Last updated: [to be set at launch]
Privacy Policy
This Privacy Policy explains what personal data Meridiar collects, why, and how you can control it. It’s written to meet UK/EU GDPR requirements.
The data controller is [legal entity name — pending registration], company number [pending], registered address [pending]. This block will be completed once the operating company is registered.
1. What we collect
- Account data — email address, hashed password (via Supabase Auth), and your token balance.
- Content data — the prompts you submit and the images generated from them, linked to your account.
- Payment data — handled by our payment processor; we receive confirmation of a successful charge and the tokens it bought, not your full card number.
- Technical data — IP address and basic request logs, used for rate limiting and abuse prevention.
- Support data — anything you send us when you contact support.
2. Why we process it
- To create and run your account, and to generate the images you request (performance of a contract).
- To process payments and keep a record of your purchases (legal obligation; performance of a contract).
- To prevent abuse of the free-generation allowance and enforce rate limits (legitimate interest).
- To block and, where required, report illegal content — see Section 4 of the Terms of Use (legal obligation).
- To respond when you contact us (legitimate interest).
3. Who we share it with
We use a small number of service providers to run Meridiar, each acting as a data processor under contract:
- Supabase — hosts our database and handles authentication.
- Cloudflare and fal.ai — run the image-generation models; your prompt is sent to them to produce the image.
- Stripe — processes card payments.
We don’t sell your personal data, and we only share it beyond the providers above if required by law.
4. International transfers
Some of the providers above may process data outside the UK/EEA. Where that happens, we rely on their standard contractual clauses or equivalent safeguards.
5. How long we keep it
We keep account and generation data for as long as your account is active, and for a reasonable period afterward to meet accounting and legal obligations. You can request deletion at any time — see Section 7.
6. Security
Access to user data in our database is restricted by row-level security tied to your account, and administrative actions run through server-side code rather than being exposed directly to the browser. No system is perfectly secure, but this is the standard we design to.
7. Your rights
Under UK/EU GDPR, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct data that’s inaccurate or incomplete;
- delete your data, subject to legal retention requirements;
- restrict or object to certain processing;
- export your data in a portable format, or transfer it to another provider where feasible;
- withdraw consent at any time, for anything we process based on consent.
To exercise any of these, email support@meridiar.com. If you’re not satisfied with our response, you can complain to your local data protection authority (in the UK, the ICO at ico.org.uk).
8. Children
Meridiar is for people 18 and over. We don’t knowingly collect data from anyone younger. If we learn we have, we’ll delete it.
9. Changes to this policy
We’ll update this page if how we handle data changes, and update the date at the top when we do.
10. Contact
Questions about this policy or your data? Email support@meridiar.com.