Meridian Blue Meridian Blue
Models Site Inspector Pricing Security Docs
Get Started
Models Site Inspector Pricing Security Docs
Get Started

Privacy Policy

Last updated: March 17, 2026

Meridian Blue, Inc. ("we," "us," or "the Company") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Meridian Blue platform and services ("Our Service").

This policy applies to all users of Our Service, whether accessed through our website, API, or any other means. By using Our Service, you acknowledge that you have read and understood this Privacy Policy. For details on your contractual relationship with us, please see our User Agreement.


I. Data Controller

The data controller responsible for your personal data is:

Meridian Blue, Inc.

Email: [email protected]

We have appointed a Data Protection Officer (DPO) who can be contacted regarding any data protection matters:

Data Protection Officer

Email: [email protected]


II. Information We Collect

2.1 Account Information

When you create a Meridian Blue account, we collect:

  • Email address
  • Name (if provided)
  • Organization name (if provided)
  • Payment information (processed by our third-party payment provider)

2.2 Usage Data

When you use Our Service, we automatically collect:

  • API request metadata (timestamps, model selected, token counts, response times)
  • IP address and approximate geographic location
  • Device and browser information
  • Pages visited and interactions with our website

2.3 Prompt and Response Data

Meridian Blue operates a zero-data-retention architecture for prompt and response content. Your API requests (prompts) and model responses are processed transiently in memory and are not stored in any long-term Meridian Blue system. We do not use your prompts or responses to train any models. For more details, see our Security page.

2.4 Cookies and Tracking

Our website uses only essential cookies required for the functioning of the site. We do not use third-party advertising cookies or cross-site tracking. You may manage cookie preferences through your browser settings.


III. How We Use Your Information

We use the information we collect for the following purposes:

(a) Service Delivery: To create and manage your account, process API requests, route traffic to upstream providers, and deliver Our Service.

(b) Billing and Payments: To calculate usage, generate invoices, process payments, and prevent billing fraud.

(c) Security and Fraud Prevention: To detect, prevent, and respond to security incidents, abuse, and unauthorized access.

(d) Service Improvement: To analyze aggregated, anonymized usage patterns to improve performance, reliability, and features.

(e) Communication: To send transactional emails (account verification, billing receipts, security alerts) and, with your consent, product updates and marketing communications.

(f) Legal Compliance: To comply with applicable legal obligations, respond to lawful requests, and protect our legal rights.


IV. Legal Basis for Processing (GDPR)

We process your personal data on one or more of the following legal bases under Article 6(1) of the General Data Protection Regulation (GDPR):

(a) Contract Performance (Art. 6(1)(b)): Processing necessary to perform our contract with you, including account registration, service delivery, billing, and customer support.

(b) Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, such as fraud prevention, service security, analytics, and service improvement, provided these interests are not overridden by your rights and freedoms.

(c) Consent (Art. 6(1)(a)): Where we process data based on your consent (such as marketing communications), you may withdraw your consent at any time.

(d) Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable legal obligations, including tax, accounting, and regulatory requirements.


V. Data Sharing and Third Parties

5.1 Upstream AI Providers

When you make an API request, we route your request to the upstream AI model provider you selected (e.g., Anthropic, OpenAI, Google, Meta, Mistral). Your prompt data is transmitted to these providers to generate a response. Each provider's data handling is governed by their own terms and privacy policies. We configure all provider integrations to disable training on your data wherever available.

5.2 Payment Processors

We use third-party payment processors to handle billing. Your payment information is transmitted directly to these processors and is not stored on our systems.

5.3 Infrastructure Providers

We use cloud infrastructure providers to host Our Service. All data is encrypted in transit and at rest.

5.4 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for advertising or marketing purposes.


VI. Data Retention

Account data is retained for the duration of your account. Upon account deletion, your data is permanently erased or anonymized within thirty (30) days.

Usage logs (API metadata, not prompt content) are retained for a maximum of ninety (90) days for security and fraud prevention, after which they are automatically purged.

Prompt and response data is never stored. It is processed transiently in memory and discarded immediately upon request completion.

Billing records are retained as required by applicable tax and accounting legislation.


VII. International Data Transfers

Our Service may involve the transfer of personal data outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, including:

(a) Transfers to countries with an adequacy decision from the European Commission (Art. 45 GDPR);

(b) Standard Contractual Clauses (SCCs) adopted by the European Commission (Art. 46(2)(c) GDPR), supplemented by additional technical and organisational measures where necessary;

(c) Binding Corporate Rules where applicable (Art. 47 GDPR).

You may request a copy of the relevant safeguards by contacting our DPO.


VIII. Your Rights

Under the GDPR, you have the following rights with respect to your personal data. You may exercise these rights at any time by contacting us at [email protected]:

Right of Access (Art. 15): Obtain confirmation of whether we process your data and request a copy.

Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.

Right to Erasure (Art. 17): Request deletion of your data where it is no longer necessary for its original purpose.

Right to Restriction (Art. 18): Request restriction of processing in certain circumstances.

Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.

Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.

Right Regarding Automated Decision-Making (Art. 22): Not be subject to decisions based solely on automated processing that produce legal effects.

Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

We will respond to all valid requests within one (1) month, with possible extension of up to two additional months for complex requests.


IX. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of all data in transit (TLS 1.3) and at rest (AES-256)
  • Zero-data-retention architecture for prompt and response content
  • SOC 2 Type II certified infrastructure
  • Regular security audits and penetration testing
  • Role-based access controls and multi-factor authentication
  • Immutable audit logging for all administrative operations

For a detailed overview of our security practices, please visit our Security page.


X. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of the breach (Art. 33 GDPR). Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay (Art. 34 GDPR).


XI. Children's Privacy

Our Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us at [email protected] and we will promptly delete it.


XII. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least thirty (30) days in advance via email or in-service notification. Your continued use of Our Service after the changes take effect constitutes acceptance of the updated policy.


XIII. Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).


XIV. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Privacy Inquiries

Email: [email protected]

Data Protection Officer

Email: [email protected]

General Support

Email: [email protected]

Website: https://meridianblue.ai

Meridian Blue Meridian Blue

One unified API to access every leading AI model

Product

Documentation Pricing

Company

Blog

Legal

Privacy Terms Security

© 2026 Meridian Blue OÜ. All rights reserved.

You're almost in.

Demand has been overwhelming — we've had over 3,000 developers sign up this month. Join the waitlist and we'll get you access as soon as possible.

We'll only email you when your spot is ready.

You're on the list!

We'll reach out to as soon as your spot opens up.

We use cookies to understand how you use our site and improve your experience. Analytics cookies (_ga, _gid) are only set with your consent. Essential cookies required for the site to function do not require consent. Privacy Policy

Cookie Preferences

Essential Cookies

Required for the website to function. These cannot be disabled.

Always Active
CookiePurposeDuration
mb_cookie_consentStores your cookie preference1 year

Analytics Cookies

Help us understand how visitors interact with our site using Google Analytics. All data is anonymized.

CookiePurposeDuration
_gaDistinguishes unique visitors2 years
_gidDistinguishes unique visitors24 hours
_ga_*Maintains session state2 years