Privacy Notice
What MeritLog collects, why, who processes it, how long it is kept, and how you get it back or delete it.
Version 1 · Effective
1. Who we are
MeritLog LLC operates MeritLog and is the controller of the personal data described here.
Write to privacy@mymeritlog.com to exercise any right in this notice or to ask how a specific piece of data is handled. We answer rights requests within 30 days, and we will tell you before we take longer.
MeritLog is not currently offered to people in the European Economic Area or the United Kingdom.
2. What we collect
Your account record: the email address you sign up with, or the email address and name Google returns if you sign in with Google. We do not receive your Google password.
Your career record: everything you choose to put in MeritLog. Roles, achievements, skills, projects, education, certifications, documents you upload, jobs you save, applications you track, outcomes you record, and compensation figures you enter.
Operational records: request identifiers, timestamps, safe error codes, and the state of background jobs. These let us run the service and investigate failures. We keep private content out of logs, analytics, and error reports.
We do not buy personal data, and we do not build a profile of you from sources outside the service.
3. Why we use it, and on what basis
Storing and showing your career record is what you signed up for, so we process that data to perform our contract with you. Every other purpose is optional, off until you turn it on, and separately revocable.
Declining an optional purpose never removes access to career data you already own. We do not condition the service on consent to analytics or marketing.
| Purpose | Legal basis (UK/EU) | Default |
|---|---|---|
| Storing your career record | Performance of your contract with us | Required for the service |
| AI extraction from sources you provide | Your consent | Off |
| AI fit analysis against a role | Your consent | Off |
| AI document generation | Your consent | Off |
| AI compensation support | Your consent | Off |
| Product analytics | Your consent | Off |
| Marketing email | Your consent | Off |
| Company job alert email | Your consent | Off |
| Connecting an external credential | Your consent | Off |
| Private share link | Your consent | Off |
4. Who else processes it
We use the sub-processors below. Each one is bound by a data processing agreement and receives the minimum data its function needs.
Resend receives one recipient address, one template identifier, and delivery metadata. It never receives your career record. PostHog receives only consent-gated, server-produced, pseudonymous events with your IP address discarded; browser autocapture and session recording are off. Sentry receives scrubbed technical failures after redaction. Inngest receives operation identifiers and no content.
We will tell you before we add a sub-processor that handles your career record.
| Provider | What it handles | Location | Retention ceiling |
|---|---|---|---|
| Supabase | Account records, Career Memory database, uploaded files | United States (us-east-1) | Until you delete the record or the account |
| Vercel | Web application hosting and request routing | United States | Operational request logs only |
| Amazon Web Services | Encryption keys, worker compute, immutable deletion records | United States (us-east-1) | Deletion records are content-free and immutable by design |
| Railway | Export, billing, retention, and deletion worker compute | United States | No durable storage; PostgreSQL remains authoritative |
| Resend | Transactional email delivery | United States | 30 days |
| Inngest | Content-free job orchestration metadata | United States | Run history up to 30 days |
| Stripe | Subscription payments | United States | As required by Stripe and financial record-keeping law |
| PostHog | Optional product analytics, only with your consent | United States (Virginia) | 1 year |
| Sentry | Scrubbed error diagnostics | United States (Iowa) | 30 days |
5. Where it is processed
MeritLog runs in the United States. If you use the service from outside the United States, your data is transferred there. Where a transfer needs a safeguard, we rely on the Standard Contractual Clauses or the UK International Data Transfer Addendum in our agreements with each sub-processor.
6. How long we keep it
Your career record stays until you delete it or close your account. Deleting a record starts an ordered deletion across the database, file storage, and each sub-processor that holds a copy.
We will not claim that deletion is instant, because it is not. Encrypted backups expire on their own schedule and are not selectively edited; a deleted record can persist in a backup until that backup expires. We record a content-free, immutable tombstone proving the deletion was requested and completed. That tombstone contains no career data.
Optional-purpose data follows the ceilings in the sub-processor table. Financial records are kept as long as tax and accounting law requires.
7. Your rights
Wherever you live, you can see what we hold, correct it, export it in a portable format, and delete it. Use Settings, or write to us and we will do it.
If the UK or EU GDPR applies to you, you also have the right to restrict or object to processing, to withdraw consent at any time without affecting what happened before, and to complain to your supervisory authority. In the UK that is the Information Commissioner's Office.
If a US state privacy law applies to you, you have the right to know, delete, correct, and obtain a portable copy, to opt out of targeted advertising and of any sale or sharing, to limit the use of sensitive personal information, and not to be treated worse for exercising a right. You may appeal a refusal by replying to our decision.
MeritLog does not sell personal information and does not share it for cross-context behavioural advertising. We honour Global Privacy Control: if your browser sends the signal, we treat it as an opt-out of product analytics.
We do not make decisions about you with legal or similarly significant effects using automated processing alone. AI features suggest and draft; you decide.
8. How it is protected
Career data is encrypted in transit and at rest. Sensitive fields are encrypted with keys held in a managed key service, bound to the purpose and to your account, so a key for one purpose cannot decrypt another.
Access is separated by purpose: each background worker holds only the database role its own job needs. Uploaded files are scanned for malware before they are processed.
No system is perfectly secure, and we will not claim otherwise. If a breach puts you at risk we will notify you and the relevant regulator within the statutory deadline.
9. Children
MeritLog is for adults managing their own careers. We do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will delete it.
10. Changes
This is version 1, effective 2026-07-27. When we change it in a way that affects you, we raise the version, record which version you were shown, and ask again where the law requires fresh consent. Superseded versions stay available on request.


