Privacy Policy & Data Handling
Last updated: July 25, 2026 · Meridiona
Applies to Meridian, the Meridiona LLP developer-productivity tool (version 1.75.0 and above).
This Privacy Policy describes what data Meridian collects, how it is processed and stored, who can access it, and how it can be deleted. It supplements, and does not replace, any Non-Disclosure Agreement between Meridiona LLP ("Meridiona," "we") and the organization that has authorized its employees to use Meridian ("Customer," "you"), and Meridiona's Terms of Use.
1. What Meridian is
Meridian is a local-first daemon that observes a developer's screen activity (window titles, on-screen text via OCR/accessibility APIs, and coding-agent session transcripts) and normalizes it into structured activity sessions, stored in a SQLite database on the user's own machine. Meridian is open source under the MIT License; the source code itself is not confidential, but the activity data it generates is.
2. What data Meridian collects
| Category | Examples | Source |
|---|---|---|
| Window & app activity | Active application name, window titles, timestamps, session durations | In-process screen capture on the user's device |
| On-screen text | Text extracted via OCR and macOS Accessibility APIs from the visible screen, browser URLs | In-process capture (capture_frames table) |
| Input signals | UI events (clicks, key activity) used to detect idle vs. active periods; no keystroke content is logged | In-process capture (capture_ui_events table) |
| Coding-agent sessions | Conversation transcripts and summaries from Claude Code, Codex, GitHub Copilot, and Cursor sessions on the user's machine | Local session-store files (e.g., ~/.claude/projects/, ~/.codex/sessions/) |
| Integration data | Ticket titles, status, and metadata from connected tools (e.g., Jira, Linear, GitHub), if the user connects them | Direct API calls from the user's device to the connected service, using the user's own credentials |
| Diagnostic/telemetry data | Application logs and error traces (structured, with any sensitive field values redacted where feasible) | Local telemetry spool on the user's device |
Meridian does not capture audio, and does not log raw keystroke content.
3. Where data is stored
All activity data is stored locally, in a SQLite database on the individual employee's own machine (~/.meridian/meridian.db). Meridiona does not operate a central server that stores customer activity data by default. There is no daemon-side network listener and no account/authentication system. Meridian does not transmit activity data off the device as part of normal operation.
Diagnostic logs and traces are likewise captured to a local spool on the device (~/.meridian/telemetry/) and are retained there subject to the retention periods in Section 5.
4. When data leaves the device
Data leaves the employee's device only in the following specific cases:
- Worklog summarization via a third-party AI provider. To generate work-log drafts and session summaries, Meridian sends relevant session text (e.g., extracted window/OCR text, coding-agent summaries) to the large-language-model provider the user configures (e.g., an Anthropic, OpenAI, or other provider account/API key supplied by the user or Customer). Meridian does not operate its own hosted model for this purpose; the user's chosen provider processes this data under that provider's own terms. Customer should ensure any provider it authorizes has data-handling terms it is comfortable with.
- Connected integrations. If a user connects a third-party tool (e.g., Jira, Linear, GitHub), Meridian exchanges data directly with that service via the credentials the user supplies, subject to that service's own terms.
- Diagnostics export (manual, user-initiated only). A user or IT admin can manually export a diagnostics bundle (logs and crash data) via the "Export Diagnostics" feature to share with Meridiona support when troubleshooting an issue. This is not automatic.
- Opt-in error reporting to Meridiona (if enabled for your deployment). Some Meridian builds support an opt-in mechanism that ships redacted, error-only diagnostic logs to a central Meridiona observability system, to help us fix bugs. This is off unless separately enabled and consented to, sends error/log data only (not full activity data), and is redacted before leaving the device. Contact us to confirm whether this applies to the build your organization has deployed.
Meridiona does not sell activity data, and does not share it with advertisers or data brokers.
5. Retention
- Activity data (
app_sessions, etc.): retained locally on the device until the user or Customer deletes it; there is no automatic expiry. - Raw capture frames (screen/OCR/UI-event records already processed into sessions): pruned automatically after 30 days by default (configurable), once consumed by the processing pipeline.
- Diagnostic telemetry (logs/traces): retained locally for 7 days by default (configurable), whether pending or already exported.
Retention windows above reflect current default configuration and may be adjusted; Customer may request Meridiona confirm the values in effect for the version it deploys.
6. Who can access the data
- The employee whose activity is captured has full access to their own local database and can inspect, export, or delete it directly.
- Customer, as the employer authorizing use of the tool, is responsible for determining its own internal policies on who within the organization may view dashboards, reports, or exports derived from this data, consistent with Customer's own employment and privacy policies and applicable law in its jurisdiction.
- Meridiona does not have standing access to Customer activity data, because it is stored locally and not transmitted to Meridiona by default. Meridiona personnel may access data only if a user affirmatively shares a diagnostics export for support purposes (Section 4.3), or as otherwise agreed in writing.
- Third-party AI/integration providers the user configures receive only the data described in Section 4, under that provider's own terms.
7. Security measures
- Activity data is stored in a local, unauthenticated SQLite database scoped to the individual employee's own user account and file-system permissions on their device: the same trust boundary as any other local application data.
- Meridian's daemon does not open any network port or run an HTTP server; there is no remote attack surface for the activity database itself.
- Data sent to third-party AI or integration providers travels over TLS to that provider's API, using credentials the user controls.
- Diagnostic logs are redacted where feasible before being written to the local spool or exported.
8. Deletion requests
Customer (or an individual employee) may request deletion of Meridian's locally stored data at any time by:
- Uninstalling Meridian and removing the
~/.meridiandirectory on the employee's device (which deletes the SQLite database and telemetry spool in full), or - Requesting Meridiona's assistance if data was shared with Meridiona directly (e.g., via a diagnostics export), in which case Meridiona will delete the shared copy within 30 days of request, absent a legal obligation to retain it.
Because activity data lives on the employee's own device by default, most deletion requests can be fulfilled directly by Customer or the employee without needing to contact Meridiona.
9. Children's data
Meridian is a workplace productivity tool not directed at children, and is not knowingly used to collect data from individuals under 18.
10. Changes to this policy
Meridiona may update this Privacy Policy as Meridian's functionality changes (e.g., new integrations, new telemetry). Material changes affecting Customer data handling will be communicated to Customer's designated contact.
11. This website (meridiona.com)
Separately from the Meridian app described above, meridiona.com (the marketing site you're reading now) uses two third-party services:
- PostHog: privacy-friendly product analytics (page views, button clicks) so we can see how people use the site. This only runs after you accept the cookie banner; declining or ignoring it means nothing is captured. See our Cookie policy for details.
- Resend: if you submit a download or waitlist form, we store what you entered with Resend so we can send you release notes and updates. The download form asks for your email and, optionally, a phone number. The waitlist form additionally asks for your name, your profession, optionally a LinkedIn profile URL, and an optional free-text comment; we use those only to decide what to build next and who to tell about it. A copy of each waitlist submission is also emailed to our own team inbox. You can unsubscribe from any email we send, and you can ask us to delete a submission at the address below.
We don't sell personal data, and we don't run cross-site ad tracking on this site.
12. Contact
Questions about this Privacy Policy or data handling can be directed to: .