Privacy Policy
Last updated: 11 August 2026
This policy describes how Meridian handles information for the web application and the native iOS application (including TestFlight and App Store builds). We take a product stance: less noise, clear numbers, and honest data handling.
Two surfaces, shared principles
- We do not sell your financial data.
- We do not run ads against your portfolio.
- The native app does not include advertising SDKs or use the advertising identifier for tracking.
Web application
- You create an account with email and password. Authentication and data storage are provided by Supabase (PostgreSQL with Row Level Security).
- Financial records (categories, sources, snapshots, balances) are associated with your user ID and stored in our database so you can access them when signed in.
- Optional third-party infrastructure (e.g. hosting on Vercel, exchange-rate APIs) may process technical requests required to run the service. Exchange-rate calls should not include your balances.
iOS application (Meridian native)
iOS supports two modes. You choose on first launch (and can change later).
- On this device only. No account required. Financial data you enter is stored only on your device (app sandbox). It is not uploaded or synced by the app in this mode.
- Cloud account (optional). You may sign in with email and password to load and refresh portfolio data associated with your Meridian web account. In this mode, email and financial records are processed under the same cloud model as the web app (Supabase, RLS by user ID).
- You can move data to this device and leave cloud on the phone, or use Delete Account in Settings when signed in with cloud.
- Optional demo portfolio data (on-device empty state) is generated locally only when you explicitly choose to load it.
- Network use for cloud mode is for authentication and portfolio sync only. Local-only mode does not send balances to our servers.
What we collect
Web & iOS cloud mode
- Account email and authentication credentials (hashed by Supabase Auth).
- Financial data you enter or sync while signed in.
- Standard technical logs from hosting (IP, user agent) as part of operating the service—not used to profile your wealth.
iOS on-device only
- We do not collect personal or financial data from the app in this mode. Data you enter remains on your device.
- Uninstalling the app or using in-app delete removes that local data (subject to any device-level backups you control).
Retention and deletion
On the web app you may delete snapshots and related records while signed in. On iOS cloud mode, use Settings → Account → Delete Account to request deletion of your account and associated cloud portfolio data. You may also contact ahmil2010@gmail.com. On iOS local mode, use Settings → Data → Delete all data, or uninstall the app.
Children
Meridian is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children.
Changes
We may update this policy as the product evolves. The “Last updated” date at the top will change when we do. Continued use of the service after updates constitutes acceptance of the revised policy where permitted by law.
Contact
Questions about privacy or this policy: ahmil2010@gmail.com