Last updated: May 2026
Privacy Policy
Meridian is software for tutoring centers. We process data about your leads, parents, and students on your behalf. This document explains exactly what we collect, how we use it, and what rights you have.
What data we store
When you use Meridian, we store the information you enter: lead contact details (name, email, phone), student records, tutor profiles, appointment schedules, payment records, and communications logs. We also store your account information (email, hashed password, organization name) and basic usage metadata (login timestamps, API request logs).
We do not store biometric data, government IDs, financial account numbers, or any data not directly entered through Meridian's interface.
FERPA compliance
Meridian is designed for use with student records in the context of private tutoring centers. Private tutoring centers are not typically subject to FERPA as "educational institutions" under the statute, but we apply FERPA-equivalent data handling practices as a matter of principle:
• Student records are accessible only to authenticated users within your organization
• Data is never sold or shared with third parties for advertising or profiling purposes
• You can request deletion of all student data at any time by contacting support
• Data is logically isolated per organization using Row Level Security (RLS) at the database layer — one organization's data is structurally inaccessible to another
If your center has specific FERPA obligations (e.g., you receive federal funding), contact us through the site for a data processing agreement.
How we use your data
We use the data you store in Meridian to:
• Render your dashboard, lead list, inbox, and reports
• Generate AI reply drafts via Google Gemini (your org's name, voice config, and the inbound message are sent to Gemini — no student PII beyond the inquiry content)
• Send email notifications to you via Resend (when enabled)
• Send the weekly summary email (when enabled)
We do not use your data to train AI models. We do not sell, rent, or share your data with third parties except as required to provide the service (Supabase for storage, Gemini for AI drafts, Resend for email).
Data isolation and security
Each organization's data is isolated at the database level using Supabase Row Level Security (RLS). Every table carries an org_id column. RLS policies enforce that all queries — even if your authentication token is compromised — are restricted to your organization's rows.
Passwords are hashed by Supabase Auth (bcrypt). API keys and service credentials are stored as environment variables and never exposed to the browser. Database connections use TLS. Backups are encrypted at rest.
Your rights
You can:
• Export your data at any time by contacting us through the site
• Request deletion of all data within 30 days of cancellation
• Update or correct any information directly through the Meridian interface
• Opt out of email notifications in Settings → General → Notifications
If you are a parent or student whose information was entered by a tutoring center using Meridian, contact that center directly — they are the data controller. You may also contact us through the site and we will facilitate your request.
Data retention
Active account data is retained as long as your subscription is active. After cancellation, data is retained for 30 days to allow for reactivation, then deleted. Backups are retained for 90 days.
You can request immediate deletion by contacting us through the site.
Contact
Questions about this policy, data deletion requests, exports, or FERPA data processing agreements: reach out through the contact form on the homepage.
Meridian Operations Co. · Brooklyn, NY