Privacy Policy

What we collect, why we have it, who else touches it and how long it stays. Written against what the software actually does rather than against a template.

In effect since 29 July 2026

Who is responsible

VVES Sp. z o.o. operates MetricPeek and decides how the personal data described here is processed. In the language of the GDPR, we are the controller.

Country:
Poland

For anything in this document, including a request about your data, write to hello@vves.pl.

What we collect about you

  • Account — your name, email address, hashed password, and the preferences you set: language, timezone, default brand voice, avatar.
  • Waitlist — if you joined before launch: your email address, optionally your name, and the IP address and browser string of the request, kept as a defence against automated signups.
  • Billing — your plan, credit balance and transaction history. Card details are entered on Stripe's side and never reach our servers; we store the customer identifier Stripe gives us.
  • Connected social accounts — the account identifier, username, avatar and capabilities of each account you connect. The access tokens themselves live with our publishing provider, not in our database.
  • What you create — files you upload, content you generate, posts you compose and schedule, hashtag lists, brand voices and reports you run.
  • Technical records — logs of requests made to external providers on your behalf, an activity log of significant actions on your account, and error reports. These exist so we can bill correctly, investigate problems and notice abuse.

Data about people who are not our users

This product analyses public social media content. When you run a report on a profile or a hashtag, we fetch publicly available data — profile information, posts, engagement counts, captions and media — and store it so the report keeps working without fetching it again.

We do this on the basis of legitimate interest: providing analytics on public content to the person who asked for it. We do not collect private accounts, we do not attempt to circumvent any platform's access controls, and we do not build advertising profiles of the people analysed.

If you are the subject of such an analysis and want the stored copy removed, write to hello@vves.pl and we will delete it.

Why we are allowed to hold it

  • To provide the service you asked for — performance of a contract. Your account, your content, your publishing and your reports.
  • To keep it working and honest — legitimate interest. Security, abuse prevention, cost control and the analysis of public content described above.
  • To meet legal duties — legal obligation. Invoices and tax records, mainly.
  • Because you agreed — consent. The waitlist and any future marketing email; you can withdraw it at any time.

Who else processes it

We use a small number of providers to run the service. Each one only receives what it needs for its job, and none of them may use it for their own purposes.

Provider What for What they see
Stripe Payments, subscriptions and invoices Billing identity, card details (handled entirely on Stripe's side), subscription and payment history
Post for Me Publishing to social networks and reading back delivery status and post metrics Your connected account identifiers and the posts you publish. Access tokens for your social accounts are held there, not by us.
Anthropic (Claude) AI generation and analysis: content drafts, caption rewriting, sentiment, recommendations, brand voice analysis The text you submit for generation or analysis, and public content being analysed
Social platform data providers Fetching public profile, post and hashtag data from Instagram and TikTok The public handles and hashtags you ask us to analyse
Unsplash Stock image search inside the content editor Your search terms
Bunny Fonts Serving the webfont used across the site Your browser makes a request to their CDN when a page loads

Some of these providers are based outside the European Economic Area. Where that is the case, transfers rely on the European Commission's standard contractual clauses.

How long we keep it

These are enforced by scheduled deletion in the software, not by intention.

Account data
Until you delete your account
Report snapshots (tracking history)
180 days
API request logs
90 days
Payment webhook records
90 days
Account activity log
365 days
Login sessions
120 minutes of inactivity
Waitlist entries
Until launch, or until you ask us to remove yours

Separately from deletion, each plan has a data window that decides how long a report or a paid search stays open for reading. That is an access rule rather than a retention rule: we do not delete what you bought, and a refresh reopens it.

What you can ask for

Under the GDPR you may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interest, and ask for your data in a portable form.

You can delete your account yourself, from your account settings, which removes it and its data. There is no self-service export yet — it is on our public roadmap, and until it ships we handle export requests by hand. Write to hello@vves.pl and we will answer within a month.

If you think we have handled your data badly, you can complain to the supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.

Cookies

We set cookies that are strictly necessary to run the site: one that keeps you signed in and one that protects forms against cross-site request forgery. Your light or dark theme preference is stored in your browser and never sent to us.

There is no analytics, no advertising and no third-party tracking on this site. That is why you are not being asked to accept anything.

How it is protected

  • Everything travels over TLS.
  • Passwords are stored hashed, never in a form we could read.
  • Provider credentials are stored encrypted, and tokens and secrets are masked before anything is written to a log.
  • Public endpoints are rate limited, and payment events are verified against the provider's signature before they are believed.

Changes

When this document changes we update the date at the top. If a change materially affects what we do with your data, we will tell account holders by email before it takes effect.