MeritLog policy

Privacy Notice

What MeritLog collects, why, who processes it, how long it is kept, and how you get it back or delete it.

Version 5 · Effective

1. Who we are

MeritLog LLC operates MeritLog and is the controller of the personal data described here.

Write to privacy@mymeritlog.com to exercise any right in this notice or to ask how a specific piece of data is handled. We answer rights requests within 30 days, and we will tell you before we take longer.

MeritLog is not currently offered to people in the European Economic Area or the United Kingdom.

2. What we collect

Your account record: the email address you sign up with, or the email address and name Google returns if you sign in with Google. We do not receive your Google password.

Your career record: everything you choose to put in MeritLog. Roles, achievements, skills, projects, education, certifications, documents you upload, jobs you save, applications you track, outcomes you record, and compensation figures you enter.

Operational records: request identifiers, timestamps, safe error codes, and the state of background jobs. These let us run the service and investigate failures. We keep private content out of logs, analytics, and error reports.

If you only browse the public job board, we collect much less: standard request logs, your analytics choice, and an approximate city derived from your IP address that is used once and discarded, as described in the next two sections.

We do not buy personal data, and we do not build a profile of you from sources outside the service.

3. Search, location, and the public job catalog

The job catalog is collected from reviewed public sources - applicant-tracking-system boards such as Greenhouse - under a reviewed-source policy. Company and salary information comes from the posting content itself. Postings are records about employers, not about you.

To prefill the location box, our hosting provider tells us the approximate city behind your IP address. We use it for that one prefill and discard it. It is not stored, and no precise location is collected in the background. The Use my location button is different: it asks your browser for coordinates only after you click it, sends them to our server, resolves them to the nearest reviewed place, and stores neither the coordinates nor the result.

Place names and coordinates come from GeoNames, used under the CC BY 4.0 licence. As you type a location, Mapbox may receive the text of your query to suggest completions; those queries are ephemeral and are never stored as your location.

4. Analytics and advertising on public pages

Optional analytics and advertising stay off everywhere until you explicitly allow both from Your Privacy Choices. Global Privacy Control keeps both off even when a previous preference allowed them. No signed-in page loads these tags.

The published container uses Google Analytics (GA4), Ahrefs Web Analytics, and Meta Pixel. When allowed, these providers may receive public-page URLs and browsing events, and Meta may use them for advertising audiences. Your Career Memory, documents, and private job inputs are excluded.

Your choice is kept in the server-set meritlog_analytics_consent cookie under public-analytics-v3. This public preference is not a database consent receipt. Turning both off stops future tag loading after the saved choice reloads the page; it does not erase data already sent.

5. Why we use it, and on what basis

Storing and showing your career record is what you signed up for, so we process that data to perform our contract with you. Every in-product option is off until you turn it on and separately revocable.

Operational logging, error monitoring, and abuse prevention run under our legitimate interest in keeping the service working. Optional analytics and advertising on public pages require your explicit consent everywhere.

Declining an optional purpose never removes access to career data you already own. We do not condition the service on consent to analytics or marketing.

PurposeLegal basis (UK/EU)Default
Storing your career recordPerformance of your contract with usRequired for the service
AI extraction from sources you provideYour consentOff
AI fit analysis against a roleYour consentOff
AI document generationYour consentOff
AI compensation supportYour consentOff
Product analyticsYour consentOff
Analytics and remarketing tags on public pagesYour explicit consent everywhere; Global Privacy Control keeps tags offOff
Keeping the service running (logs, error monitoring, abuse prevention)Legitimate interestAlways on
Approximate-city search prefill from your IP addressLegitimate interest; used once, never storedOn for public search
Marketing emailYour consentOff
Company job alert emailYour consentOff
Getting started and processing emailYour consentOff
Update-your-log reminder emailYour consentOff
Application and interview reminder emailYour consentOff
Career report emailYour consentOff
Market Observer update emailYour consentOff
MeritLog News and workforce report emailYour consentOff
Product update emailYour consentOff
Credential date reminder emailYour consentOff
Connecting an external credentialYour consentOff
Private share linkYour consentOff

6. Who else processes it

We use the sub-processors below. Each one is bound by a data processing agreement and receives the minimum data its function needs.

Resend receives one recipient address, one template identifier, and delivery metadata. It never receives your career record. PostHog receives only consent-gated, server-produced, pseudonymous events with your IP address discarded; browser autocapture and session recording are off. Sentry receives scrubbed technical failures after redaction. Inngest receives operation identifiers and no content. OpenAI receives the text you type into the writing assistant, and only when you have turned that on. We send it with storage disabled and we do not let it be used for training, but OpenAI may hold it for up to 30 days in its own abuse-monitoring logs, which is a retention we cannot shorten. Nothing else from your career record is sent, and the AI proposes; it never writes to your record on its own. Google Tag Manager loads on public pages only, never on a signed-in page. Everywhere, optional analytics and advertising stay off until you explicitly allow both. Global Privacy Control overrides an accepted preference. Turning both off stops future tag loading after your choice is saved and the page reloads; it does not erase data already sent. The container holds GA4, Ahrefs Web Analytics, and Meta Pixel. While allowed, these providers receive public-page browsing data and Meta may add you to an advertising audience. Nothing from your career record, your documents, or your job inputs is sent. Mapbox receives only the text of a location query while you type; it is not told who you are.

We will tell you before we add a sub-processor that handles your career record.

ProviderWhat it handlesLocationRetention ceiling
SupabaseAccount records, Career Memory database, uploaded filesUnited States (us-east-1)Until you delete the record or the account
VercelWeb application hosting, request routing, and the approximate city derived from your IP address for search prefillUnited StatesOperational request logs only; the derived city is used for one page render and not stored
Amazon Web ServicesEncryption keys, file storage, worker compute, immutable deletion recordsUnited States (us-east-1)Deletion records are content-free and immutable by design
RailwayExport, billing, retention, and deletion worker computeUnited StatesNo durable storage; PostgreSQL remains authoritative
ResendTransactional email deliveryUnited States30 days
InngestContent-free job orchestration metadataUnited StatesRun history up to 30 days
StripeSubscription paymentsUnited StatesAs required by Stripe and financial record-keeping law
PostHogServer-side operational and product telemetry, under its own in-product consentUnited States (Virginia)1 year
SentryScrubbed error diagnosticsUnited States (Iowa)30 days
OpenAIAI analysis of documents and jobs you submit as a signed-in user, only with your consentUnited StatesNot stored by us; up to 30 days of OpenAI abuse-monitoring logs
GoogleTag Manager and GA4 analytics on public pages only after explicit consent everywhere; Global Privacy Control keeps them offUnited StatesAs set by Google for advertising identifiers and audience membership
AhrefsPublic-page web analytics only after explicit consent; Global Privacy Control keeps it offUnited States and other locations described by AhrefsNo persistent visitor identifier; the daily uniqueness salt is deleted every 24 hours, while aggregate reports follow the Ahrefs account policy
MetaMeta Pixel public-page measurement and advertising audiences only after explicit consent; Global Privacy Control keeps it offUnited States and other locations described by MetaAs determined by Meta under its Business Tools and privacy terms
MapboxThe text of a location query while you type, to suggest placesUnited StatesQueries are ephemeral and never stored as your location

7. Where it is processed

MeritLog runs in the United States. If you use the service from outside the United States, your data is transferred there. Where a transfer needs a safeguard, we rely on the Standard Contractual Clauses or the UK International Data Transfer Addendum in our agreements with each sub-processor.

8. How long we keep it

Your career record stays until you delete it or close your account. Deleting a record starts an ordered deletion across the database, file storage, and each sub-processor that holds a copy.

We will not claim that deletion is instant, because it is not. Encrypted backups expire on their own schedule and are not selectively edited; a deleted record can persist in a backup until that backup expires. We record a content-free, immutable tombstone proving the deletion was requested and completed. That tombstone contains no career data.

Optional-purpose data follows the ceilings in the sub-processor table. Financial records are kept as long as tax and accounting law requires.

Catalog job postings follow the retention window of the reviewed source they came from and are removed when that review requires it. Consent and opt-out receipts are kept as compliance records: proving what you were shown and what you chose is itself a legal obligation, so those receipts survive the choice they record.

9. Your rights

Wherever you live, you can see what we hold, correct it, export it in a portable format, and delete it. Use Settings, or write to us and we will do it.

If the UK or EU GDPR applies to you, you also have the right to restrict or object to processing, to withdraw consent at any time without affecting what happened before, and to complain to your supervisory authority. In the UK that is the Information Commissioner's Office.

If a US state privacy law applies to you, you have the right to know, delete, correct, and obtain a portable copy, to opt out of targeted advertising and of any sale or sharing, to limit the use of sensitive personal information, and not to be treated worse for exercising a right. You may appeal a refusal by replying to our decision. In the categories those laws use, we collect identifiers (your email address), professional and employment information (the career record you build), internet activity (public-page analytics while the tags run), and coarse location (the city derived from your IP address, used once for search prefill). We collect no biometric, health, or precise geolocation data.

MeritLog does not sell personal information. On public pages we do share it for cross-context behavioural advertising, in the specific sense California law means: while the Meta Pixel runs, your visit can place you in a remarketing audience that shows you MeritLog ads elsewhere. Those tags stay off everywhere until you explicitly allow both analytics and advertising. You can withdraw that choice at any time from Your Privacy Choices on every public page; future tag loading stops after the saved choice reloads the page. We honour Global Privacy Control as an automatic opt-out of both analytics and that sharing: if your browser sends the signal, nothing loads and we do not ask again. Nothing from your Career Memory, your documents, or your job inputs is involved, and no signed-in page loads those tags at all.

We do not make decisions about you with legal or similarly significant effects using automated processing alone. AI features suggest and draft; you decide.

10. How it is protected

Career data is encrypted in transit and at rest. Sensitive fields are encrypted with keys held in a managed key service, bound to the purpose and to your account, so a key for one purpose cannot decrypt another.

Access is separated by purpose: each background worker holds only the database role its own job needs. Uploaded files are scanned for malware before they are processed.

No system is perfectly secure, and we will not claim otherwise. If a breach puts you at risk we will notify you and the relevant regulator within the statutory deadline.

11. Children

MeritLog is for adults managing their own careers. We do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will delete it.

12. Changes

This is version 5, effective 2026-09-04. When we change it in a way that affects you, we raise the version, record which version you were shown, and ask again where the law requires fresh consent. Superseded versions stay available on request.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice