Privacy policy
Updated 2026-10-05.
This covers hosted Meter at metergateway.com. If Meter runs in your own infrastructure, whoever deployed it processes your data, not us.
Who is responsible
- Mykola Sotnichenko, Ukraine — the individual who builds and provides Meter.
- Write to support@metergateway.com about anything to do with your data, and to security@metergateway.com about vulnerabilities.
What we collect
- Your account: email, name, a password hash or a Google or GitHub sign-in id, your role on the team.
- Sessions: the IP address and browser you signed in from — to keep you signed in and spot suspicious sign-ins.
- Keys: your team’s Anthropic or Ollama key, encrypted; developers’ Meter keys, only as a hash.
- Agent calls: who on the team, when, model, tokens, cost, repository, security flags, and the file paths and shell commands from tool calls, with secrets masked. We don’t keep prompt or response text.
- The team’s audit log: who invited whom, changed a role, issued or revoked a key.
- Billing: your Paddle customer and subscription ids, and invoices. We never see card details — Paddle handles them.
- A sign-in attempt counter, keyed by a hash of the email, to limit password guessing.
Why
- To provide the service you signed up for: show spend and flags, apply your team’s policies, send confirmations, alerts and reports.
- To protect accounts and the service: limit sign-in attempts, notice abuse.
- To take payment through Paddle.
- To understand how visitors find and read the public pages — only with your consent.
- We don’t sell data, show ads, or train models on it.
Who else processes data
- Oracle Cloud — hosting, region eu-frankfurt-1 (Frankfurt, Germany).
- Resend — sending email, EU region (Ireland).
- Paddle — payments; Paddle is the merchant of record and processes payment data under its own policy.
- Anthropic or Ollama — your agents’ calls go to them with your team’s key, as you configured.
- Google or GitHub — if you sign in with them.
- ImprovMX and Google — forwarding and receiving mail sent to support@ and security@.
- Google Analytics — visit statistics for the public pages, only if you agreed in the banner.
Cookies
- A session cookie — to keep you signed in.
- A language cookie — to show the site in the language you chose.
- Google Analytics cookies — on the public pages only, and only after you click “Accept” in the banner. You can decline or change your choice with “Cookie settings” at the bottom of the page. There is no analytics in the dashboard.
- No advertising cookies. Paddle’s checkout on the billing page may set its own.
How long we keep it
- Call records — 13 months, then deleted automatically.
- The event queue holds them for up to 7 days until they reach storage.
- Your account and your team’s data — until you delete them.
- After a team is deleted, its events are purged again for 8 days, so nothing that was in transit is left.
Your rights and deletion
- You can get a copy of your data, correct it, object to or restrict its processing — write to support@.
- You can delete your account yourself: the Team page in the dashboard, the “Danger zone”. An owner deletes the whole team the same way.
- After your account is deleted your events stay in the team’s figures without your name or email. But file paths in them can contain your name (such as /Users/name/), Paddle keeps its customers under its own rules, and Google or GitHub sign-in tokens are deleted by us but not revoked with those services.
- You can complain to a data protection authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your country’s authority.
Other
- Meter is a product for development teams, not for children under 16.
- If this policy changes in substance, we will update the date at the top and email team owners.