Legal
Privacy Policy
Meridian is private-first. Your health data is yours. Here's what we collect and what we do with it.
Contents
1. Who we are
Meridian ("Meridian", "we", "us") is a personal-AI service operated by Davide as a sole trader based in the United Kingdom. For the purposes of UK data protection law, we are the "data controller" of your personal data.
You can reach us about anything in this policy at privacy@meridianself.com. Our postal address is available on request.
2. What data we collect
We only collect what we need to provide and improve Meridian:
When you join the waitlist or create an account
- Contact & account data: your email address, and (if you create an account) a username and authentication details.
When you use the Meridian app
- Self-reported content: journal entries, reflections, moods, and notes you choose to record.
- Health & biometric data from services you connect: for example sleep, heart rate, heart-rate variability, resting heart rate, VO₂ max, workouts, body composition, stress, and respiration, drawn from providers such as Apple Health, Garmin, Whoop, Strava, and Terra.
- Context data you choose to connect: currently your Google Calendar, if you connect it. Section 3 explains exactly what we do with it.
- Insights we generate: the patterns and model outputs Meridian produces about you.
Automatically
- Usage & device data: basic analytics about how the website and app are used, and technical data such as browser type and IP address, used to keep the service secure and working. See our Cookie Policy.
3. Your calendar
If you connect Google Calendar, Meridian asks Google for read-only access (the calendar.readonly scope) to the calendars you have selected in Google Calendar. We ask only when you tap Connect in your Profile, never when you sign in, and holiday and birthday feeds are skipped.
We use it for one thing: working out how many hours of each day were booked, so the model can see whether a full day shows up in how you feel. That calculation happens on your device, in your browser.
What is kept, and where:
- On your device only: for each event we keep the date, the start and end time, whether it was a video call, and the title. This lives in your browser's local storage on the device you connected, which is why a connection made on a laptop does not follow you onto a phone.
- Read but not kept: guests, location and description are read on your device to work out whether an event counts as booked time and whether it was a video call. They are not stored.
- Never sent to us: no calendar information reaches Meridian's servers. Nothing calendar-derived is written to our database, so it is not in our backups and not in any export we hold. The model only ever receives the date, the booked minutes, and the video-call flag. Your event titles are shown back to you in the app and stay on your device.
The first sync reads the previous 365 days and the next 7 days, and later syncs refresh the same window.
You can disconnect at any time in your Profile, which revokes the access token and deletes the calendar store from that device. You can also revoke Meridian's access directly in your Google account.
Meridian's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sensitive (special category) data
Health and biometric data, and emotional or mental-state information you record, are "special category data" under UK GDPR and receive extra protection. We process this data only with your explicit consent, which you give when you connect a source or enter the information. You can withdraw that consent at any time, and we will stop processing and delete the associated data unless we are legally required to keep it.
We do not use this data for advertising, and we never sell it.
5. Why we use your data & our legal bases
| What we do | Legal basis (UK GDPR) |
|---|---|
| Operate the waitlist and send you launch updates | Consent |
| Provide your account and the core service | Performance of a contract |
| Process health, biometric and emotional data to generate your insights | Explicit consent |
| Keep the service secure, prevent abuse, and fix problems | Legitimate interests |
| Meet legal and regulatory obligations | Legal obligation |
6. AI, model training & your choices
Meridian uses AI/ML models to turn your data into personal insight. To do this we may send relevant data to trusted AI model providers acting as our processors under contract.
We do not use your personal content to train general-purpose or third-party foundation models. Where we improve Meridian's own models, we will ask for your separate, opt-in consent, and you can decline or withdraw it at any time without losing access to the core service.
7. Who we share data with
We share data only with service providers ("processors") who help us run Meridian, under contracts that require them to protect it and use it only on our instructions. These currently include:
- Netlify: website hosting and delivery.
- Supabase: database and authentication.
- Wearable & connector APIs you link (e.g. Apple Health, Garmin, Whoop, Strava, Terra), as the source of data you ask us to import.
- AI model providers: to generate your insights, as described above.
We may also disclose data if required by law, or to protect the rights, safety, or property of users or others. We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising.
8. International transfers
Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection.
9. How long we keep your data
We keep personal data only as long as we need it for the purposes above. Waitlist emails are kept until you unsubscribe or we close the waitlist. Account and health data are kept while your account is active and deleted within a reasonable period after you close it or withdraw consent, unless we must retain certain records to meet a legal obligation.
10. How we protect your data
We use encryption in transit, access controls, and reputable infrastructure providers, and we minimise the data we collect. No system is perfectly secure, but we take protecting your data seriously given how sensitive it is.
11. Your rights
Under UK data protection law you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw consent at any time. Using any of these rights won't affect your access to Meridian.
To make a request, email privacy@meridianself.com. You also have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk, though we'd rather sort it directly first.
12. Age & children
Meridian is intended for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
13. Changes & contact
We may update this policy as Meridian evolves. We will post the new version here and update the date above; for material changes affecting sensitive data, we will seek your consent again where required.
Questions? Email privacy@meridianself.com.