Meridino
Meridino
Home

Discover

RecommendedSearch

Track

ApplicationsInsights

Resume Tools

ATS & Resume

Account

My ProfileJob PreferencesSettings
?

Legal - policy version 2026-08-08

Privacy Policy

Effective date: 2026-08-08

Meridino (meridino.com) is operated by Feld & Co LLC, a Texas limited liability company ("Feld & Co," "we," "us," "our"). This policy explains what personal data we collect, why, who else processes it, how long we keep it, and what you can require us to do about it.

The short version: your resume and profile data are used to run the features you ask for and nothing else. We do not sell your data. We do not give it to employers. We never hold your password. We do send parts of your resume to an AI provider when you use an AI feature, and Section 5 says exactly which parts, to whom, and on what terms.

Read this together with our Terms of Service and our Data-Usage Policy.

1. Who we are and how to reach us

Feld & Co LLC is the controller of the personal data described here.

Feld & Co LLC
Email: admin@meridino.com

1714 Briar Street A

Austin, TX 78704

United States

Write to us at admin@meridino.com for any privacy question or to exercise any right in Section 10.

2. What we collect and why

We collect only what a feature needs. We do not buy personal data about you from data brokers, and we do not collect personal data about you from any source other than you and your identity provider.

CategoryWhat it isWhy we have it
Account identityYour name, email address, and account identifier released by your SSO provider (currently Google) at sign-in. Optionally, a separate contact email you choose to enter.To create and authenticate your account, to identify you as the owner of your data, and to contact you about your account.
Profile and experienceEmployers, job titles, employment dates and type, achievements and their metrics, skills and proficiency, education, certifications, publications, and narrative content you enter or confirm.To match you against postings, to run the ATS coverage check, and to build resumes from your own history.
Uploaded resume contentThe file name you uploaded, the text extracted from the resume file (PDF or DOCX), and the structured reading of that text (employers, titles, dates, achievements, skills) produced when you use resume structuring. We do not keep the file itself.To show you the reading for you to confirm or reject; and, once stored, to let you close the page and come back without us reading the same document a second time.
Target preferencesTarget roles, seniority, location and remote preference, pay floor, work-authorization and visa-sponsorship needs, and notification preferences.To decide which postings are relevant to you and to filter out ones that are not.
Application and tracker dataWhich postings you save, dismiss, or are shown; the status you record (applied, interviewing, offer, accepted, rejected, withdrawn); dates; next actions; your own free-text notes, which may include a contact person you choose to record.To run your private application tracker.
Generated contentATS coverage scores and per-requirement detail, fit scores and match explanations, resume drafts and their change logs.To give you the output of the feature you used, and to let you return to it.
Billing dataWhether you have purchased, credit balances and a ledger of credit grants and uses, and a Stripe customer identifier.To take payment for a purchase and to apply and enforce the credits it granted.
Search and security logsYour IP address, the search text you submit, the number of results returned, and the time, recorded for each search.To rate-limit searches, to detect and stop scraping and abuse of the postings pool, and to keep the service available. This is a legitimate and necessary security function.
Anti-abuse and rate-limit signalsYour IP address and a hashed device signal, together with counts of certain events (sign-ups, searches, and uses of rate-limited or free features) tied to that IP and device signal. The device signal is a SHA-256 hash computed from a first-party cookie we set on your device plus your browser's User-Agent and Accept-Language headers. We store only the hash. We never store the raw cookie value or the raw header values, and the hash cannot be reversed back into them.To detect and stop automated abuse, spam, scraping of the postings pool, and mass or automated account creation; to enforce rate limits; and to keep free per-account usage fair. This is a legitimate and necessary security function. We do not use this signal for advertising, cross-site tracking, or building a marketing or behavioral profile about you.
Consent recordThe version of this policy bundle you accepted, the server timestamp of acceptance, and your marketing-email opt-in choice.To prove what you agreed to and when.
Analytics and device dataCollected by Google Analytics, always on, on every page of the Service, for every visitor: pages viewed, approximate location derived from IP, browser and device type, referring page, and identifiers stored in cookies.To understand which parts of the product are used, and to fix and improve them. See Section 8; there is no opt-out.

What we do not collect. We do not collect biometric data, government identification numbers, Social Security numbers, financial account numbers, health data, precise geolocation, or data about children. We do not collect your card number (see Section 5, Stripe). We do not use session recording, screen recording, or keystroke logging. We do not use third-party device fingerprinting, ad or tracking pixels, or any cross-site tracking; the only device signal we hold is the hashed anti-abuse signal described above, used solely to prevent abuse, and it is stored only as a hash of a first-party cookie and two coarse browser headers, never the raw values.

The file itself is not kept. A resume file you upload is parsed in memory and is never written to file storage. We do not keep your PDF or DOCX, and there is no bucket, folder, or archive of user documents anywhere in the Service. Resume documents you download are re-generated on demand from your structured data and are not stored as files either.

What we do keep from an upload, and for how long. We keep the file's name, the text our parser extracted from it, and, if you use resume structuring, the structured reading of that text. This is stored in our database, encrypted at rest, readable only by your own account, and it exists for two reasons we will state plainly:

1. So that you can leave the page and come back. Reading a resume with AI is a paid operation and a free account gets exactly one. If we kept nothing, refreshing the page or closing the tab would force a second reading and cost you that one free use for a document we had already read. 2. So that the resume you uploaded is a real thing you can find in the product, by name, rather than only a scattering of profile entries.

This is kept for as long as your account is open, whether or not you go on to confirm the reading into your record, and is deleted when your account is deleted. We do not delete it on any earlier schedule: since we already have the information you gave us, and we can regenerate a resume for you in our own format from what you confirm into your record, there is no reading-specific expiry to track. Section 9 sets this out in full.

3. How we use personal data

  • To provide the service: extract and structure your resume, match you to postings, run the deterministic ATS coverage check, generate a resume tailored to a posting you select, render the document you download, and maintain your tracker.
  • To authenticate you and to enforce that only you can reach your own records.
  • To take payment for a purchase and to apply the credits it granted.
  • To keep the service secure and available: rate limiting, abuse and scraping detection, fraud prevention, and debugging.
  • To communicate with you about your account, transactions, security, and material changes to these policies. Marketing email is sent only if you opt in, and every marketing email has an unsubscribe link.
  • To understand aggregate product usage and improve the product.
  • To comply with law and to establish, exercise, or defend legal claims.

We do not use your resume or profile content for advertising, sell or rent it, disclose it to employers or recruiters, use it to train our own models, or make automated decisions about you that produce legal or similarly significant effects. Our scores are shown to you, about you, and are never provided to an employer or to anyone making a decision about you.

4. Legal bases (for the limited cases where EU, UK, or Swiss law applies)

Meridino is a US-intended service, described in Section 6. We do not design our practices around EEA, UK, or Swiss law, and this section exists only in case such law nonetheless applies to your use of the Service.

  • Performance of a contract (Art. 6(1)(b) GDPR): account identity, profile and resume content, preferences, applications and tracker data, generated content, and billing data. Without these we cannot provide the service you asked for.
  • Legitimate interests (Art. 6(1)(f)): security and abuse-prevention logging, rate limiting, service debugging and improvement, and defending legal claims. Our interest is keeping a small service secure, available, and viable; we have weighed this against your interests and limited the data accordingly.
  • Acceptance by use: our use of Google Analytics, described in Section 8, is always on and runs on every page. It is not conditioned on a consent step, and we do not offer an opt-out. By using the Service you accept this processing on the terms in Section 8.
  • Consent (Art. 6(1)(a)): marketing email, which you opt into separately and may withdraw at any time, and your submission of content to our AI sub-processor when you choose to use an AI feature.
  • Legal obligation (Art. 6(1)(c)): retention of tax and payment records.

Where your resume content includes special-category data (for example a disability, a trade-union role, or religious affiliation named in your history), you provide it voluntarily and we process it only to deliver the features you use, on the basis of your explicit consent under Art. 9(2)(a). You are not required to include such information, and you may remove it at any time.

5. Sub-processors: exactly who else touches your data

We use the following service providers. This list is complete as of the effective date. We will update it before adding a new sub-processor that receives personal data.

Sub-processorRoleWhat it receivesWhere it processes
Supabase, Inc. (United States)Authentication and the primary database.Your account identity from the SSO provider, and every record described in Section 2 that we store: profile, resume content, applications, generated resumes, scores, billing state, search logs, and your consent record.United States (Supabase Cloud, US East region).
Hetzner Online GmbH (headquartered in Germany)Hosting for the Meridino application server and background worker.All data described in Section 2 passes through and is processed on this server. Application data at rest lives in the database above, not on this server.The Meridino production server is located in the United States (Hillsboro, Oregon), and that is where this data is processed. We use only Hetzner's US facility for this Service; we do not route Meridino data through Hetzner's European facilities.
Anthropic PBC (United States)The AI provider behind resume structuring, bullet rewriting, and resume review.The text of your resume, your resume bullets, and the title, company, and extracted requirement keywords of the posting you are working on. Sent only when you use one of those features. See the detail below.United States.
Stripe, Inc. (United States)Payment processing.Your name, email, billing address, and card details, entered by you directly on Stripe's hosted checkout page. We never receive or store card data. From Stripe we receive only a customer identifier and payment status.United States.
Google LLC (United States)(a) OpenID Connect sign-in, through Supabase Auth. (b) Google Analytics on our web pages.(a) Your Google account is used to authenticate you; Google releases your name, email address, and account identifier to us. We send Google no resume or profile data. (b) Google Analytics receives the analytics and device data in Section 2, associated with a cookie identifier and your IP address. It receives no resume, profile, application, or billing data.United States and Google's global infrastructure.

Free and paid access to AI features. An account that has not purchased credits may use AI-based resume structuring exactly once: uploading a resume, which invokes structuring, is available once per account for free. The ATS coverage check is available once per account for free as well, but it is deterministic and does not invoke Anthropic or any AI provider. Beyond those two free uses, resume structuring, bullet rewriting, and resume review all require purchased credits. We do not claim that an unpaid account can never send content to Anthropic; the one free resume upload does.

Detail on Anthropic, because it is the disclosure that matters most. Three features send your content to Anthropic's API:

1. Resume structuring. When you upload a resume, the full extracted text of that resume is sent to Anthropic so it can be turned into structured entries for you to confirm. This includes your name, contact details, employers, dates, and everything else the document contains. It is not redacted before sending. 2. Bullet rewriting. When you generate a tailored resume for a posting, your own resume bullets, the posting's job title, and the requirement keywords our engine extracted are sent to Anthropic to produce reworded bullets. Every returned bullet then passes through our deterministic anti-fabrication gate before it can reach a resume, and a rejected bullet falls back to your original wording. 3. Resume review. When you request a written review of your resume against a posting, your resume and our engine's coverage analysis, together with the posting's title and company, are sent to Anthropic to produce the review.

Anthropic processes this content on our behalf as a service provider under its commercial terms. Under those terms, Anthropic may not train its models on our customers' content. Anthropic states that it deletes API inputs and outputs within 30 days, except where longer retention is required to enforce its usage policy or comply with law, in which case content flagged for a policy violation may be retained for up to two years. We do not control Anthropic's systems and this description reflects Anthropic's published terms as of the effective date.

If you do not want your content sent to Anthropic, do not use the resume structuring, rewrite, or review features. Every other feature, including search, matching, the fit screen, the ATS coverage check, and the tracker, runs entirely on our own deterministic code and sends nothing to any AI provider.

Other disclosures. We may disclose personal data to comply with law, a subpoena, or a lawful government request; to enforce our Terms; to protect the rights, property, or safety of Meridino, our users, or the public; and to a successor entity in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply until replaced with notice. We do not sell personal data and we do not share it for cross-context behavioral advertising.

6. Who this Service is for, and international use

Meridino is offered to, and intended for, users in the United States. We do not target or tailor the Service to users in the European Economic Area (EEA), the United Kingdom, or Switzerland.

We are based in the United States, and every sub-processor listed in Section 5 processes data in the United States. If you access Meridino from outside the United States, including from the EEA, the UK, or Switzerland, your personal data is transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction. By using the Service you accept that your data will be processed in the United States on the terms in this policy.

We have not built EEA/UK-specific consent or transfer machinery, such as a cookie-consent banner or Standard Contractual Clauses, and we do not currently offer any. If that is not acceptable to you, please do not use the Service.

7. Security

  • Authentication is SSO only. We never create, receive, store, or reset a password. There is no Meridino credential to steal, and no password database exists.
  • Tenant isolation is enforced in the database. Every table holding your data has PostgreSQL row-level security with an ownership policy tied to your authenticated user identity, so one account cannot read or write another account's rows even if the application layer is bypassed. Anonymous database access is revoked on every table. An automated cross-account isolation test runs on every code change and blocks release if it fails.
  • Least privilege. Sensitive records, including billing state, coverage results, and search logs, are not writable, and in some cases not readable, by the ordinary application role at all.
  • Encryption in transit. All traffic to the application, the database, and every sub-processor uses TLS. Data at rest is protected by our database provider's storage-level encryption.
  • Secrets are supplied to the application through environment configuration only. No credential, key, or token is stored in our source code repository.
  • Outbound request hardening. Our postings collector validates and pins every outbound address before connecting, so it cannot be redirected to internal systems.
  • Minimization. We do not store your uploaded file, your rendered resume documents, your card details, or a password, because we do not need any of them. From an upload we keep only the file name, the extracted text, and the structured reading, in the database, under the same row-level ownership rules as the rest of your account. There is no file storage bucket for user documents, so there is no bucket to misconfigure and nothing to enumerate.

No system is perfectly secure. We cannot guarantee absolute security, and you share information with us at your own risk.

8. Cookies and analytics

  • Essential cookies. Meridino sets a session cookie through our authentication provider so that you stay signed in. This is strictly necessary; the service cannot work without it. We also set one first-party cookie used only as part of the hashed anti-abuse signal in Section 2, to help us tell automated abuse apart from real visitors. It is not used for analytics or advertising, its value is never sent to any third party, and only a hash of it is ever stored.
  • Analytics is always on. We use Google Analytics (gtag.js) on every page of Meridino, for every visitor. It sets cookies and collects the analytics and device data listed in Section 2: pages viewed, approximate location derived from your IP address, browser and device type, referring page, and cookie identifiers. Google Analytics does not receive your resume, profile, applications, or billing data.
  • There is no opt-out. We do not offer a cookie-consent banner, an analytics opt-out control, or any other mechanism to turn off Google Analytics on Meridino. Using the Service means Google Analytics runs, on every page, for every visitor. If you do not want your visit measured by Google Analytics, do not use the Service. See Section 6 for who the Service is offered to and how we treat international use.
  • Your browser's own controls. You can block or delete cookies through your own browser at any time. Blocking the essential session cookie will prevent you from signing in; it has no effect on whether Google Analytics runs, since blocking cookies in your browser is your own action, not a control we provide.
  • Do Not Track and Global Privacy Control. We honor a Global Privacy Control signal as an opt-out of any sale or sharing of personal data. Because we do not sell personal data and do not use it for cross-context behavioral advertising, there is nothing to opt out of under that signal, and it has no effect on Google Analytics.
  • No advertising. We run no advertising, no ad pixels, and no ad retargeting.

9. Retention

DataHow long we keep it
Account identity, profile and resume content, preferences, applications and tracker, generated resumes and scoresFor as long as your account is open. Deleted when you delete the item, or on account deletion as described below.
Uploaded resume file (the PDF or DOCX itself)Not retained. It is parsed in memory and discarded within the request. It is never written to file storage.
Uploaded resume text and its structured reading, confirmed or notFor as long as your account is open. Deleted when your account is deleted, along with everything else in the account.
Search and security logs, including IP addressRetained for security, rate-limiting, and abuse-prevention purposes. We do not currently enforce a fixed deletion schedule for this log. We access it only for those purposes and do not use it for anything else.
Anti-abuse and rate-limit signals (IP address, hashed device signal, and event counts)Retained for security, rate-limiting, and abuse-prevention. These records exist to enforce short rate-limit windows and to investigate abuse; we access them only for those purposes and do not use them for anything else. We do not currently enforce a fixed deletion schedule for them.
Consent recordFor the life of the account and for 3 years after closure, as evidence of the terms you accepted.
Billing and payment records7 years, as required for tax and accounting purposes. Retained by us and by Stripe.
BackupsRolling operational backups are retained for no more than 35 days, after which deleted data is gone from backups as well.
Content sent to AnthropicGoverned by Anthropic, not by us. Anthropic states it deletes API inputs and outputs within 30 days, with the usage-policy exception described in Section 5.

Job postings in the shared pool are not personal data about you and are retained independently of any account.

10. Your rights and how to use them

Regardless of where you live, you may ask us to:

  • Access the personal data we hold about you, and receive an explanation of how it is used.
  • Export a copy of your account data in a portable, machine-readable format.
  • Correct anything inaccurate. Most profile data you can also edit yourself in the product.
  • Delete your account and the personal data in it.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent you previously gave, including for AI features and marketing email.
  • Not be discriminated against for exercising any of these rights. We will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right.

How. All of these rights are handled as a written request, not an in-product self-service control. Write to us at admin@meridino.com from the email address on your account. We will verify that the request comes from you before acting on it, and we may ask for information sufficient to do so.

When. We will acknowledge your request within 10 business days and complete it within 45 days. Where a request is complex, we may extend this by up to a further 45 days, and we will tell you before doing so.

What deletion means. On a verified deletion request we delete your account identity, profile, resume content, uploaded resume text and its structured reading, generated resumes, scores, applications, and tracker from our active systems. The deletion cascades through every table holding your data. Backups roll off within 35 days. We retain only your consent record and the billing and payment records we are legally required to keep, as set out in Section 9.

An authorized agent may make a request on your behalf where the law provides for it, with proof of authorization.

Complaints. If you are in the EEA or the UK you may lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve it first.

11. Children

Meridino is for adults. It is not directed to anyone under 18, and no one under 18 may create an account or use the service. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it promptly. A parent or guardian who believes a minor has given us data should contact us at admin@meridino.com.

12. Breach notification

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to your personal data, we will investigate immediately, take steps to contain it, and notify you and the relevant supervisory authorities as and when required by applicable law, without undue delay. Our notice will describe what happened, what data was involved, what we are doing about it, and what you can do.

13. Changes to this policy

We may update this policy. We will post the updated version with a new effective date, and for material changes we will give notice in the product or by email at least 14 days in advance and may require you to re-accept before continuing to use the service. Prior versions are available on request.

14. Contact

Feld & Co LLC
Email: admin@meridino.com

1714 Briar Street A

Austin, TX 78704

United States

Brave Software, Inc. and Google LLC (Programmable Search)Discovery of employers' public career-board addresses, so we know which company boards to collect postings from.No personal data. These providers receive only search phrases we compose ourselves about job titles and career-board domains. Your resume, profile, searches, and identity are never sent to them, and no text you type is ever passed through to them.United States.