HeyMetra

Data Protection & Deletion

Last updated: August 5, 2026

This page explains, in concrete terms, what HeyMetra holds on your behalf, how it is protected, and how you get rid of it. It sits alongside our Privacy Policy, which covers the legal basis for that processing, and our Security page, which covers how the service itself is built.

What we store — and what we deliberately do not

HeyMetra answers questions about accounts you already own. That shapes everything below: the useful data lives in Google Ads, GA4, Shopify, Stripe and the rest, and our job is to read it when you ask a question, not to keep a second copy of it.

We do not build a copy of your business data

When you ask a question, we call the connected tool at that moment and use the answer to reply. The result is held briefly so that follow-up questions in the same session do not re-query the same numbers, and it expires within hours. There is no data warehouse, no nightly sync, no long-term store of your campaigns, orders, customers or revenue on our side. Stop using HeyMetra and there is no accumulated archive of your business left behind.

Files you upload are temporary

A spreadsheet or document you attach to a chat is held only long enough to be read and answered — one hour — and is then discarded automatically. We do not keep uploaded files.

What we do keep

  • Your account and workspace: name, email, workspace membership and role, billing status.
  • Your chats: the questions you asked and the answers given, so a conversation can be reopened.
  • Reports you save: the report and the figures it was built from, so a saved report still opens months later.
  • Automations: scheduled reports and where they are delivered.
  • An action record: when HeyMetra changes something in a connected tool — pausing a campaign, adjusting a budget — we record who approved it and what was changed. This is a safety record and it is deliberately hard to alter.

Your connected accounts

Connecting a tool is the part people are rightly cautious about, so it is worth being precise.

  • Credentials never sit in our application database. They are held in a separate, encrypted credential store. The application works with a reference to a connection, not with your key.
  • We ask for the narrowest access that answers your questions. Read access is the default. Where a connector can also make changes, that permission is a switch you control per connection, and it is off unless you turn it on.
  • Changes need your explicit approval. HeyMetra proposes an action, shows you exactly what it would do, and does nothing until you approve it in the app. Approvals expire, and there are hard ceilings in code on how large a change can be and how many can run in a day.
  • Disconnecting revokes access immediately. The moment you disconnect, the stored credential is destroyed at the credential store and the connection stops working. It is not archived "just in case".
  • Workspaces are isolated. Every query is scoped to the workspace it came from. One customer's connections are not reachable from another's.

You can also revoke HeyMetra's access from the provider's own side at any time — in your Google, Meta or Shopify account settings — without involving us at all. We would rather you had that option than take our word for it.

How it is protected

  • Everything travels over encrypted connections (TLS).
  • Credentials are stored separately from application data and encrypted, as described above. They are never displayed back to you and never written to logs.
  • Access to production systems is limited to the people who operate the service.
  • Our infrastructure runs in the European Union (Helsinki, Finland).
  • Error reports go to infrastructure we run ourselves rather than to a third-party monitoring service, so a crash cannot carry your data somewhere we do not control.

What you can delete yourself, right now

These do not require asking us. They are buttons in the product:

  • A chat — removed from your workspace along with its messages.
  • A saved report — deleted outright, with its figures.
  • A scheduled report — cancelled and removed.
  • A connection — disconnecting destroys the stored credential immediately.
  • A team member or a pending invitation — removed from the workspace, ending their access.

Records we are required to keep for accounting purposes — invoices, for example — survive this, because tax law says they must. The action record described above is also retained; it exists precisely so that "who changed this campaign" has an answer.

Deleting your account and everything in it

To have your whole account removed, email [email protected] from the address on the account, with "Data deletion" in the subject line. If you cannot use that address, tell us the workspace name and we will verify ownership another way before doing anything.

What happens next:

  1. We confirm your request within 3 business days.
  2. Every connection on the workspace is disconnected, which destroys the stored credentials at once. This is the part that matters most, and it happens first.
  3. Your chats, reports, schedules, uploaded content and workspace records are erased from our live databases within 30 days.
  4. Encrypted backups roll off on their own schedule and are fully cycled within 90 days. Backups are never used to restore deleted accounts.
  5. We write back to confirm when it is done.

Deletion is deletion. Marking something as removed and quietly keeping it is not what happens here — the records are taken out of the database.

Two things we cannot delete, and would be misleading not to name: statutory financial records, which we must retain for the period the law sets, and data inside your own connected tools. HeyMetra reads Google Ads or Shopify; it does not own what is in them. Deleting your HeyMetra account has no effect on those accounts, which is what you would want.

Your rights

Under GDPR and Türkiye's KVKK you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, or object to how it is processed. The same address handles all of these: [email protected]. We answer within 30 days. If you are not satisfied, you can complain to your local supervisory authority — in Türkiye, the Personal Data Protection Authority (KVKK).

Contact

Zeisoft Yazılım Limited Şirketi
Email: [email protected]

Join the waitlist

We’re onboarding teams gradually — leave your email and we’ll let you know the moment your connectors are ready.