Metazoic

Legal

Privacy Policy

How Metazoic collects, uses, discloses, retains, and safeguards personal information.

1. Who is responsible

Scope

PRIV-01

This Privacy Policy applies when a person visits Metazoic websites, joins a waitlist, creates or uses a Metazoic account, or uses Metazoic applications, agents, integrations, support, and related services (collectively, the “Service”). It applies to the Service operated at metazoic.ai and its subdomains. It does not govern a third party’s independent handling of information, even when the Service links to or connects with that party.

Operator and Privacy Officer

PRIV-02

The organization responsible for this Policy is 17831544 Canada Inc., a corporation incorporated under the federal laws of Canada, operating under the Metazoic name (“Metazoic,” “we,” “us,” or “our”). Questions, requests, and complaints may be sent to support@metazoic.ai, addressed to Justin Christopher Day, Privacy Officer, or mailed to 17831544 Canada Inc., 6-2160 Highway 7, Suite 286, Vaughan, Ontario L4K 1W6, Canada.

Information handled for organizations

PRIV-03

If an organization provides an account or directs use of the Service, that organization may decide why and how information in its workspace is handled. In that context, Metazoic handles the information to provide the Service to the organization, subject to its instructions and agreement. Users should direct workspace-specific questions to their organization first and may also contact us.

2. Information we collect

Account and organization information

PRIV-04

We collect information needed to create and administer accounts and workspaces, such as name, email address, authentication and account identifiers, organization and team membership, roles, invitations, preferences, and account settings. Authentication providers may give us account identifiers and profile details but not the password used with that provider.

Content and instructions

PRIV-05

We process content that users submit, create, or make available through the Service. Depending on the features used, this can include prompts, chat messages, agent and team configurations, plans, tasks, approvals, monitor instructions and results, tool calls and results, feedback, files and attachments, generated outputs, and related metadata. This content may include personal information about the user or other people.

Connected-service information

PRIV-06

When a user or organization connects a third-party service, we receive authorization details and process the data that the user requests or permits the Service to access. Depending on the connector, this may include files and document content, email messages and drafts, project or repository data, cloud-resource information, metadata, and actions taken through the connector. The authorization screen and in-product controls describe the requested access.

Waitlist, communications, and support

PRIV-07

We collect information a person submits when joining a waitlist, asking for support, or communicating with us, including email address, message contents, and related correspondence. A waitlist submission may also record its source, submission time, a shortened browser user-agent value, and a shortened referring-page value.

Technical, usage, and security information

PRIV-08

We collect limited information needed to operate, secure, and understand the Service, such as request and support identifiers, timestamps, network information including an IP address, browser or device characteristics, authentication and access events, page or feature names, operation names, outcome and error categories, performance measurements, and token or resource usage. Operational telemetry is designed not to contain prompt text, generated output, tool arguments or results, credentials, authentication tokens, cookies, or raw provider response bodies, although information intentionally submitted by a user can remain in product records described above.

Sensitive information

PRIV-09

The Service is not designed to require government identifiers, financial-account credentials, health records, or similarly sensitive personal information. Do not submit sensitive information unless it is necessary for an authorized use, your organization permits it, and you have a lawful basis to do so. Connector credentials must be provided only through the Service’s designated authorization process, never in prompts or ordinary content.

3. How we use information

We use information to provide and administer the Service; authenticate users; maintain workspaces, content, and preferences; execute requested agents, plans, tools, integrations, and automations; produce and display results; communicate about accounts and requested support; and enforce organization-level access controls.

AI processing

PRIV-11

To provide AI features, relevant instructions, content, bounded conversation history, tool definitions, tool results, and attachments may be sent to an AI service provider. Metazoic currently uses OpenAI for its text-model runtime. Current text requests are configured as stateless requests with provider storage disabled; Metazoic nevertheless stores product content and results in its own systems as needed to provide workspace history and features. If a materially new use of personal information is introduced, we will disclose it and obtain consent where required before it begins.

Connectors and actions

PRIV-12

We use connected-service information to authenticate the connection, show or process information the user requests, perform a requested action, maintain reliable execution and audit records, and protect the Service. A connector may allow the Service to read, create, change, send, or delete information in another service; the tools enabled and the user’s instructions determine which actions are available.

Reliability, security, legal compliance, and improvement

PRIV-13

We use information to prevent fraud, misuse, and security incidents; diagnose failures; maintain service reliability; comply with law; establish, exercise, or defend legal claims; and evaluate or improve Service performance and usability using information we are permitted to use for those purposes. We do not use customer content to train a generalized AI model unless we first give clear notice and obtain any consent required by law and contract.

Service and promotional communications

PRIV-14

We may send operational messages needed to administer an account, deliver the Service, invite a waitlisted person to a beta cohort, or respond to a request. We send promotional electronic messages only where permitted by law and include required sender information and a working way to unsubscribe. Opting out of promotional messages does not stop necessary service messages.

4. When we disclose information

Service providers

PRIV-15

We disclose information to vendors that process it for us to host, secure, support, analyze, or deliver the Service. Current categories include cloud infrastructure and storage, authentication, AI processing, connected-service APIs, communications, and operational monitoring. They may process information only for the contracted service and subject to applicable confidentiality, security, and data-protection requirements.

Organizations and people using the Service

PRIV-16

Workspace content and activity may be visible to other authorized members, owners, or administrators according to the Service’s access controls. We disclose content to another person or service when a user directs the Service to communicate, share, publish, or take an action involving that recipient.

Legal, safety, and business events

PRIV-17

We may disclose information when we reasonably believe it is necessary to comply with law or valid legal process; protect rights, safety, systems, and users; investigate misuse; or complete a financing, reorganization, merger, acquisition, or sale of assets. In a business transaction, recipients must use personal information consistently with this Policy unless affected people receive legally required notice and choice.

No sale or behavioural advertising

PRIV-18

We do not sell personal information, share it for cross-context behavioural advertising, use connected-service data for advertising, or disclose personal information to data brokers. If these practices change, we will update this Policy and provide any notice, consent, or opt-out required before the change applies.

5. Connected-service disclosures

Some connected-service providers require additional disclosures about their data. Each provider section in this version forms part of this Policy. A provider-specific disclosure does not expand Metazoic’s rights beyond the rest of this Policy or the user’s instructions.

Google Workspace data

When you enable Google Workspace features, Metazoic may request Google Drive access to search, read, create, and update files in Drive, Docs, Sheets, and Slides. Metazoic may separately request Gmail access to read messages, prepare reviewable drafts, send an identified draft only after an explicit instruction, change requested message or thread labels, and, when you configure the feature, observe mailbox changes that wake a monitor. The Google authorization screen identifies the access granted; Metazoic tool, capability, and approval controls limit how the Service uses that authorization.

Use, processing, and storage

GWS-PRIV-02

Google user data is used only to provide or improve the user-facing feature you request. Requested data passes through Metazoic systems and, when needed for an AI-assisted request, may be included in input sent to our AI service provider. Requested content or a sanitized, truncated tool result may remain in workspace history, files, monitor records, or audit records as described in this Policy. Authorization credentials are stored separately from ordinary content and are not included in prompts or ordinary operational logs.

Google Limited Use

GWS-PRIV-03

Metazoic's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold, used to determine creditworthiness, or used to train a generalized AI model. Human access is limited to cases where you give affirmative permission for specific data, access is necessary for security or abuse investigation, access is required by law, or the data is aggregated and anonymized for internal operations as permitted by Google policy.

Your controls

GWS-PRIV-04

You can disconnect Google Workspace in Metazoic or revoke access through your Google account. Revocation stops new access through that authorization but does not automatically erase information already included in Metazoic workspace records. You may use available product controls or contact support@metazoic.ai to request deletion, subject to organization controls and the retention and legal exceptions in this Policy.

7. Retention and deletion

We keep information only as long as reasonably needed for the purposes described in this Policy, including providing the Service, maintaining account and workspace history, security and abuse prevention, legal compliance, dispute resolution, and enforcing agreements. The period depends on the kind of record, workspace settings, user or administrator actions, legal obligations, and technical backup or recovery cycles. Some product deletions are soft deletions, and limited records may remain for audit, recovery, backup, legal, or security purposes before they are deleted, anonymized, or no longer reasonably linkable to a person.

A person may request account or personal-information deletion through the contact channel below. We will verify the requester and the relevant organization authority where necessary, then apply available deletion controls and lawful exceptions. We do not promise immediate deletion from active systems or backups when operational, security, legal, or organization-controlled retention applies.

8. Storage, transfers, and safeguards

Locations and transfers

PRIV-22

Metazoic and its service providers may process information in Canada, the United States, and other places where they operate. Metazoic’s current primary product workloads are hosted in the United States. Information may therefore be subject to the laws and lawful access processes of those places. We use contractual and other safeguards appropriate to the information and applicable law when transferring it across borders.

Safeguards

PRIV-23

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls, credential separation, encryption for protected credentials and data in transit, tenant authorization checks, sanitized operational diagnostics, and security monitoring. No system is perfectly secure. Users must protect their accounts, use designated authorization flows, and promptly tell us about suspected unauthorized access.

9. Choices and individual rights

Product controls

PRIV-24

Users can manage available account and workspace settings, choose which tools to enable for a model run, and disconnect third-party services. Disconnecting a service stops new access through that authorization but does not automatically erase information already included in workspace records. Organization owners or administrators may control access to and retention of organization-managed accounts and content.

Privacy requests and complaints

PRIV-25

Subject to applicable law and identity verification, a person may ask to access personal information about them, learn how it has been used or disclosed, correct it, delete it, obtain a portable copy where required, withdraw consent, object to or restrict certain processing, or make a complaint without retaliation. Send a request to support@metazoic.ai with “Privacy request” in the subject line. We may need to consult the organization that controls a workspace or retain information where law or a valid exception permits. We will acknowledge and respond within the period required by applicable law. A person may also complain to the privacy regulator in their jurisdiction.

10. Cookies, browser storage, and telemetry

The Service uses HTTP-only authentication, session, invitation, and organization-selection cookies needed to sign users in, protect accounts, and route requests. It also uses browser storage for non-secret tool selections, connector authorization handoff state, diagnostics identifiers, and presentation preferences. Browser telemetry may record page and feature names, request timing, outcome categories, and technical diagnostics. We do not currently use third-party advertising cookies or behavioural advertising trackers. If non-essential analytics or similar technologies are added, we will provide any notice and choice required by law before using them.

11. Children

The Service is intended for business and professional use by people who are at least 18 years old or the age of legal majority where they live. It is not directed to children, and we do not knowingly collect personal information from a child through a personal account. A parent or guardian who believes a child has provided personal information may contact us.

12. Changes and contact

Changes and version history

PRIV-28

We may update this Policy to reflect changes in the Service, law, or our data practices. We will post a new version and effective date and provide additional notice or obtain consent when required for a material change. Earlier effective versions remain available at permanent version URLs linked from the current Policy.

Contact

PRIV-29

Questions, privacy requests, or complaints may be sent to support@metazoic.ai, addressed to Justin Christopher Day, Privacy Officer, or mailed to 17831544 Canada Inc., 6-2160 Highway 7, Suite 286, Vaughan, Ontario L4K 1W6, Canada.

Version history

This is the first effective version. Permanent link to version 1.0.0