Legal
Privacy Policy
Last updated: August 2, 2026
In short. This policy explains what personal information Maetra processes, why, how we protect it, and the rights and choices available to you. Questions? Contact [email protected].
1. Introduction and scope
Maetra ("Maetra", "we", "us", or "our") provides an AI governance platform available at maetra.io (the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the choices and rights available to you.
Maetra is generally used by organisations. Where your organisation administers a workspace, that organisation typically acts as the controller of the personal information processed within its workspace, and Maetra acts as its processor; the organisation's own privacy notice may also apply. This Policy does not cover third-party services you choose to connect to Maetra (such as source-code hosts or messaging platforms), which are governed by their own privacy policies.
2. Information we collect
Account and profile data. Your email address (your primary account identifier), name, optional job title, optional avatar, email-verification status, last-login timestamp, and account creation/deactivation timestamps.
Workspace and organisation data.Workspace name and slug, optional company name and size, optional logo, the workspace's data-residency region (see Section 6), onboarding status, team memberships and roles, fine-grained permissions, and workspace invitations (invited email, role, optional message, a hashed invitation token, and lifecycle timestamps).
Authentication data. A securely hashed session token (never stored in plain text), the client user-agent and the IP address captured at login, and session expiry; one-time verification codes (stored hashed) with their purpose, target email, attempt counter, and expiry; OAuth provider identifiers where you sign in or link a third-party account; and, where your organisation configures SAML SSO, the SSO domain, identity-provider entry point, issuer, and public certificate.
Integration and connected-source metadata. For integrations you authorise, the provider and connection status, the external account identifier, granted OAuth scopes, and OAuth access/refresh tokens (encrypted at rest, see Section 8). For connected repositories, repository metadata (identifier, full name, URL, monitored branch), pull-request settings, discovery results, and scan history.
AI agent and discovery data. Agent records (name, description, status, origin, optional owner name/email, team, platform, environment, autonomy and risk level, compliance status, and custom metadata); source references (repository, branch, commit SHA, file path and line numbers, and a content fingerprint used for deduplication); tool and data-access information; discovery scan records; and discovery evidence (evidence type, code location, a short excerpt and its hash, and a relevance score).
Governance, compliance, and security records. Approval requests (checkpoints) and decisions; agent classifications, compliance documents, gaps and deadlines, and control evidence; and runtime-security scans and incidents (incident type, severity, a preview of the analysed input — or, where you enable it, the full input for a configurable retention period — the rule applied, and review status).
Usage and audit logs. Workspace and platform audit logs (who did what, event type, entity, outcome, metadata, and a hash chain for tamper detection) and usage-metering events used for billing.
Billing and payment information. Subscription plan, interval and status, trial and period dates, seat allocations and overage settings, identifiers issued by our payments provider, entitlement snapshots, billing contact details, and checkout/webhook records used to keep subscription state in sync. We do not store full payment-card numbers; card data is handled directly by our payments provider.
Notifications and communications. In-app notifications and read receipts, channel-routing preferences where you connect a messaging platform, and transactional emails (verification, invitations, approval notifications, security alerts, and deadline reminders). Email addresses are masked in our internal logs.
Risk-map requests. If you request an AI Agent Action Risk Map, we process your work email, company or project, optional name and role, the workflow and consequential action you describe, optional context, limited campaign attribution, and any supporting files you choose to attach. The structured request is stored in our application database and attachments are stored in private cloud object storage. Access is limited to authorised Maetra reviewers. We use this information to prepare, review, and respond to your request; submitting the form does not subscribe you to marketing.
Note on source code and messages.Maetra does not persist your repository source code or messaging-platform message content in its database — for code, only metadata and fingerprints are stored. Content may be transmitted to AI model providers to perform analysis (see Section 5) but is not retained in Maetra's database.
Interaction Guard browser-extension data.When your organisation deploys Interaction Guard, the extension processes your work email, workspace and installation identifiers, the supported AI application in use, and the information needed to apply your organisation's active Guards. If a Guard covers an interaction, the prompt or supported file content may be processed to decide whether to allow, warn, require a business reason, or block before submission. Raw prompt retention follows the workspace's data handling settings; a workspace can choose to retain no prompt content. Decision records may include the matched Guard, response, application, timestamps, content length or hash, and sanitised findings.
Where an organisation enables AI-account verification, the extension may read the signed-in account address from a supported AI application's account surface. Maetra stores a one-way account fingerprint and the email domain used for categorisation, rather than the detected account email or password. Interaction Guard is scoped to the supported AI application domains disclosed in its browser-store listing; it does not collect general browsing history from unrelated websites.
3. How we use information
- Create and manage your account and workspace, and verify identity.
- Authenticate you, maintain sessions, and detect and prevent suspicious or unauthorised activity.
- Provide core features — discovering and inventorying agents, classifying and assessing risk, orchestrating approvals, tracking compliance obligations, and monitoring runtime security.
- Connect and operate the integrations you authorise.
- Send transactional and notification communications relevant to your account and governance activity.
- Process subscriptions, seats, usage-based billing, and payments through our payments provider.
- Maintain audit trails, enforce plan entitlements and role-based access, and operate, secure, and improve the Service.
- Prepare and respond to an AI Agent Action Risk Map you request.
4. Legal bases for processing
Where the EU/UK GDPR or similar laws apply, we rely on: performance of a contract (to provide the Service, manage accounts, authenticate users, operate integrations, and process billing); legitimate interests (to secure the Service, prevent abuse, maintain audit and usage logs, and improve the Service, where not overridden by your rights); consent (for example, when you connect an integration — withdrawable at any time); and compliance with a legal obligation.
5. Sharing and sub-processors
We share personal information only as needed to provide the Service. We do not sell personal information. Access by Maetra staff is limited to those who need it to operate, support, and secure the Service, subject to role-based access controls. We use the following categories of sub-processors and service providers:
- Polar (payments provider) — payment processing, subscription and seat management, checkout, and customer portal.
- Email delivery provider (configurable SMTP) — sending transactional emails, including verification codes, invitations, and notifications.
- Cloud storage provider (Amazon Web Services S3) — storing user avatars, generated documents, and private supporting files attached to risk-map requests.
- Cloud hosting provider — hosting the core application database (PostgreSQL) and optional cache; processes the application data described in this Policy.
- GitHub and GitLab (OAuth / app integrations) — authentication and repository access for AI-agent discovery, including webhooks.
- Slack (OAuth integration) — delivering alerts, approval notifications, and digests to your workspace channels.
- AI model providers (Anthropic Claude, and optionally OpenAI) — AI analysis for discovery, compliance, governance, and runtime-security scanning; they receive the content necessary to perform an analysis.
- Google Analytics — optional marketing-site analytics used to understand page and campaign performance when analytics storage is allowed. Advertising storage and personalisation are denied by default.
The specific email-delivery and hosting providers are configured per deployment. We may also disclose information where required by law, to protect rights or safety, or in connection with a corporate transaction, subject to appropriate safeguards.
6. Data residency
Each workspace is associated with a data-residency region — one of the United States (US), European Union (EU), United Kingdom (UK), or Canada (CA). Where personal information is transferred across regions in connection with the sub-processors above, we rely on appropriate safeguards where required by applicable law.
7. Data retention
We retain personal information for as long as your account and workspace remain active and as needed to provide the Service, and thereafter as required to meet legal, accounting, security, and audit obligations. Sessions and one-time codes are short-lived; where full-input storage is enabled for runtime security, analysed inputs are retained for a configurable period (30 days by default); audit logs are retained to support compliance and incident investigation. When information is no longer needed, we delete or de-identify it.
Risk-map request details and private attachments are retained while needed to prepare, review, and respond to the request and for related operational or legal needs. We delete or de-identify them when they are no longer needed.
8. Security
- Encryption in transit. Assets are served over HTTPS, and integration and webhook communications are protected with signed requests and signature verification (HMAC-SHA256 with constant-time comparison).
- Hashed passwords. Account passwords are hashed using scrypt with a random per-user salt and verified with timing-safe comparison.
- Hashed session tokens. Session tokens are strong random values stored only as SHA-256 hashes. Session cookies are set with
HttpOnly,SameSite=Lax, and (in production)Secureattributes. - Expiring one-time codes with attempt limits. Verification codes are hashed, expire after a short window, are throttled between resends, allow only a limited number of attempts, and can be used only once.
- Encrypted integration credentials. OAuth access and refresh tokens are encrypted at rest using authenticated encryption (AES-256-GCM).
- Role-based access control. Access to workspace features and data is governed by roles and fine-grained privileges, and deactivated accounts are denied access.
- Tamper-evident audit logs. Audit events are chained using cryptographic hashes to help detect tampering.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
Depending on your location and applicable law, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent where we rely on it. Because Maetra is typically used through an organisation's workspace, some requests may need to be directed to the organisation that administers your workspace. To exercise any of these rights, contact us using the details in Section 13; we may need to verify your identity first. You also have the right to lodge a complaint with your local data protection authority.
10. Cookies
The Service uses a small number of essential cookies required for it to function — in particular, a session cookie that keeps you signed in, set with HttpOnly, SameSite=Lax, and (in production) Secure attributes, storing only a reference to your session.
Analytics. The marketing site uses Google Analytics with analytics, advertising, ad-user-data, and ad-personalisation storage denied by default. Marketing events and first-touch campaign attribution are recorded only after you choose “Allow analytics.” You can choose “Keep off” and continue using the site normally.
11. Children
The Service is intended for use by organisations and their personnel and is not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided us with personal information, please contact us.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
13. Contact
Questions about this Privacy Policy, or requests to exercise your rights, can be sent to [email protected].