
| Run the product for your organisation | Content you enter or connect | Performance of a contract |
| Bill you and meet tax obligations | Organisation, seats, GSTIN, usage | Contract, and legal obligation |
| Keep the service secure and available | Sign-in records, technical logs | Legitimate interests |
| Answer your support requests | Whatever you send us | Legitimate interests |
4. Who we share it with
We share personal data only with the suppliers that run the service for us. Each one is bound by contract and may use the data only to provide their service to us.
| Supplier | What they handle |
|---|---|
| Supabase (on Amazon Web Services) | Database hosting |
| Hostinger | Application server hosting |
| Resend | Sending sign-in codes and product email |
| Sign in with Google, if you choose it | |
| AI model providers | Processing the prompts that AI features send |
We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is sold or merged, account data may transfer to the buyer, and we will tell you before that happens.
5. Where your data is held
Our databases and application servers are hosted in India. Some suppliers named above process data outside India. Where they do, transfers rely on the supplier's standard contractual protections.
6. How long we keep it
- Sign-in codes expire ten minutes after we issue them and are removed once used.
- Account and content data is kept while your organisation has an account with us.
- After cancellation, sign-in stays open for an export window so you can take your data out. After that window we delete the organisation and its content.
- Billing and tax records are kept for as long as tax law requires.
7. How we protect it
- Traffic to and from the service is encrypted with TLS.
- Each organisation's data is isolated at the database level, and that isolation is enforced by the database itself rather than only by application code.
- Access to production systems is limited to the people who need it.
- We do not store passwords for Metorite itself. Sign-in is by one-time code or by Google.
8. Your rights
Subject to local law, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also complain to your data protection authority.
If your data sits inside a customer organisation's workspace, send your request to that organisation first. We will help them answer it.
To make a request, write to privacy@metorite.com. We answer within one month.
9. Children
Metorite is a product for businesses. It is not meant for children, and we do not knowingly collect data from anyone under 16.
10. Changes
If we change this policy we will update the date at the top. If a change materially affects you, we will tell account administrators by email.