1. Who we are
Metarabbit is operated by James O’Reilly, a sole trader trading as Zumi Studios, CRO business-name registration 738695. Our establishment and contact address is 51 Bracken Road, Sandyford, Dublin, D18 CV48, Ireland. You can email support@zumistudios.com or use the enquiry form below.
For processing where we decide why and how personal data is used, James O’Reilly trading as Zumi Studios is the data controller.
2. Scope and our roles
This Policy covers the Metarabbit website, dashboard, API, support communications, billing metadata, crawler, temporary caches, and copied preview images. It does not control a target publisher's website or the independent services operated by Clerk, Stripe, Cloudflare, or Google.
We are a controller for account administration, contract acceptance, billing administration, support, fraud prevention, security, legal compliance, and our own service operations. When a customer decides which URLs to submit and why, and those URLs or pages contain personal data, we generally act as that customer's processor. The Data Processing Schedule in our Terms governs that processing. Customers remain responsible for their own privacy notices and legal bases.
3. Data we process
Account and organisation information
Clerk provides identifiers for your user, organisation, and session and the contact and profile information you choose to associate with them. We store an organisation projection containing its Clerk ID, name, plan, limits, billing-period dates, and service status. We do not receive your Clerk password.
API credentials and activity
We store a cryptographic hash and short display prefix for each API key, its label, organisation, creation time, last-used time, and revocation time. We do not store the recoverable full API key after it is shown to you. For each request we record a request ID, organisation, API-key ID where applicable, submitted normalised URL, final URL where a redirect occurs, URL hash, request type, result or error, and timestamp.
Public webpage and summary data
To answer a request, we retrieve a public page of up to 2 MB and extract metadata and readable text. Public metadata and readable text may be stored in a shared cache for up to 24 hours. When you request a summary, up to approximately 12,000 characters of readable public-page text are sent to Cloudflare Workers AI. If a page declares a public Open Graph image, we may copy up to 1 MB to Cloudflare R2 and return an expiring CDN URL alongside the publisher's original URL.
Billing information
Clerk Billing and Stripe handle checkout and payment methods. We receive subscription, plan, payer, payment status, period, and invoice-related metadata needed to provide the plan and keep financial records. We do not receive or store full card numbers or card security codes.
Support, legal, and security information
If you contact us, we process your email address, optional name, selected topic, message, and our replies. Cloudflare may process IP address, user agent, request timing, and Turnstile signals to deliver and protect the form and service. We record your Clerk user ID, accepted legal versions, and acceptance time, but not an acceptance IP address.
4. Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide accounts, API responses, plans, support, and billing administration | Account, organisation, key, request, subscription, and contact data | Performance of our contract or steps requested before a contract |
| Secure the service, prevent abuse, diagnose faults, and enforce fair limits | Identifiers, request metadata, IP/user-agent logs, Turnstile signals, errors | Our legitimate interests in operating a safe, reliable service and protecting customers and publishers |
| Manage contracts, consumer requests, tax, accounting, disputes, and regulator requests | Acceptance, billing, support, and transaction records | Legal obligations and our legitimate interests in establishing or defending legal claims |
| Send optional marketing in the future | Email and preference | Consent where required; Metarabbit does not send marketing at launch |
Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations, data sensitivity, retention, and available safeguards. You may object as described below. If information is necessary for an account, contract, security check, or legal obligation and you do not provide it, we may be unable to provide the relevant service.
We do not sell personal data, run third-party advertising, build behavioural advertising profiles, or use website analytics at launch. We do not make decisions producing legal or similarly significant effects about people based solely on automated processing.
5. AI and automated fetching
AI summarisation runs only when a customer asks for it. Zumi Studios does not use submitted URLs, webpage content, API output, or support messages to train AI models. Under our current Cloudflare service configuration and provider terms, Cloudflare does not use Workers AI customer content to train or improve its models without express consent. We would update this Policy before materially changing that position.
The publisher's server receives a request from MetaRabbitBot containing the target URL, our crawler user agent, and a Cloudflare network address. It does not receive the Metarabbit customer's IP address from us. We check robots.txt and verified publisher blocks before cache lookup or page retrieval. Redirect targets are revalidated and local/private-network targets are blocked.
7. International transfers
We are established in Ireland, but our providers operate globally and may process data outside the EEA. Where GDPR transfer rules apply, transfers rely on an applicable European Commission adequacy decision, the EU-US Data Privacy Framework where valid for that recipient and data, standard contractual clauses with supplementary measures where appropriate, or another lawful safeguard. You may ask us for more information about the safeguard relevant to your data.
8. Retention
We use defined periods instead of keeping identifiable information indefinitely:
| Information | Retention |
|---|---|
| Public metadata and readable-text cache | Up to 24 hours |
| API request URL, result, summary, and error | Up to 30 days |
| Copied CDN preview image | Up to 30 days |
| Cloudflare Worker logs | Up to 7 days |
| Cloudflare Email Service delivery analytics | Up to 31 days |
| Support enquiries and replies | 12 months after resolution, unless needed for a dispute, security investigation, or legal obligation |
| Active account, organisation, and API-key records | Until account/organisation deletion or termination |
| Legal acceptance and required contract, financial, and tax records | Generally 6 years after the relevant relationship or transaction, or longer only where law or an active claim requires it |
| Properly de-identified aggregate statistics | No fixed period where they can no longer reasonably identify a person |
Deleting an organisation removes its active D1 requests, API keys, usage records, and R2 images. Provider backups, security logs, billing records, and legal records may expire on their own schedules. We may delete data earlier when it is no longer needed or a valid publisher/data-subject request requires it.
10. Your rights
Depending on the law and circumstances, you may ask for access to personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing. You may also ask not to be subject to certain solely automated decisions, although Metarabbit does not currently make such decisions.
Send a request to support@zumistudios.com or use the form below. Describe what you need and the account, organisation, request ID, URL, or email involved. We may request proportionate information to verify identity or authority and will respond within the legally required period. Where we process data solely for a customer, we may refer the request to that customer and assist them as processor.
You can complain to the Irish Data Protection Commission at dataprotection.ie, or to the supervisory authority where you live or work. We would appreciate the chance to address the concern first, but you do not have to contact us before using a statutory complaint right.
11. Publisher and removal requests
Publishers can control future crawling through robots.txt. An authorised domain representative may also ask us to remove known cached/request data or add a block for the verified origin. We verify origin-wide requests through DNS or a domain-associated contact to prevent one person blocking another publisher's site. For a specific URL or personal-data concern, include the URL, the requested action, and enough information to assess your rights. We will prioritise credible security, privacy, and safety requests.
12. Security and incidents
Measures include encrypted transport, Clerk authentication, hashed API keys, access-limited Cloudflare bindings, private-network and redirect checks, robots.txt and publisher blocks, request/body size limits, Turnstile, short retention, scheduled deletion, and restricted transactional email delivery. Access is limited to what is reasonably needed to operate and support the service.
No online system can guarantee absolute security. If we become aware of a personal-data breach, we will investigate, contain it, and notify affected controllers, people, and regulators without undue delay where required by law. Report a suspected vulnerability using the security topic below; do not exploit or expose other people's data while investigating.
13. Children
Metarabbit accounts and paid services are for people aged 18 or over and are not directed to children. Do not knowingly submit private or sensitive information about a child. Public webpage metadata can incidentally mention children; publishers, customers, or guardians may contact us about removal or rights concerns.
14. Changes to this Policy
We will update the effective date and version when this Policy changes and retain earlier versions. We will give advance email or in-product notice of a material change where reasonably possible. If a new purpose requires consent, we will ask before using existing personal data for it.
15. Contact us
James O’Reilly trading as Zumi Studios51 Bracken Road
Sandyford
Dublin
D18 CV48
Ireland
Email: support@zumistudios.com
The email address and form are monitored on business days and we aim to reply promptly. Contact-form messages are delivered directly to the support mailbox and are not stored in the Metarabbit application database.

