Privacy policy
Meridian connects to your bank through Plaid to build a monthly view of your own money. This page describes exactly what it collects, why, who else touches it, how long it stays, and how to get rid of it.
Version 2026-08-06.2 · Last updated 6 August 2026
Who is responsible
Meridian is operated by a single individual — its founder — and is used by a small number of invited people, each with their own separate account. The founder is the operator and the data controller for everything described here. Each account's financial data is readable by that account alone: no user can see another's records, and the founder's administration tools list who has access without showing anyone's finances. For any question about this policy, or to exercise any right described below, contact ravino.juwono@gmail.com.
What is collected
Financial data, via Plaid.When you connect a bank account, Meridian requests Plaid's Transactions product and nothing else. That covers:
- Account identifiers, names, official names, types, subtypes and masked numbers
- Account balances — current, available, and credit limits
- Transactions — date, authorised date, amount, currency, description, merchant name, Plaid's category, and whether the transaction is pending
- The institution's name and the connection's status
Meridian does notrequest Plaid's Identity, Auth, Investments, Liabilities, Income, Assets, Enrich or Recurring Transactions products. It does not receive your name, address, phone number, or account and routing numbers from Plaid, and it never sees your online banking credentials — those are entered at your bank, through Plaid, and never reach this application.
Data you provide directly.CSV files you import, categories and rules you create, corrections you make to any transaction's classification, and notes you write.
Account and security data.Your email address, a one-way scrypt hash of your password (never the password), one-way digests of session tokens, one-time codes and recovery codes, and a security log of authentication events. Each security-log entry records what happened — a sign-in, a failed code, a session revoked — along with the time, the IP address the request came from, and the browser's user-agent string. It never records a password, a code, a token, an account number, or a transaction amount.
No analytics, no advertising, no tracking. There is no analytics script, no advertising network, no third-party cookie, and no tracking pixel anywhere in this application, including in its emails. The only cookies set are the session cookie and the CSRF token that protects it, both of which are strictly necessary to sign in.
Why it is collected
The lawful basis is your consent, which is recorded with a version and a timestamp before any request is made to your bank, and can be withdrawn at any time. Everything collected serves one of these purposes:
- Categorising transactions and detecting recurring payments
- Matching both sides of a credit-card payment and of internal transfers, so that money moved between your own accounts is not counted as income or as spending
- Computing your monthly close: income, spending, savings rate, and a reconciliation against your account balances
- Generating written summaries of figures that were already computed locally
- Authenticating you, and detecting unauthorised access to your account
Your financial data is never sold, rented, shared for advertising, or used to train any model.
Who processes it
Meridian depends on the following service providers. Each is used for one purpose, and receives only what that purpose requires.
| Provider | Role | What it receives | Where |
|---|---|---|---|
| Plaid Inc. | Retrieves data from your bank on your instruction | Your bank credentials (entered directly with Plaid, never seen by Meridian); returns account and transaction data | United States / Canada |
| MongoDB Atlas | Stores all application data at rest | Everything described above | Cloud region selected at cluster creation |
| Vercel | Hosts and serves the web application | Requests and responses in transit; server logs | Global edge network |
| Railway | Runs the scheduled background sync | Database access, and Plaid access tokens in memory during a sync | Cloud region selected at deployment |
| OpenAI | Writes prose summaries, and proposes categories for unclear transactions | For summaries: monthly aggregate figures, category totals, and recurring-merchant display names. For category proposals: the date, amount, description, merchant name, account type and the bank's own category of each transaction the built-in rules cannot settle. Never account numbers, bank credentials, or your email address. | United States |
| Resend | Delivers sign-in verification emails | Your email address and the one-time code | United States / European Union |
Requests to OpenAI are sent with storage disabled, so they are not retained for model training by default. If you disable AI in Settings, or leave the OpenAI key unset, Meridian uses a deterministic local summariser instead, category proposals are simply not made, and no data leaves for either purpose.
Some of these providers are outside Canada, which means your data may be processed in a jurisdiction whose laws differ from Canadian law and may permit lawful access by foreign authorities.
How long it is kept
| Data | Retention |
|---|---|
| Transactions and balances | Currently kept until you delete them |
| Your classifications, rules and notes | Kept until you delete them |
| Monthly closes | Kept until you delete them |
| AI analyses | 400 days |
| Security log | 365 days, then removed automatically |
| Sessions | At most 720 hours; removed on expiry |
| One-time codes | 10 minutes; single use |
| Consent records | Kept, including withdrawals, as evidence of what was agreed and when |
The full rules, including the one exception, are on the data-retention page.
Your rights and how to use them
- Withdraw consent. Security page → Bank-data consent. Meridian stops requesting anything further from your bank.
- Disconnect a bank.Accounts page → Disconnect. This also removes the Item at Plaid, so Plaid stops fetching on Meridian's behalf. Data already imported is kept unless you delete it.
- Delete data. Settings → Your data. You can delete imported transactions, a single connection and its accounts, all financial data, or your entire account. Deletion is immediate and irreversible.
- Export. Transactions and monthly summaries can be exported as CSV at any time from the export endpoints in the app.
- Access and correction.Every record is visible in the application, and any classification can be corrected — corrections are stored separately from the bank's original record, which is never overwritten.
Destructive actions require both a typed confirmation and a fresh verification code, even though you are already signed in.
Canadian context
The operator is in Canada and the application is built for Canadian accounts. Personal information is handled in line with the principles of the Personal Information Protection and Electronic Documents Act (PIPEDA): identifying purposes, obtaining consent, limiting collection to those purposes, limiting use and retention, keeping information accurate, safeguarding it, being open about practices, providing access, and providing a route to challenge compliance.
As a private application with a single user who is also the operator, several PIPEDA obligations are structurally trivial here — there is no third party to whom information is disclosed for commercial purposes, and no other individual whose consent must be sought. Concerns about how personal information is handled can be raised with the operator at ravino.juwono@gmail.com, and, if unresolved, with the Office of the Privacy Commissioner of Canada.
If something goes wrong
If unauthorised access to financial data is discovered, the operator will revoke all sessions, rotate every credential — the authentication key, the encryption key, the Plaid and OpenAI keys, and the database password — disconnect affected bank connections, and record the incident. Because the only individual affected is the operator, notification is immediate by definition. The procedure is written down in the repository asdocs/INCIDENT_RESPONSE.md and is summarised on the security page.
Changes to this policy
This policy is versioned. Consent is recorded against a specific version, and when the version changes, previously recorded consent stops satisfying the check and is collected again before any further bank data is requested. An old agreement is never silently carried forward over new terms.