Privacy
Privacy policy
Draft template — not legal advice. This page must be completed by the operator (all [FILL IN] fields) and reviewed by a qualified professional beforeMerolio is offered to users. It does not by itself make the service legally compliant.
Effective date: 9 October 2026. This policy explains which personal data is processed when you use Merolio (the “service”), why, with whom, for how long, and what your rights are. The controller responsible for this processing is the operator named in section 1 — not the product name.
1. Controller
Ario Niknirouie, Köpenicker Straße 43, 10179 Berlin, Deutschland. Email: hello@merolio.com. See also the Impressum. We have not appointed a data protection officer, as none is required for an operation of this size (Art. 37 GDPR, § 38 BDSG).
2. Data we process
- Account and authentication data — email address, name, a securely hashed password (stored by our authentication provider, never readable by us), email-confirmation and password-reset events, session cookies, and authentication logs including IP addresses.
- Profile data — username, headline, bio, education and links you add. Visible to others only if you make your portfolio public.
- Uploaded coursework — the files you upload (PDF, Word, PowerPoint, Excel, text, images), text extracted from them, text you paste, and your project form answers. Coursework can contain personal data of other people (e.g. teammates or lecturers); please remove it before uploading.
- AI analysis and generated content — the structured analysis of your project, your confirmations and edits, your answers to clarification questions, and generated CV bullets, interview preparation, LinkedIn text and case studies.
- Public pages — only if you publish a project: a snapshot containing the confirmed content and details you chose to show. Your original files are never published.
- Usage and security data — records of actions such as analyses, generations, uploads and publishes (type, time, AI token counts, duration — never document content), used for fair-use limits and abuse prevention; IP addresses and email addresses processed briefly in server memory for rate limiting; and technical server logs kept by our hosting providers.
- Feedback and messages — messages you send through the feedback form or by email.
- Payments (not active) — Merolio is free during the beta and processes no payment data. If paid plans are introduced, payment data will be handled by a payment provider and this policy will be updated first.
3. Purposes and legal bases
- Providing the service you sign up for — account, storage, analysis, generation, publishing (Art. 6(1)(b) GDPR).
- Security, abuse prevention, fair-use limits and keeping the service reliable (Art. 6(1)(f) GDPR; legitimate interest in a secure service).
- Improving the product from feedback you choose to send (Art. 6(1)(f) GDPR).
- Keeping records we are legally required to keep, for example for tax purposes (Art. 6(1)(c) GDPR). We do not currently rely on consent for any processing.
4. AI processing
To analyse a project, the relevant file contents, extracted text and your form answers are sent to our AI provider, Anthropic, which generates a structured analysis and text drafts. Every AI statement is labelled with its source; AI inferences are not used or published until you confirm them, and you review all generated text before using it. No decisions with legal or similarly significant effects are made about you automatically (Art. 22 GDPR).
Anthropic processes this data on our behalf under its Data Processing Addendum. Under Anthropic's commercial terms, content sent through its API is not used to train its models, and Anthropic deletes API inputs and outputs within 30 days unless longer retention is needed to enforce its usage policy or is required by law.
5. Service providers (processors)
We use these providers to run Merolio. Each processes data only on our instructions under a data processing agreement.
| Provider | Purpose | Location / transfer basis |
|---|---|---|
| Supabase | Database, authentication, private file storage | Data stored in the EU (Paris, France); Supabase, Inc. is based in the USA. DPA: [FILL IN: confirm a DPA with Supabase is in place] |
| Vercel | Hosting and serving the application | Functions run in the EU (Frankfurt, Germany); Vercel Inc. is based in the USA and serves pages through a global network. |
| Anthropic | AI analysis and text generation | USA; contracting entity for EEA customers: Anthropic Ireland, Limited. |
| Resend | Sending account emails (confirmation, password reset) | Sending region EU (Ireland); Resend is based in the USA. |
| Cloudflare | Domain name service and forwarding of emails sent to hello@merolio.com | Global network; Cloudflare, Inc. is based in the USA. |
| Stripe (planned, not active) | Payments, if paid plans are introduced | Not used yet — update before activation |
6. International transfers
Some providers are based in, or may access data from, countries outside the EU/EEA (for example the United States). Where this happens, transfers rely on the EU Standard Contractual Clauses included in each provider's data processing agreement and, where a provider is certified, on the EU–US Data Privacy Framework.
7. Cookies and local storage
Merolio uses only cookies that are necessary to keep you signed in (authentication session cookies set by our authentication provider). We do not use analytics, advertising or tracking cookies, and the app does not store personal data in your browser's local storage. Because these cookies are strictly necessary to provide the service you request, no consent banner is shown (§ 25(2) No. 2 TDDDG).
8. Retention
- Account, projects, files and generated content: kept until you delete them or your account.
- Public pages: removed immediately when you unpublish or delete the project or account.
- Usage records and feedback: kept while your account exists; deleted with your account.
- Provider backups: deleted data may remain in our database provider's backups until they are overwritten according to its backup schedule.
- Hosting and security logs: kept by our hosting and database providers for a short period according to their log retention settings.
9. Deleting your account
You can delete your account at any time from Delete account (Profile → Delete account). This permanently removes your profile, projects, uploaded files, analyses, generated content, public pages, usage records, feedback and your login. Backups are subject to section 8.
10. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw any consent at any time with effect for the future. Contact: hello@merolio.com.
You also have the right to lodge a complaint with a data protection supervisory authority, for example the authority responsible for us: the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
11. Security
Projects are private by default and isolated per user at the database and storage level; files are stored in a private bucket and are never made public; connections are encrypted in transit. No system is perfectly secure — please report vulnerabilities to hello@merolio.com.
12. Changes
We will update this policy when our processing changes (for example before introducing payments) and note the new effective date above.