Scope of this policy
This policy covers merido.dev and the Merido platform at app.merido.dev, including your account, digital company, digital employees and the features you use. Merido Gateway at gw.merido.dev is a separate service; when using it directly, refer to the policy published there.
If you bring customer or team-member data into Merido, you are responsible for informing those people and having a lawful basis to process their data. Merido processes this content to carry out the work you configure on the platform.
Data we receive
Account and contact information: your email, profile information, digital company name and the members you invite. When you request a consultation on our website, you provide your name, phone number, optional email and intended use.
Work content: knowledge, documents and instructions you provide; messages with digital employees; customer conversations from connected channels; work results and app configuration. Credentials or connection keys are received when you choose to connect a service.
Operational and transaction information: AI usage, system events, activity logs, plan status, transaction identifiers and payment history. Sensitive payment details are entered on the payment provider's checkout page, not in Merido chat.
How we use data
We use data to sign you in, manage access, operate digital employees, maintain conversation context, carry out assigned tasks and show history for your review.
Usage and transaction data support billing, allowance management, customer support, troubleshooting and abuse prevention. Information from the consultation form is used to contact you about the needs you submitted.
Data used during AI tasks
Merido does not use your uploaded knowledge or conversation content to train AI models. Generating a response still requires sending relevant context to the model handling your request — no training does not mean data never leaves the platform.
The model or AI service provider you choose has its own data processing and retention terms. If you use your own AI key, review that provider account's terms and settings. Do not include confidential or sensitive data that you are not authorised to send to the services involved.
Who processes data
Merido relies on infrastructure, storage, authentication and AI model providers to operate the service. Necessary data may be processed outside your country of residence, depending on the infrastructure and services used. Merido does not sell customer conversation content.
When you connect an external channel, app or tool, the data needed for an action is exchanged with that service under the permissions you grant. These services have their own policies; disconnecting them does not automatically delete data already sent to them.
Payments are handled through Creem. Necessary transaction data is exchanged to confirm payments, manage subscriptions and process refunds. We may also disclose information to comply with lawful requests from competent authorities.
Protection and access
Each digital company has its own AI environment, with access limited by account, role and granted scope. Connection keys, channel credentials and backups are protected through the platform's encryption mechanisms.
You should secure your account, invite only authorised people and review connected services. No system can guarantee absolute security; if you suspect an account or connection key has been compromised, revoke the relevant access and contact Merido.
Cookies and browser storage
The app uses cookies and browser storage needed to maintain sign-in, sessions and interface preferences. You can clear or block them in your browser, but some features, particularly sign-in, may no longer function as expected.
Retention and deletion
Work content is stored so you can continue using the service and review its history. Cancelling renewal or disconnecting a service is not a request to erase all data. Operational data may remain during recovery periods or in backups before cleanup.
To request account or data deletion, contact us from your account email so we can establish the scope. Some transaction records, security logs and information needed for legal obligations or disputes may need to be retained separately; not every category has the same retention period.
Your rights and choices
You can edit your digital company's content, manage members and disconnect services in the app. To request access, correction, a copy or deletion of personal data, or to stop consultation follow-ups, email team@merido.dev. We may need to verify your authority before acting on a request.
If a request concerns a digital company managed by someone else, contact that manager first. The current policy is published here with its update date. You can contact Merido for clarification about how data is handled.