Who we are
Meridian Ltd is a company registered in England and Wales. We operate the Meridian thinking workspace at meridian.so and associated subdomains.
For any questions about this policy, contact us at privacy@meridian.so.
What data we collect
We collect the following categories of data when you use Meridian:
- —Account information — your name and email address, provided when you sign up via Clerk.
- —Canvas content — the problem statements, nodes, edges, and text you create inside Meridian. This data belongs to you.
- —Usage data — how you interact with the product: pages visited, features used, session length. Collected via PostHog.
- —Payment information — billing details processed by Stripe. We do not store card numbers.
- —Uploaded documents — files you attach to canvases for context. Stored in Supabase Storage.
- —Communications — emails you send to us or responses you receive from us.
How we use your data
We use the data we collect to:
- —Provide, maintain, and improve the Meridian service.
- —Process your payment and manage your subscription via Stripe.
- —Send product and account-related emails. You may unsubscribe from non-essential emails at any time.
- —Understand how the product is used so we can improve it. PostHog analytics data is aggregated and not sold.
- —Pass your canvas content to Anthropic's Claude API to generate Meridian's questions and analysis. Your content is processed in accordance with Anthropic's data processing terms.
- —Comply with legal obligations.
Your content
All content you add to a Meridian canvas — problem statements, nodes, edges, uploaded documents — remains yours. Meridian Ltd claims no intellectual property rights over your canvas content. You may export all of your content at any time in Markdown or JSON format, and you may request deletion of your data at any time by contacting privacy@meridian.so.
AI and your data
Meridian uses Anthropic's Claude models to power the AI functionality. When you interact with Meridian, your canvas content and conversation history are sent to Anthropic's API to generate responses.
We do not use your canvas content to train AI models. Anthropic's API terms prohibit using API inputs for training without explicit consent. You can review Anthropic's privacy policy at anthropic.com/privacy.
Data storage and security
Your data is stored in Supabase infrastructure, hosted on AWS in the EU (Ireland) region. We use industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256).
Authentication is handled by Clerk, a SOC 2 Type II certified identity provider. Payments are processed by Stripe, a PCI DSS Level 1 certified provider.
We maintain internal access controls and review them regularly. We will notify you without undue delay in the event of a data breach that affects your personal data.
Data retention
We retain your account data for as long as your account is active. If you close your account, we delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.
Canvas content is deleted immediately when you archive a canvas and request deletion. We do not retain deleted canvas data in backups beyond 30 days.
Your rights (UK GDPR)
Under UK GDPR, you have the following rights:
- —Right of access — request a copy of the personal data we hold about you.
- —Right to rectification — request correction of inaccurate data.
- —Right to erasure — request deletion of your personal data.
- —Right to data portability — receive your data in a machine-readable format.
- —Right to object — object to processing based on legitimate interests.
- —Right to restrict processing — request that we restrict how we use your data.
To exercise any of these rights, email privacy@meridian.so. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
We use essential cookies for authentication and session management. We use analytics cookies (PostHog) to understand product usage. You can review our full cookie policy at meridian.so/cookies.
Changes to this policy
We will notify you by email of any material changes to this policy at least 14 days before they take effect. Your continued use of Meridian after that date constitutes acceptance of the updated policy.