Metralis, Inc. provides Noren, a business software platform that connects a manufacturer’s existing ERP systems, databases, spreadsheets, email, and other operational applications and enables chat, custom applications, and AI-powered workflows.
This Privacy Policy explains how Metralis, Inc. (“Metralis,” “Noren,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information.
This Privacy Policy applies to:
- The Noren website at
withnoren.com; - The interactive demonstration at
demo.withnoren.com; - Noren customer portals and applications;
- Sales, scheduling, support, and other communications with Metralis; and
- Other Metralis services that link to this Privacy Policy.
This Privacy Policy does not govern the independent privacy practices of our customers or third-party websites and services.
1. Our Role When Processing Information
Noren is a business-to-business service primarily used by employees and authorized users of our customers.
When Metralis processes information from a customer’s connected systems or workspace, Metralis generally acts as a service provider or processor on behalf of that customer. The customer determines which systems and information are connected, which employees receive access, and how the information is used.
Metralis independently determines how it processes information relating to website visitors, demo visitors, sales prospects, account administration, service security, and Metralis’s own business operations.
If you use Noren through your employer or another organization, that organization may be responsible for responding to requests concerning information it controls.
2. Information We Collect
The information we collect depends on how you interact with Noren.
Contact and business information
We may collect:
- Your name;
- Work email address;
- Telephone number;
- Employer or company name;
- Job title or business role;
- Information submitted when booking a meeting;
- Communications with our sales or support teams; and
- Your marketing and communication preferences.
Meeting scheduling may be provided through Cal.com or another scheduling provider. Information submitted through that service is also subject to the provider’s privacy practices.
Account and workspace information
When a customer creates or manages a Noren account, we may collect:
- Name and work email address;
- Employer and workspace membership;
- Account role and permissions;
- Authentication identifiers;
- Account and integration settings;
- Application access and grants;
- Login, session, and account activity; and
- Administrative and audit records.
A customer’s administrators may create, manage, suspend, or remove accounts and may view information about account permissions, applications, and activity within the customer’s workspace.
Interactive demo information
The Noren interactive demo uses synthetic business data. It does not provide access to a real customer environment.
When you enter or use the demo, we may collect:
- Your email address;
- The date and time of your first and most recent visits;
- Your number of visits;
- Your IP address;
- Browser and device information;
- The page or source that referred you to the demo;
- Prompts, questions, and instructions you submit;
- Applications, code, and other content generated through your use of the demo;
- Feature usage and actions taken in the demo; and
- Security, audit, and misuse-prevention records.
We may use the email address submitted through the demo to contact you about Noren, including for sales follow-up and product communications. You may opt out of marketing communications at any time.
The demo is a shared sandbox. Visitors must not submit confidential, sensitive, regulated, or real production information.
Customer and connected-system information
At a customer’s direction, Noren may connect to and process information from business systems such as ERP systems, databases, spreadsheets, email accounts, and operational applications.
Depending on the systems selected by the customer, this information may include:
- Employee names and work contact information;
- Customer and vendor contact information;
- Business email messages and attachments;
- Orders, quotes, invoices, and transaction records;
- Inventory, purchasing, maintenance, quality, and production records;
- Application records and user-generated content;
- Documents and spreadsheets;
- Operational activity and audit records; and
- Other business information selected by the customer.
Customers and users are prohibited from submitting Social Security numbers, payment-card information, personal financial credentials, health information, biometric information, information about children, or other sensitive personal information unless Metralis has expressly agreed in writing to process that information.
Email and other integrations
If a customer enables an integration and a user connects an account, we may collect the provider name, connected account email address, authorized permissions, and encrypted authentication tokens.
For Gmail and Microsoft Outlook integrations, Noren may retrieve email metadata, message contents, and attachments and may create drafts or send messages when directed by an authorized user and permitted by the relevant application.
Information obtained through an integration is used to provide the customer-requested functionality and is subject to the customer’s configuration and permissions. Users may disconnect their integrations.
AI inputs and outputs
Noren may collect and store:
- Questions and prompts;
- Uploaded spreadsheets, documents, or attachments;
- Information retrieved from authorized customer systems;
- AI-generated responses;
- Generated application code;
- Application plans, edits, and review information; and
- Usage information, including the model used and token consumption.
Information collected automatically
When you access our website, demo, or services, our systems and hosting providers may automatically collect:
- IP address;
- Browser type and device information;
- Operating system;
- Access date and time;
- Requested pages and features;
- Referring page;
- Session identifiers;
- Error and diagnostic information;
- Security events; and
- Application and account activity.
The public Noren website does not currently use advertising pixels, third-party analytics, or cross-site behavioral tracking technologies.
3. How We Use Information
We may use personal information to:
- Provide, operate, maintain, and secure Noren;
- Authenticate users and manage accounts, permissions, and integrations;
- Connect and represent customer-authorized business systems;
- Build, customize, deploy, and support customer applications;
- Provide chat, document, email, and AI-powered features;
- Generate application code, documentation, and data descriptions;
- Respond to questions and provide customer support;
- Schedule demonstrations and communicate with prospective customers;
- Send sales follow-up and product communications;
- Monitor service performance, reliability, and usage;
- Detect, investigate, and prevent fraud, abuse, security incidents, and unauthorized access;
- Maintain audit trails, backups, and disaster-recovery procedures;
- Enforce our agreements and acceptable-use requirements;
- Comply with legal obligations and lawful requests;
- Protect the rights, safety, and property of Metralis, our customers, users, and others; and
- Support a financing, merger, acquisition, restructuring, or sale of all or part of our business.
We may create aggregated or deidentified information that cannot reasonably be linked to an individual. We may use this information for analytics, service improvement, security, and other lawful business purposes. We will not attempt to reidentify information that has been properly deidentified, except to test the effectiveness of our deidentification measures where permitted by law.
4. Artificial Intelligence Providers
Noren uses third-party AI model providers, which may include OpenAI, Anthropic, and other providers selected or configured to deliver Noren features.
Information sent to these providers may include prompts, authorized customer information, document contents, application requirements, and related context needed to produce the requested output.
Metralis does not use customer data to train generalized AI models. Metralis uses commercial AI services and configurations intended to restrict providers from using customer data for generalized model training. AI providers process information according to their agreements with Metralis and their applicable service terms.
Customers and users are responsible for ensuring that information submitted to an AI feature is authorized and appropriate for processing.
5. How We Disclose Information
We may disclose personal information in the following circumstances.
Service providers
We disclose information to vendors that help us provide and operate Noren. These vendors may include:
- Microsoft Azure and other infrastructure, hosting, storage, authentication, and backup providers;
- OpenAI, Anthropic, and other AI model providers;
- GitHub and other source-code hosting and development providers;
- Cal.com and other scheduling providers;
- Google and Microsoft for user-authorized email and account integrations;
- Email delivery and communication providers; and
- Security, monitoring, professional-services, and operational vendors.
These providers may process information only for the services they provide to Metralis, subject to their contractual obligations and applicable law.
Customers and customer administrators
If you use Noren through an organization, we may disclose your account, permissions, applications, and activity information to that organization and its authorized administrators.
Connected services
We may send information to Gmail, Outlook, an ERP system, or another service when an authorized user or customer directs Noren to interact with that service.
Legal and safety purposes
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law, legal process, or a valid governmental request;
- Enforce an agreement or protect legal rights;
- Detect, investigate, or prevent fraud, abuse, or a security incident; or
- Protect the safety, rights, or property of Metralis, our customers, users, or others.
Business transactions
We may disclose information in connection with a financing, due diligence process, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction. Any recipient would be required to handle personal information consistently with applicable law and any commitments that continue to apply.
At your direction
We may disclose information with your consent or at the direction of you or the relevant customer.
6. No Sale or Targeted Advertising
Metralis does not sell personal information.
Metralis does not share personal information for cross-context behavioral advertising and does not use personal information to deliver targeted advertising based on activity across unrelated websites or services.
8. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
The applicable retention period depends on factors such as the type and sensitivity of the information, the customer relationship, contractual requirements, security needs, legal obligations, and the risk of harm from unauthorized use or disclosure.
In general:
- Customer data is retained during the customer relationship and is returned or deleted according to the customer agreement or written instructions.
- Account, application, prompt, document, integration, and operational records are retained while needed to provide and secure the service.
- Demo contact information is retained while reasonably useful for follow-up, unless the individual opts out or requests deletion.
- Security and audit records may be retained for longer periods when needed to investigate incidents, maintain audit integrity, resolve disputes, enforce agreements, or comply with law.
- Financial, contractual, and business records may be retained as required for accounting, tax, legal, and compliance purposes.
- Backup copies remain until overwritten or deleted through normal backup and disaster-recovery processes.
When information is no longer required, we may delete it, anonymize it, or securely isolate it from further use until deletion is possible.
9. Security
Metralis uses technical, organizational, and physical safeguards designed to protect personal information.
These safeguards include, as applicable:
- Encryption of customer data in transit and at rest;
- Authentication and access controls;
- Separation between customer environments;
- Role-based permissions;
- Encrypted storage of integration credentials;
- Audit trails for important activity;
- Human approval before important production actions;
- Backups and disaster-recovery procedures;
- Security testing, including penetration testing; and
- Procedures intended to detect and respond to unauthorized access.
No system is completely secure. We cannot guarantee that information will never be accessed, altered, disclosed, or destroyed without authorization.
10. Your Choices and Privacy Rights
You may unsubscribe from marketing emails by using the unsubscribe instructions in the message or by contacting us.
Depending on where you live and the law that applies, you may have the right to request that we:
- Confirm whether we process your personal information;
- Provide access to or a copy of your personal information;
- Correct inaccurate personal information;
- Delete personal information;
- Explain the categories of information we collect and disclose; or
- Honor another privacy right provided by applicable law.
You may submit a request by emailing mahmoud@withnoren.com.
Metralis may offer access, correction, or deletion when reasonably possible even when a specific privacy law does not require it.
We may need to verify your identity and authority before completing a request. We may retain information when required by law or when an exception applies, including for security, fraud prevention, legal claims, contractual obligations, and audit integrity.
If your information is controlled by your employer or another Noren customer, we may refer your request to that organization. Metralis will assist customers with valid requests as required by contract and applicable law.
We will not discriminate against an individual for exercising an applicable privacy right.
11. Third-Party Services
Our website and services may link to or integrate with third-party services. Examples include Cal.com, Google, Microsoft, and customer-selected business systems.
Metralis does not control the independent privacy practices of those services. You should review their privacy policies before providing information or connecting an account.
12. Children’s Privacy
Noren is intended exclusively for adults and business users. It is not directed to children or designed for use by anyone under 18 years of age.
We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us at mahmoud@withnoren.com. If we determine that we collected the information inappropriately, we will take reasonable steps to delete it.
13. United States Service
Noren is currently offered to customers and users in the United States. Information is primarily processed and stored in the United States.
Some service providers may process information from other locations as part of their global operations. Where required, Metralis uses appropriate contractual and organizational safeguards for such processing.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, practices, technology, or legal obligations.
When we update it, we will revise the “Last Updated” date. If a change materially affects how we use personal information, we may provide additional notice through the service, by email, or through another appropriate method.
15. Contact Us
For questions, privacy requests, or concerns, contact:
Metralis, Inc.4885 Frink Avenue
San Diego, CA 92117
United States
Email: mahmoud@withnoren.com