Skip to main content
Metomorph

Privacy Policy

How Metomorph collects, uses, discloses, and protects information across our website and AI services.

Effective date: August 6, 2026

This Privacy Policy explains how Metomorph ("Metomorph," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit metomorph.com, use the Metomorph AI workplace at chat.metomorph.com, use our applications, APIs, integrations, support channels, or professional services, or otherwise interact with us (collectively, the "Services").

If your organization has a separate master services agreement, order form, data processing addendum, business associate agreement, or similar written agreement with us, that agreement may contain additional or different privacy and security terms and will control to the extent of a conflict.

1. Our roles

For account, billing, website, sales, and direct relationship information, Metomorph generally acts as the business or controller that determines why and how personal information is processed.

For prompts, files, records, messages, integration data, and other information submitted to a workspace by or for a business customer ("Customer Content"), Metomorph generally acts as a service provider or processor on the customer’s documented instructions. The customer controls its workspace, determines what its users may submit, and is responsible for providing required notices and obtaining required permissions. If you use the Services through your employer or another organization, direct requests about Customer Content to that organization first.

2. Information we collect

Information you provide directly

  • Account and profile information: name, business email, telephone number, organization, job title, login credentials, preferences, and workspace membership.
  • Commercial and billing information: plan, transaction, invoice, subscription, and billing contact information. Payment providers may process payment-card or bank information under their own privacy notices; we generally receive billing status and transaction metadata rather than complete payment credentials.
  • Communications: contact forms, support requests, discovery-call information, survey responses, feedback, and correspondence.
  • Customer Content: prompts, instructions, conversations, model inputs and outputs, uploaded documents, images, audio, structured data, project materials, workflow configurations, and other material submitted to or generated through the Services.
  • Integration data: information a customer authorizes us to retrieve from connected systems such as document repositories, email, messaging, CRM, project-management, and other business tools, subject to the customer’s permissions and the connected provider’s terms.

Information collected automatically

  • Device and usage information: IP address, browser and device type, operating system, referring pages, pages viewed, timestamps, feature interactions, diagnostic events, approximate location derived from IP address, and similar technical data.
  • Security and audit information: authentication events, access logs, administrative actions, model and workflow activity, permissions, and records used to detect abuse, investigate incidents, and support customer audit requirements.
  • Cookies and similar technologies: information necessary to maintain sessions, remember preferences, secure the Services, and understand performance. Where required, we will request consent before using non-essential technologies.

Information from other sources

We may receive information from your organization, authorized administrators, connected services, referral partners, public business sources, fraud-prevention providers, and vendors that help us operate the Services.

3. Sensitive and regulated information

Do not submit sensitive personal information, protected health information, payment-card data, government identifiers, biometric identifiers, precise geolocation, children’s data, or other regulated information unless you are authorized to do so and your organization has confirmed that its Metomorph account is configured and contractually approved for that data. A customer that submits regulated information is responsible for having a lawful basis, providing required notices, obtaining required consents, and entering any required agreement with us.

4. How we use information

We use personal information to:

  • provide, operate, authenticate, maintain, support, and improve the Services;
  • process prompts and Customer Content, retrieve authorized context, generate outputs, and run customer-configured models, skills, agents, and workflows;
  • administer workspaces, permissions, subscriptions, invoices, and customer relationships;
  • respond to requests, provide support, and communicate about service, security, and policy updates;
  • monitor performance, troubleshoot errors, maintain audit logs, and protect the confidentiality, integrity, availability, and safety of the Services;
  • detect, investigate, and prevent fraud, abuse, security incidents, unlawful activity, and violations of our agreements;
  • develop and improve features using telemetry, feedback, and aggregated or deidentified information;
  • market our Services where permitted by law and honor communication preferences;
  • comply with law, enforce agreements, exercise or defend legal claims, and protect rights and safety; and
  • carry out another purpose disclosed when information is collected or with your direction or consent.

5. AI processing and model providers

The Services use artificial intelligence and may route Customer Content to models or infrastructure selected by Metomorph or the customer. Metomorph and its contracted model and infrastructure providers process Customer Content only as needed to provide, secure, support, and maintain the Services and as otherwise directed by the customer.

Metomorph does not use Customer Content to train generalized or shared AI models, and requires contracted providers not to use Customer Content for that purpose, unless the customer expressly enables an optional feature or separately authorizes that use in writing. We may use aggregated or deidentified information that cannot reasonably identify a person or customer to understand usage and improve the Services, and we will not attempt to reidentify it except to test whether deidentification is effective.

AI outputs may contain personal information present in Customer Content or inferred from the context supplied. Customers control who can access their workspaces and are responsible for reviewing outputs before using or sharing them.

6. How we disclose information

We may disclose information to:

  • service providers and subprocessors that provide cloud hosting, storage, AI model inference, authentication, security, monitoring, communications, support, billing, analytics, and professional services under contractual restrictions;
  • customer administrators and authorized users according to workspace settings, roles, permissions, and audit features;
  • connected services when a customer enables an integration or directs data to be exchanged with that service;
  • professional advisers such as attorneys, accountants, auditors, and insurers where reasonably necessary;
  • government authorities or other parties when we reasonably believe disclosure is required by law, valid legal process, or necessary to protect rights, safety, and security; and
  • transaction parties in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar corporate transaction, subject to appropriate confidentiality protections.

We may disclose information at your direction, with your consent, or as otherwise described when information is collected.

7. Sale, sharing, and targeted advertising

As of the effective date of this Policy, Metomorph does not sell personal information for money and does not share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. We also do not use Customer Content for targeted advertising. If these practices change, we will update this Policy and provide any legally required notice and opt-out mechanism.

8. Cookies and communications choices

You can control cookies through your browser settings. Blocking necessary cookies may prevent parts of the Services from working. You can opt out of marketing email using the unsubscribe link in the message. We may still send transactional, account, security, and legal notices. Where applicable, we honor legally recognized browser-based opt-out signals for processing that is subject to such a choice.

9. Data retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, follow customer instructions, maintain security and audit records, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information, workspace settings, contract terms, legal requirements, and backup cycles.

When an account is closed or a customer requests deletion, we delete or deidentify Customer Content in accordance with the applicable agreement and our standard deletion process, except where retention is required by law or necessary for security, fraud prevention, or legal claims. Residual copies may remain in encrypted backups until overwritten through normal cycles and will remain protected and unavailable for ordinary use.

10. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, tenant separation, logging, encryption where appropriate, vendor review, and incident-response procedures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Customers are responsible for maintaining appropriate endpoint security, safeguarding credentials, configuring permissions, reviewing connected systems, and promptly notifying us of suspected unauthorized access.

11. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; obtain information about collection, use, and disclosure; opt out of certain sale, sharing, targeted advertising, or profiling; limit certain uses of sensitive information; withdraw consent; and receive equal service without unlawful discrimination for exercising a privacy right.

To submit a request, email hello@metomorph.com with the subject “Privacy Request” and describe the request and your relationship with Metomorph. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity. If we deny a request, you may appeal by replying with the subject “Privacy Appeal.” You may also contact the regulator or attorney general with authority in your jurisdiction.

If your request concerns Customer Content in an organization-controlled workspace, contact that organization. We will assist the customer as required by our agreement and applicable law.

12. California and other U.S. state disclosures

For residents of states with comprehensive privacy laws, the categories of personal information we may have collected during the preceding twelve months are: identifiers and contact information; customer records and commercial information; internet, device, and usage activity; approximate geolocation; professional or employment information; account credentials and other sensitive information supplied by a customer; inferences; communications; and Customer Content that may fall within another statutory category depending on what a user submits.

We collect these categories from the sources described in Section 2, use them for the purposes in Sections 4 and 5, and disclose them to the categories of recipients in Section 6. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. We do not offer financial incentives in exchange for personal information. Rights and disclosures apply only when the relevant law applies to Metomorph and the information is not exempt.

13. Children

The Services are designed for businesses and are not directed to children under 18. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information in violation of this Policy, contact us so we can investigate and take appropriate action.

14. International users

Metomorph is based in the United States. If information is transferred from another country, we use safeguards required by applicable law. Local law may provide additional rights. Contact us if you need information about a transfer mechanism or a data processing addendum.

15. Third-party services and links

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own terms and policies. A customer administrator’s decision to enable an integration authorizes the exchange of information described during setup. Metomorph is not responsible for a third party’s independent privacy practices.

16. Changes to this Policy

We may update this Policy to reflect changes in the Services, law, or our practices. We will post the revised version with a new effective date and provide additional notice when required. Material changes will not retroactively reduce protections for Customer Content without appropriate notice or agreement.

17. Contact us

Questions, requests, or complaints may be sent to hello@metomorph.com or to Metomorph, Boise, Idaho, United States.