Privacy Policy

Last updated 15 July 2026

Metroit X (also known as Dremorawe, us) is operated by Aniket Thakur, an individual based in New Delhi, India. This policy explains what personal data we collect when you use our website, web app, and desktop Plugin (together, the Service), why we collect it, who we share it with, and the choices you have. By using the Service, you agree to the practices described here.

The most important thing to understand: Metroit X connects to a small desktop app (the Plugin) that you install on your own computer. When you ask the agent to do something, relevant file contents, command output, and directory listings from your own machine are sent to our backend and then to the AI model you’ve selected (Google Gemini, Anthropic Claude, or a model routed through OpenRouter) so it can generate a useful response. Don’t point the Plugin at a workspace containing data you wouldn’t want processed by a third-party AI model.

1. Personal data we collect

Account information. When you sign in with Google, we receive your name, email address, profile picture, and Google account ID. If you sign in with a username and password instead, we store your username, email, and a bcrypt-hashed (salted) password — we never store your password in plain text and never see it after hashing.

Payment information. Subscriptions are billed through Razorpay. We do not receive or store your card, UPI, or bank details — Razorpay handles that directly. We keep only the subscription ID, plan, status, and renewal date needed to manage your billing.

Queries, files, and command output (Inputs). The prompts you type, and — when the Plugin is connected — the file contents, code, directory listings, and command output the agent reads or produces on your machine while carrying out your request. These are sent to the AI model you’ve selected in order to generate a response (Suggestions), and are stored as part of your conversation history so you can resume a session later.

Device and connection information. When you connect a machine, the Plugin sends us a device name, operating system, and a device identifier so we can route your requests to the right machine and enforce your plan’s device limit.

Usage and diagnostic data. We log which tools were called (e.g. a file was read, a command was run), token usage and cost per request, permission decisions (allowed/blocked/warned), and session duration. Command text and file paths are redacted before being stored in analytics — we keep enough to debug problems and detect abuse, not a verbatim record of what you ran.

Memory. If you tell the agent something worth remembering across sessions (a preference, a fact about your project), it can save a short note to your personal memory store so future conversations don’t start from zero. This is scoped to your account only.

Cookies and local storage. See our Cookie Policy for details.

What we don’t collect. We don’t knowingly collect sensitive categories of data (health, biometric, genetic, religious information) and the Service is not directed at anyone under 18. If we learn an account belongs to someone under 18, we’ll delete it.

2. How we use personal data

  • To operate the Service — authenticate you, route your requests to your connected machine, and generate AI responses.
  • To manage your account and billing, including processing subscription payments and renewals.
  • To provide support and respond to the questions you send us.
  • To maintain and improve reliability — debugging, error tracking, and capacity planning.
  • To detect and prevent abuse, fraud, and violations of our Terms of Service or Acceptable Use Policy.
  • To comply with legal obligations.

Your Inputs are sent to the third-party AI provider whose model you’ve selected, and how that provider handles them — including whether it uses them to train or improve its models — is governed by that provider’s own terms, which vary by provider and plan tier. We don’t sell your personal data or share it for targeted advertising — Metroit X doesn’t run ads.

3. How we share personal data

We share personal data only where it’s needed to run the Service:

  • AI model providers — Google (Gemini), Anthropic (Claude), and OpenRouter (which itself routes to other model providers such as OpenAI and Moonshot AI), depending on which model you select. Your Inputs are sent to whichever provider is generating your response, subject to that provider’s own data-handling terms.
  • Infrastructure providers — our hosting (Render), database (Neon/Postgres), cache (Redis), and frontend hosting (Vercel) providers, who process data on our behalf and don’t use it for their own purposes.
  • Payments — Razorpay, to process your subscription.
  • Error tracking — Sentry, if enabled, to help us diagnose crashes.
  • Legal and safety — if required by law, or to protect the rights, safety, or property of Metroit X, our users, or the public.
  • Business transfer — if Metroit X is acquired or its assets are transferred, your data may transfer as part of that deal, subject to this policy.

We do not sell personal data to anyone.

4. Retention

We keep account data for as long as your account is active. Conversation history and diagnostic logs are kept long enough to let you resume a session and for us to debug issues or investigate abuse, then deleted or anonymized. If you delete your account, we delete your personal data within a reasonable period, except where we’re required to keep billing records for tax/accounting purposes.

5. Security

We use industry-standard measures to protect your data — encrypted transport (HTTPS/WSS), salted password hashing (bcrypt), and a multi-layer permission engine that reviews risky commands before they reach your machine. No method of transmission or storage is completely secure, so we can’t guarantee absolute security. If a data breach affecting your personal data occurs, we will notify you and the relevant authorities as required by applicable law, including the Digital Personal Data Protection Act, 2023. See our Security page for more detail.

6. Your rights and choices

You can access, correct, export, or delete your account data by contacting us. You can disconnect the Plugin from a machine, revoke a session by logging out (which invalidates that token immediately), and cancel your subscription at any time from Settings → Billing.

To exercise any of these rights, email info@dremora.co. We may ask you to verify your identity before acting on a request.

7. International use

Metroit X is operated from India and our infrastructure may process data in other countries where our hosting and AI-model providers operate. By using the Service, you consent to your data being processed outside your home country where applicable.

8. Changes to this policy

We may update this Privacy Policy from time to time. We’ll update the Last updated date above when we do, and for material changes we’ll make a reasonable effort to notify you (e.g. by email or an in-app notice).

9. Grievance Officer (India)

In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, the contact details of the Grievance Officer are:

  • Name: Aniket Thakur
  • Location: New Delhi, India
  • Email: info@dremora.co (subject line: Grievance)

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you’re not satisfied with our response, you may also lodge a complaint with the Data Protection Board of India.

10. Contact us

Questions about this policy? Email us at info@dremora.co.