Security
We take thinking seriously.
Nobody asked sees another person's answer, and only what each person approves reaches you. Four guarantees hold this in the code, and a test fails if one is removed.
Asked alone.
Each person is interviewed on their own. Nobody else who was asked sees their answer or their name, and they never see anyone else's.
- How the code holds it
Every read a link makes goes through that person's own scope, and the database decides which rows it may return. What reaches their interview is typed as public or their own, so text written from other people's answers cannot be handed to it. Only a follow-up you send carries the page to a person, leaving out what only one other person said unless you keep it.
lib/data/respondent-scope.tslib/prompts/context.tslib/grow/declassify.tssupabase/migrations/0001_metafora.sql
- How we check it
A test plants one person's words and follows every call made for somebody else; the words must never arrive. Others read the database's own policies, and refuse any code on a link's path that could read another person's rows.
tests/isolation-fixtures.test.tstests/data-fixtures.test.ts
Nothing is sent without their approval.
At the end, each person reads their answer written back to them, and it is sent only if they approve it. When they send it, the conversation itself is deleted in the same step. If they stop before sending, it is deleted after 30 days.
- How the code holds it
The approved answer is the only record kept of an interview. The one function that stores it deletes the conversation in the same database transaction, and a sweep every night deletes the unfinished.
lib/data/contribution.tslib/data/drafts.tsapp/api/cron/retention/route.ts
- How we check it
A test sends an answer and checks that nothing crossed before Send and that the conversation is gone after it. Another leaves an interview past the window and runs the sweep.
tests/about-fixtures.test.ts
Nobody edits what they said.
Nobody types the page or edits what people said. Every sentence on it is written from their answers, each person approves their own, and there is no text editor anywhere in the product.
- How the code holds it
The request that writes the page carries no text, only the instruction to write it. A link files the question a person picked by its number, never its words, and a stored answer's text cannot be changed.
app/api/c/finish/route.tsapp/api/i/[token]/join/route.tslib/data/contribution.ts
- How we check it
A test posts a typed sentence to both entry points under every field name they have ever taken, then reads the stored rows back. The sentence must be in none of them.
tests/law-fixtures.test.ts
What they write never steers the AI.
What people write reaches the AI marked as something they said, never as an instruction to follow: the guard against prompt injection.
- How the code holds it
Every answer is cleaned where it enters: the product's own control marks are disarmed and the words are kept. Each prompt then carries it inside testimony marks that a person's text cannot close.
lib/prompts/context.ts
- How we check it
A test sends an answer that forges the control marks and the closing mark. Each must be disarmed, and every word the person wrote must survive.
tests/context-fixtures.test.ts
When we write to them
When Metafora writes to the people you ask.
Only after you send the link
Metafora writes to the people you ask only after a person sends a link: shared by hand, mailed with Send, or a follow-up you approve. Metafora reminds a mailed link at most twice, and you can turn that off.
Your account
What you can do with what is yours.
No passwords
You sign in with Google or with a code sent to your email. We never hold a password.
Your AI tools read only yours
The link that connects your AI tools is shown once and can be replaced at any time. It reads your own Metaforas and answers — never anybody else's.
Delete everything that is yours
Deleting your account deletes every Metafora you made and the account itself, and your session stops working at once. What other people answered stays theirs.
Who processes data for us
Metafora runs on these providers, who process data on our behalf. What each says about its own handling is under its name.
OpenAI
The language models that interview and write. Every call is made through OpenAI's API with storage turned off.
OpenAI states that API data is not used to train its models unless a customer opts in. It may keep logs for up to 30 days to monitor abuse.
Supabase
The database and sign-in.
Supabase states that data is encrypted at rest (AES-256) and in transit (TLS).
Vercel
Hosting: the pages and the server code.
Vercel states that data is encrypted at rest and in transit.
Resend
Email: links, confirmations and notifications.
Resend states that it is SOC 2 Type II compliant.
Stripe
Billing, for accounts that pay.
Upstash
Rate limits, so that nobody can flood a link.
What we don't do
No analytics
This site carries no analytics and no advertising trackers.
No training
We do not train models on what people say.
No words in our logs
Our logs record which step ran and when — never a word anybody said.
Questions, or a problem to report
If you have found a security problem, tell us before anyone else.
Write to us