Privacy policy
Last reviewed 1 August 2026
This document is a working draft written for this site build. The company name, contact addresses and processor list are placeholders. Have a lawyer in your jurisdiction review it and replace every bracketed value before you publish.
In short
The app does its work on your Mac. Your tasks, their results, the pages it read and any credentials you connect stay on your machine. We receive anonymous counters about whether the app crashed and which features are used, and you can switch those off in Settings on the first run.
This website sets one cookie, and only to remember the choice you made in the cookie banner.
Who we are
Meridian is operated by [Company legal name], [registered address]. For anything relating to your data, write to privacy@meridian.example. Full company details are on the imprint page.
What we collect
From the app
- Anonymous, aggregated usage counters — how many tasks were started, which integrations are enabled, which app version is running. No task text, no results, no URLs.
- Crash reports, when the app stops unexpectedly: the stack trace, the OS version and the app version.
- Your licence key and the email you bought with, so we can verify activation and resend the key if you lose it.
Everything in the first two bullets can be turned off. Settings → Privacy → Send diagnostics. The app works identically with it off.
From this website
- Standard server request logs — IP address, user agent, the page requested, the time. These are kept short-term for security and rotated automatically.
- One preference cookie recording your answer to the cookie banner.
What we never collect
- The content of your tasks, or anything a task produced.
- The pages the agent opened, or the data it read from them.
- Your files, your mail, your messages, your calendar, your contacts.
- Passwords, tokens or keys for any service you connect. Those live in the macOS Keychain on your machine.
- Your location, your browsing history outside the app, or biometric data of any kind.
- Anything that would let us tie usage counters back to an individual person.
How we use what we do collect
- To answer you when you contact support.
- To find and fix crashes, and to see which features are worth continuing to build.
- To verify a licence and to process a refund when you ask for one.
- To meet a legal obligation where one applies.
We do not sell data, we do not share it for advertising, and we do not build profiles.
Legal basis (GDPR)
- Contract — processing your purchase, issuing and validating a licence.
- Legitimate interest — crash diagnostics and aggregate counters, weighed against the fact that they carry no personal content and can be disabled.
- Consent — anything non-essential, which on this site currently means nothing beyond the preference cookie you agree to in the banner.
- Legal obligation — retaining invoices for the period tax law requires.
How long we keep it
- Crash reports and diagnostics: 90 days, then aggregated beyond recovery.
- Server logs: 30 days.
- Support conversations: 24 months, so we have context if you write again.
- Purchase records: as long as tax law requires, typically several years.
Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it, where we are not required to keep it;
- restrict or object to a particular use;
- hand it over in a portable format;
- withdraw a consent you gave, at any time, without affecting what came before.
One email is enough. We answer within 30 days. If you are in the EU or UK and you are not satisfied with our answer, you can complain to your national supervisory authority.
Contact
Privacy questions: privacy@meridian.example. Everything else: support.