Security at Metena
Last updated: September 2026
Metena is built to analyze, never to act on your behalf. Here is, concretely, how your access and your data are protected.
Read-only, by design
Your platforms and wallets are connected in read-only mode. The app reads your balances to calculate your real exposure, and nothing more.
- No orders: Metena cannot buy or sell on your behalf.
- No withdrawals: no connection grants the right to move your funds.
- No transaction key is ever requested.
Your API keys, encrypted
A read-only API key is still sensitive data. We treat it as such.
- AES-256-GCM encryption before any storage.
- The master encryption key is kept only on the infrastructure server and is never shared with a third party.
- Your keys are deleted immediately when you disconnect a platform.
Communications and access
- Transport: HTTPS/TLS 1.3 on all communications.
- Authentication: signed JWT via Supabase Auth (HS256).
- Server access: SSH key authentication only.
- No plaintext passwords in logs.
Where your data is hosted
Every service has an identified host and location.
| Service | Host | Location |
|---|---|---|
| Backend API + database | Hostinger VPS | Manchester, United Kingdom |
| Authentication + PostgreSQL | Supabase | EU West region (Frankfurt) |
| Analytics | PostHog CE (self-hosted) | Hostinger, Manchester, United Kingdom |
| LLM (request processing) | Mistral AI | France (EU) |
Your data is hosted exclusively in Europe (European Union and United Kingdom).
What we do with your data
- Metena does not sell or rent your personal data.
- Your questions to the Owl and your strategy context are sent to Mistral AI (France) to generate answers. They are not stored after processing, according to Mistral AI's policy.
- Usage measurement is aggregated and anonymized, never resold.
What we do not collect
- Biometric data
- Precise geographic location
- Contacts, photos, or files from your device
- Browsing history outside the application
How long we keep your data
| Data | Retention |
|---|---|
| User account and associated data | Until account deletion + 30 days |
| Exchange API keys | Deleted immediately upon disconnection |
| Server logs | Rolling 7 days |
| Anonymized analytics events | 24 months |
Your rights and your control
Under the GDPR, you can at any time:
- Access your data and obtain a copy.
- Correct inaccurate data.
- Erase your account and all your data.
- Retrieve your data in a structured format.
- Object to its use for analytics purposes.
To exercise these rights (answer within 30 days at most), write to privacy@metena.app
Our limits, stated plainly
- Metena is a decision-support and financial education tool, not investment advice.
- The AI can be wrong: uncertainty is displayed rather than hidden, and every claim in the brief points to its source.
- No system is infallible.
Think you have found a vulnerability? Write to us: privacy@metena.app
An analysis that never touches your funds.
Try Metena free for 7 days: read-only connections, no commission, cancel anytime.
Download the app · 7 days free