Privacy Policy

Effective date: 22 June 2026

Last updated: 15 September 2026

This policy explains what Metano, Inc. (“Metano,” “we,” “us”) collects when you use our services, why we collect it, who we share it with, and the rights you have over your data. It covers our website at metano.ai, our APIs, and any product or feature we operate under the Metano name (together, the “Service”).

We are a Delaware C-Corporation. For any privacy question, write to legal@metano.ai.

1. Who this policy applies to

This policy applies to:

  • Visitors to our website.
  • Customers and authorized users of the Service.
  • People who contact us, apply for jobs, or otherwise share information with us.

If you use the Service on behalf of an organization, that organization is the controller of the data it submits to the Service; we process that data on its behalf under our customer agreement. This policy describes what we do as a controller of our own data.

2. Information we collect

We collect three categories of information.

Account information. Your name, email address, and the credentials you use to sign in. If your organization signs you up, your employer provides this.

Machine, agent, and endpoint information. Technical data we need to run the Service and keep it secure. Where your organization deploys the Metano Endpoint Sensor or another Metano collector, this includes:

  • Endpoint and environment inventory: machine, VM, container, pod, and hypervisor identifiers and configuration; operating system and version; MDM enrolment state; installed software inventory.
  • AI asset inventory: AI agents, MCP servers, plugins, tools, skills, packages, dependencies, models, and model versions in use, their provenance, and the AI bill of materials derived from them.
  • Agent runtime telemetry: agent sessions and their lifecycle; prompts, tool calls, function calls, and outputs passing through monitored agents; LLM and gateway requests including model, endpoint, and token counts; MCP calls; plugin and skill invocations; native and shell command execution.
  • Process and file activity: process creation and lineage; filesystem activity relevant to agent behaviour, including access to credential stores and configuration files; package installation events.
  • Network and transfer metadata: destinations contacted by monitored agents, per-user bandwidth volumes, and file counts and sizes transferred.
  • Browser and SaaS AI activity: use of browser-based and SaaS AI tools on monitored endpoints, including whether that use routes through an approved gateway.
  • Identity data: the human and non-human identities associated with agent activity, and attributes enriched from your identity provider such as user, group, role, and department.
  • Detection and enforcement records: alerts, severity and risk scores, policy and guardrail evaluations, blocking and kill-switch actions, and supporting evidence.
  • Standard request data: IP address, user-agent, timestamps, and error logs.

Some of this data can include the content of prompts, outputs, files, and commands.

Communications. Anything you send us by email or through support channels.

We do not knowingly collect special-category data (health, biometric, political, religious, etc.) and we ask you not to send it to us.

2A. Endpoint monitoring and your employer

The Metano Endpoint Sensor is deployed by an organization onto machines and environments it owns or controls. That organization, not Metano, decides which endpoints, users, environments, and workloads are monitored, and configures what is collected.

Where you use Metano through an employer or team, that organization is the controller of this data and Metano processes it on their instructions. The organization is responsible for giving its workforce the notices, and obtaining the consents and approvals, that local employment and privacy law requires. If you want to know what is monitored on your machine, ask your organization’s administrator.

What the Sensor does not do. It is not a general-purpose employee surveillance tool. It does not perform keystroke logging, screen recording, webcam or microphone capture, or collection of personal communications unrelated to monitored AI activity.

3. How we use it

We use the information above to:

  • Provide, operate, and improve the Service.
  • Authenticate users and prevent abuse, fraud, and security incidents.
  • Debug, monitor, and measure performance.
  • Communicate with you about your account, billing, security, and product changes.
  • Comply with legal obligations.

We do not sell your personal data. We do not use customer content, including agent prompts, outputs, and endpoint telemetry, to train, fine-tune, or develop machine-learning or AI models, and we do not send it to third-party foundation-model providers for training. We may derive aggregated, de-identified statistics that cannot reasonably be associated with any organization or individual.

4. Legal bases (EU/UK users)

Where the GDPR or UK GDPR applies, we rely on:

  • Contract, to deliver the Service you or your organization signed up for.
  • Legitimate interests, to secure the Service, prevent fraud, and improve the product, balanced against your rights.
  • Consent, for optional cookies and marketing emails, where consent is required.
  • Legal obligation, when a law requires us to keep or disclose information.

5. Who we share it with

We share personal data only with:

Sub-processors. We host the Service on Google Cloud Platform and may use a small number of additional vendors for functions such as authentication, email, payments, analytics, and AI model inference. Every sub-processor is bound by a written data-processing agreement. A current list is available on request to legal@metano.ai.

Your organization. If you use Metano through an employer or team, an administrator from that organization can see your account and activity within their tenant.

Authorities or successors. When required by law, valid legal process, or in connection with a merger, acquisition, or sale of assets, in which case we will tell affected users.

We do not share personal data for cross-context behavioral advertising.

6. International transfers

Metano is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US and in other countries where our sub-processors operate. For transfers out of the EU, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable).

7. Retention

We keep personal data for as long as your account is active and for a reasonable period after to meet legal, accounting, or security needs.

Logs and telemetry from the Platform and Endpoint Sensor are typically kept for up to 12 months. Operational logs for our public Labs services, including Skill Tracer, are kept for 90 days. Public submissions to Labs services are retained indefinitely as part of the public corpus.

When you delete your account or your organization terminates its contract, we delete or anonymize personal data within 90 days, except where law requires us to retain it.

8. Security

We use access controls, encryption in transit, encryption at rest for production stores, and standard application-security practices. No system is perfectly secure; we encourage you to use a strong password and to report any suspected vulnerability to legal@metano.ai.

9. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete data, subject to legal exceptions.
  • Object to or restrict certain processing.
  • Port your data to another service.
  • Withdraw consent where we relied on it.
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email legal@metano.ai. We will verify your identity before acting on a request and respond within the time required by applicable law (generally 30 days under GDPR, 45 days under CCPA).

California residents (CCPA/CPRA)

In the past 12 months we have collected the categories of personal information listed in Section 2: identifiers, internet/network activity, and content you provide. We collect this for the business purposes described in Section 3. We have not sold or shared personal information for cross-context behavioral advertising. You have the right to know, to delete, to correct, and to limit the use of sensitive personal information; we treat all California requests as such requests by default. We do not discriminate against users who exercise these rights.

EU / UK residents (GDPR / UK GDPR)

The controller of your personal data is Metano, Inc. Our legal bases are listed in Section 4. You have the rights listed above and can complain to your supervisory authority, for the UK, the ICO.

India residents (DPDP Act)

You can access, correct, and erase your personal data, and nominate someone to exercise these rights on your behalf in the event of death or incapacity. Contact us at legal@metano.ai to do so or to raise a grievance.

10. Cookies and tracking

We use cookies and similar technologies to keep you signed in, remember your preferences, and measure how the Service is used. Where required, we will ask for consent through a banner before setting non-essential cookies. You can disable cookies in your browser, but parts of the Service may not work without them.

We do not respond to Do Not Track signals; we treat the Global Privacy Control signal as a valid opt-out where applicable.

11. Children

The Service is not directed to anyone under 18 and is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to legal@metano.ai and we will delete it.

12. Changes to this policy

If we make a material change, we will notify you by email or through the Service before the change takes effect. Smaller updates will be reflected by changing the “Last updated” date above.

13. Contact

Metano, Inc. 1051 Craig Dr, San Jose, CA 95129, USA

Data Protection Officer, Grievance Officer, and Chief Information Security Officer: Varun Anand.

Email: legal@metano.ai