Start now

Citrum Privacy Policy

Last updated July 31, 2026

1. Introduction

This Privacy Policy explains how Surf Online ("we", "us", or "our") collects, uses, stores, and processes personal data when you visit Citrum marketing pages (citrum.cc) or sign in to a hosted panel on citrum.app.

Citrum is a hosted dashboard product of Surf Online. Surf Online operates under the trade names Meridian and Meridian.surf, and is registered with the Dutch Chamber of Commerce (KvK) under number 42127201. Data controller: Surf Online (KvK 42127201).

2. Data We Collect

When you interact with Citrum, we may collect the following information:

  • Discord Profile Information: Authorized through Discord OAuth (identify scope). This includes your unique Discord user ID, username, and avatar image.
  • Guild List: Authorized through Discord OAuth (guilds scope). This includes the list of Discord servers you are a member of, which is used solely to identify and display the panels you have permissions to manage.
  • Session Cookies: Technical cookie tokens needed to authenticate and maintain your signed-in session.
  • Technical Request Metadata: IP addresses, browser user agent strings, HTTP headers, and transaction timestamps collected for service delivery, logging, and security.

3. Controller and Processor Roles

For your Citrum authenticated session and platform-level infrastructure logs,Surf Online acts as the data controller.

For the specific content, variables, command metrics, and user interactions shown or processed within a bot panel, the bot owner is the data controller, and Surf Online acts as a data processor hosting that data on the bot owner's behalf. Bot owners are responsible for providing appropriate privacy notices and securing lawful bases under GDPR or other applicable data protection laws.

4. How We Use Data

We process your personal data for the following purposes:

  • To authenticate your identity and authorize panel access.
  • To display the correct, customized panels matching the Discord servers you manage.
  • To monitor system health, audit logs, and maintain service security.
  • To prevent DDoS attacks, fraud, and session hijacking.
  • To comply with our legal obligations and enforce our terms.

We do not sell Citrum visitor or session data.

5. Sharing and Disclosure

We do not share your personal data with third parties except with our hosting and infrastructure subprocessors listed in Section 6, when required by law or judicial request to defend our rights, or in connection with a corporate reorganization, merger, or asset sale.

6. Subprocessors

We use the following subprocessors to host, deliver, and secure Citrum. Each processes only the technical categories of data necessary for their respective service:

SubprocessorPurposeLocationData processed
ConvexBackend, database, file storage, and real-time APIUnited StatesAccount data, bot configurations, variable definitions and stored values, transcripts, platform logs
VercelFrontend hosting and edge deliveryGlobalHTTP request metadata, session cookies
DiscordAuthentication and bot APIUnited StatesOAuth profile fields, bot runtime data
CloudflareCDN, edge, and runner trafficGlobalHTTP metadata, cached assets

7. Data Retention

We retain your session data only as long as necessary to keep you authenticated. Session cookies and access tokens are short-lived. Discord OAuth profile data is cached temporarily and refreshed upon re-authentication.

Technical logs (containing IP addresses and browser metadata) are retained for a maximum of 30 days for security diagnostics and abuse prevention, after which they are deleted or anonymized, unless a legal hold or active investigation requires longer storage.

8. Cookies and Similar Technologies

Citrum uses cookies to operate the dashboard and keep you signed in. We also utilize browser local storage and session storage for UI configuration preferences.

Strictly Necessary Cookies:

  • __session: A short-lived, httpOnly access token used to verify your identity on API requests.
  • __refresh: A secure, httpOnly refresh token restricted to the auth paths, used to refresh your active login token.
  • __session_handle: A non-httpOnly cookie storing your Convex session identifier to enable live database subscription flows.

You can configure your browser to block or delete these cookies, but doing so will prevent you from signing in or viewing panel content.

9. Your Rights

Depending on your location, you may have rights under the GDPR or other regional regulations to request access to, correction of, or deletion of your personal data, or to restrict or object to processing. To exercise these rights, please contact legal@meridian.surf. For developers with a Meridian account, please refer to the main Meridian Privacy Policy for further options.

10. Security and Vulnerability Reporting

We employ technical and organizational safeguards designed to protect personal data. If you discover a potential vulnerability or security issue affecting Citrum (such as session leakage or unauthorized panel access), please report it to us immediately at security@meridian.surf. Do not exploit the vulnerability or share it publicly.

11. Changes to Policy

We may update this Privacy Policy from time to time to align with changes in our data practices or legal requirements. The latest update date will be updated in our policies center. Continued use of the Service after an update indicates your acknowledgement of the revised policy.

12. Contact

Surf Online operates under the trade names Meridian and Meridian.surf, and is registered with the Dutch Chamber of Commerce (KvK) under number 42127201.

For privacy-related inquiries, please email legal@meridian.surf.