Effective 3 August 2026

Privacy

Tetrameter measures the resources your AI calls consume. It does that from metadata — model names, token counts, timings — and the wire model structurally cannot carry a prompt or a completion. That is the single most important fact on this page, and the rest of it is the detail behind that claim and the places where the claim needs qualifying.

1. Two roles, deliberately kept apart

We handle two very different kinds of data and our obligations differ for each. Reading this page as though it were one thing is the quickest way to misunderstand it.

  • The website and your account. Here we are the controller: we decide what is collected and why. This covers signing in, membership of an organisation, and analytics on the marketing pages.
  • Telemetry your collector sends us. Here we are a processor acting on your instructions. You decide what your instrumentation reports and what it is labelled with; we store it, compute against it and show it back to you. If that data contains personal information about your own users, you are its controller and we act only on your behalf.

2. Who we are

Tetrameter is a product of Simpson AI Applications LLC, trading as KumoKodo. Simpson AI Applications LLC is the data controller for everything described in section 3, and the processor for everything in section 4. For anything on this page, including any request about your data, write to the contact form, choosing “a privacy or data request”, or directly to kitt@tetrameter.ai. The address is published here and nowhere else on the site, deliberately: a privacy request starts a legal clock, and it must not depend on a form working. We answer privacy requests within 30 days, and sooner where the law requires it.

3. What we collect when you use this site

We are the controller for everything in this section.

Your account

Signing in is delegated to an identity provider — Google, Microsoft Entra, or a link emailed to you. We never see or store a password. What we keep is what the provider returns and what you do here:

  • Your name, email address and avatar URL, as supplied by the provider.
  • A session record, so you stay signed in.
  • Which organisations you belong to and your role in each, plus any invitation issued to your email address.

Access is keyed on your email address. An API key is not a login and will not get anyone into a dashboard — the two credentials are separate on purpose, so a key can be handed to a build system without granting a person access to anything.

Analytics

We use Google Analytics 4 on the marketing pages only. It is not loaded on the dashboard or the evidence pack, so no organisation name, report URL or customer identifier is ever sent to Google.

It runs under Consent Mode with everything denied by default. Until you accept, no analytics cookie is set and no identifier is stored. Advertising features and ad personalisation are switched off and stay off whether you accept or not — we do not advertise, and we do not build audiences.

One honest qualification: under Consent Mode the Google tag itself is still fetched when the page loads, so Google sees the request even if you decline. What your choice controls is whether anything is stored or an identifier assigned. We would rather say that than let the banner imply more than it does.

The contact and security forms

We keep what you type — your message, and your email address where you gave one — for as long as it takes to answer you, and we reply to that address and nothing else. The security form does not require an address at all.

To rate limit them we store a salted SHA-256 hash of your IP address for 24 hours, never the address itself. It is enough to count requests from one source and useless for anything else, and it is deleted automatically. We chose that over a CAPTCHA deliberately: the obvious one is Google’s, and putting a script that profiles every visitor on these pages would contradict the paragraph above it.

The disclosure badge

Customers who publish a disclosure can put a badge on their own site, served from tetrameter.ai/badge/<org>. It is a plain image — no script, no iframe, no cookie — and we do not log who fetches it beyond what our host needs to serve the request. If you are reading this because you saw that badge somewhere: we have not recorded your visit, and a badge vendor quietly building a visitor graph across its customers’ sites is precisely the thing this product exists to argue against.

Server logs

Our host records the usual request data — IP address, user agent, path, timestamp — for operating and securing the service. We do not use it to profile anyone.

4. What your collector sends us

This is the product. Each recorded call carries the provider and model, input and output token counts, any cached or reasoning tokens, duration, the region your code ran in, the billed cost if your provider reported one, an error message if the call failed, and a trace identifier tying calls to one unit of work. Nothing else.

There is no field for prompt or completion text. This is structural rather than a policy we promise to keep: our collector strips anything that could carry content before it leaves your process, and the ingest schema has nowhere to put it. It is why storage costs a fraction of a prompt-storing vendor’s, and why we pass security reviews they fail.

The part most policies leave out

Four attribution labels — customer, feature, team and outcome — are free-form strings that you fill in. Our documentation instructs that customer be an opaque account identifier and not a name or an email address, because grouping is all it is for. But we cannot enforce that, and if you put personal data in one of those fields we will store it exactly as sent.

So: treat those four fields as though they were going into a report someone else will read, because they are. If you need something removed from them, tell us and we will remove it.

API keys

We store only a SHA-256 hash of each key, never the key itself, alongside its first few characters so you can tell one from another in the dashboard. That is also why a lost key is rotated rather than recovered — we genuinely cannot show it to you again.

5. Cookies and local storage

WhatWhyNeeds consent
Session cookieKeeps you signed in. Set only after you sign in.No — strictly necessary
Google AnalyticsCounts pages on the marketing site.Yes — denied until you accept
tm-theme, tm-consentYour light/dark choice and your answer to the banner. Browser local storage, not cookies — never sent to a server, ours or anyone’s.No

You can change your mind at any time: . Withdrawing consent is the same two clicks as giving it.

6. Legal bases (GDPR and UK GDPR)

PurposeBasis
Signing you in and running your accountContract
Storing and computing on your telemetryProcessor, on your instructions
Analytics on the marketing pagesConsent
Keeping the service up and abuse off itLegitimate interests

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

7. How long we keep it

  • Telemetry: kept until you delete it or close your account. There is no automatic expiry today. We would rather say that than quote a retention period we do not enforce — if you need one, ask and we will agree it with you in writing.
  • Account and membership records: for as long as the account exists, then deleted.
  • Sessions: expire on their own. Invitations: until claimed or withdrawn.
  • API key records: a revoked key’s row is kept, because rows it ingested reference it and erasing the record would erase the provenance of data you still hold.

8. Who else touches it

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to anyone for their own purposes. The services below process data on our behalf so the product can run:

ProcessorFor
VercelHosting and request logs
NeonThe database
GoogleSign-in, and analytics where consented
MicrosoftSign-in via Entra ID
ResendSign-in links and invitation emails

We will also disclose data where the law requires it, and will tell you unless barred from doing so.

9. Where it goes

The service is hosted in the United States and our processors are US-based. Where personal data moves from the UK or the EEA, it does so under the standard contractual clauses those providers offer, together with the UK addendum.

10. Your rights in the UK and the EEA

You have the right to:

  • ask what we hold about you and get a copy;
  • have inaccurate data corrected;
  • have data erased;
  • restrict or object to how we use it;
  • receive it in a portable form;
  • withdraw consent at any time, without affecting what happened before; and
  • complain to a supervisory authority — in the UK, the Information Commissioner’s Office (opens in a new tab); in the EEA, your national authority.

One routing note. If your request concerns telemetry sent by a company whose product you use, that company is the controller and we are its processor — so ask them, and we will act on their instruction. If you are not sure who holds what, write to us anyway and we will tell you which it is.

11. Your rights in California

Under the CCPA as amended by the CPRA, this section is also our notice at collection.

Categories we collect. Identifiers (name, email address, IP address); internet or network activity (pages viewed on the marketing site, where you have consented to analytics); and, in telemetry, commercial information about your AI usage in the form of model names, token counts and cost. We do not collect sensitive personal information, biometric data, geolocation beyond a coarse deployment region, or information about your education or employment.

Sources. You, your identity provider, your instrumented application, and your browser.

Purposes. To operate the service, authenticate you, produce the measurements the product exists to produce, secure the service, and — with consent — understand which marketing pages get read.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CPRA. We have not done so in the preceding twelve months. There is accordingly nothing to opt out of, but analytics consent is yours to withdraw at any time from the banner.

You have the right to know, delete, correct, and to opt out of sale or sharing; to limit the use of sensitive personal information (we hold none); and not to be discriminated against for exercising any of them. We do not offer financial incentives.

To make a request, write to the contact form or kitt@tetrameter.ai. We will verify it against the email address on your account, or against information only you would hold, before acting. An authorised agent may act for you with written permission we can verify.

12. Security

Everything moves over TLS. API keys are stored only as SHA-256 hashes. Every database index leads with the organisation id so the natural query shape is tenant-scoped — an unscoped read is both wrong and slow, rather than merely wrong. And the largest reduction in risk is the one at the top of this page: content we never receive cannot leak.

13. Children

This is a product sold to businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you think we have, tell us and we will delete it.

14. Changes

This notice is effective 3 August 2026. When it changes we will change the date at the top and, for anything that materially affects you, say so in the product rather than relying on you to re-read this page.

15. Contact

The contact form, or kitt@tetrameter.ai — for questions, requests, or to tell us something here is wrong. If something on this page does not match what the product actually does, that is a bug and we want to know.

Related: how the numbers are produced, and the questions with awkward answers.