Privacy Policy
Last updated: September 18, 2026
Meridian Technologies, LLC ("Meridian," "we," "us") publishes the Meridian Financial Command Center app for iPhone, iPad, and Mac ("the App"). This policy explains what data the App handles and how.
The short version
Your financial data lives in your own private iCloud account and syncs directly between your own devices through Apple's CloudKit. We do not run a server that stores your books, and we cannot see your data. The optional "Check Email" feature only ever reads mail with your explicit Google sign-in, and a small relay we operate helps refresh that sign-in without ever seeing your email content.
What the App stores, and where
The App stores your ledger entries, invoices, bills, contacts, projects, budgets, imported documents, and business settings using Apple's SwiftData framework, synced across your devices via your personal iCloud account (CloudKit private database). This data:
- is encrypted in transit and at rest by Apple's infrastructure under your Apple ID;
- is never transmitted to, or stored on, any server operated by Meridian Technologies, LLC;
- is inaccessible to us — we have no account system and no backend database of your financial records.
Document processing (OCR / extraction)
When you import a receipt, invoice, or statement, the App extracts text and field values on-device using Apple's PDFKit, Vision, and Foundation Models frameworks. Documents and extracted data are not uploaded to any third-party AI or OCR service.
The "Check Email" feature (optional)
If you choose to connect a Gmail account, the App uses Google's OAuth sign-in to request read-only access to your mail (the gmail.readonly scope). We use this solely to let the App fetch messages you've routed to an address or label you control, so you can review and stage financial documents into your Import Queue — nothing is imported without your review, and the App never sends, deletes, labels, or modifies your email.
To keep your Google sign-in working without embedding long-lived secrets in the App itself, a minimal relay service we operate (hosted on Supabase) exchanges and refreshes OAuth tokens with Google on the App's behalf. This relay:
- only ever handles the OAuth token handshake (authorization codes and refresh tokens);
- never requests, receives, or stores your email content or Gmail data;
- does not persist tokens — it passes Google's response back to the App, which stores your tokens securely in your device's Keychain.
You can revoke this access at any time from your Google Account's security settings, or by disconnecting Gmail in the App's settings.
What we don't do
- We don't show ads or use third-party advertising SDKs.
- We don't sell or share your data with data brokers or advertisers.
- We don't use third-party analytics or tracking SDKs in the App.
Data retention and deletion
Because your data lives in your own iCloud account, you control its retention. Deleting the App or its data from a device removes your local copy; deleting your iCloud data (or the App's iCloud container) removes your synced copy per Apple's standard iCloud data handling. The App also includes an export/backup feature that produces a JSON file under your control.
Children's privacy
The App is a business bookkeeping tool and is not directed at, or knowingly used to collect information from, children under 13.
Not tax, legal, or financial advice
The App is a record-keeping and organization tool. Figures such as the tax reserve estimate, depreciation schedules, and mileage rates are planning aids only, not tax or legal advice. Consult a licensed CPA or attorney for guidance specific to your situation.
Changes to this policy
If this policy changes, we'll update the "Last updated" date above and post the revised policy at this same address.
Contact
Questions about this policy or your data: chadagler@gmail.com.