Legal

Privacy Policy

What we store, why, and how to get rid of it. Last updated 3 September 2026.

The short version

We store the email address you sign in with, the URLs you ask us to check, the results of those checks, and the settings for your social cards. We do not sell any of it, and we do not track you around the web. There are no advertising or analytics cookies on this site.

What we hold

Your account. An email address, your plan, and when you signed up. Signing in is by emailed link, so we never store a password.

What you check. The URLs you inspect, save or audit, and what we read from those pages — titles, descriptions, tags, the address of the image a page nominates. For saved URLs and audits we keep the history so you can see whether a score moved.

Your cards. The domains you verified, your colours, layouts and chosen templates, and a count of how many cards were drawn each day. If you use your site’s favicon as a mark, we store a copy of that image so the renderer never has to fetch it while drawing.

Credentials. API keys and agent connections are stored as hashes, never in a form we could read back. A session cookie keeps you signed in for a fortnight; it is strictly necessary and there is no way to turn it off and still have an account.

Pages we fetch on your behalf

When you check a URL we fetch it as MetaManagerBot, from Cloudflare’s network. The site you are checking will see that request in its logs, including our user agent and the IP it came from. We do not send them anything about you.

Who else sees it

Cloudflare runs the whole service — compute, database and cache — and processes data on our behalf.

Polar is our merchant of record and handles payment. They collect what they need to take a payment and to meet their tax obligations. We receive a customer reference and your plan, never your card details.

Email delivery. Sign-in links and alert emails go through an email provider, which sees the address and the message.

That is the whole list. We do not sell personal data, and we do not share it for advertising.

Agents you connect

Connecting an AI agent grants it only the permissions you ticked. An agent with permission to read your account can see your saved URLs, audits and monitors, and anything it reads goes to whoever operates that agent — which is not us. Disconnect one at any time from your connected agents page; it stops working immediately.

How long

Account data lasts until you delete your account. Audits and check history last while your account does, so trends stay meaningful. Cached page content is short lived and measured in minutes. Revoked keys and disconnected agents leave a record that they existed, so an audit trail survives, but the credential itself is dead.

Your rights

Ask us for a copy of what we hold, ask us to correct it, or ask us to delete it, and we will. Deleting your account removes your saved URLs, audits, monitors, card settings and connections. Write to hello@metamanager.dev.

If you are in the UK or EU, our lawful basis is performing the contract for the parts you asked for, and our legitimate interest in running a service that is not abused for the rate limiting and abuse controls.

Changes

If we change what we collect or who sees it, this page changes first, and we will email you about anything significant. See also our Terms of Use.