HeyMetra

Data Protection & Deletion

Last updated: September 13, 2026

This page explains, in concrete terms, what HeyMetra holds on your behalf, how it is protected, and how you get rid of it. It sits alongside our Privacy Policy, which covers the legal basis for that processing, and our Security page, which covers what a tool call is allowed to do.

What we store — and what we deliberately do not

HeyMetra is a remote MCP server. Your AI assistant calls a tool, we run that call against an account you authorised, and we hand the result back to it. That shape is why the list below is short: the useful data lives in Google Ads, Search Console, Shopify, Stripe and the rest, and our job is to reach it when a tool is called, not to hold a second copy of it.

We do not build a copy of your business data

A tool call reads the connected account at that moment and returns the result. A short-lived cache means a repeated call within the same few minutes does not re-query the provider, and it expires within hours. There is no warehouse, no nightly sync, and no long-term store of your campaigns, orders, customers or revenue on our side. Stop using HeyMetra and there is no accumulated archive of your business left behind.

We do not hold what you asked

You address your own AI assistant; it decides to call a tool; we see the call and its arguments. What you typed, what the model reasoned, and what it told you never reach us — they are between you and its operator.

What we do keep

  • Your account and workspace: name, email, workspace membership and role, billing status.
  • Your connections: which accounts you authorised, the scopes granted, and a reference to the credential. The credential itself lives in a separate encrypted store.
  • A tool call record: which tool ran, in which workspace, against which connection, when, and whether it succeeded. Where a call changed something in a connected account, what it changed. This is a safety record — it is what makes "who changed this campaign" answerable, and it is what the daily change limit is counted from. It is deliberately hard to alter.

Your connected accounts

Connecting an account is the part people are rightly cautious about, so it is worth being precise.

  • Credentials never sit in our application database. They are held in a separate, encrypted credential store. The application works with a reference to a connection, not with your key.
  • We ask for the narrowest access the provider offers. Most accounts you can connect are read-only: no tool exists that could write to them. Where a connector does carry tools that change something — an ad platform, the one delivery destination you linked, the approval queue itself — those tools are named on that connector's own page, and on an ad account they are switches that stay off unless you turn them on. Where a provider has no read-only grant to give (Google Ads is one), the limit is the tool list and the approval step rather than the scope, which is why both are published.
  • Changes are bounded before they run. There are ceilings in code on how far one change can move a budget, how many campaigns it can touch, and how many changes a workspace can make in a day. A call that would exceed one is refused, not queued.
  • Disconnecting revokes access immediately. The moment you disconnect, the stored credential is destroyed at the credential store and the connection stops working. It is not archived "just in case".
  • Workspaces are isolated. Every tool call is scoped to the workspace it came from. One customer's connections are not reachable from another's.

You can also revoke HeyMetra's access from the provider's own side at any time — in your Google, Meta or Shopify account settings — without involving us at all. We would rather you had that option than take our word for it.

How it is protected

  • Everything travels over encrypted connections (TLS).
  • Credentials are stored separately from application data and encrypted, as described above. They are never displayed back to you and never written to logs.
  • Access to production systems is limited to the people who operate the service.
  • Our infrastructure runs in the European Union (Helsinki, Finland).
  • Error reports go to infrastructure we run ourselves rather than to a third-party monitoring service, so a crash cannot carry your data somewhere we do not control.

What you can delete yourself, right now

These do not require asking us. They are buttons in the product:

  • A connection — disconnecting destroys the stored credential immediately and the tools over that account stop working.
  • A team member or a pending invitation — removed from the workspace, ending their access.

Records we are required to keep for accounting purposes — invoices, for example — survive this, because tax law says they must. The tool call record described above is also retained; it exists precisely so that "who changed this campaign" has an answer.

Deleting your account and everything in it

To have your whole account removed, email hello@heymetra.com from the address on the account, with "Data deletion" in the subject line. If you cannot use that address, tell us the workspace name and we will verify ownership another way before doing anything.

What happens next:

  1. We confirm your request within 3 business days.
  2. Every connection on the workspace is disconnected, which destroys the stored credentials at once. This is the part that matters most, and it happens first.
  3. Your workspace records, connection records and tool call history are erased from our live databases within 30 days.
  4. Encrypted backups roll off on their own schedule and are fully cycled within 90 days. Backups are never used to restore deleted accounts.
  5. We write back to confirm when it is done.

Deletion is deletion. Marking something as removed and quietly keeping it is not what happens here — the records are taken out of the database.

Three things we cannot delete, and would be misleading not to name. Statutory financial records, which we must retain for the period the law sets. Data inside your own connected accounts — HeyMetra reads Google Ads or Shopify, it does not own what is in them, and deleting your HeyMetra account has no effect on those accounts, which is what you would want. And anything your AI assistant retained from a tool result: that sits with its operator under your agreement with them, and a deletion request to us cannot reach it.

Your rights

Under GDPR and Türkiye's KVKK you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, or object to how it is processed. The same address handles all of these: hello@heymetra.com. We answer within 30 days. If you are not satisfied, you can complain to your local supervisory authority — in Türkiye, the Personal Data Protection Authority.

Contact

Zeisoft Yazılım Limited Şirketi
Email: hello@heymetra.com