Legal

Privacy Policy

Effective date: 29 June 2026  ·  Last updated: 28 July 2026

Meridian is private-first. Your health data is yours. Here's what we collect and what we do with it.

Contents

  1. Who we are
  2. What data we collect
  3. Your calendar
  4. Sensitive (special category) data
  5. Why we use it & legal bases
  6. AI, model training & your choices
  7. Who we share data with
  8. International transfers
  9. How long we keep it
  10. How we protect it
  11. Your rights
  12. Age & children
  13. Changes & contact

1. Who we are

Meridian ("Meridian", "we", "us") is a personal-AI service operated by Davide as a sole trader based in the United Kingdom. For the purposes of UK data protection law, we are the "data controller" of your personal data.

You can reach us about anything in this policy at privacy@meridianself.com. Our postal address is available on request.

2. What data we collect

We only collect what we need to provide and improve Meridian:

When you join the waitlist or create an account

When you use the Meridian app

Automatically

If you turn on usage analytics

This is off unless you switch it on, and you can switch it off at any time in your profile. While it is on, Meridian records that five things happened: that you opened the app, saved a check-in, connected a data source, were shown your first pattern, and opened your week summary. For each one we store which of the five it was, the day it happened, and the time the record was written.

These records sit in your own account, under the same row-level protection as everything else you store with us. They contain no ratings, no journal or note text, and no health or body data. They are never sold, never shared for advertising, and never sent to a third-party analytics service. If you switch the setting off, the records already collected are deleted.

You are always in control of which sources you connect. Nothing from a wearable, calendar, or inbox enters Meridian until you explicitly link it, and you can disconnect any source at any time.

3. Your calendar

If you connect Google Calendar, Meridian asks Google for read-only access (the calendar.readonly scope) to the calendars you have selected in Google Calendar. We ask only when you tap Connect in your Profile, never when you sign in, and holiday and birthday feeds are skipped.

We use it for one thing: working out how many hours of each day were booked, so the model can see whether a full day shows up in how you feel. That calculation happens on your device, in your browser.

What is kept, and where:

The first sync reads the previous 365 days and the next 7 days, and later syncs refresh the same window.

You can disconnect at any time in your Profile, which revokes the access token and deletes the calendar store from that device. You can also revoke Meridian's access directly in your Google account.

Meridian's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Sensitive (special category) data

Health and biometric data, and emotional or mental-state information you record, are "special category data" under UK GDPR and receive extra protection. We process this data only with your explicit consent, which you give when you connect a source or enter the information. You can withdraw that consent at any time, and we will stop processing and delete the associated data unless we are legally required to keep it.

We do not use this data for advertising, and we never sell it.

5. Why we use your data & our legal bases

What we doLegal basis (UK GDPR)
Operate the waitlist and send you launch updatesConsent
Provide your account and the core servicePerformance of a contract
Process health, biometric and emotional data to generate your insightsExplicit consent
Keep the service secure, prevent abuse, and fix problemsLegitimate interests
Meet legal and regulatory obligationsLegal obligation
Understand whether the beta is working (usage analytics)Consent
See that your account is still in use, so we can help if you have hit a problemLegitimate interests

6. AI, model training & your choices

Meridian uses AI/ML models to turn your data into personal insight. To do this we may send relevant data to trusted AI model providers acting as our processors under contract.

We do not use your personal content to train general-purpose or third-party foundation models. Where we improve Meridian's own models, we will ask for your separate, opt-in consent, and you can decline or withdraw it at any time without losing access to the core service.

7. Who we share data with

We share data only with service providers ("processors") who help us run Meridian, under contracts that require them to protect it and use it only on our instructions. These currently include:

We may also disclose data if required by law, or to protect the rights, safety, or property of users or others. We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising.

8. International transfers

Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection.

9. How long we keep your data

We keep personal data only as long as we need it for the purposes above. Waitlist emails are kept until you unsubscribe or we close the waitlist. Account and health data are kept while your account is active and deleted within a reasonable period after you close it or withdraw consent, unless we must retain certain records to meet a legal obligation.

Usage-analytics records are deleted when you switch the setting off, and with your account when you close it. The date of your last visit is a single field that is overwritten each time, so it never builds a history.

10. How we protect your data

We use encryption in transit, access controls, and reputable infrastructure providers, and we minimise the data we collect. No system is perfectly secure, but we take protecting your data seriously given how sensitive it is.

11. Your rights

Under UK data protection law you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw consent at any time. Using any of these rights won't affect your access to Meridian.

To make a request, email privacy@meridianself.com. You also have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk, though we'd rather sort it directly first.

12. Age & children

Meridian is intended for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

13. Changes & contact

We may update this policy as Meridian evolves. We will post the new version here and update the date above; for material changes affecting sensitive data, we will seek your consent again where required.

Questions? Email privacy@meridianself.com.