← Meridian

Privacy Policy

Last updated: October 1, 2026

Overview

Meridian (“the app,” “we”) is a personal life-tracking application for habits, health, nutrition, budgeting, journaling, and related self-tracking features. This policy explains what data the app collects, how it's used, who it's shared with, and the choices you have over it.

Meridian is operated as a personal project, not a company. If you're using an account on this app, the contact at the bottom of this page is who to reach for any privacy question or request.

Information we collect

Account information. Your email address and password (handled by our authentication provider, Supabase Auth — we never see or store your password in plain form).

Profile information. Display name, an icon you choose, date of birth, and gender — all optional, entered by you.

Activity and tracking data. Whatever you choose to log: habits and their completion history, journal entries, goals and milestones, budget and expense entries, nutrition and food logs, water/sleep/fasting/meditation/workout logs, carbon-footprint entries, calendar events and to-dos, and progress photos you upload.

Health and fitness data. If you connect a Fitbit or Pixel Watch account, we sync steps, heart rate, sleep, and calorie data from the Google Health API into your account. This is entirely opt-in — nothing is synced unless you explicitly connect it, and you can disconnect at any time in Settings.

Cycle tracking data. If you turn on cycle tracking (off by default), period, symptom, mood, and related entries you log are stored the same way as any other tracking data above — private to your account, never shared with other users.

AI Coach conversations. If you use the AI Coach feature, your messages and the relevant tracking data needed to answer them are sent to Google's Gemini API to generate a response. Conversation history is stored in your account so the AI Coach has context across messages.

Friend connections. If you add a friend by email, we look up whether an account exists for that email and, once accepted, share only the specific habits you've explicitly marked as shared — never any other data.

Device and diagnostic data. If you enable push notifications, we store the browser-provided subscription details needed to deliver them. We also use automated error monitoring (Sentry) to catch bugs — this captures stack traces and the page/action that failed, not your tracking data or page content, and does not record screen replays.

How we use your information

Your data is used solely to provide the app's features to you: displaying your logs and trends, computing streaks and summaries, sending reminder notifications you've opted into, generating AI Coach responses, and syncing health data from a connected device. We do not sell your data, and we do not use it for advertising.

Third-party services we use

The app relies on the following services to operate. Each only receives the data it needs to do its job:

  • Supabase — database, authentication, and private file storage for progress photos.
  • Google Health API — only if you connect a Fitbit/Pixel Watch account, to pull in steps, heart rate, sleep, and calorie data.
  • Google Gemini API — only if you use the AI Coach, to generate responses to your messages.
  • Open Food Facts — food name searches when logging a meal, to look up nutrition facts for a product.
  • Climatiq — activity details (e.g. distance and mode of travel) when estimating a carbon-footprint entry's CO₂e, with no personal identifiers attached.
  • Vercel — application hosting, plus anonymized, aggregate performance metrics (Speed Insights).
  • Sentry — error monitoring, as described above.
  • Web Push (a W3C browser standard, not a third-party company) — delivers notifications you've opted into.

Data storage and security

  • Every table in our database enforces row-level security — your data is only ever readable by you (or, for the specific habits you mark shared, your accepted friends).
  • All connections to the app are encrypted (HTTPS/TLS).
  • Progress photos are stored in a private bucket; the app only ever generates short-lived, signed URLs to display them, never a public link.
  • An optional app-lock PIN is salted and hashed before storage — we never store it in a readable form.
  • OAuth tokens for connected services (like Google Health) are stored server-side and are never exposed to your browser.

Data retention

We keep your data for as long as your account exists. If you delete your account, every piece of data described above — habits, logs, journal entries, photos, health data, everything — is permanently deleted, generally within moments, with no recovery period.

Your rights and choices

  • Export your data at any time from Analytics, as CSV or JSON.
  • Delete your account at any time from Settings — this is permanent and immediate.
  • Disconnect your Fitbit/Google Health connection at any time in Settings; previously synced data stays until you delete it or your account.
  • Turn off cycle tracking at any time; it's opt-in to begin with.
  • Opt out of push notifications at any time in Settings or your browser's notification permissions.

Children's privacy

Meridian is not directed at children, and we don't knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we'll delete it.

Changes to this policy

If this policy changes in a meaningful way, we'll update the “Last updated” date above. Continued use of the app after a change means you accept the updated policy.

Contact

Questions, concerns, or a request about your data not covered by the self-service options above: sssigmaxx@gmail.com.