> ## Documentation Index
> Fetch the complete documentation index at: https://auth0-chore-events-autoupdate.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Understand How Metadata Works in User Profiles

> User profiles have two kinds of metadata (user and application) that let you store information that does not originate from an identity provider.

Auth0 user profiles contain two kinds of metadata:

* `user_metadata` stores user information, such as preferences that do not impact a user's core functionality.

  This data **can** be edited by logged in users if you build a form using the Management API and should **not** be used as a secure data store.

* `app_metadata` stores access information, such as permissions, Auth0 plan, and external IDs that can impact user access to features.

  This data **cannot** be edited by users and there are restrictions for what can be stored in this field.

The metadata can be modified as part of a user’s login flow. You can use metadata to:

* Store application-specific data in the user profile.
* Record whether or not specific operations have occurred for a user.
* Cache the results of expensive operations on the user profile so they can be re-used in future logins.
* Store information that does not originate from an <Tooltip tip="Identity Provider (IdP): Service that stores and manages digital identities." cta="View Glossary" href="/docs/glossary?term=identity+provider">identity provider</Tooltip> or that overrides what an identity provider supplies.
* Store information that you want to use to [customize Auth0 emails](/docs/customize/email/email-templates). For example, use `user_metadata.lang` if you want the user to be able to change the field's value, then use the information to customize the language for an email.

[Auth0 applications](/docs/get-started/applications) (or *clients*, in OIDC OAuth0 terminology) also have their own [`client_metadata`](/docs/get-started/applications/configure-application-metadata), which is separate from user profile metadata.
