Last updated: 2026-09-26
Metriqal is operated by Inventerprises AB, org.nr 559588-8578, Malmö, Sweden. Inventerprises AB is the data controller for the personal data described on this page, except where noted below that Metriqal acts as a data processor on behalf of a customer studio.
Creating a portal account via the signup form registers you directly, even while new customer onboarding is otherwise limited to a waitlist. Submitting the signup form (POST /api/portal/signup) collects: your studio name, your work email address, and either a Steam App ID or a game title (whichever you provide) plus a genre. We use this to provision your studio account, create your first tracked game record, attempt to verify your ownership of that game via public Steam data, seed an initial competitor list, and send you a one-time link by email to set your password. If you sign up again with the same email, we reuse the existing account and send a new set-password link rather than creating a duplicate.
Legal basis: performance of a contract (providing the account and service you requested).
Logging in (POST /api/portal/login) checks your email and password (stored as a bcrypt hash, never in plain text) against your account. A successful login may set an mqs_session cookie (httpOnly, secure, SameSite=Lax) that keeps you signed in; this cookie is only issued when session-cookie support is enabled on our infrastructure. The portal app also keeps your account's session key in your browser's local storage so the portal can authenticate your requests.
Legal basis: performance of a contract.
While Metriqal is in closed-signup mode, the "join the waiting list" form (POST /api/closed-signup-waitlist/join) collects your email address, and optionally your studio name, game title, and which page you signed up from. Separately, the "talk to sales" and general landing-page waitlist form (POST /api/waitlist) collects your email address, and optionally your studio name, role, and the pricing tier you asked about; if configured, this is stored in our file storage and may trigger a confirmation email to you and an internal alert email to our sales inbox. We use this data to follow up about product access or a sales inquiry, and for nothing else.
Legal basis: legitimate interest (responding to your enquiry about our product).
We use Vercel Web Analytics on our public pages to measure aggregate page views. We do not set our own tracking cookies for this; it is Vercel's built-in analytics script.
Legal basis: legitimate interest (understanding aggregate site usage).
If your studio receives our weekly digest email, it contains a 1x1 tracking pixel. If it loads, we record that the digest for that tenant and week was opened, so we can measure whether the digest is actually being read. The pixel request is authenticated with a signed token tied to your account and week, not a generic tracker.
Legal basis: legitimate interest (measuring whether a feature we send you is useful).
Public, unauthenticated endpoints (signup, waitlist, login) apply a short-lived per-IP request limit to prevent automated abuse. This is held in server memory only, is not persisted to a database, and is discarded automatically after the limit window (typically minutes to an hour).
Legal basis: legitimate interest (keeping the service available and preventing abuse).
| Name | Purpose | Set when |
|---|---|---|
| mqs_session | Keeps you signed in to the studio portal (httpOnly, cannot be read by page scripts) | After a successful portal login, if session-cookie support is enabled |
| Portal session key (browser local storage) | Lets the portal app authenticate your API requests from the browser | After a successful portal login or signup |
| Vercel Web Analytics | Aggregate, cookieless page-view counting | On every public page load |
We use the following processors to run the service. They process the data on our behalf to provide these functions.
Some of the processors above, including our hosting, database, email, and AI providers, are headquartered in, or may process data in, the United States. The safeguards that apply, as stated in each provider's own documentation (accessed 2026-09-26):
If you would like a copy of the relevant terms, contact us using the address below.
If you integrate Metriqal's telemetry SDK into your game, your players' game clients send gameplay telemetry events to our ingest endpoint. For this data, Metriqal acts as a data processor on your (the studio's) behalf. You are the controller for your players' data, and we process it only to provide the analytics service to you. The accepted fields are: a game identifier, a build/version tag, a player identifier (required to be a randomly generated ID, not a studio-internal identifier such as a real name or account ID; we validate its format and flag values that look non-random, such as an all-zero placeholder), a session identifier, an event type, a free-form event-data object you define, a client-side timestamp, a schema version, an optional traffic-source label, and an optional client-generated event ID used to prevent duplicate delivery. We do not inspect or validate the contents of the free-form event-data field beyond size and structure limits; what it contains is determined by what your game sends.
We keep your data while your account or waitlist entry is active. We do not automatically delete raw data based on its age. The one exception is a small number of narrowly scoped records, such as expired or revoked report share links, which are deleted automatically once they are no longer valid, because they are recreatable credentials rather than raw data.
To request deletion, email alexander@metriqal.se. Requests are handled manually, and we aim to respond within one month. Deleting a studio account removes the account record, your sign-in sessions and tokens, and the list of games you track; shared public game-catalog entries for those games are kept, because other studios may track the same games and rely on that shared record. Waitlist and sales-contact entries can be deleted on request. Telemetry sent through the SDK is processed on the studio's behalf (see "Data your players send us through the SDK" above); a studio may request erasure of all of its own accumulated telemetry, or of one player's telemetry on that player's own request to the studio, and we erase the matching data on request.
Under the GDPR, you have the right to:
For any privacy request or question, email alexander@metriqal.se.