MeritLog policy
Privacy Notice
What MeritLog collects, why, who processes it, how long it is kept, and how you get it back or delete it.
Version 5 · Effective
1. Who we are
MeritLog LLC operates MeritLog and is the controller of the personal data described here.
Write to privacy@mymeritlog.com to exercise any right in this notice or to ask how a specific piece of data is handled. We answer rights requests within 30 days, and we will tell you before we take longer.
MeritLog is not currently offered to people in the European Economic Area or the United Kingdom.
2. What we collect
Your account record: the email address you sign up with, or the email address and name Google returns if you sign in with Google. We do not receive your Google password.
Your career record: everything you choose to put in MeritLog. Roles, achievements, skills, projects, education, certifications, documents you upload, jobs you save, applications you track, outcomes you record, and compensation figures you enter.
Operational records: request identifiers, timestamps, safe error codes, and the state of background jobs. These let us run the service and investigate failures. We keep private content out of logs, analytics, and error reports.
If you only browse the public job board, we collect much less: standard request logs, your analytics choice, and an approximate city derived from your IP address that is used once and discarded, as described in the next two sections.
We do not buy personal data, and we do not build a profile of you from sources outside the service.
3. Search, location, and the public job catalog
The job catalog is collected from reviewed public sources - applicant-tracking-system boards such as Greenhouse - under a reviewed-source policy. Company and salary information comes from the posting content itself. Postings are records about employers, not about you.
To prefill the location box, our hosting provider tells us the approximate city behind your IP address. We use it for that one prefill and discard it. It is not stored, and no precise location is collected in the background. The Use my location button is different: it asks your browser for coordinates only after you click it, sends them to our server, resolves them to the nearest reviewed place, and stores neither the coordinates nor the result.
Place names and coordinates come from GeoNames, used under the CC BY 4.0 licence. As you type a location, Mapbox may receive the text of your query to suggest completions; those queries are ephemeral and are never stored as your location.
4. Analytics and advertising on public pages
Optional analytics and advertising stay off everywhere until you explicitly allow both from Your Privacy Choices. Global Privacy Control keeps both off even when a previous preference allowed them. No signed-in page loads these tags.
The published container uses Google Analytics (GA4), Ahrefs Web Analytics, and Meta Pixel. When allowed, these providers may receive public-page URLs and browsing events, and Meta may use them for advertising audiences. Your Career Memory, documents, and private job inputs are excluded.
Your choice is kept in the server-set meritlog_analytics_consent cookie under public-analytics-v3. This public preference is not a database consent receipt. Turning both off stops future tag loading after the saved choice reloads the page; it does not erase data already sent.
5. Why we use it, and on what basis
Storing and showing your career record is what you signed up for, so we process that data to perform our contract with you. Every in-product option is off until you turn it on and separately revocable.
Operational logging, error monitoring, and abuse prevention run under our legitimate interest in keeping the service working. Optional analytics and advertising on public pages require your explicit consent everywhere.
Declining an optional purpose never removes access to career data you already own. We do not condition the service on consent to analytics or marketing.
| Purpose | Legal basis (UK/EU) | Default |
|---|---|---|
| Storing your career record | Performance of your contract with us | Required for the service |
| AI extraction from sources you provide | Your consent | Off |
| AI fit analysis against a role | Your consent | Off |
| AI document generation | Your consent | Off |
| AI compensation support | Your consent | Off |
| Product analytics | Your consent | Off |
| Analytics and remarketing tags on public pages | Your explicit consent everywhere; Global Privacy Control keeps tags off | Off |
| Keeping the service running (logs, error monitoring, abuse prevention) | Legitimate interest | Always on |
| Approximate-city search prefill from your IP address | Legitimate interest; used once, never stored | On for public search |
| Marketing email | Your consent | Off |
| Company job alert email | Your consent | Off |
| Getting started and processing email | Your consent | Off |
| Update-your-log reminder email | Your consent | Off |
| Application and interview reminder email | Your consent | Off |
| Career report email | Your consent | Off |
| Market Observer update email | Your consent | Off |
| MeritLog News and workforce report email | Your consent | Off |
| Product update email | Your consent | Off |
| Credential date reminder email | Your consent | Off |
| Connecting an external credential | Your consent | Off |
| Private share link | Your consent | Off |
6. Who else processes it
We use the sub-processors below. Each one is bound by a data processing agreement and receives the minimum data its function needs.
Resend receives one recipient address, one template identifier, and delivery metadata. It never receives your career record. PostHog receives only consent-gated, server-produced, pseudonymous events with your IP address discarded; browser autocapture and session recording are off. Sentry receives scrubbed technical failures after redaction. Inngest receives operation identifiers and no content. OpenAI receives the text you type into the writing assistant, and only when you have turned that on. We send it with storage disabled and we do not let it be used for training, but OpenAI may hold it for up to 30 days in its own abuse-monitoring logs, which is a retention we cannot shorten. Nothing else from your career record is sent, and the AI proposes; it never writes to your record on its own. Google Tag Manager loads on public pages only, never on a signed-in page. Everywhere, optional analytics and advertising stay off until you explicitly allow both. Global Privacy Control overrides an accepted preference. Turning both off stops future tag loading after your choice is saved and the page reloads; it does not erase data already sent. The container holds GA4, Ahrefs Web Analytics, and Meta Pixel. While allowed, these providers receive public-page browsing data and Meta may add you to an advertising audience. Nothing from your career record, your documents, or your job inputs is sent. Mapbox receives only the text of a location query while you type; it is not told who you are.
We will tell you before we add a sub-processor that handles your career record.
| Provider | What it handles | Location | Retention ceiling |
|---|---|---|---|
| Supabase | Account records, Career Memory database, uploaded files | United States (us-east-1) | Until you delete the record or the account |
| Vercel | Web application hosting, request routing, and the approximate city derived from your IP address for search prefill | United States | Operational request logs only; the derived city is used for one page render and not stored |
| Amazon Web Services | Encryption keys, file storage, worker compute, immutable deletion records | United States (us-east-1) | Deletion records are content-free and immutable by design |
| Railway | Export, billing, retention, and deletion worker compute | United States | No durable storage; PostgreSQL remains authoritative |
| Resend | Transactional email delivery | United States | 30 days |
| Inngest | Content-free job orchestration metadata | United States | Run history up to 30 days |
| Stripe | Subscription payments | United States | As required by Stripe and financial record-keeping law |
| PostHog | Server-side operational and product telemetry, under its own in-product consent | United States (Virginia) | 1 year |
| Sentry | Scrubbed error diagnostics | United States (Iowa) | 30 days |
| OpenAI | AI analysis of documents and jobs you submit as a signed-in user, only with your consent | United States | Not stored by us; up to 30 days of OpenAI abuse-monitoring logs |
| Tag Manager and GA4 analytics on public pages only after explicit consent everywhere; Global Privacy Control keeps them off | United States | As set by Google for advertising identifiers and audience membership | |
| Ahrefs | Public-page web analytics only after explicit consent; Global Privacy Control keeps it off | United States and other locations described by Ahrefs | No persistent visitor identifier; the daily uniqueness salt is deleted every 24 hours, while aggregate reports follow the Ahrefs account policy |
| Meta | Meta Pixel public-page measurement and advertising audiences only after explicit consent; Global Privacy Control keeps it off | United States and other locations described by Meta | As determined by Meta under its Business Tools and privacy terms |
| Mapbox | The text of a location query while you type, to suggest places | United States | Queries are ephemeral and never stored as your location |
7. Where it is processed
MeritLog runs in the United States. If you use the service from outside the United States, your data is transferred there. Where a transfer needs a safeguard, we rely on the Standard Contractual Clauses or the UK International Data Transfer Addendum in our agreements with each sub-processor.
8. How long we keep it
Your career record stays until you delete it or close your account. Deleting a record starts an ordered deletion across the database, file storage, and each sub-processor that holds a copy.
We will not claim that deletion is instant, because it is not. Encrypted backups expire on their own schedule and are not selectively edited; a deleted record can persist in a backup until that backup expires. We record a content-free, immutable tombstone proving the deletion was requested and completed. That tombstone contains no career data.
Optional-purpose data follows the ceilings in the sub-processor table. Financial records are kept as long as tax and accounting law requires.
Catalog job postings follow the retention window of the reviewed source they came from and are removed when that review requires it. Consent and opt-out receipts are kept as compliance records: proving what you were shown and what you chose is itself a legal obligation, so those receipts survive the choice they record.
9. Your rights
Wherever you live, you can see what we hold, correct it, export it in a portable format, and delete it. Use Settings, or write to us and we will do it.
If the UK or EU GDPR applies to you, you also have the right to restrict or object to processing, to withdraw consent at any time without affecting what happened before, and to complain to your supervisory authority. In the UK that is the Information Commissioner's Office.
If a US state privacy law applies to you, you have the right to know, delete, correct, and obtain a portable copy, to opt out of targeted advertising and of any sale or sharing, to limit the use of sensitive personal information, and not to be treated worse for exercising a right. You may appeal a refusal by replying to our decision. In the categories those laws use, we collect identifiers (your email address), professional and employment information (the career record you build), internet activity (public-page analytics while the tags run), and coarse location (the city derived from your IP address, used once for search prefill). We collect no biometric, health, or precise geolocation data.
MeritLog does not sell personal information. On public pages we do share it for cross-context behavioural advertising, in the specific sense California law means: while the Meta Pixel runs, your visit can place you in a remarketing audience that shows you MeritLog ads elsewhere. Those tags stay off everywhere until you explicitly allow both analytics and advertising. You can withdraw that choice at any time from Your Privacy Choices on every public page; future tag loading stops after the saved choice reloads the page. We honour Global Privacy Control as an automatic opt-out of both analytics and that sharing: if your browser sends the signal, nothing loads and we do not ask again. Nothing from your Career Memory, your documents, or your job inputs is involved, and no signed-in page loads those tags at all.
We do not make decisions about you with legal or similarly significant effects using automated processing alone. AI features suggest and draft; you decide.
10. How it is protected
Career data is encrypted in transit and at rest. Sensitive fields are encrypted with keys held in a managed key service, bound to the purpose and to your account, so a key for one purpose cannot decrypt another.
Access is separated by purpose: each background worker holds only the database role its own job needs. Uploaded files are scanned for malware before they are processed.
No system is perfectly secure, and we will not claim otherwise. If a breach puts you at risk we will notify you and the relevant regulator within the statutory deadline.
11. Children
MeritLog is for adults managing their own careers. We do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and we will delete it.
12. Changes
This is version 5, effective 2026-09-04. When we change it in a way that affects you, we raise the version, record which version you were shown, and ask again where the law requires fresh consent. Superseded versions stay available on request.