Privacy Policy
Effective date: 19 September 2026 · Last updated: 19 September 2026
Who we are
Metacenta is published by Sico Software Ltd, a company registered in Scotland. Metacenta produces a Data & AI technical review of a dbt project and its repository. It reads named artefacts you send and repository metadata; it never connects to a warehouse and never reads production data. We are registered with the UK Information Commissioner's Office (ICO) — registration number ZC106029. Privacy questions: privacy@sico.software.
Data we collect
Account data. Your email address, and your name if you give us one, held so you can sign in and retrieve your review. Access is by invitation only — there is no signup — and an address we have not invited never receives a sign-in link. We also record when you last signed in.
dbt artefacts you send us. manifest.json, and optionally run_results.json, sources.json and catalog.json. These describe the structure of your project: models, sources, tests, columns, and what your last build did. They are read to produce the review.
Repository metadata. Through a read-only token you supply: the file tree, languages, contributor counts and which CI configuration exists. Nothing is cloned. The only file contents ever fetched are named dbt configuration files (dbt_project.yml, packages.yml). profiles.yml is excluded by filename, because it is the one dbt file that holds warehouse credentials.
The findings. The review, the per-finding worklist and the PDF as delivered. These are held per client with database-level isolation, so one client's findings are not reachable from another client's session.
Enquiries. What you type into the enquiry form on our front page — your email address, optionally your company, and what you tell us about your stack. Used to reply to you. There is no mailing list.
How we use your data
- To produce the technical review you commissioned, and to let you retrieve it later
- To confirm who you are when you sign in, and to show your colleagues' access on your own team list
- To reply to an enquiry you sent us
AI processing. By default the review runs with ZERO calls to any language model, and a run with none produces the complete document. An optional interpretive pass sends a findings DIGEST — check identifiers, severities, counts, and example model, source and file names — to a third-party model provider. It is off unless you agree to it, the report states what was sent, and owner names and email addresses are excluded from it by construction rather than by filtering. No file contents, no SQL and no query results leave our systems on either path. A run_results.json does contain compiled SQL; it is read for pass/fail status and discarded at the boundary, never stored and never sent anywhere. The lawful basis for this processing is contract performance — it is necessary to deliver the service you signed up for.
Data sharing
We do not sell your data. We share data only with sub-processors required to operate the service:
- Anthropic — The optional interpretive pass over the findings digest, only where you have agreed to it. Never receives file contents, SQL or query results.
- GitHub — Read via a read-only token you supply, to collect repository metadata. We send them nothing about you.
- SuperTokens — Self-hosted authentication. Holds the email address you sign in with.
- Hetzner Online GmbH — our VPS provider (Germany, EU). All personal data is stored on this server.
- Resend Inc. — transactional email (account and billing notifications).
- PostHog Inc. — product analytics (page views, feature usage; no personal data).
- Sentry Inc. — error monitoring (stack traces; personal data scrubbed before transmission).
Data retention
We keep your review and the artefacts' derived findings for as long as the engagement is live and you want to be able to retrieve them. Ask and they are deleted — there is no period we are obliged to keep them for. The artefacts you sent are not retained beyond producing the review; what is retained is the findings and the documents built from them.
Your rights under UK GDPR
As a UK resident you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Restriction — ask us to limit how we process your data
- Objection — object to processing based on legitimate interests
To exercise any right, email privacy@sico.software. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
Security
All data is transmitted over TLS. Our server (Hetzner, Germany) is access-controlled via SSH key and Tailscale VPN. Integration credentials and API keys are encrypted at rest using pgcrypto symmetric encryption.
Cookies
We use one strictly necessary session cookie to keep you logged in. We do not use advertising or tracking cookies. PostHog analytics uses a first-party cookie; it does not track you across other sites.
Changes to this policy
Material changes will be communicated by email and by updating the effective date above. Continued use of the service after notification constitutes acceptance.
Contact
Sico Software Ltd · privacy@sico.software