MetisAI Privacy Policy
1. Information We Collect
When you use MetisAI, we collect: email address (for account identification), name and basic profile information, Google Drive files that you create through MetisAI, and your AI assistant preference (ChatGPT, Claude, Gemini, or DeepSeek).
2. How We Use Your Information
We use your information to: provide MetisAI life companion services, store and manage your life story documents in your Google Drive, manage progress tracking and document organisation, and communicate with you about your account.
3. How We Access Your Google Drive
Your Privacy is Protected — Most Stringent Google Security Scope
MetisAI uses Google's most restrictive permission level (drive.file scope). This means: ✓ MetisAI can ONLY see files it creates for you during the conversation with you · ✓ MetisAI CANNOT see your other Google Drive files · ✓ Your photos, documents, and other files are completely hidden from MetisAI · ✓ Each user's data is completely isolated · ✓ Your files remain in YOUR Google Drive — you control them.
You can revoke MetisAI's access at any time through your Google Account settings, and your files will remain safely in your Drive.
MetisAI uses limited Google Drive access to: create folders for organising your life story documents, save and update your life story files, manage progress tracking spreadsheets, and archive previous versions of your documents.
A Note About Google's Permission Screen
When you connect your Google Drive to MetisAI for the first time, Google will display one or more security screens asking you to confirm that you are granting MetisAI access to your Drive. This is a standard legal requirement introduced by Google to ensure full transparency about third-party app access. You may see messages that appear formal or even cautionary — this is normal and expected. Google shows these screens to all users connecting any third-party application, regardless of how trusted or restricted that application is.
Please read each screen carefully and confirm. What you are approving is strictly limited: MetisAI can only process and manage files that it creates for you. It cannot access your photos, personal documents, emails, or any other files already in your Drive.
If you are uncomfortable at any point, you can cancel and contact us at metis@sustensis.co.uk before proceeding.
4. Data Storage and Security
Your data is stored securely: account information stored in Microsoft Azure cloud services with enterprise-grade security · all data encrypted in transit (HTTPS/TLS) and at rest (AES-256) · Google Drive files remain in your Google Drive account under your control · access tokens encrypted and stored securely in Azure Table Storage · we, as a company, do not see, sell or share your information with third parties · all access is logged and auditable for security purposes.
5. Administrator Access
Like all cloud services, system administrators have technical capability to access user data for legitimate purposes only, including: technical support and troubleshooting (with user permission), security incident investigation, legal compliance requirements, and system maintenance and updates.
Important: All administrative access is logged, audited, and restricted to authorised personnel only. We are legally and ethically bound to protect your privacy and only access data when necessary for these legitimate purposes.
6. Your Rights
You have complete control over your data: access your personal data at any time · request deletion of your account and data · revoke Google Drive access at any time through your Google Account settings · export your life story documents from your Google Drive · request corrections to your personal information · withdraw consent for data processing.
7. Data Retention
We retain your data as long as your account is active. When you delete your account: your account information is permanently deleted from our servers within 30 days · your Google Drive files remain in your Drive (you control them), so you can continue to update them in whichever way you wish after account closure · you can manually delete Drive files at any time · access tokens are immediately revoked and deleted.
8. Third-Party Services
MetisAI integrates with the following third-party services: Google Drive (for file storage, subject to Google's Privacy Policy), Microsoft Azure (for secure data storage and hosting), AI Assistants — ChatGPT, Claude, Gemini, or DeepSeek (as per your choice — you interact with them directly), and Payhip (for payment processing and licence management). These services have their own privacy policies which govern their use of your data.
9. User Data Isolation
Your data is completely private: each user's data is completely isolated from other users · no user can access another user's documents or information · your Google Drive access token is unique to you and cannot be used by others · all data is partitioned by user email for complete separation.
10. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify users of any material changes via email or through the MetisAI dashboard. Your continued use of MetisAI after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy concerns, questions, or to exercise your rights, contact:
Email: sustensis@sustensis.co.uk · Company: Sustensis Ltd · Website: https://metisai-gateway5.azurewebsites.net
12. GDPR Compliance (For EU Users)
For users in the European Union, we comply with GDPR requirements: Legal Basis — data processing is based on your explicit consent · Right to Withdraw — you can withdraw consent at any time · Data Portability — you can export all your data · Right to Erasure — you have the right to be forgotten · Data Protection Officer — contact tony.czarnecki@sustensis.co.uk for data protection inquiries · Supervisory Authority — you have the right to lodge a complaint with your local data protection authority.
13. Children's Privacy
MetisAI is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information.
14. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this privacy policy and applicable laws.
Last Updated: 10 April 2026