Skip to content
Metric VaultHelp Center
Open app

Subprocessors and data flow

Every outside service involved in delivering Metric Vault, exactly what each one receives, and what never leaves the platform.

Last updated 2026-08-06

Summary#

Metric Vault is built on a small set of outside services. This page names them, states exactly what each one receives, and — more usefully for a vendor review — states what they do not receive. The short version: the search-data and AI providers get the domain, keyword or content you submitted and nothing about who submitted it; Stripe gets your billing relationship and never gives us your card number; and no provider receives your reports or your account credentials.

The formally published sub-processor list is on the GDPR & Data page at metricvaultai.com/legal/gdpr. This page is the operational version of it, mapped to the features that trigger each transfer.

Overview#

Every processor is bound by a data processing agreement requiring it to process personal data only on our instructions, apply appropriate security measures, and assist us with our own obligations. None is authorised to use your data for its own purposes.

Three principles decide what leaves the platform, and they are worth reading before the tables.

Providers receive the query, not the querier. When you run a tool, the domain or keyword goes to the data provider. Your email address does not. There is nothing in a provider request that identifies which account made it.

Nothing is sent to train a model. We do not use your data to train third-party AI models, and we do not permit our providers to.

Card data never transits our systems. Payment details are entered on Stripe's pages and are never processed by, stored on, or passed through Metric Vault.

The published sub-processor list#

These are the processors named on the GDPR & Data page.

Sub-processorLocationRole
Stripe, Inc.USAPayment processing and subscription billing
DataForSEOUkraine / InternationalSearch, keyword, backlink and SERP data
Uptime RobotUSAPlatform availability monitoring
Cloud hosting and infrastructure providersUSAServer, database and platform delivery

Every service that touches data, and what it receives#

This is the fuller operational map, including the services that sit inside the "hosting and infrastructure" line above and the providers behind individual features.

ServiceWhat triggers itWhat it receivesWhat it does not receive
CloudflareEvery request. It is the hosting, edge network, application database and object storageEverything the platform stores, as the infrastructure it runs on. Also the interface strings sent for translation, and image prompts when blog artwork is generated
Managed authentication providerSign-in, sign-up, password reset, Google sign-inYour email address, display name and password, held as an encrypted hashYour analyses, reports, billing details or usage
StripeUpgrading, managing a subscription, every renewalYour email address, the plan you chose, your billing address and the card details you enter on Stripe's own pagesYour analyses, reports, keywords, domains or usage data
DataForSEORunning any tool that needs search, keyword, backlink or SERP dataThe domain, URL, keyword or brand you submitted, plus the settings for that run such as country and deviceYour email address, account details, plan, or anything identifying who ran the query
Google PageSpeed InsightsPageSpeed and Core Web Vitals checksThe URL you submitted and whether you asked for mobile or desktopAnything about your account
Google Search Console and AnalyticsOnly if you connect themThe authorisation you granted, the site you selected, and the date range and dimensions of each query. Data flows mainly the other way: Google returns your own measured figuresYour Metric Vault password, other customers' data, or anything from tools you have not connected
OpenAIMost research and analysis tools, the assistant, and in-app chatThe prompt: the domain, keyword or brand you submitted, the provider data retrieved for it, and content you pasted into a writing toolYour email address or account details
Anthropic (Claude)Long-form writing, strategic synthesis, web-grounded checks, the responsiveness analyzerThe same shape of promptThe same
Google (Gemini)AI visibility measurement, as one of the assistants testedThe brand or prompt being measuredThe same
PerplexityFact checking with citations, source discovery, and AI visibility measurementThe brand, query or claim being checkedThe same
Transactional email providerTeam invitations, alert emails, scheduled report notificationsThe recipient's address and the content of that messageYour reports, unless you scheduled one to be delivered by email
Uptime RobotContinuous availability checksNothing of yours. It checks whether the platform responds. The public status page is stats.uptimerobot.comAny customer data at all
Social platforms — LinkedIn, X, Facebook, Instagram, Threads, TikTokOnly if you connect a channelThe authorisation you granted, and the posts you publish or schedule through the composerAnything from the rest of the platform
Stock image searchSearching for a stock image in the blog studioThe search term you typedAnything about your account
AI image providerGenerating blog artworkThe image promptAnything about your account
Translation providerTranslating dynamic interface text into another languageThe interface strings being translatedCustomer data. Report content is translated as text with data values masked

Several of these are optional and never activate unless you use the feature. Search Console, the social channels, the blog studio and its image tools all require an explicit connection or action from you. See Integrations for what each integration does and Disconnecting an integration for removing one.

What leaves the platform when you run a tool#

Worth tracing once, because it is the question every vendor review asks.

  1. You submit a domain, URL, keyword or brand in the dashboard.
  2. The server checks your plan, your credits and, for any URL you supplied, that the target is a public internet address rather than a private or internal one.
  3. The query is sent to the relevant provider — DataForSEO for search data, Google for page speed, an AI provider for analysis or writing. Your account identity is not part of that request.
  4. The provider's answer comes back, is analyzed and scored, and the finished result is stored against your account.
  5. If the tool is one of the cached ones, the provider's answer is also kept in a shared cache keyed by the tool and the query, so the next lookup of the same thing does not re-bill the provider. That cache carries no account identifier. See Result caching and freshness.

Nothing in that path sends your reports, your saved work, your team, your billing details or your credentials anywhere.

What never goes to a third party#

Never sentNote
Your passwordIt is held only by the authentication provider, as a hash
Your reports and saved resultsThey stay on the platform. The exception is one you deliberately export, email or share by link
Your credit and usage figuresMetering is internal
Your team listExcept that an invitation email necessarily reaches the invitee's address
Your card numberIt is never on our systems to send
Your browsing historyThe Chrome extension reads the active tab address only when you click it. See The Chrome extension

Notes for a vendor review#

  • Transfers. All of the above are US-based or international. For EEA, UK and Swiss customers those transfers are covered by Standard Contractual Clauses or the UK IDTA. Copies are available on request. See GDPR and compliance.
  • Changes. If we onboard a new sub-processor that materially affects your data, the GDPR page and this article are updated, and we notify you where required.
  • A complete named list. The published list above names the processors we formally disclose. If your assessment needs every vendor named, including the hosting and identity providers, write to hello@metricvaultai.com and we will provide the current list rather than leaving you to infer it.
  • Documents. Ask the same address for a data processing agreement, the applicable SCCs or IDTA, or a completed security questionnaire.
  • Provider behavior. Where the data comes from explains what each data source actually measures and how fresh it is, and AI models used across the platform maps each feature to the model behind it. Those two are the right pages when the question is about data quality rather than data protection.

See also

Was this article helpful?