Privacy Policy
Last updated September 9, 2026
Who runs Metron
Metron is a personal health-tracking project operated by a private individual, not by a company. For any question about your data — access, export or deletion — write to [email protected].
What Metron stores
Only what the app needs to work:
- Your account: email address, an optional display name, a profile picture URL if you sign in with Google, and your interface preferences (language, theme, units).
- The health data you enter: the markers you create, their numeric values, dates, optional notes, categories, and comparison cards.
- The files you upload: lab reports as PDF, image or CSV. They are kept on the server’s own disk, or in S3-compatible object storage when the deployment is configured for it.
- Sign-in sessions: a session token and its expiry, plus the IP address and browser user-agent of the device that signed in.
What Metron does not collect
No name is required, and Metron never asks for your birth date, address, gender or phone number. There are no advertising identifiers, no analytics or tracking scripts, and no third-party cookies. An entry is a number, a unit and a date — it is not enriched, profiled, or linked to anything outside your account.
Signing in with Google
Google sign-in requests only the basic sign-in scopes — openid, email and profile. That gives Metron your email address, display name and profile picture, and nothing else: no access to Gmail, Drive, Calendar or your contacts. The tokens Google returns are stored so you stay signed in. You can revoke Metron’s access at any time in your Google account’s permissions page.
How uploads are processed
Parsing happens on Metron’s own server. PDFs are read through their text layer; when a report is a photo or a scan, optical character recognition runs locally on the server. Your file is not sent to any external OCR or AI service. Intermediate parse results are held in memory for at most 30 minutes and then discarded.
Who can see your data
Only you — unless you choose otherwise. Two features share data, and both are yours to start and to revoke: public share links, which can be given an expiry date, and connections with another Metron user, which grant read-only access to your charts. Nobody else is given access. The operator can technically reach the database for maintenance and backups, and does not read your health data.
Third parties
Google, only if you choose Google sign-in. The hosting provider that runs the server, and S3-compatible object storage when the deployment uses it. That is the whole list: no analytics providers, no ad networks, no data brokers. Fonts are served from Metron’s own domain, so your browser does not contact Google Fonts.
Retention and deletion
Your data stays until you remove it. In Settings you can reset your data, which deletes your markers, their entries, your share links and your uploaded files. To have the entire account removed, write to [email protected] and it will be deleted.
Security
Traffic is served over HTTPS, passwords are stored hashed, session cookies are signed, and the app sends a strict Content-Security-Policy. To be straightforward about it: Metron is a small, self-run project, not a certified medical system. Please do not upload anything you would not be comfortable having stored here.
Not medical advice
Metron displays numbers you provide. It does not diagnose, interpret results, or replace a clinician. Discuss your results with a qualified professional.
Changes to this policy
If this policy changes in a way that affects how your data is handled, the updated text and a new date will appear on this page.