MetrXSEO · Updated 3 September 2026

Privacy policy

MetrXSEO is a client-reporting console operated by IP SUBNET ZERO LLC. This policy explains what the service collects on behalf of the businesses that use it, how that information is stored, and how to have it deleted.

Who this covers

MetrXSEO is not a consumer product. Accounts are created by us for the businesses we work with; there is no public sign-up. Two groups of people are described here: the users we give accounts to, and the customers of those businesses whose activity appears in the reports — website visitors, and people who send an Instagram message to a connected account.

What we collect about users

  • Name and email address, so an account can exist and be addressed.
  • A bcrypt hash of the password — never the password itself.
  • Sign-in records: the time, the IP address and the browser's user-agent string, kept so an account owner can see who reached their data and so we can detect password guessing.
  • An activity log of administrative actions taken in the console, including messages sent from the Instagram inbox and who sent them.

A session cookie (sid) is set on sign-in. It is strictly necessary for the service to function, holds an opaque random token rather than any personal data, and is not used for advertising or analytics. Starting a Facebook or Instagram connection additionally sets a short-lived, encrypted cookie (meta_oauth_state or ig_oauth_state) that exists only to prove the request came from us; it expires after ten minutes and is deleted as soon as the connection finishes. We set no other cookies and run no advertising or third-party analytics trackers on this site.

What we collect on behalf of businesses

When an administrator connects a platform, MetrXSEO reads that business’s own marketing data on a nightly schedule and stores it so it can be reported over time. Depending on which platforms are connected, that includes:

  • Google Analytics 4 and Google Search Console — aggregated traffic, acquisition and search-performance figures.
  • Google Ads — campaign spend and performance.
  • PostHog and Google Tag Manager — on-site behaviour and tag configuration.
  • Cloudflare — edge request analytics for the business's own domain.
  • DataForSEO — search-ranking, backlink and public business-profile data.
  • Instagram and Facebook — the connected professional account's profile, follower and media counts, post insights, and, where enabled, its Direct message conversations.

Third-party credentials supplied by a business (API keys, OAuth tokens) are encrypted at rest with AES-256-GCM and are never shown back in full.

Instagram data

When an administrator connects an Instagram professional account using Facebook Login, we retrieve and store the account’s profile information, follower and media counts, its posts and their insights, and — only for accounts where an administrator has explicitly switched Direct messages on — the conversations that account receives. For a conversation that means the sender’s Instagram-scoped ID and username, the message text, and for any photo, video or file sent, its type and the Instagram link to it, along with timestamps.

Message text, attachment links and drafted reply suggestions are encrypted at rest with AES-256-GCM. We do not copy the media itself; the stored link points back to Instagram and expires on their side. Access is restricted to users the account owner has granted access to that specific site, and sending a reply additionally requires the manager role.

Message content is deleted automatically 180 days after it was sent. That deletion runs nightly across every stored conversation, including accounts that have been disconnected or had messages switched off, so it does not depend on an account still being in use.

Direct messages are off by default and are enabled per account by an administrator. We do not send messages automatically: a person writes or reviews and approves every reply before it is sent.

Reply suggestions and AI

Where enabled, MetrXSEO can draft a suggested reply to an Instagram message. The recent messages in that conversation are sent to Anthropic’s API to produce the draft. The suggestion is shown to a member of staff, who must choose to use it and press Send; nothing is sent on the model’s own. The model provider does not use the content to train models.

We do not use any data described in this policy for advertising, profiling, audience building or resale, and we do not use it to train our own models.

Who we share it with

Nobody, other than the infrastructure and platform providers needed to run the service: Cloudflare (hosting, database and file storage), the platforms listed above that the data comes from, Anthropic and Perplexity for the generated summaries described above, and Resend for transactional email. We do not sell data or share it with advertisers or data brokers.

How long we keep it

Reporting data is retained for as long as the business is a client, so that year-over-year comparisons remain possible. Instagram Direct message content is purged 180 days after it was sent. Sign-in records and the administrative activity log are retained for security and audit purposes. On request we will delete a business’s data entirely.

Deleting your data

From Facebook or Instagram: removing MetrXSEO under Settings → Apps and Websites sends us a deletion request automatically. On receiving it we revoke the stored credential, stop all collection for the affected accounts, and permanently delete their stored Direct message conversations. You are given a confirmation code and a status page.

By email: write to creator@3dprintcraze.com and we will do the same within 30 days. If you sent a message to a business using MetrXSEO and want that conversation removed, email us with the Instagram handle you messaged from and we will delete it.

Security

Access is per-site and role-based: a user sees only the sites they have been granted, and only managers can send messages. Passwords are hashed with bcrypt, third-party credentials and message content are encrypted at rest, sign-in is rate-limited per IP address and per account, and changing a password invalidates existing sessions. The service runs on Cloudflare Workers with data stored in Cloudflare D1 and R2.

Changes and contact

Material changes to this policy will be reflected in the date at the top of this page. Questions, requests and complaints: creator@3dprintcraze.com, IP SUBNET ZERO LLC.