Privacy Policy
Last updated April 18, 2026
Metric Tower ("we", "us") builds tooling for security teams. We take a data-minimal approach: we collect only what we need to run the product you're paying for, and we tell you plainly what that is.
What we collect
- Account data: name, email, team affiliation, role, password hash (never the plaintext).
- Billing data: plan tier, credit balance, invoice history. Payment card details are held by Stripe, never by us.
- Scan data: targets you scan, findings the scanners produce, logs from your scan runs.
- Telemetry: first-party anonymised analytics (Plausible-compatible proxy, no cross-site tracking), application error reports (GlitchTip, self-hosted).
- Security records: failed login attempts, IP + ASN + country on login, browser fingerprint snapshot. Used to detect account abuse.
What we don't collect
- Third-party advertising cookies or trackers.
- Cross-site browsing history.
- Biometric or facial data.
- Contents of public free-tool queries beyond what's needed for rate-limit accounting.
Your rights
If you're in the EU/UK, GDPR grants you the right to access, rectify, erase, or export your data, and to object to processing. You can exercise these from your profile page when logged in, or by emailing [email protected].
Data retention
Account data is kept while your team exists. Scan findings are kept as long as they remain assigned to an active scan (you can delete a scan at any time). Activity logs are retained for the window set by your plan tier.
Contact
Data protection queries: [email protected]. We aim to respond within 10 working days.
This policy will be updated as the product evolves. Material changes are announced on the changelog and (if you're opted into product emails) notified in advance.