Privacy Policy — MetraForge
Last updated: 10 September 2026
MetraForge is operated by Telos Labs Private Limited (“Telos Labs”, “we”, “us”), Flat N-501, V3S Indralok, Plot GH 1, Indirapuram, Makanpur, Ghaziabad 201014, Uttar Pradesh, India.
MetraForge is business software for manufacturers. It is sold to organisations, and accounts are created by an organisation’s administrator — you cannot sign yourself up. This policy explains what we do with data in the MetraForge mobile and web applications.
1. What we collect
Account information. Your name, email address, and a hashed password. We create this record when your organisation invites you. We also store session information so you stay signed in.
Business records you enter. Everything you create in the app: customers, suppliers, quotations, sales orders, invoices, payments, inventory and stock movements, work orders, bills of materials, machines and production lines, and your company profile. Some of these records contain personal data about other people — for example a customer’s contact name, phone number, or GSTIN.
Files you upload. Documents and images you attach to records.
Activity records. An audit log of significant actions taken in your organisation’s workspace, used for accountability and troubleshooting.
Technical information. Server logs containing IP address, request paths, and timestamps, kept for security and debugging.
We do not collect location data, contacts, photos beyond files you explicitly attach, advertising identifiers, or behavioural analytics. The app contains no advertising and no third-party tracking or analytics SDKs.
2. Why we use it
To provide the service: authenticating you, storing and returning your organisation’s records, generating documents such as invoices and quotations, and running the features you use. To keep the service secure and working: diagnosing faults, preventing abuse, and maintaining the audit trail. To contact you about the service where necessary.
We do not sell your data, and we do not use your business records to train machine-learning models.
3. Where your data goes
Your organisation’s business data is stored in a database dedicated to your organisation — MetraForge does not put multiple customers’ records in shared tables.
We use the following service providers, who process data on our behalf:
| Provider | Purpose | Where | What it sees |
|---|---|---|---|
| Neon | PostgreSQL database hosting | AWS Singapore (ap-southeast-1) | All stored records |
| Cloudflare R2 | File attachment storage | Cloudflare’s global network | Files you upload |
| OpenAI | The in-app AI assistant (see section 4) | United States | Only what that feature sends |
| DigitalOcean | Application servers | London, United Kingdom | Data in transit and in memory |
Your data is stored and processed outside India. Records are held in Singapore, application servers run in the United Kingdom, uploaded files are stored on Cloudflare’s global network, and the AI assistant sends data to the United States. We rely on these providers’ contractual and technical safeguards to protect data in transit and at rest. If your organisation needs data to remain in India, tell us before you begin using MetraForge.
4. The AI assistant
MetraForge includes an AI assistant. When you use it, we send your message and the business records relevant to your question to OpenAI, which generates the response. If you ask the assistant to read a document you upload, that document is sent to OpenAI as well.
Two things worth being explicit about:
- The assistant can only read data you already have permission to see. It runs against a read-only view of your organisation’s database and respects your role’s permissions.
- We do not store your conversations with the assistant. Messages are processed in the moment and are not written to your organisation’s database.
OpenAI does not use data sent through its API to train its models. Prompts and responses may be retained by OpenAI for up to 30 days for abuse monitoring and are then deleted.
The assistant cannot currently be switched off at an organisation level. If that matters to your organisation, contact us at teloslabspvtltd@gmail.com before you begin using MetraForge.
5. Who the data belongs to
When your organisation uses MetraForge, your organisation decides what data is entered and why. Telos Labs stores and processes it on your organisation’s instructions. If you are an employee using MetraForge and you have a question about why particular data is held, ask your organisation’s administrator first — they control it, and they can correct or remove records directly in the app.
For personal data about third parties that your organisation enters — your customers’ and suppliers’ contact details, for instance — your organisation is responsible for having a lawful basis to hold it.
6. How long we keep it
Business records are kept for as long as your organisation’s account is active, because they are your organisation’s operating records. MetraForge uses soft deletes: when you delete a record in the app it is marked inactive and hidden rather than immediately erased, so it can be recovered and so historical documents remain consistent.
When an organisation’s account ends, we keep its data for 90 days so the organisation can export records or reinstate the account, then permanently delete the database and the stored files.
Server logs are kept for 90 days.
7. Security
Data is encrypted in transit using HTTPS. Passwords are stored hashed, never in plain text. Sessions use HttpOnly cookies. Each organisation’s records live in a separate database, so a query in one organisation’s workspace cannot reach another’s. File download links are short-lived and expire after five minutes. Access within your organisation is governed by the roles and permissions your administrator sets.
No system is perfectly secure, and we do not claim otherwise.
8. Your rights
Under India’s Digital Personal Data Protection Act, 2023, you may ask to access the personal data we hold about you, ask us to correct it, ask us to erase it, and nominate someone to exercise these rights on your behalf.
Most of these you can do directly in the app — your profile is editable, and your administrator can update or remove your account.
To delete your account and its personal data, use Settings → Request account deletion in the app, or write to us at teloslabspvtltd@gmail.com. We will confirm and complete the deletion within 30 days. Deleting your account removes your personal data; the business records your organisation owns remain with your organisation, which controls them. Full details are on our account deletion page.
9. Children
MetraForge is business software and is not directed at children. We do not knowingly collect data from anyone under 18.
10. Changes
If we change this policy we will update the date at the top and, for significant changes, notify organisation administrators by email.
11. Contact
teloslabspvtltd@gmail.comTelos Labs Private Limited
Flat N-501, V3S Indralok, Plot GH 1, Indirapuram, Makanpur,
Ghaziabad 201014, Uttar Pradesh, India