Privacy Policy
Working draft for counsel review · Not yet effective
Third Draft for Counsel Review — Not for Publication
Effective Date: [TO CONFIRM: effective date]
Last Updated: [TO CONFIRM: last-updated date]
Drafting note. Every bracketed item must be resolved before publication. This draft assumes that [TO CONFIRM: full legal name and entity type], doing business as Meridian, is the sole entity responsible for the personal information described here. People who create, edit, support, or operate Content do so as authorized Meridian personnel or contractors under Meridian's direction and are not separate data controllers or independent recipients of user information.
Some sections describe optional, user-initiated features. Those sections apply only if Meridian makes the feature available and the user chooses to use it. Before an optional feature collects personal information not otherwise described here, Meridian will provide any additional notice and request any consent required by law. Do not delete an optional-feature module from this counsel draft merely because that feature is not yet available; keep the module expressly conditional and complete it before launch. Background technologies and processing that users do not affirmatively activate—including analytics, session replay, advertising pixels, email tracking, device fingerprinting, and cross-site data sharing—must be confirmed against the deployed Service before publication, described as a current practice if active, and may not be enabled merely because they appear in this draft.
This Privacy Policy explains how [TO CONFIRM: full legal name and entity type], doing business as Meridian (“Meridian,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you use a Meridian website, application, mobile service, mini-program, email, research service, subscription, or other product or service that links to this Privacy Policy (collectively, the “Service”).
In this Privacy Policy, “Content” means research, Articles, Notes, signals, charts, posts, comments, messages, files, and other material made available through or submitted to the Service.
This Privacy Policy applies to visitors, readers, free and paid subscribers, account holders, people who communicate with Meridian, and people who provide Content or services to Meridian through the Service. It does not govern a third-party website or service that presents its own privacy notice. When a third party is integrated with the Service, that third party's notice may also apply, but this Privacy Policy still describes Meridian's own collection, use, and disclosure in connection with the integration.
1. Who Is Responsible for Your Information
[TO CONFIRM: full legal name] is the controller, business, or personal information handler responsible for the processing described in this Privacy Policy, as those terms are used under applicable law.
Authorized Meridian personnel and contractors may process personal information under Meridian's direction when they need it to perform their work. Meridian applies role-based access and confidentiality obligations appropriate to the person's responsibilities. They do not receive user information for independent purposes merely because they create, edit, support, or operate Content.
Contact information for Meridian is provided in Section 20.
2. Personal Information We Collect
The information Meridian collects depends on how you interact with the Service, the choices you make, and the features made available to you.
2.1 Account, identity, and authentication information
We may collect:
- name, display name, username, email address, telephone number, postal address, profile image, and other account or profile fields you provide;
- internal account, customer, device, and authentication identifiers;
- verification status, account status, login timestamps, account-recovery information, and security events; and
- information used to authenticate you, such as password verifiers, one-time codes, session tokens, or credentials handled by an authentication provider.
Authentication providers may store and verify passwords or other credentials on our behalf. [TO CONFIRM BEFORE PUBLICATION: whether Meridian ever receives or stores a readable password; if it does not, state that clearly.]
If third-party sign-in is available and you choose to use it, Meridian receives the account identifier and profile information that the provider makes available based on your settings and the permissions you grant. This may include your name, email address, profile image, phone number, and authentication-related information. The sign-in provider also processes information under its own privacy notice.
2.2 Subscription, offer, and transaction information
We may collect:
- the research, Content, service, plan, or tier you request;
- subscription status, start and end dates, renewal status, entitlements, free trials, discounts, coupons, credits, and cancellation information;
- purchase amount, currency, tax information, invoices, receipts, refunds, payment status, and customer, order, subscription, or contract identifiers;
- billing name, billing address, and limited payment-method information made available to Meridian, such as payment-method type, card brand, last digits, wallet type, or tokenized identifier; and
- records of an offer, your acceptance, confirmations, renewals, cancellations, policy or offer version, timestamp, channel, and transaction status.
Payment information may be submitted directly to the payment provider identified at checkout. A payment provider may process information for payment authorization, fraud prevention, tax, sanctions screening, regulatory compliance, and its own legal obligations under its privacy notice.
[TO CONFIRM BEFORE PUBLICATION: all active payment providers, app stores, wallets, merchant-of-record arrangements, the information each provider sends to Meridian, whether full payment credentials ever touch Meridian systems, and applicable retention. Name or link material independent providers.]
2.3 Content use, reading activity, and financial interests
We may collect information about how you access, use, and organize Content, including:
- pages, research, Articles, Notes, asset pages, charts, signal records, paywalls, or other Content you view;
- reading and viewing history, access times, time spent, scroll position, saves, bookmarks, downloads, searches, link sharing, and navigation paths;
- securities, digital assets, currencies, commodities, rates, economic themes, sectors, regions, asset classes, and other subjects with which you interact;
- watchlists, portfolios, lists, alerts, follows, preferences, and saved filters, if those features are available;
- subscription, notification, email, language, time-zone, theme, accessibility, and reading-display preferences;
- whether Content is available, locked, or unlocked for your account; and
- interactions with search results, feeds, content ordering, recommendations, alerts, advertisements, or other personalized features, where used.
Meridian may infer interests or preferences from this activity where described in Section 4 and Section 12. Financial interests and reading activity are not made public merely because you use the Service. [TO CONFIRM BEFORE PUBLICATION: whether Meridian creates inferred-interest profiles, the purposes, the fields used, the personnel and providers with access, and the available objection or opt-out controls.]
2.4 Device, network, location, and log information
Meridian and its service providers may automatically receive:
- IP address, browser and device type, operating system, app version, language, mobile carrier or internet service provider, and device, browser, cookie, advertising, installation, session, or account identifiers;
- referring and exit pages, URL and UTM information, timestamps, pages or screens viewed, links clicked, error, performance, request, and diagnostic logs;
- security, authentication, rate-limit, fraud, and abuse signals;
- approximate location, such as country, region, state, or city, derived from IP address; and
- administrative audit information, such as the acting account, action, timestamp, reason, IP address, user agent, and before-and-after values.
If Meridian offers a location-based feature and you choose to enable it, Meridian may collect precise or background location only after providing the feature-specific notice and obtaining the device permission or consent required by law. You may withdraw device permission in your operating-system settings, although the feature may then stop working.
[TO CONFIRM BEFORE PUBLICATION: the exact logs and identifiers generated in production; whether advertising IDs, device fingerprinting, precise location, background location, or cross-device identification are used. Classify each item as a current practice or an expressly user-triggered optional feature; do not imply that inactive background tracking is already occurring.]
2.5 Email, push, SMS, and other notification information
When Meridian sends an email, push notification, SMS, or in-app message, we may collect:
- the recipient address, telephone number, device or app identifier, push token, and selected topic or Content;
- message, campaign, template, and provider identifiers;
- send, delivery, failure, bounce, complaint, unsubscribe, suppression, and permission status; and
- information about engagement with the message, such as whether and when it was opened or a link was clicked.
Where Meridian uses recipient-level email tracking, a pixel or redirected link may create an open or click timestamp and technical information such as IP address and user agent. Email-client security, image proxying, link scanning, privacy tools, and forwarding can make these signals inaccurate. [TO CONFIRM BEFORE PUBLICATION: whether production emails use pixels, redirected links, or other recipient-level engagement tracking; the exact fields collected; the purpose, legal basis, retention, personnel and providers with access, and user controls.]
If push notifications are available and you enable them, Meridian and its notification provider may process a device or app identifier and push token to deliver the notifications you select. You can withdraw permission through Meridian or your device settings.
If SMS or telephone notifications are available and you request them, Meridian and its communications provider may process your telephone number, consent record, delivery status, and responses. [TO CONFIRM BEFORE PUBLICATION: supported channels, consent and opt-out language, short code or sender identity, and whether message content or replies are retained.]
2.6 Communications, support, surveys, and events
We collect information you provide when you contact support, report a problem, make a complaint, exercise a privacy request, respond to a survey, provide feedback, register for an event, or otherwise communicate with Meridian. This may include your contact information, message content, attachments, screenshots, recordings, device information, relevant logs, and our response history.
If calls, video sessions, or support sessions are recorded, Meridian will provide any notice and obtain any consent required by law. Please do not send a password, full payment-card number, government identifier, brokerage credential, or other sensitive information through an ordinary support channel unless Meridian requests it through an approved secure method.
If Meridian operates an office, studio, event venue, or other physical location, it may collect visitor registration, access, badge, photograph, audio or video, and CCTV information for safety, security, event, and facilities purposes after providing any notice required by law. [TO CONFIRM BEFORE ANY PHYSICAL-SITE OR IN-PERSON-EVENT COLLECTION: locations, fields, recording zones, notice, access, sharing, lawful basis, and retention.]
2.7 Public Content and communications, if available
If Meridian offers public profile, posting, commenting, rating, reaction, sharing, chat, or similar features and you choose to use them, we may collect the Content and files you submit, your public identifier and profile fields, timestamps, interactions, moderation records, and reports concerning that Content.
Information you choose to publish may be visible to other users, search engines, embedded widgets, API users, partners, or the general public. It may be indexed, cached, screenshotted, quoted, copied, or reshared beyond Meridian's control. A direct link described as private or unlisted may still be viewed and reshared by anyone who receives the link.
If messaging is available, recipients retain their copies of messages. Meridian may process messages and related metadata to deliver the feature, provide support, enforce the Terms, detect malicious links, spam, fraud, or prohibited content, and protect users. Messages are not end-to-end encrypted unless Meridian expressly states otherwise for the relevant feature.
[TO CONFIRM BEFORE PUBLICATION OR BEFORE ENABLING A PUBLIC FEATURE: visibility defaults; search indexing; deletion behavior; moderation and safety scanning; API or widget access; whether public Content or public-facing identifiers are used in analytics, datasets, benchmarks, AI training, market research, or licensed products; and the required feature-specific notice and controls.]
2.8 Market data, exchange access, and financial-account connections, if available
Meridian may provide market data or third-party financial features in several ways:
- Server-provided data. A market-data provider may receive a request from Meridian's systems. Meridian will disclose personal information to that provider only where needed for the service, licensing, security, or legal requirements.
- Direct embeds and widgets. A third-party chart, video, news, or market-data feature displayed in the Service may receive your IP address, device and browser information, cookies, page URL, and interaction data directly under its own privacy notice.
- Exchange entitlements. If Meridian offers paid or licensed exchange data and you request access, Meridian may disclose contact, account, professional, usage, or subscriber-status information to the exchange or licensor as required by its agreement. Meridian will identify the recipient, information, purpose, and required agreement at or before enrollment.
- Financial-account connections. If Meridian offers and you choose to connect a brokerage, exchange, bank, wallet, portfolio, or other financial account, Meridian may receive the account identifier, connection token, account type, holdings, positions, watchlists, balances, orders, executions, transactions, cost basis, or other information identified on the connection screen.
- Instructions or execution. If a future feature permits an instruction, order, transfer, or transaction, Meridian may process the instruction and related instrument, price, quantity, timing, status, error, confirmation, and account information necessary to provide the feature.
Before a financial connection is activated, Meridian will identify the provider, the categories requested, the purpose, whether access is read-only or permits instructions, how to disconnect the connection, and any additional terms. Meridian will state at the connection screen whether it receives a financial-account password or instead uses a provider token or other delegated access method.
[TO CONFIRM BEFORE ENABLING EACH FEATURE: providers and legal roles; direct-browser versus server-side data flows; exchange reporting; data categories and permissions; credential handling; read/write scope; refresh frequency; retention after disconnection; deletion propagation; and whether a regulated or adviser activity is implicated.]
2.9 AI-assisted and automated features, if available
If Meridian offers an AI-assisted feature and you choose to use it, Meridian may process prompts, questions, instructions, Content, files, images, audio, feedback, outputs, and related usage and technical information to provide, secure, troubleshoot, and evaluate the feature.
The feature-specific notice will identify any external model or infrastructure provider that receives personal information, applicable retention, whether a person may review inputs or outputs, and whether inputs or outputs are used to improve or train a Meridian or third-party model.
[TO CONFIRM BEFORE ENABLING EACH AI FEATURE: exact input and output categories; model and hosting providers; provider legal role; human review; training and evaluation uses; logging and retention; international transfers; opt-out or deletion controls; safety moderation; and whether financial, support, private-message, or sensitive information is excluded.]
2.10 Identity verification, KYC, tax, sanctions, and fraud information, where required
Where a payment, payout, licensed market-data service, financial connection, business account, promotion, or legal obligation requires verification, Meridian or the identified provider may process:
- date of birth, address, nationality, citizenship, tax residence, tax identifier, government identification, photograph, selfie, liveness result, signature, or proof of address;
- business identity, incorporation, employment, professional status, beneficial-owner, and authorized-representative information;
- sanctions, politically exposed person, restricted-party, adverse-media, fraud, risk, and verification results; and
- information from government records, public sources, identity providers, payment providers, fraud services, or other verification sources.
Meridian will provide additional notice and obtain separate consent where required before collecting sensitive information for such a check. [TO CONFIRM BEFORE PUBLICATION: checks that occur in the deployed Service, affected users, providers, categories Meridian receives, decision and appeal process, legal basis, retention, and cross-border flows.]
2.11 Professional and work-related information
If you interact with Meridian in a professional capacity, create or administer Content on Meridian's behalf, apply for a role, or provide services to Meridian, we may process your work contact information, employer, title, professional qualifications, biography, areas of expertise, work account, assigned responsibilities, Content, uploads, editorial or administrative actions, permissions, payment or tax information, and audit records.
Employment, recruiting, and contractor records maintained outside the Service may be governed by a separate notice where required.
2.12 Sensitive personal information
Some laws define account credentials, financial-account information, government identifiers, precise location, biometric information, racial or ethnic origin, religious beliefs, political opinions, health information, sexual orientation, union membership, or other categories as sensitive.
Meridian does not require you to provide sensitive information for ordinary reading or subscription use, except limited account credentials and payment information needed to provide and secure the Service. Optional features may require additional sensitive information only as described above and at the point of collection.
[TO CONFIRM BEFORE PUBLICATION: every sensitive category processed by Meridian or a provider; whether Meridian uses sensitive information beyond permitted service, security, legal, or verification purposes; and any required limit-use link or consent.]
3. Sources of Personal Information
Meridian may collect personal information:
- directly from you, including during registration, checkout, settings, support, a survey, an event, or use of a feature;
- automatically from your browser, device, email application, and interaction with the Service;
- from authentication, payment, app-store, wallet, communications, fraud, verification, analytics, support, hosting, and other service providers;
- from a third-party account or integration that you choose to connect;
- from an exchange, market-data licensor, financial institution, or data aggregator when you request a related feature;
- from systems used to migrate an existing Meridian account, subscription, or service, where applicable;
- from public sources, government lists, compliance databases, and security or anti-fraud sources where permitted by law; and
- from another person or organization you direct or authorize to provide information to Meridian.
If applicable law requires Meridian to tell you the source of information obtained indirectly, Meridian will do so within the required period.
4. How We Use Personal Information
Meridian may use personal information to:
- create, authenticate, secure, maintain, update, and delete accounts;
- provide, personalize, and administer the Service, Content, subscriptions, entitlements, settings, and optional features you request;
- process transactions, administer trials and promotions, send receipts, calculate or collect tax, address failed payments, prevent duplicate charges, and support cancellation or refunds;
- deliver research, Content, alerts, emails, push notifications, SMS, and other communications and honor your preferences;
- maintain reading history, saves, bookmarks, watchlists, searches, alerts, and other requested features;
- operate search, ranking, recommendation, summarization, moderation, calculation, and other automated features where enabled;
- measure audience, Content, message, product, and campaign performance;
- troubleshoot, test, monitor, audit, research, analyze, improve, and develop the Service;
- prevent, detect, investigate, and respond to fraud, abuse, manipulation, spam, account compromise, prohibited conduct, technical failures, and security incidents;
- enforce the Terms and other agreements and protect Meridian, users, and others;
- respond to support, privacy, complaint, and other requests;
- verify identity, perform sanctions or fraud screening, and satisfy tax, accounting, consumer-protection, financial, licensing, recordkeeping, and other legal or regulatory obligations;
- establish, exercise, or defend legal claims and respond to lawful process;
- send marketing and measure marketing where permitted, subject to your choices; and
- carry out another purpose disclosed at collection or with your direction or consent.
[TO CONFIRM BEFORE PUBLICATION: deployed personalization, inference, recommendation, analytics, campaign measurement, advertising, and marketing purposes. Distinguish current background processing from expressly optional future features and narrow any public-facing statement that would otherwise misdescribe deployed processing.]
5. Legal Bases for EEA and UK Processing
If the EU GDPR or UK GDPR applies, Meridian relies on one or more of the following legal bases. The basis depends on the purpose and context.
- Contract. To create an account and provide requested Content, subscriptions, transactions, or optional features, Meridian may rely on performance of a contract or steps you request before entering a contract.
- Legal obligation. For billing, tax, sanctions, lawful requests, recordkeeping, and regulatory compliance, Meridian may rely on a legal obligation.
- Legitimate interests. For account and Service security, fraud prevention, support, auditing, limited product analytics, and agreement enforcement, Meridian may rely on its legitimate interests after considering and balancing your rights and interests.
- Consent. For nonessential cookies or device access, certain marketing, precise location, sensitive information, and other processing where law requires permission, Meridian may rely on consent, which you may withdraw prospectively.
- Vital interests. Where applicable, Meridian may rely on vital interests to protect a person's life or physical safety in an emergency.
Meridian does not rely on legitimate interests where your interests or fundamental rights override Meridian's interests. You may object to processing based on legitimate interests as described in Section 14.
[TO CONFIRM BEFORE PUBLICATION: purpose-by-purpose lawful-basis assessment, legitimate-interest assessments, and all processing that requires consent under GDPR, UK GDPR, PECR, or applicable ePrivacy law.]
6. How We Disclose Personal Information
Meridian may disclose personal information to the following categories of recipients for the purposes described in this Privacy Policy.
6.1 Service providers and processors
These may include providers of:
- cloud hosting, databases, storage, content delivery, backup, and application infrastructure;
- authentication, identity verification, KYC, sanctions, fraud prevention, and security;
- payment processing, merchant-of-record services, billing, subscription administration, app distribution, and tax calculation;
- email, push, SMS, customer support, survey, and communications services;
- market data, charts, news, financial connections, exchange entitlements, and related infrastructure;
- analytics, crash reporting, performance monitoring, consent management, and product improvement;
- AI models, search, content processing, transcription, translation, and moderation, where enabled; and
- legal, accounting, banking, insurance, audit, and other professional services.
Providers that process information on Meridian's behalf are contractually restricted as required by law.
[TO CONFIRM BEFORE PUBLICATION: active processors and service providers, data categories, purposes, contracts, subprocessor terms, processing locations, and transfer mechanisms. Maintain a current provider list at [TO CONFIRM: URL].]
6.2 Independent third-party controllers or businesses
Some third parties, such as payment providers, app stores, identity providers, exchanges, financial institutions, or other services you connect directly, may process information as independent controllers, businesses, or personal information handlers for their own compliance, security, or operational purposes. Meridian does not direct that independent processing, and the third party's privacy notice also applies.
[TO CONFIRM BEFORE PUBLICATION: every material independent third party, its legal role, data categories and direction of transfer, purpose, location, and privacy-notice link. Do not label a provider as independent merely because its contract uses that term; confirm the role for each processing activity.]
6.3 Authorized Meridian personnel and contractors
Authorized Meridian personnel and contractors may access personal information under Meridian's direction as needed to operate and administer the Service, create and deliver Content, process subscriptions, communicate with users, provide support, maintain security, analyze performance, and comply with law. Meridian limits access according to role and business need and applies confidentiality obligations.
6.4 Other users and the public
If you use a public feature, Meridian discloses the information you choose to make public as described in Section 2.7. If you communicate with another person through the Service, Meridian discloses the communication and related account information needed to deliver it to that recipient.
6.5 Connections and integrations you choose
Meridian may disclose information to a third-party service, exchange, financial institution, market-data provider, social network, app, device, or account when you request a connection or direct Meridian to make the disclosure. The feature notice and the third party's privacy notice describe the applicable processing.
6.6 Legal, safety, and enforcement recipients
Meridian may disclose information if it reasonably believes disclosure is necessary to comply with law, regulation, subpoena, court order, or other valid process; protect rights, safety, property, or the integrity of the Service; investigate fraud, abuse, manipulation, or a security incident; prevent harm; or enforce an agreement. Meridian may challenge or narrow a request where appropriate and lawful.
6.7 Business transactions
Meridian may disclose information to advisers, counterparties, financing sources, and a successor in connection with a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate safeguards and applicable law. Meridian will provide notice of a new controller where required.
6.8 At your direction or with consent
Meridian may disclose information when you direct it to do so, request a feature, or give consent. Meridian may also disclose aggregated or deidentified information as described in Section 9.
Where an event, webinar, survey, contest, promotion, or co-branded service offers an optional disclosure to a sponsor, partner, speaker, prize provider, or other identified organization, Meridian will identify that organization, the information, and the purpose before the disclosure and obtain any consent required by law. Registering for a Meridian event does not by itself authorize an undisclosed sponsor to use your information for its independent marketing.
7. Cookies, Local Storage, Pixels, and Similar Technologies
Meridian may use cookies, local storage, software development kits, pixels, tags, scripts, web beacons, redirected links, and similar technologies. A separate Cookie Notice should identify the technologies actually deployed, their providers, purposes, durations, and available controls.
[TO CONFIRM BEFORE PUBLICATION: complete production inventory across websites, apps, mini-programs, emails, embedded content, and third-party checkout or authentication pages. Confirm each vendor, cookie or identifier, first- or third-party status, duration, data collected, cross-site activity, consent category, and opt-out behavior. The public Cookie Notice must list deployed technologies; this counsel draft retains future coverage but does not authorize an inactive technology to be switched on without the required update and controls.]
- Strictly necessary. Authentication, account security, fraud prevention, load balancing, checkout, consent-state storage, and other functions required to provide a service you request.
- Functional. Language, time zone, theme, accessibility, reading, media, and other preferences.
- Analytics and performance. Page and feature use, traffic sources, errors, crashes, speed, conversion, and product improvement.
- Advertising and measurement. Ad delivery, attribution, frequency management, audience matching, campaign measurement, and interest-based advertising.
- Embedded third-party content. Charts, videos, maps, news, social features, support tools, and other third-party functions.
- Email interaction. Delivery, opens, link clicks, bounce, complaint, and campaign measurement.
Where applicable law requires consent, Meridian will not use nonessential technologies before providing the required notice and obtaining valid consent. Rejecting nonessential technologies must be as accessible as accepting them. You may adjust available choices through [TO CONFIRM: Cookie Settings link]. Browser and device settings may also block or delete some technologies, but essential functions may then stop working.
7.1 Do Not Track and Global Privacy Control
[TO CONFIRM BEFORE PUBLICATION: actual DNT response.] If accurate, Meridian may state: “Because there is no generally accepted standard for Do Not Track signals, Meridian does not respond to DNT.”
[TO CONFIRM BEFORE PUBLICATION: technical and legal handling of Global Privacy Control and other recognized opt-out preference signals.] Where required by applicable law, Meridian will treat a valid Global Privacy Control signal as a request to opt out of sale, sharing, or targeted advertising for the browser, device, and, where required and technically feasible, the known account associated with the signal.
8. Advertising, Sale, Sharing, and Targeted Advertising
The terms “sell,” “share,” and “targeted advertising” have specific and sometimes broad meanings under U.S. state privacy laws. Disclosure to an analytics, advertising, measurement, or audience-matching provider may fall within one of those definitions even when Meridian receives no money.
[TO CONFIRM BEFORE PUBLICATION THROUGH A DEPLOYMENT AND CONTRACT AUDIT: whether Meridian sells personal information; shares it for cross-context behavioral advertising; processes it for targeted advertising; discloses identifiers or activity for audience matching; or permits third parties to collect information across websites or services. Confirm the preceding 12 months, recipient categories, data categories, minors, contracts, opt-out link, cookie tool, and GPC behavior.]
If the audit confirms that Meridian does not engage in these activities, use and substantiate the following statement:
Meridian does not sell personal information for money. Meridian does not share personal information for cross-context behavioral advertising or process it for targeted advertising. In the preceding 12 months, Meridian has not done so.
If the audit identifies covered activity, remove that statement and disclose the categories, purposes, recipients, prior-period activity, and choices, including a conspicuous [TO CONFIRM: “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” link] and recognition of legally required preference signals.
9. Aggregated and Deidentified Information
Meridian may create and use aggregated or deidentified information for analytics, research, security, benchmarking, market analysis, service improvement, and other lawful purposes. If Meridian maintains information as deidentified under applicable law, Meridian will maintain and use it in deidentified form and will not attempt to reidentify it except to test deidentification or as otherwise permitted by law.
Publicly available information that can still be associated with a person or account is not necessarily deidentified. [TO CONFIRM BEFORE PUBLICATION: deidentification standard, contractual restrictions, recipients, and whether public-facing identifiers or Content are included in any external dataset, benchmark, model, or licensed product.]
10. Retention
Meridian retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, preserve settings or history you request, comply with tax, accounting, licensing, and legal obligations, maintain transaction and consent records, prevent fraud, resolve disputes, enforce agreements, and protect the Service.
Meridian considers the amount, nature, and sensitivity of information; the risks of unauthorized use or disclosure; the purposes of processing; whether those purposes can be achieved by other means; user expectations; and legal requirements.
- Account, profile, and authentication information. While the account is active and for [TO CONFIRM: period or criteria] afterward for security, claims, legal, or operational needs.
- Subscription, offer, payment, invoice, tax, consent, renewal, and cancellation records. [TO CONFIRM: period by jurisdiction and record type.]
- Reading activity, financial interests, saves, watchlists, searches, alerts, and personalization. [TO CONFIRM: period or account-controlled deletion behavior.]
- Email, push, SMS, campaign, delivery, open, and click information. [TO CONFIRM: period by message and data type.]
- Marketing suppression records. As long as reasonably needed to honor the opt-out or complaint, subject to applicable law.
- Meridian support and feedback submissions. Bug reports, feature requests, Contact Us records, related contact details, AI assessments, and handling history are retained until the matter reaches a final state and for 24 months afterward. Screenshots and other support attachments are retained for 12 months after the related matter reaches a final state. A non-personal product decision derived from an approved feature request may be retained while the requirement remains active and for 36 months after retirement.
- KYC, sanctions, tax, fraud, and identity-verification information. [TO CONFIRM: period required by provider, contract, or law; distinguish results from source documents.]
- Financial-account connection tokens and imported account data. [TO CONFIRM: active-connection period, post-disconnection deletion, and legally required records.]
- Support AI and live-chat records. Meridian uses automated processing to filter spam, organize support submissions, suggest priority, and identify possible duplicates. Locally stored live-chat transcripts are retained for 12 months after the chat ends; raw chat-provider event content is removed after 30 days. Successfully delivered internal support-notification payloads are removed after 90 days. Provider-side terms and retention remain [TO CONFIRM BEFORE ENABLING IN PRODUCTION].
- Public Content, comments, messages, and moderation records. [TO CONFIRM: deletion, deidentification, integrity, recipient-copy, and legal-hold rules.]
- Device, cookie, analytics, security, diagnostic, and audit logs. [TO CONFIRM: period by log and risk.]
- Backups. Until deletion or overwriting under the documented backup cycle of [TO CONFIRM: period.]
Meridian may retain information longer if litigation, an investigation, a legal hold, or another lawful need requires it. When retention is no longer necessary, Meridian will delete, deidentify, or securely isolate the information, as appropriate. Deletion from active systems may not immediately remove information from backups, public caches, search indexes, or copies retained by another recipient.
11. Your Choices
11.1 Account and profile
You may review or update available account and profile information through settings or by contacting Meridian. You may request account deletion through [TO CONFIRM: account deletion tool or URL] or Section 20.
If deletion affects an active paid subscription, Meridian will explain the effect on access and renewal and will take the steps needed to stop or administer future charges before closing the account. Meridian may retain transaction and other records where required or permitted by law.
11.2 Research, service, and marketing communications
You may manage available Content-delivery, alert, newsletter, and marketing preferences through [TO CONFIRM: preference center] or the unsubscribe link in an optional email. Opting out of marketing does not prevent Meridian from sending transaction, subscription, account, security, legal, or support messages. If research or other requested Content is itself delivered by email, turning off that delivery means you will no longer receive that Content by email.
11.3 Push, SMS, and location
You may change push and location permissions in Meridian or your device settings. You may opt out of SMS using the method stated in the message or settings. Changes may be device-specific and may prevent the related feature from working.
11.4 Third-party connections
If a connected-account feature is available, you may disconnect it through [TO CONFIRM: settings path] or the third-party provider. Disconnection stops future access through the connection but may not delete information already received or records Meridian must retain. Section 10 describes retention.
11.5 Cookies and advertising
You may use [TO CONFIRM: Cookie Settings link], browser or device settings, a legally recognized preference signal, and any [TO CONFIRM: privacy choices link] to exercise available cookie and advertising choices. Choices may be specific to a browser or device unless law requires Meridian to apply them more broadly to a known account.
11.6 Public Content and messages
If public or messaging features are available, settings may let you edit, delete, or limit certain information. Copies may remain in search caches, backups, quotations, reshares, recipient accounts, or records Meridian keeps for integrity, security, enforcement, or legal reasons.
12. Automated Processing and AI
Meridian may use automated systems to authenticate accounts, enforce access rights, detect fraud or abuse, calculate Content-related metrics, organize or recommend Content, moderate submissions, operate search, or provide AI-assisted features where enabled.
[TO CONFIRM BEFORE PUBLICATION: whether Meridian performs profiling or uses inferred interests; whether any decision is made solely by automated means; whether any such decision produces a legal or similarly significant effect; meaningful information about logic or main factors; and available objection, opt-out, contest, and human-review procedures.]
If accurate, Meridian may state:
Meridian does not use solely automated processing to make decisions that produce legal or similarly significant effects about you.
If Meridian introduces such processing, it will provide any notice, explanation of main factors, opportunity to contest, human review, opt-out, consent, and other safeguards required by law before the processing begins.
13. U.S. State Privacy Disclosures
Residents of states with applicable comprehensive privacy laws may have rights to:
- know whether Meridian processes personal information and access or receive a copy of it;
- correct inaccurate information;
- request deletion, subject to exceptions;
- obtain portable information;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit or withdraw consent for certain sensitive-information processing;
- use an authorized agent;
- appeal a refusal to act on a request; and
- receive equal service and not be unlawfully discriminated against for exercising a right.
The categories Meridian may collect are described in Section 2, sources in Section 3, purposes in Section 4, and recipient categories in Section 6. Section 8 addresses sale, sharing, and targeted advertising.
[TO CONFIRM BEFORE PUBLICATION: laws and thresholds applicable to Meridian; state-specific category tables; categories collected, disclosed, sold, or shared in the preceding 12 months; sensitive-information uses; financial incentives; authorized-agent requirements; appeal method; request methods; response timing; toll-free number if required; opt-out link; GPC; and whether a separate U.S. State Supplement will be published at [TO CONFIRM: URL].]
To submit a request, use Section 20. Meridian may verify identity and authority using information reasonably related to the request. An opt-out request generally will not require identity verification beyond what is necessary to associate the request with the relevant browser, device, or account. Meridian will explain any denial and any available appeal right.
14. EEA and UK Rights
If the EU GDPR or UK GDPR applies, you may have the right to:
- access personal data and information about its processing;
- correct inaccurate or incomplete data;
- request deletion in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller;
- withdraw consent prospectively; and
- lodge a complaint with your local supervisory authority.
You may exercise these rights using Section 20. Meridian may request information reasonably necessary to verify your identity. Requests are generally answered within one month, subject to lawful extensions. A request is normally free, although Meridian may charge a reasonable fee or refuse a request where permitted for manifestly unfounded or excessive requests.
[TO CONFIRM BEFORE PUBLICATION: supervisory authority details, whether Meridian must appoint an EU representative, UK representative, or Data Protection Officer, and the contact details to add in Section 20.]
15. Other Privacy Rights and Requests
Depending on where you live, you may have additional rights to access, correct, delete, restrict, object, withdraw consent, obtain portability, receive information about recipients, complain to a regulator, or appeal a decision. Rights are subject to legal limitations and exceptions.
To make a request, use Section 20. Meridian may verify your identity and authority, will use verification information only for the request and related security, and will respond within the period required by applicable law. An authorized agent may make a request where law permits, subject to verification. Meridian will not unlawfully discriminate against you for exercising a privacy right.
16. International Processing and Transfers
Meridian is operated from [TO CONFIRM: controller home country]. Meridian and its service providers may process information in [TO CONFIRM: principal processing countries and regions], where privacy laws may differ from those where you live.
Where required, Meridian uses a lawful transfer mechanism, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an applicable Data Privacy Framework certification, or another approved mechanism. Meridian uses a mechanism only where it applies to the relevant entity and transfer.
You may request information about applicable safeguards using Section 20. [TO CONFIRM BEFORE PUBLICATION: data-flow map, hosting and support regions, onward transfers, transfer assessments, vendor mechanisms, certifications, EU or UK establishment, and representative details.]
17. Additional Notice for Individuals in Mainland China
[TO CONFIRM BEFORE PUBLICATION: whether this section applies because Meridian offers the Service to individuals in Mainland China or analyzes their behavior there. If applicable, provide a Chinese-language notice and complete every item below before collection.]
Where the Personal Information Protection Law of the People's Republic of China (“PIPL”) applies, [TO CONFIRM: legal entity] is the personal information handler responsible for the processing described in this Privacy Policy.
Meridian will provide clear notice of the purpose and method of processing, categories of personal information, retention period, recipients, and methods for exercising rights. Where required, Meridian will obtain consent or separate consent, including for sensitive personal information, disclosure to another handler, public disclosure, and cross-border transfers. Withdrawing consent will not affect processing completed lawfully before withdrawal.
If Meridian transfers personal information outside Mainland China, Meridian will identify the overseas recipient's name, contact information, processing purpose and method, categories transferred, and the method and procedure for exercising rights with the overseas recipient. Meridian will obtain separate consent and use the applicable security assessment, certification, standard contract, or other required transfer measure.
Individuals may have rights to know, decide, restrict or refuse processing; access and copy information; correct or supplement it; delete it in specified circumstances; transfer it where legal conditions are met; withdraw consent; and request an explanation of processing rules.
[TO CONFIRM BEFORE PUBLICATION: Mainland China contact, local or overseas recipient details, sensitive-information list, separate-consent flows, data localization or cross-border mechanism, retention, request-response process and timing, automated-decision safeguards, and any personal information protection officer or representative required by PIPL.]
18. Security
Meridian uses administrative, technical, and physical safeguards designed to protect personal information, taking into account the nature of the information, the Service, and the risks of processing. Measures may include access controls, confidentiality requirements, security monitoring, incident response, vendor review, and secure disposal, where implemented.
No system, transmission, or storage method is completely secure, and Meridian cannot guarantee absolute security. You are responsible for protecting your credentials and using available account-security tools.
Meridian maintains procedures to investigate suspected personal-data incidents and will notify affected individuals and regulators where required by law. If you believe your account or information is at risk, contact [TO CONFIRM: security email or form].
[TO CONFIRM BEFORE PUBLICATION: production security baseline, responsible team, access review, encryption coverage, multi-factor authentication, logging, vulnerability management, vendor risk process, incident-response and notification procedures, certifications, and every specific security representation. Do not add a specific standard or certification unless verified.]
19. Children
The Service is not directed to anyone under [TO CONFIRM: minimum age; recommended 18], and a person below that age may not use the Service. Meridian does not knowingly collect personal information from a person below the applicable minimum age. If Meridian learns that it has done so, it will take reasonable steps to delete the information and deactivate the account, subject to legal obligations.
If you believe an underage person has provided personal information, contact Meridian using Section 20. [TO CONFIRM BEFORE PUBLICATION: align the minimum age and any age-screening process with the Terms and all app-store or regional requirements.]
20. Contact Us
Questions, concerns, complaints, security reports, and privacy requests may be sent to:
Controller / Responsible Entity: [TO CONFIRM: full legal name and entity type]
Mailing Address: [TO CONFIRM: physical mailing address]
Privacy Email: [TO CONFIRM: monitored privacy contact address]
Security Contact: [TO CONFIRM: security email or form]
Privacy Request Form: [TO CONFIRM: URL]
Telephone: [TO CONFIRM: number if required or offered]
EU Representative: [TO CONFIRM: name, address, email, or “not required”]
UK Representative: [TO CONFIRM: name, address, email, or “not required”]
Data Protection Officer: [TO CONFIRM: contact only if appointed or legally required]
Mainland China Contact or Representative: [TO CONFIRM: details if applicable]
You may also complain to the data-protection or consumer-privacy regulator with authority where you live.
21. Changes to This Privacy Policy
Meridian may update this Privacy Policy to reflect changes in the Service, law, or its practices. Meridian will post the revised version and update the effective date. If a change is material, Meridian will provide additional notice or obtain consent where required by law. Meridian will not treat continued use as consent where applicable law requires a separate affirmative choice.
Before Meridian begins processing a new category of personal information for a materially different purpose, it will update this Privacy Policy or provide a just-in-time notice and obtain any required consent. Prior versions will be retained or made available where required.