Privacy Policy
Meridian is software a company uses to run its customer success work. The company that signs up is our customer; the people it invites are its users. This policy explains what Meridian reads, what it keeps, what it never keeps, and how we handle information from Google accounts that users choose to connect.
1. Each customer has its own Meridian
Every customer has a separate instance of Meridian: its own database, its own web address and its own AI provider keys. Data from one customer is never shared with, visible to, or used for another.
2. Information the customer provides
- Account information from the customer's CRM or files: company names, contract values, renewal dates, owners, health and usage figures, and fields the customer defines.
- User information: each user's name, work email address and role, and the settings they choose.
- Content users create: notes, commitments, drafts and settings.
3. Information from Google accounts
A user can connect their own Google account. Connecting is optional and each user decides for themselves; an administrator cannot connect on someone's behalf. When a user connects, Meridian asks for these permissions, for these purposes only:
- Your email address (
openid,email): to identify which Google account is connected. - Read Gmail (
gmail.readonly): to show a user their recent email with a customer's contacts on that customer's page; to give drafts the context of what was already said on a thread; and, only if the user separately switches on "read my customer email", to read email to or from the customer companies in their Meridian account and record what it says on the right account. Email that is not to or from a customer is looked at only to decide that, and is not read further or kept. - Send email (
gmail.send): to send emails from the user's own address when the user presses Send, or, only where their company has turned this on, emails Meridian scheduled under that company's rules, each held first so the people on the account can stop it. Meridian never sends to an address that is not on file at the customer. - Read calendar (
calendar.readonly): to see a user's upcoming meetings with customers so Meridian can prepare them for the call.
What we keep from Google data, and what we never keep
- Never kept: the full text of an email or a calendar invitation. Meridian reads it, writes a short record, and lets the original go. Email and meetings shown on a customer's page are read live from the user's own account each time and are not stored.
- Kept, as part of the customer's records: for each customer email Meridian reads, a short record: the subject, who was on it, the date, a brief summary, the tone, any promises or next steps, and, where the customer says something about the product or the company, a one-line statement with a quote of at most 200 characters. New people at a customer who appear on an email may be added as contacts (name and email address). Emails sent through Meridian are recorded on the account.
- Kept, encrypted: the refresh token Google issues when a user connects, so Meridian can act for them without asking them to sign in again. It is encrypted before it is stored and is deleted when the user disconnects.
How Google data is used, and Limited Use
Meridian's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the user-facing features described above, which the user can see in the app.
- We do not use Google user data for advertising, we do not sell it, and we do not transfer it to others except as needed to provide these features (see section 5), to comply with law, or as part of a merger or acquisition with notice.
- We do not use Google user data, or any content derived from it, to develop, improve or train generalized or non-personalized AI or machine-learning models.
- No person at Meridian reads a user's Google data unless the user asks us to for a specific message, it is necessary for security purposes such as investigating abuse, it is required to comply with law, or it is aggregated and anonymized for the service's internal operations.
4. How we use information
To provide Meridian's features to the customer and its users: showing each person what needs them, writing drafts they review, answering questions they ask about their accounts, and keeping the records the customer's team works from. We use operational data, such as error logs and counts of AI requests, to run and secure the service.
5. Who processes information for us
- The customer's chosen AI provider (Anthropic, OpenAI or Google), using the customer's own key: to read a conversation and write its record, or to write a draft or an answer. Content is sent for that request only, under the provider's terms for API use. Meridian is set up only with API services whose terms do not allow the provider to train its models on the content sent.
- Hosting: Render (the application) and Supabase (the database).
- Slack, where the customer installs Meridian's Slack app, to post and read the messages the customer sets up.
We do not sell personal information.
6. Security
Data is encrypted in transit. Google refresh tokens are encrypted before storage. Each customer's data lives in its own database. Access within a customer's Meridian is controlled by roles its administrators set, and every settings change is recorded with who made it.
7. Keeping and deleting information
- A user can disconnect Google at any time from their Profile. Disconnecting revokes Meridian's access with Google and deletes the stored token. A user can also remove access from their Google Account's security settings.
- Records already made on a customer's accounts belong to that customer and stay until the customer deletes them or ends its use of Meridian, when its instance and database are deleted.
- Sign-in history and AI usage counts are kept for 90 days; the history of changes people make is kept for two years, and changes to settings are kept for as long as the instance exists.
- To ask us to delete information, email [email protected].
8. Children
Meridian is a business tool and is not directed to children under 16.
9. Changes
If we change this policy we will update the date above, and tell customers of material changes before they take effect.
10. Contact
Caden Duve · [email protected]