← Meridian

Privacy policy

How Meridian handles your data. Meridian is operated by Localize Partners, TODO — registered address. Questions about this policy or your data: TODO — contact@yourdomain.

Draft — this policy is not final: the operator details below are still placeholders. entityAddress, contactEmail, governingLaw

What we collect

Account: your email address and a password. Passwords are hashed by our authentication provider and are never visible to us.

Company profile: the company name (and any trading names you add), country of origin, website, up to five product categories you want to localize, revenue and headcount bands, target markets, and your intended form of entry into Saudi Arabia.

Access requests: if you ask for access from the landing page, we store the email address you submit and any company name or note you add.

Usage records: which analyses you ran and when, together with the token counts and cost of each run. We use this to operate rate limits and to understand what the platform costs to run.

Error diagnostics: when something fails, we record what failed — the page or endpoint, the error message, a technical stack trace, your browser's user-agent string, and, if you are signed in at the time, your email address. This is how we learn that something is broken; without it a broken screen reaches nobody and stays broken.

We do not collect documents. There is no file or catalogue upload — every field above is typed by you.

What we do not do

Your company profile is visible only to the account that created it. It is never shared with other users, never anonymised into a shared dataset, and never used to improve results for anyone else.

We do not sell your data, and we do not use it for advertising.

We do not use your profile to train AI models. It is sent for analysis and the result is returned to you (see below).

AI processing

Analysis is the product, so this is explicit: when you run Market demand, Partners & buyers, or the Localization roadmap, your company profile — company name, product categories, scale and intent — is sent to Anthropic's API together with our own curated Saudi market data, and the model's answer is returned to you.

Anthropic processes this as our service provider. Under Anthropic's commercial terms, API inputs and outputs are not used to train their models.

Results are cached against your profile so that revisiting a screen does not re-run the analysis. Editing your profile invalidates the cache and the next visit recomputes.

If you use the interface in a language other than English, the finished English result is machine-translated for display. Translations are cached by content, not by user.

Cookies

Authentication cookies keep you signed in. These are strictly necessary — without them the platform cannot tell who you are.

One functional cookie remembers your interface language.

We use no advertising or third-party tracking cookies, and no analytics that profile you across sites.

Who processes your data

Supabase — database, authentication and storage. Your data is held in the European Union (AWS eu-west-1, Ireland).

Vercel — application hosting and delivery.

Anthropic — AI analysis, as described above.

Our email provider — delivery of sign-in, password-reset and access-request messages.

How long we keep it

Your account and company profile are kept until you delete them or ask us to.

Cached analysis results are kept alongside your profile and are replaced when it changes.

Usage and cost records are retained for operational and accounting purposes.

Error diagnostics are kept for 30 days and then deleted.

Access requests that are not approved are kept so that we do not lose track of who asked; ask us and we will delete yours.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it and close your account.

You can edit your company profile yourself at any time from the profile screen.

To make any of these requests, write to TODO — contact@yourdomain. We will respond within 30 days.

If you are in the EEA or the UK and believe we have handled your data improperly, you may complain to your national data-protection authority.

Security

Every table holding user data is protected by row-level security, so one account cannot read another's records even if application code is wrong.

Traffic is served over HTTPS. Credentials for our providers are held server-side and are never exposed to the browser.

No system is perfectly secure. If a breach affects your data, we will tell you.

Changes

This policy was last updated on 2026-08-18. If we change it materially we will say so in the platform rather than update it quietly.

Privacy policyTerms of use