Privacy Policy
Last updated: July 28, 2026
Meridian (“we”, “us”, “our”) operates the web application at meridianloop.app (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the Service.
By accessing or using the Service, you acknowledge that you accept the practices and policies outlined in this Privacy Policy. Your use of the Service is also subject to our Terms of Service.
What This Policy Covers
This Privacy Policy covers personal data we collect when you access or use the Service. “Personal data” means any information that identifies or relates to a particular individual, including information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws.
This policy does not cover the practices of companies we do not own or control, or people we do not manage — including third-party service providers whose separate privacy policies govern their handling of data.
Categories of Personal Data We Collect
Account & Profile Data
- Name (first and last)
- Email address
- Organization / workspace membership
- Profile avatar and display preferences
Source: Provided directly by you when creating an account, or via third-party authentication (Google, GitHub, Linear) through our identity provider.
Authentication Data
- OAuth provider identifiers (Google, GitHub, Linear account IDs)
- Session tokens and authentication cookies
Source: Collected automatically when you sign in through our identity provider (Clerk).
Content & Usage Data
- Projects, documents, and content you create within the Service
- Collaboration activity (canvas edits, comments, chat messages)
- AI assistant interactions (prompts, generated responses, tool calls)
Source: Generated by your use of the Service. AI interaction data may include prompts and responses processed by third-party AI providers (see Sub-processors).
Device & Technical Data
- IP address
- Browser type, operating system, and device information
- Page interactions and referring URLs
- Error and crash reports
Source: Collected automatically when you access the Service.
How We Use Your Personal Data
- Service delivery: To provide, maintain, and improve the Service's features
- Authentication: To verify your identity and manage your account
- Collaboration: To facilitate real-time collaboration and attribution of edits
- AI features: To process prompts and generate AI-assisted responses and content
- Communication: To send service-related notifications, updates, and security alerts
- Analytics: To understand usage patterns, track errors, and improve performance
- Security: To detect, prevent, and respond to security issues, fraud, or abuse
- Legal compliance: To comply with applicable legal obligations and respond to lawful requests
How We Share Your Personal Data
We share personal data with the categories of third parties described below. We do not sell your personal data.
Sub-processors
We use third-party service providers (sub-processors) to operate the Service. These providers process personal data on our behalf under written agreements that include data protection terms. Our current sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Clerk | Authentication, identity management, session handling | United States |
| Supabase | PostgreSQL database, realtime subscriptions | United States / EU (configurable) |
| Liveblocks | Real-time collaboration, presence, multiplayer state | United States / EU |
| Vercel | Web application hosting, CDN, edge compute | Global (edge network) |
| PostHog | Product analytics, feature flags, error tracking | United States / EU |
| Sentry | Error monitoring and crash reporting | United States / EU |
| Resend | Transactional email delivery | United States |
| OpenAI | AI model inference (chat, completions) | United States |
| Anthropic | AI model inference (chat, completions) | United States |
| Google Cloud | AI model inference | Global |
| OpenRouter | AI model routing and inference | United States |
We may update our sub-processor list as we add or replace providers. Material changes will be reflected in this policy. If you would like to be notified of sub-processor changes, contact us at privacy@meridianloop.app.
Other Disclosures
- Legal compliance: We may disclose personal data when required by law, subpoena, or other valid legal process.
- Business transfers: In connection with a merger, acquisition, or asset sale, personal data may be transferred subject to the protections in this policy.
- Consent: We may disclose personal data with your consent.
Data Security
We implement reasonable technical and organizational measures to protect personal data, including:
- Encryption in transit (TLS 1.2+) for all data transmissions
- Encryption at rest for stored data (database, backups)
- Role-based access controls and least-privilege principles for internal access
- Regular security reviews and dependency auditing
- Scoped API keys and machine-to-machine authentication for service integrations
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
Data Retention
- Account data: Retained for the duration of your account. Deleted within 30 days of account closure, except where retention is required by law.
- Content data: Retained until you or a workspace admin deletes it. Deleted workspace content is purged within 30 days.
- Authentication & session data: Session tokens expire per our identity provider's configuration. Authentication logs retained for 12 months for security auditing.
- Analytics & error data: Retained for up to 13 months, then aggregated or deleted.
- AI interaction data: Retained per your workspace configuration. AI traces may be processed in privacy mode, which strips prompt/completion content and retains only metadata (tokens, cost, latency, tool names).
- Backup data: Backups are retained according to our backup schedule and purged on rotation.
Tracking Tools and Opt-Out
We use PostHog for product analytics and Sentry for error tracking. These tools collect device and usage data via cookies and similar technologies. The data collected is used to understand how the Service is used, identify errors, and improve features.
You can opt out of analytics tracking by adjusting your browser settings to refuse cookies or by using the in-app privacy controls if available. Disabling cookies may affect some features of the Service.
European Union / EEA / UK Data Subject Rights
If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the GDPR and UK GDPR:
- Right of access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request that we limit processing of your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at privacy@meridianloop.app. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
State Law Privacy Rights (US)
If you are a resident of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or other states with applicable privacy laws, you have the right to:
- Know what personal data we collect and how it is used
- Request deletion of your personal data
- Request correction of inaccurate personal data
- Opt out of the “sale” or “sharing” of your personal data (we do not sell personal data)
- Limit the use of sensitive personal data
To exercise these rights, contact us at privacy@meridianloop.app. We will not discriminate against you for exercising your privacy rights.
Personal Data of Children
The Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected personal data from a child, contact us at privacy@meridianloop.app and we will take steps to delete it.
International Data Transfers
Your personal data may be processed in countries other than your own, including the United States. Where personal data is transferred from the EU/EEA/UK to countries that do not provide an adequate level of protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we may also provide notice through the Service or via email. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
- Email: privacy@meridianloop.app
- Website: meridianloop.app