Privacy Policy
1Who this covers
This policy covers the Meridian applications, the website at meridiancash.io, and the API behind them. Meridian, based in New York, United States, is the controller of the personal data described here.
Connecting a bank is the largest thing this app asks of anybody, so this document is written to be read rather than to be survived. If something in it is unclear, write to privacy@meridiancash.io and we will answer and fix the wording.
2What we collect
What you give us. Your email address, and — if you subscribe — the billing details our payment processor needs. We never receive or store your card number.
What your institutions give us, through Plaid. For each account you connect: the institution, the account name, type and last four digits, balances, transactions with their amounts, dates, merchants and categories, and investment holdings and their cost basis. This is your ledger, and it is the reason the app exists.
What we hold to keep the account working. A hashed sign-in code while one is outstanding, a hashed session token for each device you are signed in on, and the sealed token that reads a bank connection.
What the server writes down. Ordinary request logs: the time, the path, the response, and the IP address the request came from. They exist to find faults and to stop abuse.
What we do not collect. Your bank username and password never reach us — you type those on your institution’s own page inside Plaid. We do not ask for your government ID, your social security number, your phone number or your date of birth. This website sets no cookies and runs no analytics.
3Why we hold it
- To run the app. Your ledger is what every screen and every calculation is made of.
- To sign you in. The code we email you, and the session that follows it.
- To bill you. If you are on a paid plan.
- To keep it working and safe. Diagnosing faults, rate-limiting, and investigating abuse.
- To answer you. Support email, and the account notices we have to send.
- To meet legal obligations. Tax and accounting records, and responses to lawful requests.
Where the GDPR applies, our bases are performing our contract with you (running the app, billing), our legitimate interests (security, fault diagnosis, preventing abuse), your consent where we ask for it, and legal obligation. You can withdraw consent at any time.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use your ledger to build products for anybody but you.
4The assistant, and models
Meridian’s assistant works under one rule: the model does not do the math and does not see your raw ledger. Your question is turned into a query, our engine computes the answer from your data, and the model explains the result.
What leaves our servers for a model provider is therefore your question and a structured, minimal result — not a dump of your transactions. We do not permit model providers to train on it.
5Who else sees it
Only the providers the Service is built out of, each doing one job under contract with us:
- Plaid Inc. — connects your bank and brokerage accounts and returns balances, transactions and holdings. Their privacy policy.
- Resend — delivers the sign-in codes and account email we send you. Their privacy policy.
- Stripe — takes payment for a subscription on the web; card details go from your browser to Stripe and never reach our servers. Their privacy policy.
- DigitalOcean — hosts the server and the database the service runs on. Their privacy policy.
- A model provider — receives a question and a structured result when you use the assistant, under the rule in section 4.
Beyond those: when the law compels us, and then only what is compelled and, unless we are forbidden from saying so, after telling you; and if the business is ever sold or merged, to the acquirer, who is bound by this policy until it tells you otherwise.
That is the whole list. There are no advertisers and no data brokers on it.
6How long we keep it
- Your ledger — for as long as your account is open.
- A disconnected institution — removing a bank deletes the accounts, transactions and holdings that came through it, and revokes the token that read it.
- A closed account — deleted from the live database within 30 days, and gone from encrypted backups within 90 as those rotate.
- Sign-in codes — minutes. They expire and are deleted.
- Sessions — until you sign out, which deletes the row.
- Request logs — up to 90 days.
- Invoices and tax records — as long as tax law requires, which is usually several years, and separately from your ledger.
7How it is protected
- Everything travels over TLS. The server is reachable only through a single proxy that terminates it.
- The token that reads a bank connection is sealed with AES-256-GCM before it is written down, so a stolen backup is not a set of live bank connections.
- Sign-in codes and session tokens are stored as SHA-256 hashes, never as themselves, so a stolen database is not a set of live logins.
- Data is scoped to its owner at the query, and access to production is limited to the people who run the Service.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator without undue delay, and say what happened rather than that “an incident occurred”. If you have found a vulnerability, write to privacy@meridiancash.io.
8What you can ask for
- A copy. Export your ledger from the app, in a format something else can read.
- A correction. Data that came from an institution is corrected at the institution and re-synced; anything else, tell us.
- Deletion. Close your account, or ask us to close it.
- Restriction or objection to a particular processing, and portability of what you gave us.
- To know what we hold, where it came from, and who it went to.
Write to privacy@meridiancash.io. We answer within 30 days, we do not charge for it, and we will not treat you differently for asking. If you are in the EEA or the UK you may also complain to your data protection authority; if you are in California, the rights above are the ones the CCPA gives you, and we do not sell or share your information.
9Where it is processed
The Service runs on servers in the United States, and our providers process data there. If you use it from outside the United States your data is transferred there; where the GDPR applies, we rely on the European Commission’s standard contractual clauses with providers that need them.
10Children
The Service is not for anybody under 18, and we do not knowingly collect data from a child. If you believe a child has an account, write to privacy@meridiancash.io and we will delete it.
11Changes to this policy
We may update this policy. If a change materially affects what we do with your data, we will email you at least 30 days before it takes effect. The date at the top always says when it last changed, and continuing to use the Service after that date is acceptance of it.
12Contact
Privacy: privacy@meridiancash.io. Everything else: support@meridiancash.io. We answer within one or two business days.
The Terms of Service cover the rest of the agreement.