Legal

Privacy Policy

Effective date: October 4, 2026. Met keeps your contacts on your device and in your own iCloud. We store only what's needed to run your account, we never sell data, and we ask before any contact details go to our processing partner.

What counts as personal data

Personal data is any information about an identifiable person. In Met that includes the details on a business card or badge you scan (name, title, company, email, phone, website, the card photo), the notes and tags you add about someone, follow-up drafts, and your own account and share-card details.

Most of the people in your Met contacts are not Met users. When you capture someone's details you are responsible for doing so lawfully, for example because they handed you their card. We treat their information with the same care as yours.

Where your contacts live

Contacts, notes, tags, events, drafts and card photos are stored on your device. If iCloud Drive is on, they are also stored in your own iCloud account, which Apple operates. We cannot see or access your iCloud data.

What we store on our servers

  • Your account: the email address and display name from Sign in with Apple or Google, the provider's account identifier, and session tokens used to authenticate the app.
  • Your share card, if you publish one: the name, role, company, phone, email and LinkedIn URL you choose. It is public at its mettree.com/c/ link until you change or delete it.
  • Scan problem reports, only when you tap Report Scan Issue: the card photo, the text read from it, the parsed fields and your note. Photos are deleted after 7 days and reports after 30 days.
  • Abuse-prevention counters: per-account request counts and hashed IP addresses, kept for up to 2 days.

We do not store the card text or notes that pass through our servers to clean up a scan or write a follow-up draft.

Our processing partner: OpenAI

Met can use OpenAI, a third-party AI service, to do two things:

  • Clean up a scan: the text read from a card or signature, plus the email, phone and website found on it, is sent to OpenAI to separate the name, title and company.
  • Write a follow-up draft: the contact's name, title and company, where you met, your notes, tags and availability are sent to OpenAI to write the draft.

Card photos are never sent to OpenAI. Met asks for your permission before sending anything, and you can change your choice at any time in Settings. If you decline, scans are cleaned up on your device only, and follow-up drafts are written by our own template on our servers without OpenAI.

We send requests with storage turned off. Under OpenAI's API terms, the data is not used to train models; OpenAI may keep it for up to 30 days to detect abuse, then deletes it. Don't put sensitive information such as health or financial details in notes.

Sign-in

  • Sign in with Apple: we receive an Apple identity token and, the first time, your name and email. Apple may give us a private relay address instead of your real email.
  • Sign in with Google: we request only your basic profile and email address. Met does not access Gmail, Google Calendar or any other Google data.

Device permissions

  • Camera: used to scan cards, badges and QR codes. Text is read on your device with Apple's Vision framework. A card photo leaves your device only if you send a scan problem report.
  • Contacts: used only when you import selected contacts or add one to your iPhone's address book.
  • Calendar: read on your device to suggest the event you're at when you add context. Calendar data is not sent to us.
  • Notifications: follow-up reminders are scheduled on your device. Their content is not sent to us.

Subscriptions

Met Pro is billed by Apple through the App Store. We never see your payment details; the app checks your subscription status with Apple.

Analytics and crash reports

  • PostHog receives product-usage events, such as "a contact was captured". They are tied to a random identifier for your app install, not to your name or email, and contain no contact details, notes or drafts. Session recording is off.
  • Sentry receives crash and error reports: stack trace, device model, iOS and app version. Reports contain no contact details, notes, drafts or session tokens, and no screenshots.

Newsletter

If you subscribe on mettree.com, your email address is stored with Resend, our email provider, after you confirm it from the email we send. Every newsletter has an unsubscribe link.

Service providers

None of these providers sell your data; all are bound by data-processing terms.

  • Apple: Sign in with Apple, iCloud, App Store and subscriptions.
  • Google: Sign in with Google (profile and email only).
  • OpenAI: scan clean-up and follow-up drafts, with your permission.
  • Vercel: hosting for api.mettree.com and mettree.com.
  • Neon: the database for accounts, sessions, share cards and scan problem reports.
  • Resend: newsletter email.
  • Sentry and PostHog: crash reports and usage analytics.

Deleting your data

You can delete your account in the app under Me → Settings → Delete Account. This deletes your account, sessions and share card from our servers before clearing data on your device. If the server can't confirm the deletion, the app tells you and keeps your local data so you can try again.

Contacts in your iCloud stay in your iCloud account, which you control. To request a copy or deletion of anything else, email us.

Children

Met is not directed at children under 13, and we don't knowingly collect their personal data.

Changes

We'll update the effective date when this policy changes and tell you in the app about material changes.