Skip to content
Metric VaultHelp Center
Open app

What data we store

Every category of information Metric Vault holds, why it is held, where it lives, and what is deliberately never stored on our systems.

Last updated 2026-08-06

Summary#

This page lists every category of information Metric Vault holds about you and your work, what each one is for, and where it lives. It is written to be complete enough to answer a security questionnaire or a data-mapping exercise without having to ask us. If a category is not on this page, we do not hold it.

For how long each of these is kept, and what happens when you close an account, see Data retention and deletion. For the outside services involved, see Subprocessors and data flow.

Overview#

Everything falls into six groups.

Who you are is the small amount of account information needed to sign you in and bill you. What you asked us to analyze is the domains, keywords, brands and URLs you submit. What we produced is the results, reports and history those analyses generated. How you have set things up is your preferences, your team and your connected integrations. What you have used is the credit and usage counters that make your plan work. How the platform is running is operational information such as error records and aggregate performance figures.

Two boundaries run through all of it.

Your analyses and reports are visible to you and to the people you have invited into your workspace. They are not shown to other customers, and they are not used to train AI models.

Card numbers are never stored, processed or transmitted by Metric Vault. Payment details live with Stripe.

Account and identity#

WhatWhy it is heldWhere it lives
Email addressIt is your account identifier and the address alerts and invoices go toThe managed authentication service, and our application database as the owner of your work
Display nameShown in the interface and on team invitationsThe managed authentication service
PasswordSign-in. Stored as an encrypted hash by the authentication service, never in readable form, and never visible to anyone at Metric VaultThe managed authentication service
Sign-in methodWhether the account uses email and password, Google, or bothThe managed authentication service
Email confirmation statusAn address that has not been confirmed is never treated as an accountThe managed authentication service
Account creation dateShown as Member since on the Account screenThe managed authentication service

There is no field for a postal address, a phone number or a job title. If you send one to support in a message, that message is retained as correspondence.

Billing#

WhatWhy it is heldWhere it lives
Your plan and when it was setEvery entitlement check in the product reads itOur application database
Subscription state, billing cycle and renewal dateShown in the Subscription card and used to keep your plan accurateStripe, read back into the product
Invoices and transaction recordsTax, accounting and your own recordsStripe
Billing country and a tokenised payment methodFraud prevention and taking paymentStripe
Card number, expiry and security codeNot held. These are entered on Stripe's pages and never reach usStripe only

See Invoices and receipts for retrieving invoices, and Managing billing in the customer portal for the Stripe billing portal.

What you submit for analysis#

WhatWhy it is held
Domains, URLs, keywords and brand names you enter into a toolThey are the input to the analysis, and they are stored with the saved result so you can reopen it
Competitor domains you compare againstSame
Pages you add to the competitor monitorThe monitor has to know what to check
Keywords you add to rank alerts and position trackingThe tracker has to know what to watch
Content you paste into the writing and optimization toolsIt is the input to the analysis. Drafts you have not saved stay in your browser
Content you write in the blog studio, including uploaded imagesIt is your content, held so the blog can publish it

What the platform produces for you#

WhatWhy it is held
Saved tool results, including the rendered reportSo the Library can reopen a run without spending credits again. See Saved Work
Activity logA record of runs and workspace events. Not shown to customers; support and the admin Run Log read it
Captured snapshots of monitored pages, and the changes detected between themThe monitor compares each check against the previous one, so it has to keep the previous one
Rank alert historyThe position chart over time
Scheduled report definitions and a record of each runSo a schedule keeps firing and you can see whether it delivered
Shared report pagesA share link serves a stored copy of the report so it can be opened without signing in. See Sharing a result by link
AI visibility tracking history for brands you trackThe trend lines in the AI visibility tools
Responsiveness analyses you have savedSo you can reopen them

Settings, team and integrations#

WhatWhy it is held
Notification preferencesWhich emails and alerts you want. See Notification preferences
White-label branding: company name, logo, colors and custom footerApplied to your exports and share pages. See White-label reports
Team memberships and pending invitationsWho is in your workspace and who has been invited but not accepted
Connected Google account, the access it granted, and cached Search Console figuresSo the integration keeps working without asking you to reconnect on every page load. Disconnecting removes the connection and the cached figures. See Google Search Console
Connected social accounts and the access each grantedSo scheduled posts and social analytics can run. Disconnecting removes the connection. See Connecting social accounts
Blog sites you created and their mediaYour published content and its images

Interface preferences such as theme, language, filters, date ranges, recently viewed items, tour progress and unsaved drafts are stored in your browser, not on our servers. Clearing your browser storage resets them and loses nothing that is on the server.

Usage and metering#

WhatWhy it is held
Credits used this month, split into tool runs and AI runsEnforcing your plan's allowance and drawing the usage meter
Credits used per tool this monthThe breakdown in the usage popover
An hourly call counterThe fair-use limit that keeps automated abuse off the light tools
Recommendation usage this monthThe separate allowance for Get Recommendations

See Tracking your usage and How credits work.

Operational information#

WhatWhy it is held
Technical information collected automatically: IP address and approximate city-level location, browser and device type, pages and features used, referring URL, session timestampsUnderstanding how the platform is used, diagnosing faults, and security monitoring. It is not used to build advertising profiles and is not sold
Error recordsGrouped by the shape of the error, so a recurring fault can be found and fixed. Messages are normalised before storage: URLs, email addresses, identifiers and numbers are replaced with placeholders
Aggregate performance figuresCounted per tool per hour across the whole platform, not per person
A record of administrative changes made to an accountIf a plan is changed, usage reset or an account suspended by our team, the actor, the action, the target and the time are recorded
Support messages and bug reports you sendAnswering you, and fixing what you reported

Caches#

Metric Vault keeps a shared cache of provider data in front of the paid search-data providers, so that a repeat lookup of the same domain or keyword does not re-bill the provider. This is the one store that is not scoped to an account, so it is worth being exact about what it contains.

PropertyDetail
What is cachedThird-party search data about a public domain, keyword or brand, and the analysis built from it
What the cache is keyed byThe tool and the query, plus settings such as country and device
What the key does not containAny account identifier. There is no way to ask the cache who ran a lookup
What it changes for youNothing about your entitlement. A cached result still spends your credit, because you ran a report

Separate short-lived caches hold page-speed results per URL, benchmark figures per domain, extension quick-view data per domain, and translated interface strings. None of them is keyed by an account. Result caching and freshness explains how caching affects freshness and credits.

What we do not store#

Not heldNote
Card numbers, expiry dates or security codesHandled entirely by Stripe
Your password in readable formThe authentication service holds a hash. Nobody at Metric Vault can read or set it
Browsing history from the Chrome extensionThe extension reads the address of the active tab only when you click it and start an analysis. No history, cookies or form data from any site is collected. See The Chrome extension
Special categories of personal dataHealth, biometric, racial or ethnic origin, political opinion or religious belief data is not requested, collected or processed
Your analyses, shown to other customersSubmitted domains, reports and competitive intelligence are not shared between accounts
Your data, used to train AI modelsNeither ours nor a third party's

Where it lives#

The application, its database and its object storage run on managed cloud infrastructure in the United States. Identity is held by a separate managed authentication service. Payments and card data live with Stripe. Blog images live in object storage alongside the application.

Our formal commitments on encryption in transit, encryption at rest and encrypted backups are set out on the Security page at metricvaultai.com/legal/security. Subprocessors and data flow lists every outside service involved and exactly what each one receives.

If you are in the EEA, the UK or Switzerland, transfers to the United States are covered by Standard Contractual Clauses or the UK IDTA as applicable. See GDPR and compliance.

See also

Was this article helpful?