Meridex

Legal

Privacy Policy

Effective 21 August 2026.

This Privacy Policy explains what Meridex collects, why, and who else sees it. We built Meridex to collect as little personal information as the product can function on — this page is meant to be short and read in full.

How your account works

Meridex accounts are email-first and passwordless. The email address you sign in and check out with is the core piece of personal information we store. We use it to send your one-time sign-in links, agent proposal notifications, billing and account-security emails, and receipts. We do not collect your name, mailing address, date of birth, or government ID. The Service uses a strictly necessary session cookie to keep you signed in after you sign in — it is not used for advertising or analytics.

You can sign in with a Google account, with Apple (on the desktop app), or with a one-time link emailed to you. Every route establishes the same single fact: that you control an email address. If you use Google or Apple, we ask only for your email address on that account — no name, no profile, no photo, no contacts, and no ongoing access to any Google or Apple service. We never receive your Google or Apple password, we cannot act on that account, and you can disconnect Meridex at any time from your Google or Apple account settings. If you would rather not involve either of them, the emailed sign-in link does the same job.

What else we store, and why

  • Your brokerage connection. Meridex connects to a brokerage account you choose — either through SnapTrade’s connection portal (which supports a range of brokerages) or, for Robinhood, directly through Robinhood’s own authorization screens — which you complete directly with the brokerage or SnapTrade, never with us. We never see or store your brokerage password. What we do receive and store is the resulting access credential, encrypted at rest, used solely to operate the Service (requesting quotes and positions, and placing orders you approve), and never appearing in logs, API responses, support tooling, or any sale or share of data.
  • Your run settings, proposals, and their outcomes. Which agents you run under All-Access, the proposals sent to you, and whether you approved, skipped, or let one expire — so your dashboard can show your history and we can generate a receipt for anything that fills.
  • Your subscription status. Provided by Stripe: your All-Access subscription, billing status, and renewal dates. We never see or store your card number — Stripe handles payment details directly.
  • Basic request metadata for security and abuse prevention — for example, a hashed, non-reversible form of your IP address, never the raw address.
  • If you use the Meridex iPhone app: a device push-notification token, so we can alert you when a new agent proposal is waiting on your decision. The token identifies your device to Apple’s push service, not you personally, and is deleted the moment you sign out of the app on that device.
  • If you list an agent as a publisher: the agent’s display name, asset class, status, and computed track record, plus a one-way sha256 hash of its ingest credential. The credential itself is shown to you once at creation and is never stored in plain text anywhere, including in our own database. See Publisher Terms for how a listing’s record is measured.

Who processes data on our behalf

This is the complete list — we do not use any other third-party data processor.

  • Vercel hosts the Service and, as any web host does, logs requests (including IP addresses) for operational and security purposes.
  • Neon (Postgres) stores the data described above.
  • Stripe processes payments and holds your billing details and email.
  • Your brokerage — whichever one you connect — is your broker of record. If you connect through SnapTrade’s portal, SnapTrade facilitates that connection and holds the access credential SnapTrade itself issues; if you connect Robinhood directly, the Service connects to your dedicated Robinhood Agentic account through an authorization you grant directly on robinhood.com. Either way, that connection is used to read your account, positions, and quotes, and to place the orders you approve.
  • Resend delivers transactional email (sign-in links, proposal notifications, receipts, and security notices).
  • Google verifies your identity if — and only if — you choose to sign in with a Google account. Google tells us the email address on that account and nothing else. Choosing the emailed sign-in link instead means Google is never involved.
  • Apple verifies your identity if — and only if — you choose to sign in with Apple on the desktop app; Apple tells us the email address on that account and nothing else. Apple also delivers push notifications to the Meridex iPhone app, if you use it, via your device’s push token as described above. Choosing the emailed sign-in link instead means Apple is never involved in sign-in.

Meridex contains no third-party advertising SDKs — Meta, TikTok, or otherwise — and the site does not use analytics tools that fingerprint your device or build an advertising profile. We do not sell your personal information, and we have never sold it — see the “Your rights” section below.

Cookies and tracking

Beyond the strictly necessary session cookie described above, the meridex.app website does not set advertising or analytics cookies and does not use any third-party tracking script.

Data retention and deletion

We keep account and agent-activity data for as long as your account is active, and for a limited period after that as needed for legal, tax, and dispute-resolution purposes. You can request deletion of your account at any time by emailing us; deleting your account permanently removes your account data, including proposals, run settings, subscription history, and your brokerage-connection reference, and disconnects your brokerage connection. Deleting your account through the app cancels your All-Access subscription as part of deletion; if you cancel by other means, cancel your All-Access subscription separately if you also want billing to stop.

Your rights

Depending on where you live, you may have the right to access, correct, or delete your personal information, or to object to certain processing. Contact hello@meridex.app to exercise any of these rights.

California residents: we do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. You may request access to or deletion of your personal information as described above.

EEA/UK residents: where GDPR applies, our legal bases for processing are performance of our contract with you (providing the Service), our legitimate interests (security and fraud prevention), and compliance with legal obligations (billing records). You may lodge a complaint with your local data protection authority.

Children: the Service requires users to be at least 18 and is not directed to, or intended for use by, children. Consistent with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from anyone under 13, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided us information, contact us and we will delete it promptly.

Security

We encrypt sensitive credentials at rest, restrict access to production data, and never store your brokerage login or full card number. No system is perfectly secure, but we design Meridex to collect the least data it can and to protect what it does hold.

Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the “Effective” date above and, where required, notify you by email.

Contact

Delvir Limited Liability Co., 30 N Gould St Ste R, Sheridan, WY 82801, United States — hello@meridex.app.