Privacy Policy

Last updated July 29, 2026

This Privacy Policy explains how Metryx, operated by Neighbors Enterprises LLC ("Metryx", "we", "us", or "our"), collects, uses, and shares information when you use our Service. By using the Service, you agree to this policy.

1. Information we collect

  • Account information you provide, such as your name and email address.
  • Discord data from servers you connect, collected through the Metryx bot: message and activity metadata, member and role information, voice activity, moderation events, and invite data used to produce your analytics.
  • Instagram data from the professional account you connect, retrieved from Meta with your permission: your account profile, media, insights, comments, and, if you turn those features on, direct messages and the posts you schedule. Section 2 spells out exactly what we pull and how long we keep it.
  • Usage information, such as how you interact with the dashboard, for security and to improve the Service.
  • Payment information, handled by our payment processor, Stripe. We do not store full card details.

2. Instagram and Meta platform data

When you connect an Instagram professional account (Business or Creator), you sign in through Instagram and grant Metryx a set of permissions. Everything below comes from Meta Platforms, Inc. through the Instagram API with Instagram Login, and only for accounts you connect yourself.

  • Account profile: your Instagram user id, username, display name, profile picture, follower and following counts, and post count.
  • Media: your posts, reels, and stories, including captions, media type, permalinks, and publish times.
  • Insights: account and per-post metrics such as views, reach, accounts engaged, likes, comments, saves, shares, profile views, link taps, watch time, and story navigation. Also aggregate follower and engaged-audience demographics by age, gender, country, and city, which Instagram reports only as counts and never as named people.
  • Comments on your posts, including the text, the commenter's username, and the timestamp, so you can read, reply to, hide, or delete them and so the comment rules you set up can act on them.
  • Direct messages, only if you turn on messaging features. When you enable the inbox or a DM auto-responder, we receive and store messages sent to your account, including the sender's username and the message text, so a rule can reply and so you can see the thread. Leave those features off and we do not store your DMs.
  • Content you schedule: the captions, images, video, alt text, tagged usernames, and collaborator handles you upload to Metryx for publishing. We hold that until the post publishes or you delete it, and we hand it to Meta at publish time.

Snapshots and history. Instagram's own insight windows are short, and per-post metrics carry no history at all, so Metryx keeps its own record. We capture follower counts hourly, roll each day into a daily account snapshot, and re-capture post metrics on a decaying schedule (hourly for the first couple of days, then roughly daily, then weekly). That is what your charts, reports, and health scores read from, and we keep it for as long as your account is active so your history does not disappear when Meta's window closes. On first connect we also pull the roughly 30 days of daily figures Meta still remembers.

Your Instagram access token is encrypted at rest, stored separately from your analytics, and used only for the API calls the features you enabled actually need. Disconnecting deletes it. We do not sell Instagram data, we do not share it with advertisers, and we do not use it for anything other than running the features you turned on.

3. How we use information

  • to provide, maintain, and improve the Service;
  • to generate the analytics, reports, and insights you request;
  • to process payments and manage subscriptions;
  • to communicate with you about your account, security, and (with your consent) product updates;
  • to detect, prevent, and address abuse or technical issues.

4. Our role: controller and processor

Metryx wears two hats, depending on whose data is involved.

  • For your own account, billing, and usage data, we are the controller: we decide why and how that data is processed, and this policy is our direct commitment to you.
  • For data about other people, meaning the members of a Discord server you connect or the people who comment on and message your Instagram account, we act as a processor (or "service provider" under some laws) on behalf of the customer who connected the server or account. We process that data only to provide the Service they configured, following their instructions and settings.

6. AI-assisted moderation

When a server enables Metryx's AI-assisted moderation (automod), we process message content and member activity to evaluate it against the rules the server owner configured, and, where enabled, to take automated action such as a warning, mute, kick, or ban. We keep a record of these decisions (a moderation case) so the action can be reviewed, appealed, or reversed.

This processing happens as part of our processor role described above: we act on the server owner's configured rules, not on our own independent judgment about any individual. Someone actioned by an automated decision can request human review through the appeal tools built into the Service.

7. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share it only with service providers (subprocessors) who help us run the Service, under contracts that protect your data, including:

  • Clerk, for authentication;
  • Stripe, for payments;
  • our hosting, storage, and database providers, to run the Service;
  • Discord, to the extent required to operate the bot;
  • Meta Platforms, to the extent required to operate the Instagram features you connect, including publishing a post you scheduled and sending a comment reply or DM that a rule you configured triggers.

Discord and Meta are also sources of information, not just recipients. Your Discord analytics are built from what the bot observes in the server you connect, and your Instagram analytics are built from what Meta returns for the account you connect. Both platforms have their own privacy policies covering what they do with your data on their side.

We may also disclose information if required by law, to protect our rights or users, or in connection with a merger, acquisition, or sale of assets.

8. Data retention

We keep information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Because the point of Metryx is history that outlives what a platform will tell you, daily snapshots and rollups stay in place while your account is active. When you disconnect a server or account, or delete your Metryx account, we delete or de-identify the associated data within a reasonable period, except where retention is required by law. The next section covers how to do that.

9. Deleting your data

You can delete your data yourself, from inside the app, at any time.

  • Disconnect Instagram or Discord. Open Settings, then Connection, and disconnect the account or server. For Instagram we delete the stored access token right away and stop calling Meta entirely. Your collected history is kept so that reconnecting picks up where you left off. If you want the history gone too, delete the profile or your account, or email us.
  • Delete a profile. Open Settings, then Details, and use the danger zone. This removes the profile and everything collected under it: connections, tokens, Instagram snapshots, media, comments, messages, and scheduled posts.
  • Delete your account. Open Settings, then Personal details, and use the danger zone at the bottom. This cancels any active subscription, deletes every profile you own along with all platform data under them, removes you from profiles other people own, and deletes your login. It is not reversible. The mobile app offers the same thing.
  • Ask us to do it. Email privacy@nbrs.app from the address on your account and tell us what you want deleted. We will confirm the request and complete it within 30 days.

You can also revoke Metryx's access from your Instagram settings, or from Apps and Websites in your Facebook settings. That cuts off our access immediately and we stop collecting. It does not by itself remove what we already collected, so email privacy@nbrs.app if you want that removed as well.

10. Security

We use reasonable technical and organizational measures to protect your information, including tenant isolation and encryption in transit. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To make a request, contact us at privacy@nbrs.app. We will not discriminate against you for exercising these rights.

12. California privacy rights

If you are a California resident, the CCPA gives you the right to know what personal information we collect, request deletion or correction of it, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. To exercise any California privacy right, contact privacy@nbrs.app.

13. Requests from server members

If you are a member of a Discord server that uses Metryx, but you don't have a Metryx account yourself, the server owner is generally the right party to contact first, since they control how the Service is configured for their community. You can also contact us directly at privacy@nbrs.app, and we will assist consistent with our role as a processor, including routing your request to the relevant server owner where required.

14. Marketing communications

If you opt in to product updates, you can unsubscribe at any time using the link in those emails or by contacting us. Account and service messages are not marketing and may still be sent.

15. Cookies

We use cookies and similar technologies that are necessary to sign you in, keep you signed in, and operate the Service. We do not use them to sell your data or serve targeted advertising.

16. Children

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

17. International users

We may process and store information in countries other than your own, including the United States. Where we transfer information, we take steps to ensure it remains protected consistent with this policy.

18. Data breach notification

If we become aware of a security incident that compromises your personal information, we will notify affected users and, where required, the relevant regulator, without undue delay and in accordance with applicable law.

19. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice. Your continued use of the Service after changes take effect means you accept the updated policy.

20. Contact

Questions about this policy or your data? Contact us at privacy@nbrs.app. See also our Terms of Service.