Start now

Privacy Policy

Last updated September 17, 2026

1. Introduction

Meridian (meridian.surf) is a trade name of Surf Online, eenmanszaak, registered at Compagnie 13, 6711 VP Ede, Nederland, KvK 42127201; omzetbelastingnummer 527407975B01; BTW-id NL005515281B63 ("we", "us", or "our"). This Privacy Policy explains how we collect, use, store, and share personal data when you use Meridian.

Data controller: Surf Online, eenmanszaak, registered at Compagnie 13, 6711 VP Ede, Nederland, KvK 42127201; omzetbelastingnummer 527407975B01; BTW-id NL005515281B63.

Privacy questions: legal@meridian.surf. Security reports: security@meridian.surf (see section 9).

2. Information we collect

We collect information needed to run Meridian, including:

  • Account data: display name, @handle, email (when provided through linked sign-in), avatar, preferences, plan, and billing status.
  • Linked sign-in data: when you connect a provider, we receive profile fields that provider shares with us (for Discord account sign-in, typically user id, username, avatar, and email via the identify and email scopes).
  • Bot configurations: flows, settings, logs metadata, and content you create in the builder.
  • Bot-stored data: values your bots persist (for example Storage variables), optional transcripts, and short-lived interactive message variables.
  • Protected transcript access: if a transcript requires Discord role verification, we may request identify, guilds, and guilds.members.read in a separate OAuth flow to confirm access.
  • Payment data: billing contact and subscription metadata processed by Stripe. We do not store full card numbers.
  • Platform analytics: first-party operational metrics such as bot online counts, commands created, commands run, and button clicks. We do not use third-party advertising analytics on the dashboard.
  • Support and email: messages you send to us and transactional emails we send to you.

3. Controller and processor roles

For your Meridian account and platform operation, Surf Online is the data controller.

For personal data your bots collect from Discord users (messages, member identifiers, stored variables, transcripts, and similar), you are the controller and Surf Online acts as a processor hosting that data on your instructions through the Service. You must provide any notices and obtain any consents required by law for your bots.

Third-party applications you authorize through Meridian OAuth are independent controllers. We are not responsible for their processing. See our Developer terms.

4. How we use information

We use personal data to:

  • Provide, host, and secure the Service.
  • Run your bots and store configurations.
  • Process payments, wallet balance, and gift cards.
  • Send transactional and support messages.
  • Monitor platform health and aggregate usage trends.
  • Detect abuse, fraud, and technical issues.
  • Comply with law and enforce our policies.

Legal bases (GDPR Article 6)

Where the GDPR applies, we process personal data on the following bases. More than one basis may apply to the same processing activity.

PurposeTypical dataLegal basis
Create and manage your Meridian account; provide dashboard, builder, and hostingAccount data, linked sign-in profile, bot configurationsContract — Art. 6(1)(b) (performance of our contract with you)
Run your bots and store configurations / Storage / transcripts on your instructionsBot configurations, bot-stored data, tokens needed to run botsContract — Art. 6(1)(b); where we act as processor for Discord end-user data, we process under your instructions (see section 3 and our DPA)
Process payments, subscriptions, wallet balance, and gift cardsBilling contact, Stripe metadata, wallet/gift-card ledger fieldsContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) where tax/accounting retention applies
Send transactional and support messages (account, billing, security, service notices)Email, support thread contentContract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) for essential service communications
Monitor platform health and aggregate usage trends (operational metrics that are strictly necessary)Aggregated/operational metrics (e.g. bot online counts)Legitimate interests — Art. 6(1)(f) (keeping the Service reliable and performant)
Product analytics (PostHog usage events, page views, signed-in user id) — only after consentAnalytics events as described in section 10Consent — Art. 6(1)(a); you may withdraw at any time (see sections 10 and 11)
Affiliate / referral attribution (__affiliate_ref) — only after consentReferral cookie and related attribution metadataConsent — Art. 6(1)(a)
Detect abuse, fraud, security incidents, and enforce our Terms / AUPAccount metadata, logs, security signalsLegitimate interests — Art. 6(1)(f) (protecting users, Discord communities, and the Service); legal obligation — Art. 6(1)(c) where applicable
Comply with law, respond to lawful requests, establish/exercise/defend legal claimsRelevant account, billing, and log dataLegal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f)

Legitimate interests. Where we rely on Art. 6(1)(f), our interests are operating a secure, reliable Discord-bot hosting platform, preventing abuse and fraud, and improving core reliability. We balance these against your rights and expectations; you may object under section 11 where the GDPR allows.

Consent. Where we rely on consent (non-essential analytics and affiliate attribution), refusing or withdrawing consent does not affect access to core Meridian features that do not depend on that processing.

We do not sell personal data.

5. Sharing and disclosure

We share data only when needed to operate Meridian:

  • Subprocessors listed in section 6 who host or process data for us.
  • Discord and other platforms your bots connect to, under their policies.
  • Legal requests when required by law or to protect rights and safety.
  • Business transfers in a merger, acquisition, or asset sale, with notice where required.

6. Subprocessors

We use the following subprocessors to deliver Meridian. Each processes only the data needed for its role:

SubprocessorPurposeLocationData processed
ConvexBackend, database, file storage, and real-time APIUnited StatesAccount data, bot configurations, variable definitions and stored values, transcripts, platform logs
VercelFrontend hosting and edge deliveryGlobalHTTP request metadata, session cookies
DiscordAuthentication and bot APIUnited StatesOAuth profile fields, bot runtime data
RailwayBot runtime hosting for all bots on the platformUnited StatesBot tokens, runtime state, Discord gateway traffic, execution logs
StripePayment processing and subscriptionsUnited StatesBilling contact, payment method metadata (not full card numbers)
CloudflareCDN, edge, and runner trafficGlobalHTTP metadata, cached assets
ResendTransactional emailUnited StatesEmail address, message content for service emails
PostHogAnalyticsEuropean UnionUsage events, page views, and user id when signed in

We may update this list as our infrastructure changes. Material changes will be communicated according to our Terms of Service.

7. International transfers

We are established in the European Union. Some subprocessors process personal data in the United States or other countries outside the EEA/UK (see the location column in section 6), including Convex, Railway, Stripe, Resend, Discord, and others as listed.

Where personal data is transferred from the EEA (or UK) to a country without an adequacy decision, we use appropriate safeguards, including:

  1. EU Standard Contractual Clauses (SCCs) adopted by European Commission Decision 2021/914, using the module(s) that match the transfer role (typically Module 2 controller→processor for our own vendor contracts, and Module 3 processor→processor where we are processor and the vendor is our subprocessor — exact modules per vendor as set out in our contracts). UK transfers use the UK International Data Transfer Addendum / UK IDTA where required.
  2. EU–US Data Privacy Framework (DPF) (and UK Extension where applicable), where a vendor is certified and the framework is a valid transfer tool for that flow. We will note DPF participation for certified vendors on request or in an updated subprocessor notice.
  3. Supplementary measures as appropriate, including encryption in transit and at rest, access controls, and contractual security commitments.

Copies of transfer safeguards. Relevant SCC sets and transfer details for our subprocessors are available on request at legal@meridian.surf. Our Data Processing Agreement addresses transfers of Customer Content we process as a processor.

If the transfer tool for a vendor changes (for example, DPF certification status), we will update our records and this policy or the subprocessor notice as needed.

8. Data retention

We keep account data while your account is active. When you request deletion from Account → Danger zone, we delete personal data and bot configurations within 7 days after the grace period, unless a longer period is required by law.

If we terminate your account for abuse or legal reasons, we may retain relevant data for investigations, dispute resolution, or legal hold.

Short-lived data (for example interactive message variables) expires automatically on a shorter schedule.

9. Security and vulnerability reports

We use technical and organizational measures to protect data. No method of transmission or storage is completely secure.

Reporting bugs. Sensitive issues (authentication, sessions, billing, account takeover, or exposure of private user or bot data) should be reported through our help center while signed in. Do not post exploit steps, tokens, or customer data in public channels.

General UI bugs and feature requests may be shared in our Discord server.

Do not run bulk scans, credential stuffing, or denial-of-service tests against production. If you accidentally access data you should not have, stop and report it.

Contact: security@meridian.surf. Qualifying security reports may receive a bounty or account credit at our discretion. Nothing here is a binding offer.

10. Cookies and similar technologies

Surf Online uses cookies and similar technologies on Meridian (meridian.surf) to operate the Service, keep you signed in, remember preferences, and — only with your consent — measure product usage and attribute referrals.

Cookies are small text files stored on your device. We also use local storage and session storage for similar purposes.

Strictly necessary cookies. These are required for Meridian to work and do not require consent:

  • __session: short-lived access token (httpOnly) for authenticated requests.
  • __refresh: refresh token (httpOnly, limited path) to renew your session.
  • __session_handle: identifies your Convex session for real-time dashboard features.

Blocking these cookies may prevent you from signing in or using the dashboard.

Functional preferences (non-tracking). We may store preferences such as theme, builder settings, and UI state locally to improve your experience. These preference stores are not used for advertising.

Marketing / attribution — consent required. Affiliate referrals use a signed __affiliate_ref cookie (30-day attribution window) when you arrive through a referral link. This cookie is not strictly necessary. We set or read it for attribution only after you consent via our cookie banner (or equivalent preference center). You can withdraw consent at any time under Account → Privacy & security or the banner preferences.

Analytics — consent required. Meridian uses first-party product analytics (PostHog, proxied at /ingest) to measure performance and improve the UI. Analytics scripts and non-essential analytics cookies/events load only after you consent.

  • We do not run product analytics by default.
  • Rejecting analytics is as easy as accepting; choices are not pre-ticked.
  • You can change your mind anytime from the site notice or Account → Privacy & security.
  • We do not use third-party advertising cookies on the dashboard, and we do not sell cookie data.

Global Privacy Control and Do Not Track. If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of product analytics (and we will not set analytics until you later give affirmative consent through our banner, if we offer that override). We also respect an explicit analytics opt-out stored in your Meridian account preferences. We may still use strictly necessary cookies to operate the Service.

Your choices. Most browsers let you block or delete cookies. Essential cookies are required for core features. For analytics and affiliate attribution, use our cookie banner or Account → Privacy & security. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

11. Your rights and choices

Depending on where you live (including the EEA, UK, and California), you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.

You can:

  • Download a data export from Account → Privacy (data takeout).
  • Request account deletion from Account → Danger zone.
  • Contact us at legal@meridian.surf or through support for other requests.

You can grant or withdraw consent for product analytics and affiliate attribution from the site cookie banner or under Account → Privacy & security. Where we rely on consent, withdrawing it does not affect prior lawful processing. You may also lodge a complaint with your local supervisory authority.

12. Third-party services

Meridian integrates with Discord and other services. Data processed by those platforms is governed by their policies. Review their privacy terms before connecting your bots or accounts.

13. Children's privacy and age eligibility

Meridian accounts are intended for users who are at least 16 years old, or older if the age of digital consent (or contractual capacity) in your country is higher. In the Netherlands and elsewhere in the EEA where GDPR Article 8 applies with a national age of 16, we do not knowingly offer Meridian accounts to children under 16.

We do not knowingly collect personal data from anyone under 16 in the EEA/UK in connection with a Meridian account. If you believe a minor under this age provided us account data, contact legal@meridian.surf and we will delete it.

Discord end-users. Servers and bots you operate may include younger Discord users. You (as controller of bot end-user data — see section 3) are responsible for any notices, consents, or age-appropriate design required for your bots. Meridian does not verify the ages of Discord members who interact with your bots.

We additionally do not knowingly collect personal information from children under 13 as defined under COPPA. The EEA/NL eligibility line of 16+ remains the primary rule for Meridian accounts.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the last updated date. Continued use after changes means you accept the updated policy where permitted by law.

15. Contact

Privacy questions: legal@meridian.surf or our official support channels.

Data controller: Surf Online, eenmanszaak, registered at Compagnie 13, 6711 VP Ede, Nederland, KvK 42127201; omzetbelastingnummer 527407975B01; BTW-id NL005515281B63.