What data we store
Every category of information Metric Vault holds, why it is held, where it lives, and what is deliberately never stored on our systems.
Last updated 2026-08-06
Summary#
This page lists every category of information Metric Vault holds about you and your work, what each one is for, and where it lives. It is written to be complete enough to answer a security questionnaire or a data-mapping exercise without having to ask us. If a category is not on this page, we do not hold it.
For how long each of these is kept, and what happens when you close an account, see Data retention and deletion. For the outside services involved, see Subprocessors and data flow.
Overview#
Everything falls into six groups.
Who you are is the small amount of account information needed to sign you in and bill you. What you asked us to analyze is the domains, keywords, brands and URLs you submit. What we produced is the results, reports and history those analyses generated. How you have set things up is your preferences, your team and your connected integrations. What you have used is the credit and usage counters that make your plan work. How the platform is running is operational information such as error records and aggregate performance figures.
Two boundaries run through all of it.
Your analyses and reports are visible to you and to the people you have invited into your workspace. They are not shown to other customers, and they are not used to train AI models.
Card numbers are never stored, processed or transmitted by Metric Vault. Payment details live with Stripe.
Account and identity#
| What | Why it is held | Where it lives |
|---|---|---|
| Email address | It is your account identifier and the address alerts and invoices go to | The managed authentication service, and our application database as the owner of your work |
| Display name | Shown in the interface and on team invitations | The managed authentication service |
| Password | Sign-in. Stored as an encrypted hash by the authentication service, never in readable form, and never visible to anyone at Metric Vault | The managed authentication service |
| Sign-in method | Whether the account uses email and password, Google, or both | The managed authentication service |
| Email confirmation status | An address that has not been confirmed is never treated as an account | The managed authentication service |
| Account creation date | Shown as Member since on the Account screen | The managed authentication service |
There is no field for a postal address, a phone number or a job title. If you send one to support in a message, that message is retained as correspondence.
Billing#
| What | Why it is held | Where it lives |
|---|---|---|
| Your plan and when it was set | Every entitlement check in the product reads it | Our application database |
| Subscription state, billing cycle and renewal date | Shown in the Subscription card and used to keep your plan accurate | Stripe, read back into the product |
| Invoices and transaction records | Tax, accounting and your own records | Stripe |
| Billing country and a tokenised payment method | Fraud prevention and taking payment | Stripe |
| Card number, expiry and security code | Not held. These are entered on Stripe's pages and never reach us | Stripe only |
See Invoices and receipts for retrieving invoices, and Managing billing in the customer portal for the Stripe billing portal.
What you submit for analysis#
| What | Why it is held |
|---|---|
| Domains, URLs, keywords and brand names you enter into a tool | They are the input to the analysis, and they are stored with the saved result so you can reopen it |
| Competitor domains you compare against | Same |
| Pages you add to the competitor monitor | The monitor has to know what to check |
| Keywords you add to rank alerts and position tracking | The tracker has to know what to watch |
| Content you paste into the writing and optimization tools | It is the input to the analysis. Drafts you have not saved stay in your browser |
| Content you write in the blog studio, including uploaded images | It is your content, held so the blog can publish it |
What the platform produces for you#
| What | Why it is held |
|---|---|
| Saved tool results, including the rendered report | So the Library can reopen a run without spending credits again. See Saved Work |
| Activity log | A record of runs and workspace events. Not shown to customers; support and the admin Run Log read it |
| Captured snapshots of monitored pages, and the changes detected between them | The monitor compares each check against the previous one, so it has to keep the previous one |
| Rank alert history | The position chart over time |
| Scheduled report definitions and a record of each run | So a schedule keeps firing and you can see whether it delivered |
| Shared report pages | A share link serves a stored copy of the report so it can be opened without signing in. See Sharing a result by link |
| AI visibility tracking history for brands you track | The trend lines in the AI visibility tools |
| Responsiveness analyses you have saved | So you can reopen them |
Settings, team and integrations#
| What | Why it is held |
|---|---|
| Notification preferences | Which emails and alerts you want. See Notification preferences |
| White-label branding: company name, logo, colors and custom footer | Applied to your exports and share pages. See White-label reports |
| Team memberships and pending invitations | Who is in your workspace and who has been invited but not accepted |
| Connected Google account, the access it granted, and cached Search Console figures | So the integration keeps working without asking you to reconnect on every page load. Disconnecting removes the connection and the cached figures. See Google Search Console |
| Connected social accounts and the access each granted | So scheduled posts and social analytics can run. Disconnecting removes the connection. See Connecting social accounts |
| Blog sites you created and their media | Your published content and its images |
Interface preferences such as theme, language, filters, date ranges, recently viewed items, tour progress and unsaved drafts are stored in your browser, not on our servers. Clearing your browser storage resets them and loses nothing that is on the server.
Usage and metering#
| What | Why it is held |
|---|---|
| Credits used this month, split into tool runs and AI runs | Enforcing your plan's allowance and drawing the usage meter |
| Credits used per tool this month | The breakdown in the usage popover |
| An hourly call counter | The fair-use limit that keeps automated abuse off the light tools |
| Recommendation usage this month | The separate allowance for Get Recommendations |
See Tracking your usage and How credits work.
Operational information#
| What | Why it is held |
|---|---|
| Technical information collected automatically: IP address and approximate city-level location, browser and device type, pages and features used, referring URL, session timestamps | Understanding how the platform is used, diagnosing faults, and security monitoring. It is not used to build advertising profiles and is not sold |
| Error records | Grouped by the shape of the error, so a recurring fault can be found and fixed. Messages are normalised before storage: URLs, email addresses, identifiers and numbers are replaced with placeholders |
| Aggregate performance figures | Counted per tool per hour across the whole platform, not per person |
| A record of administrative changes made to an account | If a plan is changed, usage reset or an account suspended by our team, the actor, the action, the target and the time are recorded |
| Support messages and bug reports you send | Answering you, and fixing what you reported |
Caches#
Metric Vault keeps a shared cache of provider data in front of the paid search-data providers, so that a repeat lookup of the same domain or keyword does not re-bill the provider. This is the one store that is not scoped to an account, so it is worth being exact about what it contains.
| Property | Detail |
|---|---|
| What is cached | Third-party search data about a public domain, keyword or brand, and the analysis built from it |
| What the cache is keyed by | The tool and the query, plus settings such as country and device |
| What the key does not contain | Any account identifier. There is no way to ask the cache who ran a lookup |
| What it changes for you | Nothing about your entitlement. A cached result still spends your credit, because you ran a report |
Separate short-lived caches hold page-speed results per URL, benchmark figures per domain, extension quick-view data per domain, and translated interface strings. None of them is keyed by an account. Result caching and freshness explains how caching affects freshness and credits.
What we do not store#
| Not held | Note |
|---|---|
| Card numbers, expiry dates or security codes | Handled entirely by Stripe |
| Your password in readable form | The authentication service holds a hash. Nobody at Metric Vault can read or set it |
| Browsing history from the Chrome extension | The extension reads the address of the active tab only when you click it and start an analysis. No history, cookies or form data from any site is collected. See The Chrome extension |
| Special categories of personal data | Health, biometric, racial or ethnic origin, political opinion or religious belief data is not requested, collected or processed |
| Your analyses, shown to other customers | Submitted domains, reports and competitive intelligence are not shared between accounts |
| Your data, used to train AI models | Neither ours nor a third party's |
Where it lives#
The application, its database and its object storage run on managed cloud infrastructure in the United States. Identity is held by a separate managed authentication service. Payments and card data live with Stripe. Blog images live in object storage alongside the application.
Our formal commitments on encryption in transit, encryption at rest and encrypted backups are set out on the Security page at metricvaultai.com/legal/security. Subprocessors and data flow lists every outside service involved and exactly what each one receives.
If you are in the EEA, the UK or Switzerland, transfers to the United States are covered by Standard Contractual Clauses or the UK IDTA as applicable. See GDPR and compliance.
See also
Was this article helpful?
Thanks — feedback noted for the docs team.